Insights · DFSA and DIFC

DFSA cyber and IT requirements: what DIFC firms need to evidence

A plain-English guide to the DFSA’s cyber risk management rules (GEN 5.5), its outsourcing expectations (GEN 5.3.21) and the evidence a DIFC firm should be able to show.
The short answer

If the DFSA authorises your firm, you must maintain a written cyber risk management framework approved by your governing body, oversee any IT provider you rely on, and report material cyber incidents to the DFSA within 72 hours at the latest. The rules are proportionate and outcome-based, so the test is whether you can show your controls fit your business and actually work. Outsourcing IT does not outsource responsibility.

Key points
  • Technology and cyber expectations for DIFC firms sit mainly in GEN 5.5 (cyber risk management) and GEN 5.3.21 (outsourcing) of the DFSA Rulebook.
  • A written cyber risk management framework, approved by your governing body and reviewed annually, is the foundation.
  • Material cyber incidents must be reported to the DFSA as soon as reasonably practicable and within 72 hours at the latest.
  • Using a managed service provider does not transfer accountability: you must choose it carefully and supervise it.
  • Evidence matters as much as controls. Keep it where you can find it in minutes.

Which DFSA rules cover IT and cyber security

There is no single IT rulebook. For a firm authorised by the Dubai Financial Services Authority (DFSA), the technology and cyber expectations sit in a few places in the General (GEN) module of the DFSA Rulebook, and in DIFC data protection law.

  • GEN 5.5, Cyber risk management. The core cyber rules: a written framework, governance, protective controls, monitoring, incident response and reporting.
  • GEN 5.3, Systems and controls, including GEN 5.3.21 on outsourcing. Using a provider does not remove your responsibility.
  • DIFC Data Protection Law (Law No. 5 of 2020), enforced by the DIFC Commissioner of Data Protection. It governs how you protect personal data and report breaches.

The DFSA applies these proportionately. A ten-person advisory firm and a bank are not expected to look the same, but each must be able to show that its approach fits its size, complexity and risk.

What GEN 5.5 expects in practice

The table summarises the main areas and the evidence that tends to satisfy a reviewer. It is a guide for orientation; the Rulebook text is the authority.

AreaWhat the DFSA expectsEvidence worth keeping
Framework and governanceA written cyber risk management framework, approved by your governing body, proportionate to your business and reviewed at least annually. Senior management is accountable for oversight of cyber risk.The approved framework, minutes showing your governing body reviewed it, named owners, a statement of risk tolerance.
Know your assets and risksA current inventory of ICT assets, classified by sensitivity and criticality, and regular cyber risk assessments.Asset register; risk register with owners and treatment decisions.
ProtectControls such as anti-malware, network security, least-privilege access with regular reviews, strong authentication (including multi-factor authentication for internet-facing systems and privileged access), change management, timely patching, encryption proportionate to sensitivity, and staff awareness training.MFA coverage report, patch compliance reports, access review records, configuration baselines, training completion records.
TestRegular resilience testing, with annual testing expected for internet-facing systems, and a process to fix what it finds.Penetration test report; remediation tracker with dates and sign-off.
Detect and respondMonitoring for actual and potential cyber incidents, a written incident response plan that is tested and reviewed, and a process to investigate, contain and recover.Monitoring alerts and reviews, the incident response plan, exercise or test records.
ReportMaterial cyber incidents reported to the DFSA as soon as reasonably practicable, and in any event within 72 hours of becoming aware, using the form on its electronic portal (GEN 5.5.19).Incident log, materiality decision record, copy of the report submitted.

The exact wording, and any change since this guide was reviewed, is in GEN 5.5 in the DFSA Rulebook.

Outsourcing IT does not outsource responsibility

GEN 5.3.21 says that a firm that outsources functions or activities directly related to financial services to a service provider, including one in its own group, is not relieved of its regulatory obligations. It must do due diligence in choosing a suitable provider, supervise the outsourced activity effectively, and deal effectively with any failure by the provider that leads, or might lead, to a breach of DIFC legislation. The guidance describes an arrangement as material where weakness or failure of the service would cast serious doubt on the firm’s continuing ability to remain fit and proper or to comply with DFSA-administered laws and rules.

GEN 5.5 adds specific expectations for third-party ICT service providers: due diligence before you appoint, contract terms covering incident notification and remediation, and effective supervision afterwards. In practice that means a register of your IT and cloud providers, proportionate checks before you sign, and evidence that you review them. Our guide to vendor and outsourcing management covers how to do that.

Cyber incident reporting: the 72-hour clock

GEN 5.5.19 requires a firm to report a material cyber incident to the DFSA as soon as reasonably practicable, and in any event within 72 hours after becoming aware of it or having information that reasonably suggests it has occurred, using the form on the DFSA electronic portal. The Rulebook guidance lists factors for judging materiality, including risk to customer information, data leakage, business disruption, financial loss and the effect on stakeholders. Other reporting may also apply. A personal data breach, for example, may need to be notified to the DIFC Commissioner of Data Protection as soon as practicable.

Decide these things before an incident, not during one:

  • Who decides whether an incident is material, and how quickly they can be reached.
  • Who has access to the DFSA portal, and whether the reporting process has been rehearsed.
  • Which logs, contacts and system details you will need in the first 24 hours.
  • How your IT provider must notify you, in writing in the contract, so that their delay does not use up your 72 hours.

Gaps that tend to surface in reviews

These are patterns that commonly appear when regulated firms test their own controls:

  • Multi-factor authentication with exceptions: legacy protocols, shared mailboxes, service accounts and “temporary” exclusions that became permanent.
  • An incident response plan that exists on paper but has never been exercised.
  • No single register of technology providers, so nobody can say which ones are material.
  • Evidence scattered across individual mailboxes, which turns a simple request into a scramble.
  • Personal or unmanaged devices reaching firm data with no controls.

Most are cheap to fix once you can see them. Our audit readiness checklist shows how to build the evidence pack that exposes them early.

If you are in ADGM instead

The Financial Services Regulatory Authority (FSRA) in Abu Dhabi Global Market has its own Cyber Risk Management Rules, in force since 31 January 2026. They share the same goals but differ in detail, including a 24-hour deadline for notifying material incidents. See our page for ADGM firms and the comparison on our regulated industries page.

Sources and further reading

Last reviewed 19 September 2026. This guide is general information, not legal or regulatory advice. Rules change, so check the current text and take advice from your compliance officer or legal adviser before relying on it.

Written by
CEO, Cre8 IT
Rob Crossley is CEO of Cre8 IT, a Dubai-born managed IT and cyber security company that has supported businesses across the UAE, Saudi Arabia and the UK since 2012. Cre8 IT is certified to ISO 27001:2022 and ISO 9001 and is a certified Microsoft Partner.
FAQ

Frequently asked questions

Does the DFSA require ISO 27001?

No. GEN 5.5 does not require a particular standard; it sets proportionate, outcome-based expectations. ISO 27001 is one recognised way to structure and independently evidence your approach, and many firms use it alongside GEN 5.5. See our ISO 27001 guide.

How quickly must a DFSA-authorised firm report a cyber incident?

As soon as reasonably practicable, and in any event no later than 72 hours after becoming aware of a material cyber incident (or having information that reasonably suggests one has occurred), using the form on the DFSA electronic portal. Whether an incident is material is a judgement based on the factors in the Rulebook guidance, so agree your process and decision-maker in advance.

Can a DIFC firm outsource IT and cyber security to a managed service provider?

Yes, but you remain responsible. Carry out due diligence before you appoint, agree contract terms covering incident notification and remediation, and supervise the provider throughout the relationship. Material arrangements deserve the closest scrutiny.
Related guides

Keep reading

Each guide links to the regulator’s own text and shows when it was last reviewed.
Vendor management

IT vendor and outsourcing management for DFSA and FSRA firms

How to manage IT providers when you are regulated in DIFC or ADGM: a register, tiering, due diligence, contract terms and ongoing oversight.
4 min read · Reviewed 19 September 2026
Audit readiness

IT audit readiness for DIFC and ADGM firms: an evidence-first checklist

How to be ready when a regulator, auditor or client asks for proof of your IT and security controls: the evidence pack, a mock audit and a six-week plan.
3 min read · Reviewed 19 September 2026
ISO 27001

ISO 27001 for financial firms: how it supports DFSA and FSRA expectations

What ISO/IEC 27001:2022 certifies, how its controls map to DFSA and FSRA cyber expectations, and how to read a supplier’s certificate.
4 min read · Reviewed 19 September 2026

Talk to a specialist about your obligations

Tell us about your firm and your regulator, and we will suggest a practical first step, whether that is a gap assessment or ongoing support.