Gulf Cooperation Council
External attack surface management for UAE organisations
UAE regulators expect organisations to know the digital assets behind every critical service, and to keep their boards informed about exposure. The Cyber Security Council’s CIIP Policy asks CII entities to identify those assets and analyse their vulnerability exposure, and the Central Bank’s new Operational Risk Management Regulation took effect on 14 September 2026. EASMLens gives you the external view both assume.
Serving organisations in Dubai, Abu Dhabi, Sharjah.
What the rules in United Arab Emirates expect
Critical Information Infrastructure Protection Policy
The Cyber Security Council’s CIIP Policy, version 1.0 of May 2023, applies to CII entities across energy, transport, financial services, health, digital infrastructure (including DNS, cloud and data centre providers), government and more. Clause 2.2.2.1 requires entities to identify the components of each critical service, including information systems, digital assets and networks. Clause 2.2.2.3 requires them to analyse threats and vulnerability exposure for those components.
The policy keeps the entity accountable when third parties deliver a service and encourages technical security assessments of suppliers. A 2024 national report found around 155,000 remotely accessible UAE assets vulnerable through misconfiguration, and the Council warned in April 2026 that a large share of publicly accessible files contain sensitive personal data.
CBUAE Operational Risk Management Regulation
The Central Bank’s Operational Risk Management Regulation, C 1/2026, applies to all licensed financial institutions from 14 September 2026. It requires boards and senior management to be informed regularly of ICT and cyber risk exposures (Article 8.4), actionable intelligence for situational awareness of vulnerabilities (8.7.3), proactive management of systems run by third-party providers and of obsolete systems (8.8), and a register and ongoing monitoring of third-party arrangements that support critical operations (13.9).
Free zones and Dubai
In ADGM, the FSRA’s Cyber Risk Management Framework has applied to authorised persons since 31 January 2026. The DIFC and ADGM run their own data protection regimes. Dubai government entities follow DESC’s Information Security Regulation, which DESC issues on request rather than publishing. The federal UAE Information Assurance Standard is not publicly available, so we do not quote its controls.
What each rule asks for, and what EASMLens shows you
| Rule | What it asks for | What EASMLens shows you |
|---|---|---|
| CIIP Policy 2.2.2.1 | Identify the digital assets behind each critical service | The internet-facing assets and services attributed to your organisation |
| CIIP Policy 2.2.2.3 | Analyse threats and vulnerability exposure | Exposed services with known vulnerabilities, prioritised by exposure |
| CIIP Policy 2.1.5 | Stay accountable for third parties; assess suppliers | Supplier exposure under your domains and brand |
| CBUAE C 1/2026 Art 8.4, 8.8 | Inform the board of exposures; manage third-party and obsolete systems | Board-ready exposure trends, including end-of-life software on the internet |
Reporting clocks
CBUAE licensed financial institutions
4 hours for significant events affecting critical operations, summary within 24 hours; 72 hours for high-risk incidents
ADGM Data Protection Regulations
Without undue delay and where feasible within 72 hours
Federal PDPL
Period to be set by Executive Regulations not yet issued
Questions for the board
- 1If we are designated CII, could we show the Council the digital assets behind each critical service, including cloud and supplier-hosted systems?
- 2For licensed financial institutions: which internet-facing weaknesses reached the board this quarter under Article 8.4, and could we meet the 4-hour clock?
- 3Which of our suppliers and cloud providers expose our data or brand on the internet, and does our third-party register show it?
How EASMLens supports these obligations
- Continuous discovery of the digital assets behind your critical services
- Exposure intelligence on known vulnerabilities, end-of-life software and exposed file shares
- Third-party exposure monitoring to support CIIP and CBUAE third-party duties
- Email domain security grading to reduce impersonation of your brand
EASMLens discovers your attack surface from DNS, certificate transparency, internet-wide scan datasets and public records, then runs non-destructive checks against the assets in your scope. It never attempts exploitation. It provides discovery, monitoring and evidence. It does not certify an organisation against any framework, and no product can.
Frequently asked questions
- Is there a fixed breach notification deadline under the federal PDPL?
- Not yet. The PDPL leaves the period to Executive Regulations, which had not been issued at the time of writing. ADGM, the DIFC and sector regulators have their own rules.
- Do you quote the UAE Information Assurance Standard?
- No. Its control text is not publicly available, so we describe it rather than quoting control numbers that cannot be checked.
- Can data stay in the UAE?
- Tell us the obligation you are working to and we will confirm what we can commit to contractually.
Related guides
Primary sources
- CIIP Policy v1.0 (UAE Cyber Security Council)
- CBUAE Operational Risk Management Regulation C 1/2026
- ADGM FSRA Cyber Risk Management Framework
- National Cyber Accreditation Program (u.ae)
Regulatory content reviewed on . General information only, not legal advice.