IT audit in Dubai: three different things get sold under one name, and buying the wrong one is expensive.
An assessment against a framework, a technical penetration test, and a formal certification are three separate pieces of work with different costs, different durations and different outputs. Buyers routinely ask for one and are sold another, then discover at the deadline that what they hold does not answer the question they were asked. We start by establishing which of the three you actually need, and reasonably often the honest answer is a narrower and cheaper piece of work than the one being proposed elsewhere.

- Scope firstBefore anyone quotes
- In-houseTesting, not subcontracted
- RetestIncluded, closure evidenced
- OngoingEvidence kept current
Six audit disciplines, and the difference between them.
Framework gap assessment
A structured review of your current state against a named framework, whether ISO 27001, NIST CSF, CIS Controls, DESC ISR or a sector regulation. The output is a gap register with severity, effort and a named owner per gap, plus a costed remediation plan. This is what you need when somebody has told you to comply with something and you do not yet know how far away you are.
Technical testing
Penetration testing and vulnerability assessment against your actual systems. This finds exploitable weaknesses rather than missing documentation, and it answers a completely different question from a framework assessment. Both are often required and they are not substitutes for one another, which is the confusion we most frequently unpick.
Access and privilege review
Who has access to what, who granted it, whether it is still needed, and who signed off the review. The most common finding across every audit we run is access nobody can justify: dormant accounts, standing administrative rights, forgotten guests, and service accounts with more privilege than the task requires.
Cloud and tenant posture review
Microsoft 365 and Azure configuration against benchmark, covering identity, conditional access, data protection, logging and retention. Cloud misconfiguration is now a larger practical exposure than unpatched servers for most UAE mid-market businesses, and it is the area least often audited.
Operational resilience review
Backup verified by an actual restore rather than a green job report, disaster recovery tested against stated objectives, and business continuity arrangements exercised rather than documented. Restore testing is the most commonly faked control in UAE IT, and it is trivially easy to verify.
Evidence production and audit support
Assembling the pack an assessor, bank, insurer or enterprise customer will ask for, and sitting with you through the questions. The distinction that matters is between evidence a control exists and evidence it operated over a period, and it is the second one that assessors want.
Find the engagement you actually need.
Someone has asked us for evidence
A bank running enhanced due diligence, an enterprise customer with a supplier assessment, an insurer at renewal, or an investor in diligence. Usually the most urgent trigger and usually with a deadline attached.
- Cybersecurity audit and compliancePosture assessment and the evidence pack that answers supplier questionnaires and bank reviews.
- Microsoft 365 reporting and auditingAudit log retention, access recertification evidence, and the reports regulated firms are actually asked for.
- Compliance ManagerControl mapping and improvement scoring against the frameworks that apply to you.
A UAE regulator applies to us
Sector supervision drives the scope and the cadence. Getting the applicability right is the single most valuable early step, because over-scoping wastes a year of budget and under-scoping produces a finding.
- DESC ISR complianceDubai Information Security Regulation for government entities, critical providers and their suppliers.
- NESA and UAE IA complianceThe federal Information Assurance Standards regime for critical national infrastructure.
- DFSA IT complianceIT and cyber obligations for DIFC-licensed financial firms.
- ADGM IT complianceFSRA-aligned controls and evidence for Abu Dhabi Global Market entities.
- DIFC Data Protection LawData protection obligations specific to the DIFC free zone.
- UAE PDPL complianceFederal Decree-Law 45 of 2021 readiness and the operational controls behind it.
We need something tested, not reviewed
A framework assessment tells you whether a control exists. A test tells you whether it holds. Regulated firms usually need both, on a cadence.
- VAPT testing DubaiCombined vulnerability assessment and penetration testing, with a retest letter confirming closure.
- Penetration testing DubaiFocused offensive testing against external services, internal networks or applications.
- Vulnerability assessment UAEScanning and prioritised remediation on the cadence your regulator expects.
The underlying controls we assess
An audit finding is only useful if somebody can close it. These are the practice areas we remediate against, which is why our audits do not end at the report.
- Microsoft EntraIdentity, conditional access and privileged access, where most access findings are closed.
- Microsoft security DubaiThe wider Microsoft security stack and what your existing licence already covers.
- Microsoft PurviewClassification, data loss prevention and retention, which underpin most data-handling findings.
- Veeam backup DubaiImmutable backup and evidenced restore testing, the most commonly faked control in UAE IT.
- SOC as a service DubaiMonitoring and response, which most frameworks expect and few mid-market firms staff.
- Incident response DubaiThe plan assessors ask to see, and the exercise record proving it has been rehearsed.
Four things that shape our engagements.
We scope you down when the evidence supports it
The applicability review comes first and it regularly concludes that a narrower obligation applies than the client had been told. That reduces the engagement we could have sold. Over-scoping compliance is a genuine and expensive problem in this market, usually because the vendor scoped the work rather than the regulation.
Testing is ours, so the cadence holds
Vulnerability assessment and penetration testing are delivered in-house rather than subcontracted. When testing is a regulatory cadence rather than a one-off, a missed quarter is a finding regardless of whose diary caused it, and coordinating through a third party introduces delay you do not control.
We close findings, not just list them
The common failure is an excellent report handed over by a consultancy who then leaves. Twelve months later the same findings recur because nobody had the remit or the skills to fix them. We can both identify and remediate, which is why the finding count falls between assessments rather than staying constant.
Evidence maintained continuously
Compliance is an operating state rather than a project. Testing calendars, access reviews, restore tests and policy reviews run on a rhythm and the pack stays current, so a request becomes an export rather than a fortnight of archaeology.
Six situations that bring UAE businesses to us.
Bank enhanced due diligence
A banking partner asks for evidence of IT controls as part of a review, usually with a short deadline and no guidance on format. Among the most common triggers we see.
Enterprise customer supplier assessment
A large client sends a security questionnaire and makes the contract conditional on the answers. Frequently the first time a growing business discovers what it cannot evidence.
Tender requiring a framework
A public or corporate tender names ISO 27001 or DESC ISR alignment. The realistic answer is often a documented position with a dated plan rather than full compliance by the deadline.
Cyber insurance renewal
Insurers now ask specific, verifiable questions about MFA coverage, privileged access, EDR and backup immutability, and price on the answers.
After an incident
Something happened, and the board wants independent assurance about what else is exposed. The scope here is usually broader and the timeline shorter.
Investor or acquirer diligence
IT and security diligence during a transaction, where an inability to evidence controls affects valuation rather than merely causing inconvenience.
Assessment, test, or certification: which do you actually need?
| Gap assessment | Technical test | Formal certification | ||
|---|---|---|---|---|
| Answers the question | How far are we from the standard | Can this actually be broken into | Can we prove it to a third party | |
| Typical trigger | A regulator or contract names a framework | A regulator sets a testing cadence, or a customer asks | A customer or tender requires the certificate | |
| Output | Gap register and costed remediation plan | Findings by severity, plus a retest letter | Certificate from an accredited body | |
| Typical duration | 2 to 4 weeks | 1 to 3 weeks per scope | 6 to 12 months including remediation | |
| Who performs it | Us | Us, in-house | An accredited certification body, we prepare you | |
| Repeats | Annually or on major change | On the cadence your regime sets | Surveillance audits, then recertification | |
| Common mistake | Buying this when a test was asked for | Buying the cheapest scope and presenting it as comprehensive | Starting this before the gap assessment |
Four steps, and the first one changes the price.
- 1
Applicability and scoping
Week 1
What has actually been asked of you, by whom, in what words, and by when. Which framework genuinely applies at your classification, and what you already hold that transfers. Output is a written applicability statement, and it frequently shrinks the engagement.
- 2
Assessment or testing
Weeks 2 to 4
Evidence gathered directly rather than a questionnaire filled in by the client, because self-assessment produces the answers people believe rather than the ones that are true. For technical scopes, testing against the agreed boundary with findings ranked by exploitability and impact.
- 3
Remediation
Weeks 3 to 12
Findings closed in severity order with a named owner each, and a retest confirming closure rather than a claim of it. Where a finding will not be closed, it gets a documented risk acceptance signed at the right level, which assessors accept and silence they do not.
- 4
Evidence pack and ongoing rhythm
Ongoing
The pack assembled, validated against what the requester actually asked for, and then maintained: testing calendar diarised, access reviews scheduled, restore tests evidenced, policies reviewed annually. The transition from project to operating state is where most programmes quietly fail.
“Our bank gave us three weeks to evidence our IT controls and two firms quoted us for a nine-month ISO 27001 programme, which was not what the bank had asked for. GR read the actual request, told us it was a control questionnaire rather than a certification requirement, ran a two-week assessment, closed the critical items and produced the pack. The bank accepted it. The difference was that somebody read the question first.”
What UAE businesses ask before commissioning an audit.
Twelve questions to settle before an audit is quoted.
What are you actually being asked for
- Who is asking, and can you show us their exact wording?The clause matters. "Security assessment" means different things to a bank and a regulator.
- Is a named framework specified, or is it open?A named framework sets the scope. Open wording usually means less work than feared.
- Is there a deadline, and is it real?It changes sequencing entirely. We will tell you honestly if it is not achievable.
- Do they want an assessment, a test, or a certificate?Three different engagements. Ask them directly rather than guessing.
What do you already have
- Do you hold any current certification?ISO 27001 often transfers a substantial proportion of the work to another framework.
- When was the last technical test, and were findings closed?A report with open findings evidences the opposite of what you need.
- Can you produce access review evidence for the last quarter?Not a user list. Evidence somebody reviewed and signed it off.
- Has a backup restore been performed and documented?The single easiest control to verify and the most commonly assumed.
What happens after the report
- Who will close the findings?An audit that produces findings nobody can action is an expensive document.
- Is a retest included, or quoted separately?Closure evidence is usually what the requester actually wants.
- Will the evidence be maintained, or rebuilt next year?Continuous is cheaper than annual reconstruction, and always current.
- Does the same provider assess and remediate, and is that a conflict?Fair question. Ask it of us too, and see the answer in the FAQ below.
The three pages most audit buyers read next.
VAPT testing Dubai
Testing delivered in-house with a retest letter confirming closure, which is what requesters usually want.
DESC ISR compliance
The Dubai regulation, including scoping, its testing cadence, and what suppliers rather than entities must do.
Microsoft security Dubai
Where most audit findings actually get closed, and what your existing licence already covers.
Send us the exact wording of what you have been asked for.
The clause, the questionnaire, or the tender requirement. We will tell you in writing which of the three engagements it actually calls for, what you already hold that transfers, and what a realistic timeline looks like. If the answer is smaller than you were quoted elsewhere, that is what we will say.
Related Services
Explore more solutions that work great with this service
Cybersecurity Audit
Security assessment and compliance audit
VAPT Testing
CREST-certified vulnerability assessment and penetration testing
DESC ISR Compliance
Dubai Information Security Regulation, scoping to evidence
NESA / IA Compliance
UAE Information Assurance Standards compliance
Microsoft Security Dubai
Entra, Defender, Purview, Sentinel, and what you already own
M365 Reporting & Auditing
Tenant reporting, audit logs, and usage analytics
Penetration Testing
Black, grey, and white-box penetration testing
UAE PDPL Compliance
Federal Decree-Law 45 of 2021 readiness and operations