IT support for DMCC companies: built around what your licence category actually obliges you to do.
DMCC is not one kind of business. A gold trader in Almas Tower, a VARA-regulated virtual asset firm in the Crypto Centre, and a five-person consultancy in a serviced office in Cluster W have almost nothing in common technically, and their compliance obligations are completely different. We support all three, from the same Business Bay operations desk twenty minutes up the road, and we scope each one against the licence they actually hold rather than a generic free zone package.

- 24,000+DMCC member companies
- 5 minP1 remote response
- Band 2JLT on-site, within 3 hours
- VARA-awareCrypto Centre obligations
Eight scopes we deliver to companies licensed in DMCC.
Serviced office and flexi-desk reality
Many DMCC members start in a serviced office or flexi-desk where the internet is provided by the building and you have no control over the router, the firewall, or who else is on the network. We design around that: a company-owned firewall behind the landlord connection where the tenancy allows, always-on VPN where it does not, and endpoint-level protection that assumes the network is hostile because it genuinely is.
VARA-regulated virtual asset firms
Crypto Centre members licensed through VARA carry obligations most free zone companies never see: a documented cybersecurity framework, regular penetration testing, quarterly compliance reporting, and annual audit. We deliver the technical half of that, VAPT on a defined cadence, hardened identity, logged privileged access, and evidence packaged for the regulator rather than left in a console.
Commodities and precious metals traders
Gold, diamond, tea and coffee traders run a distinctive stack: trading and inventory systems, high-value document flows, wire instructions moving by email, and AML obligations attached to the goods. The dominant technical risk here is business email compromise on payment instructions, so the controls that matter are mail authentication, impersonation protection, and an out-of-band verification process for payment changes.
Identity as the actual perimeter
With staff moving between towers, working from home, and travelling, there is no meaningful network boundary. Entra ID with conditional access, phishing-resistant MFA where the business will accept it, named privileged accounts with just-in-time elevation, and quarterly access reviews. This is the single highest-value control for a DMCC company and it is usually the one missing.
Tower connectivity and dedicated circuits
Carrier availability genuinely varies between JLT clusters and towers. We check what is actually deliverable to your floor before you commit to a lease clause, arrange dedicated circuits where the shared building service is not adequate, and configure failover so a single carrier fault does not stop trading.
Microsoft 365 done properly, not just bought
Most DMCC members buy Microsoft 365 during setup and never configure it. We take tenants from default to hardened: mail authentication with SPF, DKIM and DMARC at enforcement, retention aligned to your record-keeping obligations, data loss prevention on the document types that matter, and third-party backup, which neither Microsoft nor your reseller provides.
Fast joiner and leaver handling
DMCC companies scale headcount in bursts around trading seasons and funding rounds. Documented provisioning means a new starter has their laptop, licences, access and MFA on day one, and a leaver loses everything the same hour rather than three weeks later. Ex-employee access is one of the most common findings when we audit a new client here.
Evidence for audits and banking relationships
DMCC members face scrutiny from more directions than most: the authority itself, banking partners running enhanced due diligence, VARA for virtual asset firms, and counterparties. We keep an evidence pack current, access controls, patch status, backup and restore test results, incident log, so a request does not turn into a two-week scramble.
Who owns your Microsoft tenant, really?
Company formation in DMCC is usually handled by a setup consultant who bundles a package: licence, visas, bank introduction, office, and often email and Microsoft 365. That last item is where a problem gets planted quietly, and it surfaces two years later when you try to leave.
- The tenant is frequently created under the consultant partner account rather than in your company name, with their staff holding global administrator. That means they can read every mailbox in your business, and you cannot remove them.
- Your domain is sometimes registered to the consultant too. Combined with tenant control, that is total control of your email, which for a trading company is total control of your payment instructions.
- Check it yourself in ten minutes: sign in to the Microsoft 365 admin centre, open the list of global administrators, and look at who is on it. Then check your domain registrar record. If either surprises you, fix it before anything else on this page.
- Transferring a tenant to your own control is routine and we do it regularly. It is far easier while the relationship with the consultant is still good than after a dispute.
Four reasons we fit this free zone specifically.
Twenty minutes away, and we publish the band
Our operations desk is in Iris Bay Tower, Business Bay. JLT is Band 2 on our published coverage: same business day standard, within 3 hours for an emergency. We measured the drive at both peaks rather than estimating it, and if we cannot hold a band we say so instead of writing a number we will miss.
We read your licence before we scope
A DMCC trading licence, a services licence, and a VARA virtual asset licence carry completely different technical obligations. We ask which one you hold in the first conversation, because scoping a Crypto Centre member the same way as a consultancy is how providers end up delivering something that fails an audit.
We know the towers, not just the postcode
Building access rules in JLT vary by tower management company, and losing forty minutes in a lobby is a real cost during an outage. Our engineers have worked across the cluster and we register access in advance rather than discovering the process on the day something breaks.
We can actually do the security work, not refer it
Penetration testing, vulnerability assessment, SOC monitoring and incident response are delivered by us, not subcontracted. For a VARA-regulated member that matters, because the testing cadence is a licence condition rather than a nice to have, and coordinating it through a third party adds delay you do not control.
Six member profiles and what each one actually needs.
Precious metals and diamond traders
High-value wire instructions moving by email make business email compromise the dominant risk. Mail authentication at enforcement, impersonation protection, and a documented out-of-band verification step for any payment change.
Crypto Centre and Web3 firms
VARA obligations drive the scope: documented cybersecurity framework, penetration testing on a cadence, hardened identity, privileged access logging, and evidence formatted for quarterly reporting.
Commodity trading and shipping desks
Trading platforms, document flows for letters of credit and bills of lading, and counterparties in multiple time zones. Uptime during trading hours matters more than anything else in the stack.
Professional services and consultancies
Small teams, heavy document work, client confidentiality obligations. Microsoft 365 configured properly, backup, and device management. Usually the cleanest engagements in the free zone.
Regional headquarters of overseas groups
A DMCC entity acting as the Middle East office of a parent elsewhere. The work is integration: connecting to group identity and systems without breaching either the parent policy or UAE data expectations.
Early-stage companies in flexi-desks
No control over the network, no IT person, and a licence renewal that will arrive faster than expected. Endpoint-first security, cloud-only infrastructure, and nothing that assumes a server room.
What changes depending on the DMCC licence you hold.
| Licence profile | Baseline | Added scope | Evidence expected by | |
|---|---|---|---|---|
| Trading, general commodities | M365 hardened, endpoint protection, backup, device management | Mail authentication at enforcement, payment-change verification process, impersonation protection | Banking partners during enhanced due diligence | |
| Precious metals and stones | As above | Document retention, restricted access to high-value records, audit logging on document movement | Auditors, banking partners, counterparties | |
| Virtual assets, VARA regulated | As above | Documented cybersecurity framework, penetration testing cadence, privileged access logging, incident response plan, SOC monitoring | VARA, quarterly and at annual audit | |
| Professional services | As above | Client confidentiality controls, data loss prevention, retention matched to engagement records | Clients, professional bodies | |
| Regional headquarters | As above | Group identity federation, cross-border data mapping, parent-policy alignment | Group internal audit |
Four options, honestly compared.
| Feature | Contracted IT partner | The building IT provider | A freelance engineer | Nobody, until something breaks |
|---|---|---|---|---|
Published response times | Sometimes | Rarely | ||
Cover when your engineer travels | ||||
Can deliver VAPT for a VARA licence | Rarely | |||
Owns Microsoft 365 hardening | Varies | Varies | ||
Independent of your landlord | Not applicable | |||
Audit and evidence pack maintained | ||||
You keep tenant and admin ownership | Often not | Often not | Not applicable | |
Scales when you take a second floor | Tied to the building | Depends on one person | ||
Cost when nothing is wrong | Monthly fee | Bundled in rent | Zero | Zero |
Cost when something is very wrong | Included | Chargeable | Whatever they quote | Highest of all |
Twelve checks worth running on your own setup this week.
Money and email, where the losses actually happen
- Is DMARC published and set to reject, not none?A DMARC record in monitoring mode stops nothing. For a trading company sending payment instructions, this is the highest-value control there is.
- Is there a written out-of-band rule for payment changes?A phone call to a previously known number, never a number in the email. Business email compromise is the dominant loss event for commodities traders.
- Is impersonation protection on for your directors?Lookalike domain and display-name spoofing of the managing director is the standard opening move.
- Does anyone outside finance have access to banking portals?Check actual access, not the policy.
Identity, the real perimeter in a free zone
- Is MFA enforced on every account, including service accounts?One unprotected legacy account is the whole control.
- Can you list every ex-employee who still has an active account?If it takes more than five minutes to answer, the answer is worse than you think.
- Are there shared logins for any system?A shared trading or portal account destroys attribution and fails any audit.
- Is conditional access restricting sign-in by location or device?A credential that works from anywhere is a credential that works for whoever bought it.
The things that only matter once, catastrophically
- Has a Microsoft 365 restore actually been tested?Microsoft does not back you up in the sense you mean. Retention is not backup and the shared responsibility model says so explicitly.
- Is company data on personal devices with no management?Common in flexi-desk companies and invisible until a phone is lost.
- Who holds the global administrator account for your tenant?If it is your setup consultant or your previous IT provider, you do not control your own company.
- For VARA members: when was the last penetration test?If the answer is "at licensing", the cadence obligation is already slipping.
Four steps from first call to supported.
- 1
Licence and obligation review
Day 1
Which DMCC licence you hold, whether VARA applies, who else asks you for evidence, and what your tower and tenancy allow us to do on the network. Thirty minutes, and it changes the scope more than anything technical.
- 2
Tenant and estate audit
Week 1
Who holds global administrator, what MFA coverage actually looks like, which accounts belong to people who left, whether backup exists and has ever been restored, DMARC state, and device inventory. You get the findings in writing whether or not you engage us.
- 3
Close the critical gaps
Weeks 1 to 2
Tenant ownership recovered if needed, MFA enforced, dormant accounts removed, mail authentication moved to enforcement, backup deployed and a restore proved. Fast, high-value, and largely invisible to your staff.
- 4
Steady state and evidence
From week 3
Service desk live with named engineers, monitoring in place, documented joiner and leaver process, and an evidence pack that stays current. For VARA members, the testing calendar is set and diarised rather than reactive.
“Our bank asked for evidence of our IT controls as part of a review and we had almost nothing to give them. GR audited us in a week, told us plainly that our setup consultant still held global admin on our tenant, and got that transferred to us. The bank review passed. The part that stayed with me is that they told us about the admin problem before we had signed anything with them.”
What DMCC members ask us.
What DMCC members usually scope alongside this.
JLT IT services
The geographic view: towers, access, drive times, and on-site coverage across the JLT cluster.
VAPT testing Dubai
Penetration testing and vulnerability assessment, delivered in-house, with a retest letter that satisfies counterparties.
IT AMC Dubai
The contract shape most small and mid-size DMCC members take: covered support, backup, and device management.
Tell us your licence category and we will tell you what you actually need.
A short call covering which DMCC licence you hold, whether VARA applies, your headcount, and your tower. You get back a written scope and, if you want it, a free audit of who currently holds global administrator on your Microsoft tenant. That last check surprises people often enough that we offer it whether or not you engage us.
Related Services
Explore more solutions that work great with this service
VAPT Testing
CREST-certified vulnerability assessment and penetration testing
IT AMC Dubai
Annual maintenance contracts for IT infrastructure
Managed IT Services
Complete outsourced IT department
Microsoft 365
Complete Microsoft 365 setup, migration & support
Cybersecurity Companies Dubai
Cyber buyer's guide, 7 services to evaluate