FAQ

Questions regulated firms ask us.

Short, sourced answers on DIFC and ADGM expectations, Microsoft 365, ISO 27001, Cyber Essentials and working with Cre8 IT.
DIFC, ADGM and the regulators

The rules behind the questions

What is the difference between the DFSA and the FSRA?

The DFSA regulates financial services in the Dubai International Financial Centre (DIFC) in Dubai. The FSRA regulates financial services in Abu Dhabi Global Market (ADGM) in Abu Dhabi. Each has its own rulebook, so a firm follows the rules of the regulator that authorises it, and a group with entities in both must meet both.

Which cyber rules apply to DIFC firms and which to ADGM firms?

DIFC firms follow the DFSA Rulebook, mainly GEN 5.5 on cyber risk management and GEN 5.3.21 on outsourcing. ADGM firms follow the FSRA’s Cyber Risk Management Rules in GEN 3.5, in force since 31 January 2026. See our DFSA guide and our page for ADGM firms.

How do incident reporting deadlines differ between DIFC and ADGM?

The DFSA expects a material cyber incident to be reported as soon as reasonably practicable and within 72 hours at the latest. The FSRA expects notification immediately and within 24 hours at the latest. Personal data breaches follow separate data protection rules: as soon as practicable in DIFC, and within 72 hours where feasible in ADGM.

Are these pages legal advice?

No. They summarise what regulators publish and how firms can meet it. Confirm the current rules and take advice from your compliance officer or legal adviser about your own obligations.
Microsoft 365 and security basics

Plain answers to common security questions

What is Microsoft 365 governance?

It is the set of decisions, settings and records that control who can reach your data, from which devices, how long it is kept and how you would prove it. It covers identity, devices, sharing, retention and logging. See the full guide.

What is multi-factor authentication and why do regulators expect it?

Multi-factor authentication (MFA) asks for a second proof of identity, such as an authenticator app, as well as a password. Stolen passwords are a common way in, and MFA stops most of those attacks. The DFSA’s cyber rules expect MFA for internet-facing systems and privileged access.

What is the difference between ISO 27001 and Cyber Essentials?

ISO 27001 certifies a full information security management system covering governance, risk, people, suppliers and technology. Cyber Essentials is a UK scheme that verifies five technical controls. Cyber Essentials is a quicker, cheaper baseline; ISO 27001 is broader. See our guides to ISO 27001 and Cyber Essentials.

What does “audit ready” mean for IT?

It means you can produce, on request, evidence that your controls exist, operate and are reviewed: registers, dated reports and records with named owners. Our audit readiness checklist shows how to build it.

What is SOC as a Service?

SOC as a Service is round-the-clock threat monitoring by a dedicated security operations centre, delivered as a managed service, so you get 24/7 detection without building your own team.
AI, fraud and cyber incidents

New risks, and what to do when something goes wrong

Can our staff use ChatGPT or other AI tools with client data?

Only with clear rules in place. Free and personal versions of some AI tools can use what people type to improve their models, and the firm has no control over where that data goes. Business versions typically exclude your data from training and give you admin controls, retention settings and audit logs. Decide which tools are approved and which data must never be entered (client, personal and confidential information), write it into an AI use policy, and assess AI providers as you would any other supplier.

Is Microsoft 365 Copilot safe for a regulated firm?

It can be, but it exposes weaknesses in your permissions. Copilot can find and summarise anything a user already has access to, so files that are overshared across SharePoint, Teams and OneDrive become easy to surface. Before switching it on, review who can see what, label confidential data and confirm your retention and logging settings. See our Microsoft 365 governance guide.

How do we stop fake invoice and payment-change emails?

Treat any email that asks you to change bank details or make an urgent payment as possibly fraudulent, even if it comes from a real supplier or colleague, because their account may have been compromised. Confirm every change by calling a number you already hold, never one in the email. Require two people to approve new payees and large transfers. Protect email with multi-factor authentication, flag messages from external senders, and set up SPF, DKIM and DMARC so others cannot easily send email as your domain.

Could a deepfake of our CEO be used to authorise a payment?

Yes. Voices and video can now be faked convincingly. In a widely reported 2024 case in Hong Kong, an employee transferred about US$25 million after a video call with what appeared to be the company’s senior managers. The defence is process rather than spotting fakes: no payment is approved on the strength of a call, video or message alone, and urgent or confidential requests are always verified through a separate channel you already trust.

What should we do in the first hours after a cyber attack?

Contain it, preserve evidence and note the time. Disconnect affected devices from the network, but do not wipe or switch them off. Call your IT or incident response provider. Change passwords from a clean device and check for unexpected email forwarding rules. Record what happened and when. Then decide whether the incident is material: DIFC firms must report within 72 hours and ADGM firms within 24 hours (see reporting deadlines). A personal data breach may also need reporting to the data protection regulator.

Should we pay a ransom?

Take advice before making any decision. Paying does not guarantee you will get your data back or that it will not be published, it marks you as willing to pay, and paying a sanctioned group can be unlawful. Involve your senior management, legal adviser, insurer and the police early, and keep to your regulator’s reporting deadlines. The best position is never to have to decide: tested, offline backups let you restore without paying.

How do we know our backups will work when we need them?

Test them. Restore real files regularly and, at least once a year, a whole system, and time how long it takes. Keep at least one copy offline or immutable so ransomware cannot encrypt or delete it, and another copy off site or in a separate cloud account. Record each test with its date and result: that record is exactly the evidence regulators, auditors and insurers ask for.
Budgets, insurance and testing

What good security looks like for a small firm

What is the minimum cyber security a small regulated firm should have?

Multi-factor authentication for everyone, managed and encrypted devices with endpoint detection and response, prompt patching, email security, offline and tested backups, regular staff awareness training and a written incident response plan. For a regulated firm, each control also needs a named owner and dated evidence that it works, because a regulator will ask you to show it, not just describe it.

How much should a small financial firm budget for cyber security?

It depends on your size, systems and regulator, so be wary of any single figure. Most small firms spend in a few predictable areas: security tools licensed per user (often through Microsoft 365), a managed monitoring service, annual testing, staff training and cyber insurance. Start from your risks and your regulator’s expectations rather than a percentage of turnover. Ask us for a free estimate based on your set-up.

Do we need cyber insurance, and what will insurers ask for?

It is not usually a regulatory requirement, but many firms carry it to cover incident response, recovery costs and liability. Insurers increasingly expect minimum controls before they will quote, commonly multi-factor authentication, endpoint detection and response, offline backups, patching, staff training and an incident response plan. Without them, expect higher premiums, exclusions or a refusal. Read the exclusions carefully, including how the policy treats ransom payments and known, unpatched weaknesses.

How often should we run a penetration test?

Most firms test at least once a year and after significant changes, such as a new system, an office move or a major upgrade. Regular vulnerability scanning in between catches common weaknesses as they appear. Check what your regulator, clients and insurer expect, fix what the test finds, and keep the report and a record of the fixes as evidence.
Working with Cre8 IT

About our service

Where is Cre8 IT based and who do you support?

Our head office is in Jumeirah Lake Towers, Dubai, with offices in the United Kingdom and Riyadh. We have supported businesses since 2012 across hospitality, retail, finance and education, including regulated financial firms.

Which certifications does Cre8 IT hold?

We are certified to ISO 27001:2022 for information security and ISO 9001 for quality management, and we are a certified Microsoft Partner.

What does managed IT support include?

A helpdesk phone line and ticketing system, proactive monitoring of networks and devices, virus detection and removal, scheduled backups with tested recovery, on-site visits as often as you need, and 24/7 emergency support.

How is managed IT support priced?

A fixed monthly rate shaped around your requirements, your budget and how often you want us on site. Ask for a free estimate.

Do you offer 24/7 support?

Yes. We provide 24/7 emergency IT support, on site or remote.

Can start-ups and non-profits get a free consultation?

Yes. New start-ups and non-profits can book a complimentary 30-minute consultation.

Talk to a specialist about your obligations

Tell us about your firm and your regulator, and we will suggest a practical first step, whether that is a gap assessment or ongoing support.