Insights

Expert guides for regulated firms in the UAE.

Plain-English guidance on DFSA and FSRA technology expectations, Microsoft 365 governance, Cyber Essentials, ISO 27001, audit readiness, vendor management, office moves, managed IT services, penetration testing and how to choose an IT company.
How we write these guides

Sourced, dated and written by a named expert

Each guide cites the regulator’s own text or another primary source, states when it was last reviewed, and is written under the name of a Cre8 IT specialist rather than a faceless team.
They describe what regulators expect and how firms can meet it. They are not legal advice, and where the rules are a matter of judgement we say so.

What every guide includes

All guides

Topics regulated firms ask us about

DFSA and DIFC

DFSA cyber and IT requirements: what DIFC firms need to evidence

A plain-English guide to the DFSA’s cyber risk management rules (GEN 5.5), its outsourcing expectations (GEN 5.3.21) and the evidence a DIFC firm should be able to show.
6 min read · Reviewed 19 September 2026
Microsoft 365

Microsoft 365 governance for regulated firms: a practical baseline

How to govern Microsoft 365 in a DFSA- or FSRA-regulated firm: identity, devices, data, logging and licences, with a 30-day order of work.
4 min read · Reviewed 19 September 2026
Cyber Essentials

Cyber Essentials for UAE firms: what it is and when it is worth it

What Cyber Essentials covers, what changed in April 2026, whether it matters for DIFC and ADGM firms, and how it compares with ISO 27001 and the regulators’ own rules.
4 min read · Reviewed 19 September 2026
ISO 27001

ISO 27001 for financial firms: how it supports DFSA and FSRA expectations

What ISO/IEC 27001:2022 certifies, how its controls map to DFSA and FSRA cyber expectations, and how to read a supplier’s certificate.
4 min read · Reviewed 19 September 2026
Audit readiness

IT audit readiness for DIFC and ADGM firms: an evidence-first checklist

How to be ready when a regulator, auditor or client asks for proof of your IT and security controls: the evidence pack, a mock audit and a six-week plan.
3 min read · Reviewed 19 September 2026
Vendor management

IT vendor and outsourcing management for DFSA and FSRA firms

How to manage IT providers when you are regulated in DIFC or ADGM: a register, tiering, due diligence, contract terms and ongoing oversight.
4 min read · Reviewed 19 September 2026
Office moves

Office IT relocation in Dubai: a checklist for moving without downtime

What to plan for your IT when your firm moves office in Dubai or Abu Dhabi: internet lines, cabling, the comms room, WiFi, phones, security and a weekend cut-over.
5 min read · Reviewed 6 October 2026
Managed IT

Managed IT services in Dubai: what’s included and what drives the cost

How managed IT services work for firms in Dubai and Abu Dhabi: what a good contract covers, how pricing is structured, what is usually extra and how to compare providers.
4 min read · Reviewed 6 October 2026
Choosing a provider

How to choose an IT company in Dubai: 10 questions to ask before you sign

The 10 questions to ask any IT company in Dubai before you sign: who answers at 2am, what the SLA says, backups, certification, costs and how you would leave.
6 min read · Reviewed 7 October 2026
Penetration testing

What is a penetration test, what does it cost in the UAE, and do you need one?

What a penetration test is, how it differs from a vulnerability scan, what it costs in the UAE in 2026 and how to tell if your business needs one.
6 min read · Reviewed 7 October 2026

Talk to a specialist about your obligations

Tell us about your firm and your regulator, and we will suggest a practical first step, whether that is a gap assessment or ongoing support.