DESC ISR v3 in Dubai: What the Information Security Regulation Requires
What DESC's Information Security Regulation (ISR v3) requires, who is in scope, and why it matters commercially in Dubai.
What the Central Bank of the UAE expects of banks and payment firms on cybersecurity, and how to evidence it.
The Central Bank of the UAE (CBUAE) supervises the country's banks, finance companies and payment institutions — and cybersecurity is now a core part of that supervision. If you are regulated by CBUAE, or partner with a firm that is, security is not just good practice; it is a supervisory expectation. This guide explains what that means in practice.
CBUAE's remit covers banks, exchange houses, finance companies, and the growing set of licensed payment-service providers and stored-value operators. As financial services digitise, the systems that move money and hold customer data have become the front line — and CBUAE expects the firms it supervises to manage that risk actively, not reactively. ITSEC's CBUAE cybersecurity practice is built around these obligations.
The expectations track international good practice: a documented information-security governance structure with clear ownership; risk management tied to the systems that matter; regular, independent security testing; operational resilience and tested incident response; and protection of customer data and funds. For payment and fintech firms specifically, the security of APIs, transaction flows and third-party integrations is central — a weakness in a payment path is a direct financial and regulatory risk. Our fintech security practice focuses on exactly these systems.
Supervisory expectations are met with evidence, not intent. Independent penetration testing and VAPT of the systems that hold customer data and process payments turns “we take security seriously” into a documented, defensible position — findings identified, prioritised and closed. That evidence base is what stands up in a supervisory review.
If your firm is CBUAE-regulated, or building toward a licence, security governance and testing are part of the licence to operate. ITSEC helps UAE banks, payment institutions and fintechs build the controls and produce the evidence supervisors expect. Visit our CBUAE cybersecurity page to scope an engagement.