UAE Financial-Sector Cybersecurity: What CBUAE Expects of Banks and Payment Firms
What the Central Bank of the UAE expects of banks and payment firms on cybersecurity, and how to evidence it.
What DESC's Information Security Regulation (ISR v3) requires, who is in scope, and why it matters commercially in Dubai.
Any organisation that works with the Dubai Government — as an entity, a partner or a supplier — will sooner or later meet the Information Security Regulation (ISR) issued by the Dubai Electronic Security Center (DESC). The current version, ISR v3, raised the bar, and compliance is mandatory for those in scope. This guide explains what ISR v3 is and who it affects.
The Dubai Electronic Security Center is the government body responsible for cybersecurity in the Emirate of Dubai, and the Information Security Regulation is its mandatory standard. DESC released ISR Version 3.0, building on the earlier v2, to reflect a tougher threat landscape and modern technology use. It applies to Dubai government entities and, importantly, to the contractors, partners and suppliers that connect to or handle their information. ITSEC's DESC cybersecurity practice helps organisations meet it.
ISR v3 is organised across a set of security domains spanning governance, asset management, access control, cryptography, physical security, secure development, supplier risk, incident management, business continuity, cloud security and security operations. The emphasis is on a managed, evidenced programme — not a one-time checklist. For organisations already aligned to ISO/IEC 27001, much of the groundwork carries over, but ISR adds Dubai-specific expectations that have to be met on their own terms.
ISR compliance is often a condition of doing business with the Dubai Government: non-compliance can mean exclusion from procurement and contract termination. For suppliers, treating ISR as a sales enabler rather than a burden is the right framing — being demonstrably compliant opens doors that closed ones. Testing the controls with independent penetration testing and VAPT is part of proving that compliance is real.
If your organisation works with the Dubai Government, ISR v3 is not optional. ITSEC runs ISR gap assessments, remediation and the testing that evidences compliance. Visit our DESC cybersecurity page to get started.