DESC ISR v3 in Dubai: What the Information Security Regulation Requires
What DESC's Information Security Regulation (ISR v3) requires, who is in scope, and why it matters commercially in Dubai.
What VAPT (vulnerability assessment + penetration testing) actually delivers, why UAE regulators expect it, and how to scope an engagement.
Penetration testing is one of the few security activities a UAE regulator will explicitly ask you to evidence. Whether you are a VARA-licensed VASP, a DFSA or ADGM firm, or a CBUAE-regulated payment institution, “we run VAPT” is not a box to tick — it is proof that your controls have been tested by someone trying to break them. This guide explains what VAPT actually delivers and how to scope it properly.
VAPT stands for Vulnerability Assessment and Penetration Testing, and the two halves do different jobs. A vulnerability assessment is broad and largely automated — it inventories known weaknesses across your systems. A penetration test is narrow and manual — a skilled tester chains weaknesses together to see how far a real attacker could actually get. You need both: the assessment for coverage, the test for depth. A report that is only automated scan output is not a penetration test, however it is labelled.
Across the UAE's regulators, security testing is a recurring expectation. VARA's framework for virtual-asset firms includes threat-led testing for higher-risk activities; financial regulators expect regular, independent assessment of the systems that hold client data and money. The common thread is independence and evidence — testing done by a qualified third party, documented, with findings tracked to closure. ITSEC's VAPT services are built to produce exactly that evidence for UAE-regulated firms.
Scope depends on your stack, but a thorough programme typically spans network, web application, mobile, API and — for digital-asset businesses — blockchain and smart-contract testing. For the highest-risk firms, this extends to threat-led penetration testing (TLPT), where the test is driven by realistic threat intelligence about who would actually target you and how. Whatever the scope, the deliverable that matters is a clear, prioritised report your engineers can act on — not a 300-page scan dump.
Start from risk and obligation: what are your most sensitive systems, and what does your licence require you to test and how often? Define the targets, the rules of engagement, and whether the test is black-box, grey-box or white-box. Agree remediation support up front — the value is in fixing what's found, then retesting to confirm it's closed. For UAE fintechs, our fintech security practice maps testing scope to the regulator you answer to.
If a licence, a client or an audit is asking you to evidence penetration testing, the answer is a scoped, independent VAPT programme — not a one-off scan. ITSEC delivers network, web, mobile, API and blockchain testing for UAE-regulated firms, with clear remediation reporting. Visit our VAPT page to scope an assessment.