DESC ISR v3 in Dubai: What the Information Security Regulation Requires
What DESC's Information Security Regulation (ISR v3) requires, who is in scope, and why it matters commercially in Dubai.
What a virtual CISO (vCISO) does, when it makes sense for UAE-regulated firms, and how it compares to a full-time hire or a one-off consultant.
Many UAE-regulated businesses hit the same wall: their licence or their clients expect a senior security leader — someone accountable for the security programme, the risk decisions and the regulator conversations — but the business isn't yet large enough to justify a full-time Chief Information Security Officer. A virtual CISO (vCISO) fills exactly that gap. This guide explains what a vCISO does, when it makes sense in the UAE regulatory context, and what to look for.
A vCISO is an experienced security executive who runs your security programme on a fractional basis — part-time, retained, or project-based — rather than as a full-time hire. The remit is leadership, not just hands-on testing: setting security strategy, owning the risk register, defining policy, guiding architecture decisions, managing audits and assessments, and representing security to the board and to regulators. Think of it as renting the judgment of a CISO who has done it before, scaled to what your business needs right now.
Three situations recur. First, regulated licensing: a VARA-licensed VASP, a DFSA or ADGM firm, or a CBUAE-regulated payment institution is typically expected to have clear security governance and an accountable owner — but a 15-person fintech rarely needs, or can afford, a full-time CISO. Second, growth: a company scaling fast needs someone to build the security foundation before an incident or an audit forces the issue. Third, gaps: a business between CISOs, or one whose technical team is strong but lacks board-level security leadership. In each case a vCISO provides the seniority without the full-time cost. ITSEC's vCISO service is built around these UAE-regulated scenarios.
A full-time CISO makes sense once security is a large, continuous, in-house function — but that is a senior salary and a long hiring cycle. A one-off consultant delivers a report and leaves. A vCISO sits in between: ongoing accountability and continuity, at a fraction of the cost, with the flexibility to scale hours up around an audit or a funding round and down in quieter periods. For most UAE fintechs, VASPs and regulated SMEs, that middle path is the right fit until headcount and risk justify a full-time role.
A vCISO engagement should produce more than meeting attendance. Expect a documented security strategy tied to your specific regulator, a live risk register with owners and timelines, policies your team actually follows, and readiness for the assessments your licence requires. It should also connect to delivery: the strategy is only real if the controls are tested. ITSEC pairs vCISO leadership with hands-on penetration testing and VAPT, so the risks the vCISO identifies are actually validated and closed — and where your obligations sit with a specific authority, mapped to that regulator's expectations, for example CBUAE for banks and payment firms or fintech security more broadly.
Begin with a short scoping conversation: what licence you hold or are pursuing, what security leadership you have today, and what's driving the need — an audit, a client requirement, a funding round, or a gap. From there a vCISO can propose a right-sized engagement, usually starting with a rapid assessment of where you stand before committing to a cadence.
If your UAE business needs security leadership and accountability without a full-time hire, a vCISO is the efficient answer. ITSEC provides fractional CISO leadership for VASPs, fintechs and regulated firms across the UAE. Visit our vCISO service page to scope an engagement.