Macksofy Technologies
Dubai · Pentest
CERT-In EmpanelledDubai

Penetration Testing in Dubai · DESC ISR, DIFC & DFSA

DESC ISR + DIFC + DFSA-aligned penetration testing for Dubai BFSI, hospitality, smart-city operators and free-zone fintech — Mumbai BKC senior bench.

01
DESC + DFSA + DIFC
Regulator submission ready
02
0 hr
BOM → DXB flight
03
0-7 wks
Typical engagement
04
Regional APT
Threat-actor emulation
Pentest in Dubai

How a Macksofy pentest engagement runs in Dubai.

Dubai penetration testing is unusual in the Middle East market because the regulator stack is unusually dense for one emirate. Every Dubai-domiciled entity faces the federal layer (NESA / UAE IA Standards from TDRA, federal PDPL 2021), the emirate layer (DESC Information Security Regulation v2 for Dubai-government-adjacent entities), and — for DIFC-licensed entities — the financial-free-zone layer (DFSA cyber-resilience expectations plus DIFC Data Protection Law). The pentest must produce evidence that closes the most-stringent regulator in the engagement scope. Macksofy delivers Dubai pentest engagements with all four submission formats pre-templated; the senior consultant selects the right one at kickoff based on the entity's regulator profile.

DESC ISR v2 is the headline framework. The Dubai Electronic Security Centre's Information Security Regulation v2 (effective 2024, updated 2025) imposes a 14-domain control framework with annual audit submission for Dubai-government-adjacent entities. The pentest scope must produce evidence for ISR v2 domains 1-5 (governance, asset management, identity, access control, cryptography) and the operational-testing evidence for domains 6-14 (network security, applications, OT, supplier management, incident response, BCP, monitoring, vulnerability management, awareness). Macksofy maintains the DESC ISR v2 control register and submission template; pentest findings map directly to the control numbering DESC inspectors read.

DIFC + DFSA scoping has its own profile. DIFC-licensed entities (Category 1-5 Authorised Firms, designated investment businesses, market intermediaries) face DFSA cyber-resilience expectations that the DFSA Authorised Officer reviews at the annual cyber-resilience self-assessment cycle. The pentest must produce the evidence that supports the self-assessment claims. Scoping covers the DIFC entity's customer-facing platform, the DFSA-supervised trading or asset-management platform, the DIFC Data Protection Law DPIA evidence, and (where the entity is part of a global parent) the parent's cyber-resilience standard. Macksofy maintains the DFSA cyber-resilience-self-assessment template and pre-fills it from pentest evidence.

Adversary emulation is the default methodology. Dubai BFSI and hospitality clients run modern EDR (CrowdStrike Falcon, SentinelOne, Microsoft Defender for Endpoint, Trend Micro Vision One) and modern SIEM (Splunk Enterprise Security, Microsoft Sentinel, IBM QRadar, Securonix). Macksofy's Dubai pentest bench is calibrated to operate under this telemetry — AMSI / ETW patching, direct syscall invocation, in-process LDAP queries — with the post-engagement EDR-and-SIEM detection-content reconciliation that drives purple-team integration. Threat-actor emulation profiles are calibrated to the regional threat landscape (FIN8-style financial actors, MuddyWater / OilRig-style regional APTs targeting energy and government, Lazarus-adjacent groups targeting financial services).

Smart Dubai operator scope is a specific Dubai capability. Smart Dubai initiatives, government-portal operators (UAE PASS digital-identity, Dubai Now app, DubaiNow integration partners) and smart-city back-end operators face DESC ISR plus NESA plus citizen-data-residency requirements. Pentest scopes for these operators cover citizen-portal AppSec depth, digital-identity integration trust paths, cross-tenant isolation evidence, and the citizen-data residency-and-encryption controls the Dubai Digital Authority expects. Macksofy has shipped this scope into Smart Dubai-adjacent operators.

Hospitality and retail pentest scoping in Dubai is unique to the region. Emaar, Damac, Majid Al Futtaim, Jumeirah Group, Atlantis, Address Hotels — Dubai hospitality and large-format retail estates run complex IT-and-OT environments (PMS systems like Opera and OnQ, point-of-sale, kiosk networks, smart-room controls, restaurant-payment terminals, loyalty-platform integration). Pentest scopes here include PMS authentication-and-authorisation depth, POS-network segregation, smart-room control-plane integrity (the hotel-IoT angle that became a regulator priority after several regional smart-room compromise incidents), and loyalty-program data-isolation. Customer-data flows for foreign-tourist data trigger PDPL + DIFC DP Law + (where applicable) GDPR cross-border-transfer evidence collection.

Procurement reality matters. Dubai BFSI and DIFC fintech procurement closes through the CISO and the Authorised Officer (the DFSA-mandated senior individual responsible for cyber). DESC-scoped Dubai-government-adjacent entity procurement closes through the head of IT and the entity's DESC Liaison Officer. Hospitality procurement closes through the CISO with the GM operations and the brand-parent's CISO copied. Engagement letters cover trespass-and-deception, physical assessment indemnity (which the hotel-pentest cases routinely use), and the production safe-harbour clause for live PMS / POS testing. UAE law applies with DIFC Courts jurisdiction for DIFC entities or UAE federal courts otherwise. Engagement billed in AED with 5% VAT line.

Onsite cadence is anchored from Mumbai BKC. BOM → DXB flight is 3 hours; most Dubai client sites are 20-30 minutes from DXB. Senior consultants land Tuesday morning, kickoff Tuesday afternoon (DIFC, Business Bay, Internet City, JLT, Dubai South, Trade Centre) and run a 5-7 week engagement with two further onsite legs (mid-engagement and closing). For sustained multi-quarter programmes we maintain an embedded Dubai-resident tech lead with a local mobile and a DIFC visiting-base. Most engagements complete with a final DESC ISR / DFSA / DIFC DP Law evidence pack the client's regulator-liaison submits within the next reporting window.

Engagement workflow

Five phases. Dubai timeline.

Every Macksofy pentest engagement in Dubai runs through the same phased protocol — adapted to Dubai-specific procurement, regulator and delivery realities.

01
Phase 01
Regulator-Profile & Scope
  • Joint kickoff with CISO + Authorised Officer (DFSA) / DESC Liaison (DESC-scoped) / GM + brand-CISO (hospitality)
  • Submission format selection — DESC ISR v2, DFSA self-assessment, DIFC DP Law DPIA or NESA
  • Engagement letter — UAE law, DIFC Courts jurisdiction for DIFC entities, AED billing with 5% VAT
  • Threat-actor emulation profile — FIN8 / MuddyWater / OilRig / Lazarus-adjacent per entity threat model
02
Phase 02
Recon & Initial Access
  • OSINT against the entity's customer base, employee base and supplier-vendor ecosystem in the region
  • Regional spear-phish lure calibration (Arabic + English bilingual lure, Ramadan / Eid / National Day timing)
  • DESC ISR-domain-6 external attack-surface enumeration with the entity's DESC Liaison sign-off
  • Physical assessment legs at DIFC / Business Bay / Internet City / JLT towers where the engagement letter permits
03
Phase 03
Adversary Emulation
  • EDR-aware tradecraft against CrowdStrike Falcon / Sentinel / SentinelOne / Trend Micro Vision One telemetry
  • ADCS / Kerberos / SCCM / AAD-Connect privilege paths on the entity's identity estate
  • Hospitality PMS / POS / smart-room control-plane / loyalty platform abuse cases where in scope
  • Smart Dubai citizen-portal / digital-identity integration / cross-tenant isolation testing where in scope
04
Phase 04
Regulator-Format Reporting
  • DESC ISR v2 14-domain crosswalk per finding with submission-format pre-filling
  • DFSA cyber-resilience-self-assessment evidence pre-fill for DIFC Authorised Firms
  • DIFC Data Protection Law DPIA evidence collection and breach-notification-format pre-fill
  • PDPL 2021 cross-border-transfer evidence pack with contractual-safeguard reference
05
Phase 05
SOC Tabletop & Re-test
  • Joint SOC tabletop with the entity's SOC / MSSP partner and kill-chain replay
  • EDR + SIEM detection-content reconciliation — paired Sigma / SPL / KQL rules per missed alert
  • Free re-test of every Critical and High inside the regulator-defined remediation window
  • Embedded Dubai-resident tech lead handover for multi-quarter programme continuity
Industries served

Which Dubai verticals we deliver Pentest for.

DIFC-licensed BFSI

DIFC Category 1-5 Authorised Firms — DFSA cyber-resilience self-assessment pre-fill + DIFC DP Law DPIA.

Foreign-bank regional HQs

JLT / DIFC / Business Bay foreign-bank regional HQs — parent-control-catalogue crosswalk on Dubai entity.

Smart Dubai operators

UAE PASS / Dubai Now / smart-city operators — DESC ISR + citizen-data-residency + cross-tenant isolation testing.

Hospitality & retail majors

Emaar / Damac / Majid Al Futtaim / Jumeirah / Atlantis / Address — PMS / POS / smart-room / loyalty platform scope.

Free-zone fintech (DIFC / ADGM-adjacent)

DIFC fintech and adjacent ADGM-licensed entities — DFSA / FSRA self-assessment + cyber-resilience evidence.

Airlines & logistics

Emirates / FlyDubai / DP World / Dubai Customs — booking-platform / cargo-platform / customs-clearance scope.

What ships

The Dubai deliverable pack.

Every Dubai pentest engagement closes with the pack below — regulator-ready evidence, technical detail and board-readable summaries.

  • Pentest report with DESC ISR v2 / DFSA / DIFC DP Law / NESA submission-format pre-fill per entity scope
  • Regional threat-actor emulation playbook with technique-by-technique reconciliation
  • Hospitality / smart-city / DIFC fintech / Smart Dubai scope-specific finding catalogue
  • EDR + SIEM detection-content (Sigma / SPL / KQL) shipped post-engagement
  • DESC ISR v2 14-domain control register with submission-ready evidence collection
  • DFSA cyber-resilience-self-assessment pre-filled template for DIFC Authorised Firms
  • PDPL 2021 + DIFC DP Law cross-border-transfer evidence pack
  • Free re-test of every Critical and High inside the regulator-defined remediation window
Recent Dubai engagement

A Dubai pentest case study.

DIFC-licensed Category-3 Asset Manager (Dubai HQ at DIFC Gate Village, US + EU institutional client base)
Scope

Adversary-emulation pentest — single objective: silent reach of the portfolio-management system from a guest Wi-Fi position by D+12 without SOC detection; CrowdStrike Falcon endpoint, Splunk Enterprise Security, Okta IDP; DFSA cyber-resilience self-assessment evidence; DIFC DP Law DPIA for institutional client data; 6-week engagement with three DIFC onsite legs

Outcome

Objective met at D+9 via a vendor-portal watering-hole compromise → Okta phish → assume-role to the portfolio-management system; 8 missed Splunk ES use-cases reconciled and 9 paired SPL rules adopted by the SOC inside two weeks; DFSA cyber-resilience self-assessment pre-fill accepted on first read; DIFC DP Law DPIA evidence pack accepted by the DIFC Data Protection Commissioner without rework; one ADCS ESC4 path closed pre-disclosure that would have allowed PMS-administrator escalation to the back-office GL.

What clients say · Trusted India + UAE

Rated 4.9 ★ from 612 client reviews.

CERT-In Empanelled
Govt of India · MeitY
EC-Council ATC
Authorized Training
ISO 27001 Certified
Info Security Mgmt
We've worked with three Big 4 firms before Macksofy. None found what their team did in our payments stack. The most actionable report we've received in a decade.
AK
Aisha Khan
Information Security Manager · Listed Fintech · BKC, Mumbai
The CHFI training Macksofy delivered for our cyber cell raised investigation quality measurably. Practical, India-context-aware, and respectful of our operational realities.
IK
Inspector K. Joshi
Cyber Cell · Maharashtra Police · Mumbai
Came in with zero security background. 5 weeks later I was running Burp Suite and Metasploit confidently. Cleared CEH on the first attempt.
VI
Vivek Iyer
DevSecOps Lead · Healthcare SaaS · Hyderabad
FAQ

Questions Dubai buyers ask before signing.

Yes — every Dubai pentest with a DESC-scoped entity maps findings against the DESC ISR v2 14-domain control framework. The submission pack is pre-filled from the engagement's evidence — DESC inspectors accept it on first read without rework. We maintain the DESC ISR v2 control register against the current DESC release cycle.
More services in Dubai

Other Macksofy engagements in Dubai.

Pentest in other cities

Same engagement, other Macksofy metros.

Talk to us

Get a fixed-price proposal in 48 hours.

Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.

CERT-In Empanelled
Information Security Auditor · India
  • CERT-In Empanelled
  • EC-Council ATC · CompTIA Authorized
  • 20,000+ professionals trained
  • India + UAE engagements
Human verification· Cloudflare Turnstile

By submitting this form you agree to be contacted by Macksofy. We typically respond within a few business hours and never share your details. Protected by Cloudflare Turnstile and rate limiting.