Macksofy Technologies
UAE · Cloud Security
CERT-In EmpanelledUAE

Cloud Security Audit in the UAE · Federal

Cloud security audit across the UAE on AWS Bahrain / UAE, Azure UAE North / Central, OCI Abu Dhabi, Google Cloud Dammam and G42 sovereign cloud — UAE IAS, DESC ISR v2, ADHICS, DFSA / FSRA and Smart Dubai cloud-first policy aligned.

01
0 regulators
UAE IAS · DESC · ADHICS · DFSA · FSRA · SIA · TDRA · PDPL
02
0 clouds
AWS · Azure · OCI · GCP · G42 sovereign
03
AR + EN
Bilingual reporting where required
04
0-12 wk
Engagement duration by scope
Cloud Security in UAE

How a Macksofy cloud security engagement runs in UAE.

UAE cloud-security audits sit under a layered regulatory stack that no global Big-4 cloud-audit template handles cleanly. UAE IAS (NESA) at the federal level via the UAE Cybersecurity Council and TDRA, with the Critical Information Infrastructure Protection (CIIP) overlay for designated sectors. Dubai Electronic Security Centre (DESC) Information Security Regulation v2 for any Dubai-government and semi-government workload, with the Smart Dubai cloud-first policy directing public-sector workloads to approved cloud regions. Abu Dhabi Health Information and Cyber Security (ADHICS) for any healthcare workload in Abu Dhabi (DOH-regulated hospitals, clinics, payers and the Malaffi health-information exchange). SIA / TDRA cloud-policy for licensed telecom and digital-government operators. DFSA / FSRA technology-risk modules for free-zone BFSI in DIFC and ADGM respectively. UAE Federal PDPL 2021 for personal-data-processing workloads with the UAE Data Office cross-border-transfer overlay. Audits have to evidence the right controls per workload, not a single relabelled global template — and the inspector will not accept a CIS-only scorecard.

We audit UAE cloud estates across the full set of regions that actually serve UAE workloads. AWS Bahrain (me-south-1) plus the AWS UAE Local Zone (Dubai) when available, with cross-region pairing to AWS Bahrain or AWS Frankfurt depending on the residency obligation; Microsoft Azure UAE North (Dubai) and UAE Central (Abu Dhabi) as the primary federal-residency-acceptable pairing; Oracle Cloud Infrastructure Abu Dhabi region used by several federal and semi-government workloads; Google Cloud Dammam (me-central-2) where UAE BFSI has chosen GCP as the analytics fabric and the Bahrain / KSA cross-region is the BCP design; and the G42 / Core42 sovereign-cloud regions (Khazna data centres, the Etisalat / e& enterprise cloud, the Bayanat-adjacent geospatial cloud) for the federal-ministry workloads that require sovereign hosting under the UAE Cybersecurity Council guidance. We also audit the hybrid links back to on-prem datacentres in Khazna (Abu Dhabi), Equinix DX1 / DX2 (Dubai), Etisalat / e&-operated colocation sites, and the operator-specific managed-services overlays.

Findings are mapped per workload to UAE IAS Tier-1 / Tier-3 control profiles, DESC ISR v2 cloud-specific controls (the v2 update introduced cloud-operations-specific evidence requirements absent from v1), ADHICS Section 4 (technical controls) for healthcare workloads, DFSA Technology Risk GEN 6 cloud annex for DIFC BFSI, FSRA cloud-risk expectations for ADGM, SIA / TDRA cloud-policy for licensed operators, ISO 27017 / 27018 for the cloud-baseline crosswalk, and the CIS AWS / Azure / OCI / GCP Foundations Benchmarks for the technical scorecard layer. UAE Federal PDPL Article 22 cross-border-transfer evidence is recorded per workload with the UAE Data Office submission template where in scope. Data residency, sovereignty (the distinction matters under UAE law — residency-in-region is not the same as sovereign-control-of-operations), and KMS / HSM key-custody arrangements are evidenced explicitly per workload.

Common scopes we deliver against: a federal-ministry workload on a G42 / Core42 sovereign-cloud region with the cross-region DR design and the UAE Cybersecurity Council CIIP applicability assessment; a Dubai-government / semi-government smart-services platform (the kind of workload that anchors Smart Dubai initiatives) with DigitalDubai / UAE PASS integration audit and the DESC ISR v2 cloud-controls pack; an ADHICS-regulated healthcare workload on Azure UAE North with the Malaffi HIE integration and the DOH-specific evidence; a DFSA-regulated BFSI workload in DIFC running on AWS Bahrain primary and Frankfurt DR with the GEN 6 cloud annex evidence; a FSRA-regulated ADGM asset-management workload on Azure UAE Central with the cross-region pairing to UAE North; a multinational regional-HQ workload spanning UAE and onward to KSA (SAMA CSF / NCA ECC-2 overlay), Egypt, Bahrain or Oman; and the federal-CIIP designated workload running across multiple emirates with the per-emirate audit reconciliation.

Engagements run 4-6 weeks for a single-cloud single-workload audit, 6-8 weeks for a multi-cloud landing zone, 8-10 weeks for a federal-CIIP designated workload audit with cross-emirate reconciliation, and 10-12 weeks for the largest multi-cloud + sovereign-cloud hybrid estates. Onsite kickoff is in Dubai (DIFC / Business Bay / Internet City), Abu Dhabi (Al Maryah Island / ADGM / Khalifa City) or Sharjah depending on the client. A UAE-resident lead consultant remains onsite throughout the engagement, with Mumbai BKC senior support flying in for the board reviews and the major regulator-pack walkthroughs. We coordinate directly with the hyperscaler's UAE / KSA / Bahrain account team — AWS MENA / EMEA, Microsoft Gulf, Oracle Cloud Gulf, Google Cloud MENA — and the on-prem / sovereign-cloud operator (Khazna Data Centres, Etisalat / e&, Du, G42 / Core42, Equinix Gulf) to evidence the shared-responsibility controls in one binder.

The technical audit toolset is the same regulator-grade set the Mumbai BFSI practice uses, with UAE-specific overlays. Prowler v3 + ScoutSuite + Pacu / CloudFox for AWS, with the Azure-equivalent (Azucar, PowerZure, Stormspotter) and OCI-equivalent (Cloud Guard policy review, IAM federation audit) and the GCP-equivalent (Forseti-style review, GCP IAM Recommender consumption). CrowdStrike Falcon Cloud Security or Wiz where the client already owns a CNAPP. UAE-specific add-ons: UAE PASS integration security review (OIDC / SAML federation, attribute-release minimisation, the federal-identity broker hop), DigitalDubai service-mesh attestation review, the Malaffi HIE integration audit for healthcare workloads, and the federal-CIIP applicability-determination workflow with the UAE Cybersecurity Council where the workload's CIIP status is unclear.

Reports include a federal-versus-emirate control crosswalk so a single workload running across Dubai and Abu Dhabi tenants does not get audited twice with conflicting findings — the most common pain point we see on UAE multi-emirate cloud estates, and the one that most often surfaces in CAG-equivalent UAE federal-audit-board reviews. Sovereign-cloud workloads on G42 / Core42 / Khazna get a separate sovereign-control attestation pack because the shared-responsibility model is different — the operator carries the operational-control disposition the hyperscalers do not, and the audit evidence has to reflect that. Arabic-language deliverables are produced where a UAE federal-ministry or Dubai-government entity requires them; the senior consultant on the engagement is the same person who signs both the English and the Arabic version.

Commercial terms are local. Billing in AED with the 5% UAE VAT line, invoiced from the regional billing entity. Engagement letter under UAE law (DIFC Courts jurisdiction for DIFC entities, ADGM Courts for ADGM, UAE federal courts otherwise) with explicit UAE PDPL Article 22 cross-border-transfer discipline for any evidence movement to consultant endpoints. Records-retention aligned to the strictest regulator on the engagement — typically DFSA 7 years for BFSI, DESC ISR v2 5 years for Dubai-government, ADHICS retention for healthcare, with the federal-CIIP retention overlaid where applicable. Re-testing of all critical and high findings is included in the base SoW with a 30-day window aligned to the strictest regulator's remediation SLA.

Engagement workflow

Five phases. UAE timeline.

Every Macksofy cloud security engagement in UAE runs through the same phased protocol — adapted to UAE-specific procurement, regulator and delivery realities.

01
Phase 01
Regulator + Cloud-Region Scoping
  • Workload-by-workload regulator mapping (UAE IAS / DESC ISR v2 / ADHICS / DFSA / FSRA / SIA / PDPL)
  • Cloud-region pairing under UAE residency + sovereignty obligation per workload
  • CIIP applicability assessment with UAE Cybersecurity Council where status is unclear
  • Engagement letter under UAE law + UAE PDPL Article 22 cross-border-transfer discipline
02
Phase 02
Control-Plane + Identity Audit
  • AWS Organisations / Azure Management Group / OCI Compartment / GCP Resource Hierarchy review
  • IAM Identity Center / Entra ID / OCI IAM / GCP IAM role inventory with last-used timestamps
  • Pacu + Azucar + PowerZure privilege-path enumeration + SCP / Policy diff
  • UAE PASS / DigitalDubai / Malaffi HIE federation review per applicable workload
03
Phase 03
Workload + Data-Plane Audit
  • Prowler v3 + ScoutSuite + CNAPP (Wiz / CrowdStrike) breadth scan with UAE-tuned ruleset
  • CIS AWS / Azure / OCI / GCP Foundations + ISO 27017 / 27018 mapping per workload
  • Residency vs sovereignty evidence — region pairing, KMS / HSM key-custody, ops-personnel screening
  • Sovereign-cloud (G42 / Core42 / Khazna) shared-responsibility attestation per workload
04
Phase 04
Detection + Hybrid Edge
  • CloudTrail / Defender / OCI Audit / GCP Audit Logs pipeline integrity
  • SIEM telemetry reconciliation with client SOC (Splunk / Sentinel / Chronicle / QRadar)
  • Hybrid link audit — Direct Connect / ExpressRoute / FastConnect into Khazna + Equinix DX
  • G42 / Core42 sovereign-cloud monitoring integration where in scope
05
Phase 05
Federal-Emirate Crosswalk + Arabic Pack
  • Federal-versus-emirate control crosswalk to avoid conflicting findings on multi-emirate workloads
  • UAE IAS Tier-3 + DESC ISR v2 + ADHICS + DFSA / FSRA + UAE PDPL artefact pack
  • Arabic-language report where UAE federal-ministry / Dubai-government client requires it
  • 30-day re-test of critical / high findings + closure ledger filed with each regulator's channel
Industries served

Which UAE verticals we deliver Cloud Security for.

Federal ministries + CIIP-designated entities

Federal workloads on G42 / Core42 sovereign cloud + Khazna hybrid — UAE Cybersecurity Council CIIP overlay.

Dubai-government + Smart Dubai

Smart-services platforms with DigitalDubai / UAE PASS integration — DESC ISR v2 + Smart Dubai cloud-first policy.

Abu Dhabi healthcare (DOH-regulated)

ADHICS-regulated healthcare workloads on Azure UAE North with Malaffi HIE integration audit.

DIFC + ADGM free-zone BFSI

DFSA / FSRA regulated cloud estates on AWS Bahrain + Frankfurt or Azure UAE Central + UAE North pairing.

Licensed telecom + digital-government operators

Etisalat / e& / du / Du Pay / Bayanat-adjacent operators under SIA / TDRA cloud-policy + PDPL overlay.

GCC-spread regional HQs

Multinational HQs spanning UAE + KSA (SAMA / NCA) + Bahrain + Oman + Egypt with cross-emirate reconciliation.

What ships

The UAE deliverable pack.

Every UAE cloud security engagement closes with the pack below — regulator-ready evidence, technical detail and board-readable summaries.

  • UAE IAS (NESA) Tier-1 / Tier-3 + CIIP applicability evidence pack
  • DESC ISR v2 cloud-controls pack in registered-auditor route format
  • ADHICS Section 4 technical-controls evidence for healthcare workloads
  • DFSA Technology Risk GEN 6 cloud annex + FSRA cloud-risk evidence for free-zone BFSI
  • UAE Federal PDPL Article 22 cross-border-transfer record with UAE Data Office template
  • G42 / Core42 sovereign-cloud shared-responsibility attestation per workload
  • Federal-versus-emirate control crosswalk artefact for multi-emirate estates
  • Bilingual English / Arabic report where federal-ministry / Dubai-government required + 30-day re-test ledger
Recent UAE engagement

A UAE cloud security case study.

UAE federal ministry — multi-emirate workload on G42 sovereign cloud + Azure UAE North hybrid
Scope

Cloud security audit across G42 sovereign-cloud region + Azure UAE North + Khazna hybrid + UAE PASS integration; UAE IAS Tier-3 + DESC ISR v2 + UAE PDPL Article 22 + CIIP applicability assessment

Outcome

63 findings closed in 7 weeks · CIIP applicability determined with UAE Cybersecurity Council and codified · 12 sovereign-cloud shared-responsibility attestation gaps closed with G42 / Core42 operator counter-signature · UAE PASS attribute-release minimised across 8 service integrations · federal-emirate crosswalk filed with the federal-audit-board reconciling Dubai + Abu Dhabi tenants · bilingual English / Arabic report signed off in same engagement.

What clients say · Trusted India + UAE

Rated 4.9 ★ from 612 client reviews.

CERT-In Empanelled
Govt of India · MeitY
EC-Council ATC
Authorized Training
ISO 27001 Certified
Info Security Mgmt
We've worked with three Big 4 firms before Macksofy. None found what their team did in our payments stack. The most actionable report we've received in a decade.
AK
Aisha Khan
Information Security Manager · Listed Fintech · BKC, Mumbai
The CHFI training Macksofy delivered for our cyber cell raised investigation quality measurably. Practical, India-context-aware, and respectful of our operational realities.
IK
Inspector K. Joshi
Cyber Cell · Maharashtra Police · Mumbai
Came in with zero security background. 5 weeks later I was running Burp Suite and Metasploit confidently. Cleared CEH on the first attempt.
VI
Vivek Iyer
DevSecOps Lead · Healthcare SaaS · Hyderabad
FAQ

Questions UAE buyers ask before signing.

All five. The sovereign-cloud shared-responsibility model is different — the operator (G42 / Core42 / Khazna for the federal-ministry workloads, Etisalat / e& for licensed-operator workloads) carries the operational-control disposition the global hyperscalers do not, and the audit evidence has to reflect that. We produce a separate sovereign-cloud shared-responsibility attestation pack alongside the hyperscaler evidence on hybrid estates.
Cloud Security in other cities

Same engagement, other Macksofy metros.

Talk to us

Get a fixed-price proposal in 48 hours.

Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.

CERT-In Empanelled
Information Security Auditor · India
  • CERT-In Empanelled
  • EC-Council ATC · CompTIA Authorized
  • 20,000+ professionals trained
  • India + UAE engagements
Human verification· Cloudflare Turnstile

By submitting this form you agree to be contacted by Macksofy. We typically respond within a few business hours and never share your details. Protected by Cloudflare Turnstile and rate limiting.