Home / News / How to Prepare for a Cyber Security Questionnaire from the DFSA or FSRA

NEWS

Фотогрфия

How to Prepare for a Cyber Security Questionnaire from the DFSA or FSRA

06.08.2026

By Marina Ivashina, Head of Compliance at TechnoPeak

Sooner or later, almost every financial firm in the UAE opens an email that contains some version of this sentence: “Please complete the attached cyber security questionnaire and return it within 10 business days.”

It might come from the DFSA or the FSRA. From a banking partner during onboarding. From an investor running due diligence. Or from a prospective client whose procurement team simply won’t sign anything without it.

The attachment might hold 30 questions. It might hold 300. Either way, most firms discover the same uncomfortable truth within the first hour: answering a cyber security questionnaire honestly is much harder than it looks. Question three asks when your Incident Response Plan was last tested, and the room goes quiet.

The good news? Preparing for these questionnaires is a very learnable skill. Having helped firms in the DIFC and ADGM through quite a few of them, I can tell you exactly what the requesting party is looking for — and how to be ready before the email arrives.

Why cyber security questionnaires exist in the first place

Nobody sends a 300-question spreadsheet out of spite (although at question 247 you may start to wonder). The purpose is genuinely practical. Whoever sent it wants to understand four things:

  • how you manage cyber risk day to day
  • how resilient your business would be if something went wrong
  • whether basic security controls actually exist
  • whether the risks from your vendors and suppliers are under control

For banks and investors, the questionnaire is part of due diligence or onboarding. For clients, it is vendor assessment. For regulators such as the DFSA and FSRA, it feeds into thematic reviews and supervision — and as we covered in our article on what DIFC and ADGM regulators actually require for cyber resilience, those expectations have become considerably more specific in recent years.

What a security questionnaire actually evaluates

The format varies, but the substance rarely does. Almost every cyber security questionnaire circles the same six areas.

Governance — who actually owns this?

Expect questions like: Who is responsible for cyber security? How often are risks reviewed? Does senior management receive reporting?

The sender is checking whether cyber security has an owner and oversight — or whether it lives in the vague territory of “our IT guy handles that.” (He may well be excellent. But “the IT guy handles it” is not a governance framework, and assessors can smell the difference through a spreadsheet.)

Policies and procedures — and the evidence behind them

You will be asked about your Information Security Policy, Incident Response Plan, Access Control Policy, and your business continuity and disaster recovery plans (BCP and DRP).

Most firms happily tick “Yes” to all of these. The real test comes one step later, when the assessor asks to see them — with a recent review date, a named owner, and some sign that anyone has read them since they were written.

Access management — the questions everyone gets wrong

Is multi-factor authentication (MFA) enabled everywhere? Are privileged accounts controlled? Are user access rights reviewed regularly, and can you show the review?

This section gets extra scrutiny for a simple reason: a large share of real incidents begin with one compromised account. If your answer to “are access reviews performed?” is “we did one when Ahmed left,” it’s worth fixing that before the questionnaire arrives, not after.

Incident response — have you actually rehearsed?

How are incidents reported? Who leads the response? Have you run an exercise?

Firms that have tested their incident response — even a modest tabletop exercise once a year — answer these questions in five confident minutes. Firms that haven’t tend to produce answers that sound aspirational rather than factual. Assessors notice.

Business continuity and disaster recovery

Do you have a BCP and DRP? Are they tested? When was the last test, and what did it find?

This is usually where evidence becomes the sticking point. A continuity plan that has never been tested is a hypothesis, not a plan. If you want a refresher on what good looks like, we’ve written a practical guide to disaster recovery essentials.

Third-party risk — because your vendors are your risk too

Modern financial firms run on cloud platforms, SaaS tools and managed IT providers. Questionnaires increasingly ask how you oversee those vendors: due diligence before signing, security clauses in contracts, and periodic reviews afterwards.

The irony of receiving a vendor assessment questionnaire and realising you’ve never sent one to your own vendors is not lost on anyone. Consider it a nudge.

The five most common mistakes

After enough questionnaires, the failure patterns become predictable:

  1. Treating it as paperwork. Most questions implicitly ask for evidence. A bare “Yes” without anything behind it rarely survives a follow-up call.
  2. Outdated policies. A policy last reviewed three years ago doesn’t reassure anyone — it raises more questions than it answers.
  3. Undocumented good work. Many firms genuinely do access reviews, run backups and train staff — and write none of it down. In an assessment, work that isn’t documented might as well not have happened.
  4. Conflicting answers from different departments. When IT says backups are daily and operations says weekly, the assessor stops reading answers and starts reading between them.
  5. Starting preparation when the questionnaire arrives. Ten business days is enough time to collect evidence. It is not enough time to create two years of it.

How to prepare before you receive one

The single most useful habit is maintaining a small compliance evidence library — one organised folder that holds:

  • current, dated versions of your key policies
  • records of risk reviews and management reporting
  • access review evidence
  • staff security training records
  • BCP/DRP test reports
  • vendor due diligence and assessments
  • an incident log (even if it mostly says “nothing happened” — that’s a record too)

None of this requires a big team or an enterprise GRC platform. It requires an owner, a folder structure, and an hour or two a month. When the questionnaire lands, you’re assembling answers from evidence you already have — instead of reconstructing history under a deadline.

What regulators and assessors really want to see

Here is the part that surprises people: nobody expects perfection. In years of working with regulated firms, I have never seen an assessor reject a company for honestly saying “this control is partially implemented, and here is our plan to complete it.”

What they want to see is:

  • Ownership — someone is clearly accountable for cyber security
  • Consistency — answers, policies and practice tell the same story
  • Evidence — claims are backed by dated records
  • Improvement — gaps are known, tracked and being closed

A firm with modest but real controls and honest documentation will outperform a firm with a beautiful 80-page policy suite that nobody has opened since it was written. Assessors read impressive-but-untouched policies the way teachers read essays written the night before. They always know.

How TechnoPeak can help

TechnoPeak works with DIFC- and ADGM-based firms on exactly this: preparing for regulatory reviews, cyber security questionnaires, investor due diligence and vendor assessments, and building the compliance evidence library that makes all of them easier. It’s one of the reasons FSRA-regulated firms in Abu Dhabi work with us, alongside our broader cybersecurity services and managed security services.

If you’re not sure whether your current documentation would stand up to scrutiny, a focused Cyber & Compliance Readiness Assessment is a practical place to start. We’ll tell you honestly where you stand — ideally before someone with a 300-row spreadsheet does.

Marina Ivashina is Head of Compliance at TechnoPeak, where she helps UAE financial firms turn regulatory requirements into working practice.

See more

Get a Free IT Audit

Contact us now – our team is ready to assist you!





    By clicking the "Send Message" button, you agree to our
    processing policy.