Here is a quick experiment. Ask your team one question: “Where does our cyber risk framework live?” If the answer starts with “I think” and ends with “somewhere in SharePoint” — welcome, this article is for you. Most firms are in the same folder.
ADGM’s new cyber risk rules came into force on 31 January 2026, which means the grace period — official and psychological — is over. If the FSRA sends a questionnaire, or asks a follow-up after an incident, “I think it’s in SharePoint” is not the answer anyone wants to give.
Having helped several firms tidy this up since January, here is what the rules actually ask for — and where firms quietly fall short.
The FSRA amended its General Rulebook (the section everyone calls GEN 3.5) to make cyber risk management an explicit, board-level obligation for all Authorised Persons and Recognised Bodies. Not a recommendation, not guidance — a requirement, in force since 31 January 2026.
A real document: how you identify, assess and manage cyber risk. It should match the size and complexity of your firm — a three-person advisory firm does not need a bank’s framework. It does need its own.
Your board (or senior management) has to approve the framework and own it. In practice this means cyber risk appears in board minutes at least occasionally — and someone specific is named as accountable. “IT handles it” is not a governance model.
An inventory of your systems and data, classified by how critical they are. I have never seen an assessor reject a firm for having a slightly untidy asset register. I have seen them raise an eyebrow at firms that could not produce one at all.
If a material cyber incident happens — or you suspect one — the FSRA expects to hear about it immediately, and no later than 24 hours after detection. Which quietly implies something bigger: you need a tested process for detecting and escalating incidents in the first place. A notification deadline is only scary if nobody is watching the systems.
Not an annual check-up. Ongoing monitoring of your environment, with evidence that someone actually looks at what the tools produce.
Almost nobody fails on ambition. Firms fail on evidence — and it is usually the same three gaps.
First: the framework exists but was written once and never touched. We did one review where the document still named an employee, Karim, as incident coordinator — Karim had left eight months earlier. Nobody noticed, because nobody had opened the file.
Second: the board “approved” the framework, but there is no trace of it. No minute, no resolution, no signature. If it is not written down, for a regulator it did not happen.
Third: incident response exists on paper but has never been rehearsed. A plan that has never been tested is a hypothesis, not a plan.
If you answered “yes” to all five, you are in better shape than most of the market. If two or more were a “no” — you have a list, and that is honestly a fine place to start.
Here is the part that should lower your blood pressure: the regulator is not hunting for perfection. The framework is proportionate by design. What they want is proof that your firm treats cyber risk as a management topic, not an IT afterthought — a living document, a named owner, a tested process. All of that is achievable for a small firm, often in a few weeks of focused work.
If you would rather not do it alone, this is exactly what we do at TechnoPeak: we build and maintain the framework, keep the evidence audit-ready year-round, and stand next to you when the regulator calls. It starts with a free gap assessment — no obligation, NDA on request.
Marina Ivashina is Head of Compliance at TechnoPeak. She helps DIFC and ADGM firms pass regulatory reviews without drama — and reads the rulebooks so you don’t have to.
Downtime: the profit killer
Core elements every Dubai business should demand
Is it possible to work from home and keep your data safe?
Contact us now – our team is ready to assist you!