ALTALLO

Discover service providers, without the noise.

One Firm, Three Regulators: Navigating Cybersecurity Across London, Abu Dhabi and Dubai

By: Abacus · Published: 2026-09-16

Abacus maps the FCA, DFSA and FSRA cybersecurity, data transfer and accountability requirements facing investment firms expanding into the UAE.


Abacus ADGM Series, Paper 2. One Firm, Three Regulators: Navigating Cybersecurity Across London, Abu Dhabi and Dubai.

For alternative investment firms, expansion into the Gulf is rapidly becoming a question of when, not if. In the first half of 2025, the Dubai International Financial Centre (DIFC) reported 440 wealth and asset management companies, including 85 hedge funds, while Abu Dhabi Global Market (ADGM) reported 154 asset and fund managers overseeing 209 funds. Those figures represent six-month increases of approximately 13% in DIFC hedge funds and 26% in ADGM funds.

Yet opening an office is the straightforward part. The more consequential challenge for CTOs and CFOs is extending a UK control environment across two UAE financial centers and three regulators, and then meeting their distinct requirements for cybersecurity, data protection and regulatory accountability.

The FCA foundation. For firms already regulated by the UK Financial Conduct Authority, much of the required cybersecurity foundation should already exist. The FCA expects firms to identify and manage technology and cyber risks through effective governance, proportionate systems and controls, operational resilience arrangements, and appropriate oversight of outsourced service providers.

The FCA does not prescribe a single cybersecurity framework. Requirements arise across the Principles for Businesses, SYSC rules, operational resilience rules, outsourcing guidance, data protection law, and regulatory notification obligations. A fund manager must demonstrate that cyber risk is understood, governed, and managed consistently across governance and strategy, risk management, service mapping and design, service continuity, change management, incident management, third-party management, identity and access management, threat and vulnerability management, and physical security.

A well-run FCA-regulated manager will already possess many of the policies, governance structures, and technical controls expected by the Dubai Financial Services Authority and the Financial Services Regulatory Authority. The mistake is assuming that the FCA control environment can simply be copied into the UAE without considering local legal entities, regulatory reporting lines, data-transfer rules, and accountability requirements.

Data location is not the same as data sovereignty. Neither the DIFC nor ADGM should automatically be interpreted as requiring every system or dataset to be hosted physically within the UAE. The more important issue is whether personal, confidential, and regulated information remains subject to lawful processing, controlled access, and valid cross-border transfer arrangements.

Under Article 26 of DIFC Data Protection Law No. 5 of 2020, personal data may be transferred outside the DIFC where the destination provides an adequate level of protection. Where adequacy is unavailable, the exporting organization must generally establish another lawful mechanism, such as appropriate safeguards, recognized contractual clauses, or a relevant statutory exception. ADGM's Data Protection Regulations 2021 also follow a similar model for international transfers.

Firms should map where investor, employee, trading, and compliance data is stored, accessed, backed up, and supported. They should document the legal basis for each transfer, check whether administrators and cloud providers use offshore support locations, implement approved contractual safeguards, and ensure regulators can obtain timely access to records. Encryption and regional cloud hosting can reduce risk, but neither replaces the legal transfer assessment.

Local accountability must be visible. UAE regulators expect cybersecurity ownership to exist within the regulated entity, not solely at a London headquarters or global managed service provider. DFSA GEN 5.5.2 and FSRA GEN 3.5.1 require regulated firms to establish and maintain an appropriate Cyber Risk Management Framework. The governing body and senior management must receive meaningful cyber risk information, approve the framework, and be able to explain material exposures, dependencies, and remediation decisions.

Group policies can remain global, but local responsibilities should be documented through board terms of reference, delegated authorities, incident escalation matrices, and named regulatory contacts. The local entity must retain sufficient knowledge and control to oversee outsourced technology functions. Outsourcing operational activity remains viable in the region but does not outsource regulatory accountability.

FSRA-regulated firms are expected to notify the regulator promptly of significant events affecting the firm, including material technology or cyber incidents. A response plan should specify who determines materiality, who can contact the FSRA outside normal business hours, how evidence is preserved, and how initial notifications are supplemented as facts develop. Firms should not wait for forensic certainty before escalating a potentially significant incident.

Treat the DFSA control mapping as the implementation plan. DFSA GEN 5.5.2 requires a regulated firm to establish and maintain an appropriate Cyber Risk Management Framework. The DFSA's associated cyber risk expectations broadly align with established frameworks such as ISO 27001 and the NIST Cybersecurity Framework, covering governance, identification, protection, detection, response, and recovery.

Rather than maintaining a separate narrative claiming that an FCA program is equivalent, firms should map each DFSA expectation directly to a policy, control owner, operating procedure, and item of evidence. This commonly identifies explicit local board reporting, DIFC-specific breach and notification workflows, locally accountable control owners, documented threat-intelligence processes, more formal cyber metrics, UAE legal-entity asset inventories, and evidence that regional third parties are continuously monitored.

The objective is not to build three security programs. It is to establish one global control framework with jurisdiction-specific overlays for the FCA, DFSA, FSRA, UK GDPR, DIFC data protection law, and ADGM data protection regulations. Success depends on disciplined scoping, control mapping, local accountability, and pre-opening testing, rather than a last-minute compliance exercise.

Read Paper 1, Complexity and Cyber Risk, at https://www.altallo.com/perspectives/abacus-complexity-and-cyber-risk-gulf-expansion. Abacus profile on ALTALLO: https://www.altallo.com/marketplace/vendors/abacus. Abacus website: https://abacustechnology.com. This paper is provided for general information and is not advice on any specific firm, jurisdiction, or arrangement.

← Back to all Perspectives