INSIGHTSINSIGHT
BEYOND NUMBERS

AI, Technology & Digital Assets · 8 July 2026 · 10 min read

UAE Cyber Resilience: A Board Operating Model for Third-Party and Ransomware Risk

Boards can strengthen cyber resilience by governing critical services, identity, suppliers, recovery and incident decisions as one operating system.

Akash Chetwani, CFASenior Partner · AdvisoryIRAA Global

Contents

AI, Technology & Digital Assets · 10 minute read · July 2026
IRAA INSIGHTSAI, Technology & Digital Assets · Perspective

Cyber resilience is the ability to keep critical operations safe, make informed decisions during an attack and recover to a trusted state. It requires board ownership of business risk, not only a technology team’s list of security tools.

The UAE Information Assurance Regulation provides a risk-based control reference for implementing entities, while the National Cloud Security Policy addresses governance, data lifecycle, location, identity, incident handling, supply chain and resilience for cloud consumers and providers. Other sector and contractual requirements may also apply.

Identify revenue, payment, customer, production, payroll and regulatory processes that cannot tolerate prolonged disruption. Map their applications, infrastructure, data, identities, facilities and third parties. Set recovery time and recovery point objectives approved by business owners.

An asset inventory should include cloud resources, software-as-a-service, endpoints, network devices, code repositories, domains, certificates and operational technology. Unknown assets cannot be patched, monitored or recovered.

Classify data by sensitivity and operational importance. Apply protection through its lifecycle, including creation, use, sharing, archive and deletion.

Require multifactor authentication for remote and privileged access. Use named accounts, least privilege and periodic access recertification. Remove access promptly when roles change or employment ends.

Separate administrator and ordinary accounts. Protect emergency accounts, service identities, API keys and secrets. Monitor unusual privilege, impossible travel, repeated authentication failure and changes to security controls.

Payment and supplier-master changes should require independent verification and dual approval. Cybercrime frequently becomes financial loss through manipulated email or identity rather than technical intrusion alone.

The UAE National Cloud Security Policy emphasises governance, contractual protection, data location, supply-chain security, identity, incidents and portability. Before onboarding a provider, understand processing locations, sub-processors, encryption, access, logs, backup, recovery and exit.

Contract for incident notification, evidence, support, audit information, service continuity, deletion and return of data. A certification is useful evidence but does not establish that the service configuration is secure for the company’s use.

Concentrations deserve board visibility. Several critical systems may rely on one cloud region, identity provider or managed-service company. Test failure of the shared dependency.

“A backup is not a resilience control until the business has restored it within the required time.”

Maintain protected, tested backups separated from normal administrative credentials. Define isolation procedures, clean recovery environments, forensic preservation and the order in which services return.

The incident plan should name executive, technical, legal, privacy, communications, finance and insurer roles. Maintain offline contacts. Decisions about law enforcement, customers, authorities and any demand require coordinated legal and risk assessment.

Federal Decree-Law No. 34 of 2021 criminalises unauthorised access and interference with systems and data, among other cybercrimes. Preserve evidence and use official reporting channels. Do not engage attackers through improvised individual action.

An incident can trigger personal-data obligations depending on the facts and applicable regime. The response team should determine data types, individuals, locations, confidentiality, availability, likely consequences and containment.

Keep a decision log and protect legal privilege where applicable. Communications should be accurate and consistent; premature certainty can compound operational damage.

After recovery, investigate root cause, persistence, control failure and lessons. Track remediation to verified closure rather than declaring success when systems restart.

Useful metrics include critical assets covered, privileged access reviewed, vulnerability remediation by risk, phishing reports, backup restore success, incident containment time, vendor findings and overdue actions. Avoid a single score that hides control failure.

Run technical tests and executive simulations. A tabletop exercise should force decisions about shutdown, manual operation, customer communication, regulator engagement and recovery priority. Record actions and repeat the scenario after remediation.

01

Map: Identify critical services, assets, data and dependencies.

02

Protect: Strengthen identity, endpoints, networks and data.

03

Govern: Control cloud, suppliers, contracts and concentration.

04

Recover: Test isolated backups and clean restoration.

05

Exercise: Rehearse executive, legal and communications decisions.

06

Improve: Verify remediation and retest material controls.

Cyber resilience is demonstrated in operation: access is controlled, suppliers are understood, recovery works and leaders can make difficult decisions from reliable information. That capability protects customers and enterprise value more effectively than any one security product.

A response plan should specify who may isolate systems, suspend customer services, activate manual procedures, engage external specialists and approve public or regulatory communications. It should also identify deputies and secure communication channels in case corporate email or identity services are unavailable. These choices become slower and more contentious when they are first debated during an attack.

Ransomware planning should address the business consequences of encryption, theft and extortion separately. Restoring systems does not resolve stolen information, and a ransom demand does not prove that data will be deleted. Legal, privacy, insurance, law-enforcement and sanctions considerations may affect the available options. The executive team should know which advisers to contact and what evidence must be preserved without allowing an untested playbook to dictate a decision automatically.

Third-party assurance should be proportionate to the service. For a provider supporting identity, payments, customer data or core operations, ask how privileged access is controlled, how incidents are detected and notified, how backups are isolated, where data and administrators are located, which sub-processors are material and how service can be exited. Certifications can support the review, but they should not replace analysis of the actual service and contract.

Concentration deserves board attention. Several apparently separate applications may depend on one cloud region, identity provider, managed service or telecommunications route. Map those common dependencies and test whether the documented recovery strategy survives their loss. Contractual recovery objectives should be compared with the time the business can tolerate, and gaps should have a named owner and funded treatment.

After exercises and incidents, verify closure rather than accepting a list of recommendations. Evidence might include restored data, revised access, corrected monitoring, updated contracts and repeated simulation. A small set of tested controls and clear decision rights gives the board a more reliable view of resilience than a large dashboard of unverified security activity.

Official UAE government references. Links verified 10 August 2026.

  1. UAE Information Assurance Regulation
  2. UAE National Cloud Security Policy
  3. Federal Decree-Law No. 34 of 2021 on Cybercrimes

Online edition: https://iraaglobal.com/insights/uae-cyber-resilience-board-third-party-ransomware/

Continue reading

More insight for the decisions ahead.

Keep exploring practical guidance from IRAA Global, or move from reading to a focused conversation with our advisory team.

More from Akash Chetwani, CFAView the contributor profile and latest articles.Explore all insightsBrowse tax, accounting, governance and business guidance.Corporate Tax & VATReview IRAA Global tax and compliance capabilities.Book a consultationDiscuss the priorities and evidence relevant to your business.

Continue online: www.iraaglobal.com/insights

About the contributor

Akash Chetwani, CFA

Akash Chetwani, CFA

Senior Partner · Advisory

Cross-border advisory for professionals, founders, investors, and globally connected families.

Phone+971 56 921 0222
Emailinfo@iraaglobal.com
ProfilesIRAA Global on LinkedIn · Contributor page and articles

IRAA Insights brings specialist analysis into a clear editorial format for business leaders, investors, founders, and globally connected families.

Company structure

Our company network.

The IRAA brand operates through affiliated entities registered in Dubai Mainland and a partner-firm arrangement. Each entity is a separate legal entity and operates independently.

Dubai Mainland

IRAA Accountants LLC

Company activity

Accounting, bookkeeping and tax-support engagements, subject to the agreed scope.

Dubai Mainland

IRAA Management Consultants LLC

Company activity

Management, business and finance advisory engagements.

Dubai Mainland

IRAA Properties LLC

Company activity

Property-related advisory and support activities.

Partner firm

Rays and Insight Chartered Accountants LLC

Company activity

Audit and assurance engagements delivered through the partner firm.

Iraa Global LLC FZ owns and manages the IRAA brand. Client services are delivered through the relevant affiliated entity or partner firm for each engagement.

Company information: www.iraaglobal.com/company

IRAA GLOBALAudit · Tax · Advisory

A connected advisory firm for businesses operating across borders.

Core services

Audit & AssuranceCorporate Tax & VAT
Business SetupAccounting & Bookkeeping
Risk & Regulatory AdvisoryAnti-Crisis Management
India-UAE AdvisoryPrivate Advisory
IRAA Insights

Insight beyond
numbers.

What Next?

IRAA Global

Dubai office503 Mustafawi Carpet Building
Sharaf DG Metro Exit 1
Dubai, United Arab Emirates

Contact+971 56 921 0222
+971 50 677 9455
info@iraaglobal.com
www.iraaglobal.com

Layout & Design by Suresh Tamang