HomeFrameworksDFSA Cyber Risk
Dubai Financial Services Authority (DFSA) · United Arab Emirates (DIFC)

DFSA Cyber Risk Management Rules (GEN 5.5) compliance software

The DFSA's Cyber Risk Management Rules for every DIFC Authorised Firm, transcribed from the Rulebook paragraph by paragraph — 51 obligations across seven sections, with the 72-hour notification clock as a rule of its own.

At a glance
  • RegulatorDubai Financial Services Authority (DIFC)
  • InstrumentDFSA Rulebook GEN 5.5, RMI361/2023 — in force 1 January 2024
  • Structure7 sections, 18 Rules (5.5.2–5.5.19), 51 assessable paragraphs
  • NotificationMaterial Cyber Incident to the DFSA within 72 hours, via the DFSA portal
DFSA Cyber RiskAvailable
Overview

What DFSA Cyber Risk requires

Who it applies to

  • DFSA Authorised Firms — banks, asset managers, brokers, insurers and intermediaries in the DIFC
  • Authorised Market Institutions
  • Registered Auditors and Credit Rating Agencies
  • Groups with entities in both DIFC and ADGM, which answer to the DFSA and the FSRA respectively

The Dubai Financial Services Authority regulates financial services in the Dubai International Financial Centre. Its Cyber Risk Management Rules — GEN 5.5 of the General Module, made under RMI361/2023 and in force since 1 January 2024 — apply to every DFSA Authorised Firm, Registered Auditor, Credit Rating Agency and Authorised Market Institution.

The Rules require a written Cyber Risk Management Framework approved by the Governing Body and reviewed at least annually; governance that places ultimate responsibility on the board and senior management and defines a Cyber Risk tolerance; an ICT asset inventory and regular risk assessment; a set of protective measures from anti-malware and network security through least-privilege access, MFA for internet-facing and privileged access, change and patch management, encryption, physical security and annual training; a resilience-testing programme with internet-facing systems tested at least annually; continuous monitoring, a tested Cyber Incident Response Plan and responsible recovery; and notification of material Cyber Incidents to the DFSA within 72 hours.

The DFSA does not prescribe a framework — ISO/IEC 27001, NIST CSF, CIS Controls, CPMI-IOSCO and the CSA CCM are all acceptable bases — but its 2024 Cyber Thematic Review examined firms against these Rules in detail. GRCLens carries the Rules as they are written, each 'must' paragraph as its own assessable control with the DFSA's own Guidance beside it, so an ISO-based programme can show the DFSA exactly which Rule each control satisfies.

In the platform

How GRCLens supports DFSA Cyber Risk

DFSA Cyber Risk runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.

Rulebook wording, paragraph by paragraph

Each 'must' is a control with its Rule and paragraph cited — 5.5.9(b), 5.5.17(3) — and the DFSA's Guidance for that Rule beside it, so the assessment reads the way the Rulebook does.

Six indicators the DFSA would ask about

72-hour notification readiness, framework and governance, third-party ICT risk, access and MFA, resilience testing, and the protection baseline — each a count of unmet Rules with thresholds set low, because a rule breach is a finding at one.

Beside the FSRA catalogue

The ADGM GEN 3.5 catalogue has the same seven-part shape. A group with a DIFC and an ADGM entity reads two dashboards with the same sections and evidences shared controls once.

Mapped to the standard you already run

ISO/IEC 27001 Annex A and the Rules share most of their substance. Controls assessed for the ISO programme are reused, and the gap the DFSA cares about — the Rules with no ISO counterpart, such as 72-hour notification — is shown as such.

Questions

DFSA Cyber Risk frequently asked questions

Does the DFSA require a specific cybersecurity framework?

No. The DFSA does not prescribe a framework but expects the Cyber Risk Management Framework to be consistent with the G7 Fundamental Elements of Cybersecurity for the Financial Sector, and its Guidance names ISO/IEC 27000, NIST CSF, CIS Controls, CPMI-IOSCO and CSA CCM as acceptable bases. GRCLens assesses against the Rules themselves and maps them to whichever standard the firm runs.

How quickly must a Cyber Incident be reported to the DFSA?

GEN 5.5.19 requires notification as soon as reasonably practicable and in any event no later than 72 hours after the firm becomes aware, or has information reasonably suggesting, that a material Cyber Incident has occurred, using the form on the DFSA electronic portal.

We are regulated by the FSRA in ADGM, not the DFSA. Which module applies?

The ADGM FSRA Cyber Risk Management catalogue (GEN 3.5). The two regimes are similar in shape but differ in detail — the FSRA's notification window is 24 hours, for instance — so GRCLens carries them as separate frameworks. A group with entities in both runs both.

Talk to us about DFSA Cyber Risk

Security Solution Consultants provides DFSA cyber risk readiness and advisory alongside the platform, so you can combine tooling with hands-on expertise.