compliance
DFSA
Compliance
Financial Services
Dubai
DIFC

Meeting DFSA Cyber Regulations in DIFC

Security Engineer
December 7, 2025
7 min read
Meeting DFSA Cyber Regulations in DIFC
Understanding GEN 5.5.5 and 5.5.15: Building genuine cyber resilience for financial firms operating in the Dubai International Financial Centre.

Strengthening Cyber Resilience under DFSA GEN: A Focus on 5.5.5 and 5.5.15

Let's face it, cybersecurity isn't just an "IT problem" anymore. It's a boardroom conversation, a regulator's concern, and for financial firms, a matter of survival. If you're part of a regulated entity in DIFC, you're no stranger to the DFSA. The Dubai Financial Services Authority (DFSA) has been clear about this: if you operate in the DIFC, your resilience against cyber threats isn't optional: it's expected.

The GEN Rulebook lays this out pretty clearly. And two rules in particular stand out:

  • GEN 5.5.5 – Identification and Assessment of Cyber Risk
  • GEN 5.5.15 – Testing the Resilience of ICT Assets and Controls

Think of these two rules as a cycle: one helps you understand your risks, and the other makes sure your defences actually hold up when tested. Together, they move firms away from a "paper compliance" mindset and into real-world resilience.

GEN 5.5.5: Knowing What You Have and What Could Break

You can't protect what you don't know exists. That's the whole spirit of GEN 5.5.5. The DFSA is essentially saying: "Start with the basics. What systems do you have, how important are they, and what could happen if they go down?"

Here's how it breaks down:

Keep a full ICT asset inventory

Every server, cloud service, database, and even those dusty legacy systems sitting in a corner need to be accounted for. If it connects to your business, it's part of your attack surface. Too many firms discover "forgotten" systems only after they've been breached.

Classify by importance

Not all assets are equal. Your client database or trading platform obviously deserves more attention than your office printer. Classification forces firms to think: "If this asset was compromised, what would the impact be?"

Assess threats and vulnerabilities

This is where risk assessment becomes dynamic. Threats evolve constantly — today's issue might be ransomware, tomorrow it could be a supply chain compromise. GEN 5.5.5 pushes firms to consider both what's happening externally in the cyber threat landscape and what's lurking internally in terms of misconfigurations or outdated software. Proper Threat Intelligence.

Understand residual risk and business impact

Even with the best controls, some risk will remain. The question is: how much can your firm live with? The DFSA expects businesses to map residual risk back to board-level risk appetite. In other words: if you say your tolerance for downtime is "near zero," then your cybersecurity measures need to back that up.

The real beauty of 5.5.5 is that it reframes cybersecurity as a governance issue, not just a technical one. It requires firms to tie risk identification into strategy, operations, and investment decisions.

GEN 5.5.15: Putting Defences to the Test

If 5.5.5 is about knowing your risks, 5.5.15 is about proving you can handle them. On paper, many firms look secure. Policies are documented, controls are in place, and risk registers look neat. But the DFSA isn't impressed by pretty paperwork. They want evidence, and not just any evidence. Certified and Accredited evidence. This isn't your every day Penetration Testing/VAPT.

GEN 5.5.15 is where that evidence comes in. It forces firms to test their ICT assets and controls under real-world conditions.

Here's what that looks like in practice:

Run a structured testing programme

Testing isn't just about firewalls and antivirus. The DFSA expects firms to test across the board: processes, detection systems, incident response, and even employee awareness. If a phishing simulation catches 30% of your staff, that's a resilience gap just as much as an unpatched server.

Test regularly (and risk-based)

Annual penetration testing on internet-facing systems is the baseline. But that's not enough. If you've just launched a new platform or handle high-risk transactions, regulators expect more frequent testing. One-size-fits-all doesn't work here.

Use a mix of testing methods

Vulnerability scans are the start, not the end. The DFSA points to:

  • Vulnerability assessments
  • Scenario-based simulations
  • Penetration testing
  • Red team exercises

Each has a different purpose: scans find weaknesses, pen tests show how attackers could exploit them, and red teaming challenges your ability to detect and respond under pressure. Be careful here, as not many Cyber Security Companies can provide these, even though they say they can. DFSA doesn't care about their marketing materials, they care about their capabilities.

Prioritise remediation

Testing without fixing is pointless. GEN 5.5.15 stresses remediation and continuous improvement. The results should feed straight back into risk assessments under 5.5.5, creating a feedback loop: assess → test → fix → reassess.

This is what separates true resilience from checkbox compliance.

The Power of the 5.5.5 + 5.5.15 Loop

Individually, these rules are strong. Together, they're driving your security forward.

  • 5.5.5 asks: "What assets matter most, and what risks do they face?"
  • 5.5.15 asks: "Can those assets withstand real-world attacks?"

For example, imagine your 5.5.5 assessment highlights your online banking system as critical and high-risk. Under 5.5.15, that system isn't just listed in a register; it's subjected to penetration testing, Threat Led Penetration Testing (TLPT) or even red teaming to prove it can stand up to an attack.

The results then flow back into your risk assessment. Maybe you discover multi-factor authentication was misconfigured. That residual risk level just went up, and now the board needs to know.

This continuous cycle — identify, test, remediate, reassess is exactly the resilience model the DFSA wants firms to embed.

What This Means for Firms

For those operating in the DIFC, GEN 5.5.5 and 5.5.15 aren't just more boxes to tick. They come with real implications:

Governance integration: Cyber resilience must sit on the board agenda. Risk appetites, budgets, and investments all flow from this.

Evidence of compliance: Regulators will want to see inventories, classifications, test reports, and remediation plans — not just policies.

Resource commitment: Building inventories, running regular tests, and hiring external red teams isn't cheap. But neither is a breach.

Stronger resilience: Ultimately, this isn't just about avoiding fines. It's about building trust in your firm's ability to withstand cyber shocks and protect clients.

Closing Thoughts

The DFSA's approach here is refreshingly pragmatic. They're not asking firms to chase perfection. They're asking them to be realistic: know your assets, know your risks, and then prove, with evidence, that your defences work.

GEN 5.5.5 and GEN 5.5.15 work hand-in-hand to create that resilience loop. Done properly, they turn cybersecurity from a compliance exercise into a living, breathing part of business operations.

Because at the end of the day, resilience isn't about looking secure on paper. It's about being able to take a punch and keep moving. And in today's financial world, that's the difference between a minor incident and a business-ending event.

This likely doesn't come as a surprise to anyone in DIFC, but it may open eyes to what true regulatory compliance looks like. This isn't some quick fix risk assessment and the cheapest VAPT you can find. This is protecting your business, your reputation and your customers, with accredited and certified regulatory compliance. If you're not convinced your current testing provider is capable, please reach out to our team who will be happy to discuss.