Skip to content

Cybersecurity

Find what an attacker would find, before they do.

Penetration testing, cloud posture review and hardening against ISO 27001 and the UAE Information Assurance Standards, with remediation ranked by real exploitability rather than scanner severity.

  • Dubai head office, GCC-wide delivery
  • Arabic and English throughout
  • Written scope and fixed timeline before you commit

You walk away with

  • Penetration testing
  • Cloud posture review
  • ISO 27001 readiness
  • Incident response plan

Typical timeline

3–8 weeks

Typical engagements start around

AED 12,000 per project

What good looks like

unverified findings in a report we hand over
0unverified findings in a report we hand over
window for the included retest
90 dayswindow for the included retest
ranked remediation plan, not a scanner dump
1ranked remediation plan, not a scanner dump

The problem this solves

You have a scanner report with four hundred findings, most of them false, and no idea which three actually matter. Meanwhile the enterprise client you want to sign has sent a security questionnaire with ninety questions, and answering it honestly would lose the deal. Both problems have the same root: nobody has tested what an attacker could really do.

Where this usually hurts

  • Four hundred findings, three that matter

    A scanner report ranked by CVSS knows nothing about your architecture, so the team burns weeks on criticals that are unreachable and misses the medium on the login flow.

  • The security questionnaire is blocking a deal

    An enterprise client sent ninety questions. Answering them honestly loses the deal; answering them optimistically loses it later, at audit.

  • Cloud posture nobody has reviewed

    A public bucket, a wildcard IAM role and a long-lived key in a repository's history. Not clever attacks — the ones that actually happen.

  • Compliance as a document exercise

    Policies were written, nobody follows them, and no one can produce the evidence a control is actually operating.

We test systems the way an attacker would approach them, then help you fix what we found. That means chaining findings rather than listing them: a medium-severity information leak plus a weak password policy plus an over-permissive role is not three mediums, it is one path to your customer database, and it is the only finding on the report that should keep anyone awake.

Exploitability, not severity

Automated scanners rank by CVSS, which knows nothing about your architecture. A critical rating on a service unreachable from the internet, behind an allow-list, holding no sensitive data, is a lower priority than a medium on your login flow. Every finding we report carries the actual path, the actual impact and a reproduction someone on your team can run.

  • Each finding proved with a reproduction, not inferred from a version banner
  • Findings chained into attack paths, which is how they are ranked
  • False positives removed before you see the report, not after you have chased them
  • A retest included once you have fixed things, so the report ends green

Cloud posture is where the real gaps are

In practice, most Gulf breaches we are called about are not clever exploits — they are a public storage bucket, a leaked long-lived key, an IAM role with a wildcard, or an unrotated credential in a repository's history. We review identity, network exposure, secrets handling, logging and backup integrity across your accounts, because that is where the cheap wins live.

Compliance as a by-product

ISO 27001, SOC 2, the UAE Information Assurance Standards and PCI DSS overlap heavily, and none of them are satisfied by a document alone. We map controls to the technical evidence that proves them — logs, configuration, access reviews — so preparing for an audit becomes collecting artefacts you already generate rather than writing policies nobody follows.

A control you cannot produce evidence for is a control you do not have.
— How we scope every readiness engagement

When something has already happened

If you are mid-incident, containment comes before analysis: isolate, rotate every credential in reach, preserve logs before they roll off, and establish what left the building. We help you run that, then produce the timeline and the notification assessment your regulator and your clients will require.

What is included

  • Scoped penetration test

    External, internal, web, API or mobile, with written authorisation and an agreed rules-of-engagement document.

  • Cloud posture review

    Identity, network exposure, secrets, logging and backup integrity across your AWS, Azure or OCI accounts.

  • Ranked remediation plan

    Attack paths rather than a finding list, sequenced by exploitability and the effort each fix costs.

  • Hardening support

    We work alongside your engineers on the fixes, rather than handing over a PDF and leaving.

  • Compliance mapping

    Findings and controls mapped to ISO 27001, SOC 2 or UAE IAS, with the evidence each one needs.

  • Free retest

    One full retest of remediated findings within ninety days, so the report you show clients ends clean.

What we build with

  • Application

    • Burp Suite
    • Nuclei
    • Semgrep
    • OWASP ASVS
  • Cloud & infrastructure

    • Prowler
    • ScoutSuite
    • Trivy
    • CIS Benchmarks
  • Monitoring

    • Wazuh
    • OSQuery
    • Sigma rules

How engagements are sized

Three sizes, so the scope matches the problem rather than the budget matching a template. Every tier is a starting point — the number moves with what we find in discovery, and you see the revised figure before anything is signed.

  • Essential

    One clear problem, scoped tightly and shipped.

    From

    AED 12,000

    per project

    One application or a cloud account, tested and reported.

    • Single-scope test
    • Ranked findings
    • One retest
    Get a firm number
  • Growth

    The full engagement, with measurement and iteration built in.

    From

    AED 40,000

    per project

    External, internal and cloud, with remediation support and compliance mapping.

    • Multi-surface testing
    • Hardening alongside your team
    • ISO 27001 or SOC 2 mapping
    Get a firm number
  • Enterprise

    Multi-entity, regulated, or integrated across several systems.

    From

    AED 110,000

    per project

    Continuous assurance, red teaming, or a full certification readiness programme.

    • Continuous scanning
    • Red team exercise
    • Audit readiness programme
    Get a firm number

Prices are in AED excluding 5% VAT. Other currencies on the pricing page.

How delivery actually runs

The phases below are what a typical engagement moves through, with the durations we plan against. You always know which phase you are in and what leaves it.

See the full process
  1. 1

    Scope and authorise

    3–5 days

    What is in scope, what techniques are excluded, testing hours and an escalation contact — written and signed before anything starts.

  2. 2

    Test

    1–3 weeks

    Manual testing against the agreed scope, chaining findings into real attack paths rather than listing them individually.

  3. 3

    Report and prioritise

    3–5 days

    Findings ranked by exploitability and remediation effort, with an executive summary that a non-technical board can act on.

  4. 4

    Fix and retest

    2–4 weeks

    We work alongside your engineers on the fixes, then retest everything remediated so the report you show clients ends clean.

  • Scope and authorise · You get

    • Rules of engagement
    • Written authorisation
    • Test schedule
  • Test · You get

    • Verified findings
    • Reproduction steps
    • Attack path analysis
  • Report and prioritise · You get

    • Technical report
    • Executive summary
    • Ranked remediation plan
  • Fix and retest · You get

    • Hardening support
    • Full retest
    • Clean closing report

Built for the UAE

What working with a Dubai partner actually changes

Most of what follows is invisible until it goes wrong — a supplier who cannot keep data in-country, an invoice the FTA rejects, a support rota that is asleep for half of your working day. These are the questions we answer before they become findings.

UAE buyers increasingly ask for alignment with the Information Assurance Standards or, in Dubai, the ISR framework, alongside ISO 27001. These overlap heavily, so we map findings to whichever your customer or regulator actually asks for rather than certifying against all of them.

  • Data residency, decided up front

    AWS me-central-1, Azure UAE North and OCI Dubai are all in scope. We map the whole data path — backups, logs, metrics and support access — rather than the primary database alone, and put the result in writing.

  • PDPL, and the free zones

    Federal Decree-Law No. 45 of 2021 governs most of the mainland; DIFC and ADGM entities fall under their own data protection laws instead. We establish which applies to your entity before we design anything that touches personal data.

  • VAT and e-invoicing that pass

    Five per cent VAT, FTA-compliant tax invoices, the audit file the authority can request, and readiness for e-invoicing as the mandate phases in. Configured in the build, not patched after the first filing is rejected.

  • Your hours, your languages

    Delivery runs on Gulf hours with real overlap with your team, in Arabic and English. Customer-facing interfaces, documents and training are produced in both where you need them, with RTL treated as a design requirement rather than a translation step.

Sectors we do this in most

Not the only sectors we work in — the ones where we have shipped this service enough times to know the regulatory edges and the usual traps.

  • Fintech

    Onboarding, KYC and dashboards that build trust and convert.

  • Healthcare

    Compliant, accessible experiences patients actually use.

  • B2B SaaS

    Marketing sites and product UX that feed qualified pipeline.

In-house, generalist agency, or us

An honest comparison, including where the other two options are the better call.

Hiring in-houseWorking with us
Time to first outputThree to five months to source, notice-period and onboard, in a market where senior specialists are scarce and expensive.Two to three weeks from signature, with people who have shipped this before.
Cost shapeFixed monthly cost plus visa, insurance, end-of-service and equipment, whether or not there is a full workload.Scoped to the work. Costs stop when the work does.
Breadth of skillOne or two specialisms per hire. Anything outside them gets improvised or outsourced anyway.Design, engineering, security and growth from the same team, without a handoff between vendors.
Institutional knowledgeStays in the building — which is the real advantage, and the reason to hire eventually.Documented and handed over. We write runbooks so you can take it back in-house.
When it is the wrong choiceRarely, once the workload is genuinely full-time and permanent.If you need someone in your standups every day for years, hire. We will say so.

Questions people ask before starting

Not without your explicit agreement. Rules of engagement are written first: what is in scope, what techniques are excluded, what hours we test in, and who to call if something behaves unexpectedly. Denial-of-service testing is opt-in and separately scoped, never bundled.

Ready to talk about Cybersecurity?

Tell us what you are building and where it is stuck. We will come back with a scope, a timeline and a number — usually within two working days.

Step 1 of 3 · What you need

Which services are you interested in?