UAE Cyber Security Compliance Training

Yellow circular logo with intertwined abstract shapes next to "Business Continuity Management (BCM).
EASMLens external attack surface management platform logo
NSPM network security policy management logo
PhishLens phishing simulation and awareness logo

Our UAE cyber security training helps government entities, healthcare providers, financial institutions and their suppliers meet the UAE Information Assurance Standard, the Dubai Information Security Regulation (ISR), ADHICS, financial regulator rules and UAE data protection law. SSC delivers practical courses live online or on-site in Dubai, Abu Dhabi and across the Emirates.

Emirati and expatriate professionals at a training table in a high-rise office with a Gulf city skyline, representing UAE cyber security training
UAE requirements depend on your emirate, sector and free zone, and training should match.

UAE cyber security training courses at a glance

CourseTypical durationBest for
UAE Information Assurance Standard practitioner3 daysFederal and semi-government entities, critical infrastructure and contractors
Dubai ISR practitioner2 daysDubai Government and semi-government entities and their suppliers
ADHICS for healthcare2 daysAbu Dhabi healthcare providers, insurers and health technology suppliers
Cyber risk for UAE financial institutions2 daysCBUAE, DFSA and ADGM regulated firms
UAE data protection: PDPL, DIFC and ADGM1 dayData protection officers, legal, privacy and IT teams
Internal auditor for UAE frameworks3 daysInternal audit and compliance teams

UAE Information Assurance Standard and Dubai ISR

The UAE Information Assurance Standard, formerly known as the NESA standard, organises controls into management and technical families and prioritises them, with a documented risk assessment deciding which controls apply beyond the core set. The Dubai Information Security Regulation, issued by the Dubai Electronic Security Center (DESC), applies to Dubai Government and semi-government entities and flows to their contractors and suppliers. Its latest version strengthens cloud security, data residency for critical information, IoT and OT security, and supply chain controls.

UAE IA and Dubai ISR practitioner

Typical duration: 2 to 3 days. Who it is for: security, risk and IT teams in entities subject to the UAE IA Standard or the Dubai ISR.

  • Applicability, roles and the structure of each framework
  • Risk assessment and control selection, and the documented statement of applicability
  • Third-party, cloud and data residency requirements
  • Preparing for compliance assessments and evidencing controls

You will be able to: assess your organisation against the framework that applies and plan the work to close gaps.

ADHICS for Abu Dhabi healthcare

Hospital IT and clinical team reviewing a secure records interface on a tablet, representing ADHICS healthcare information security training
In Abu Dhabi healthcare, information security is a condition of licensing and connection to shared health records.

The Abu Dhabi Healthcare Information and Cyber Security Standard (ADHICS), issued by the Department of Health, applies to licensed healthcare facilities, insurers and health technology providers. Version 2, effective from August 2024, groups controls into Basic, Transitional and Advanced levels, so requirements scale with the size of the organisation. Our course covers the domains, control levels, audit preparation and the data breach reporting process.

Financial services and data protection

Financial services professionals reviewing a risk dashboard in a glass-walled office, representing cyber risk training for UAE financial institutions
Each UAE financial regulator sets its own incident reporting clock.
  • Central Bank of the UAE: the operational risk management regulation that took effect in September 2026, with technology, cyber and business continuity requirements and tight incident notification timeframes.
  • DFSA and ADGM FSRA: cyber risk management rules for firms in the DIFC and ADGM, including board oversight, multi-factor authentication, testing and incident notification.
  • Data protection: the UAE Personal Data Protection Law, Federal Decree-Law No. 45 of 2021, for onshore organisations, and the separate DIFC and ADGM data protection regimes for firms in those free zones.

How the UAE framework training is delivered

  • Live online. Instructor-led virtual classes over Microsoft Teams or Zoom, with breakout exercises, shared workbooks and the option to split longer courses into half-day sessions across a week or two.
  • On-site at your premises. Private training for your team at your office, delivered by a consultant who can use your own policies, systems and examples in the exercises.
  • Private and tailored. Every course can be run for a single organisation, with case studies drawn from your sector and the depth adjusted to your team’s experience.

For Gulf clients, sessions can be supported with bilingual English and Arabic materials on request.

What participants receive

  • A course workbook and the slides used in class
  • Reusable templates and checklists, such as audit checklists, risk registers and report formats, depending on the course
  • A case study pack and practice questions
  • A certificate of completion from Security Solution Consultants

Certificates and accredited exams

Every participant who completes a course receives a certificate of completion from Security Solution Consultants. Lead Auditor and Lead Implementer courses can include an accredited certification exam through our accredited training partner, for standards where the partner offers one. Your quote confirms the exam body, exam format and certificate for each course, so there are no surprises on the day.

Why train with SSC

  • Taught by practitioners. Our trainers are working consultants and auditors who work with UAE government, healthcare and financial clients and build UAE framework modules into GRCLens, so examples come from real engagements rather than slides.
  • We hold ourselves to the same standard. SSC is certified to ISO/IEC 27001 and follows a Secure by Design approach. See our Trust Centre.
  • Hands-on with real tools. Exercises can use GRCLens, the GRC platform built by SSC, so participants practise with risk registers, control libraries and evidence the way they will at work.
  • Training that connects to delivery. If your team needs help after the course, the same people can support implementation, internal audits and certification readiness.

Related: the GRCLens UAE IA, Dubai ISR, ADHICS modules and the UAE framework pack. See all training courses.

Frequently asked questions

It depends on your emirate, sector and free zone. Federal and critical entities follow the UAE IA Standard, Dubai Government entities the Dubai ISR, Abu Dhabi healthcare ADHICS, and financial firms their regulator's rules. The training starts by mapping what applies.

The national information assurance standard, formerly known as the NESA standard, with management and technical control families prioritised by risk. It applies to federal and semi-government entities, critical infrastructure and their contractors.

Healthcare facilities licensed by the Abu Dhabi Department of Health, health insurers and health technology providers. Version 2 scales requirements through Basic, Transitional and Advanced control levels.

No. Firms in the DIFC and ADGM follow their own free zone data protection laws. Onshore organisations follow the federal PDPL. Our data protection course covers all three.

Yes. We deliver private on-site courses across the UAE, as well as live online classes.

Plan UAE cyber security training for your team

Tell us how many people need training, which courses interest you, and whether you prefer live online or on-site delivery. We will come back with a tailored proposal and quote.

Prefer email? Write to info@secsolutionshub.com