Skip to content
Blog

Security Insights & Resources

Expert insights on cybersecurity, compliance frameworks, penetration testing, and security best practices.

Penetration Testing 5 min

The UAE Buyer's Guide to Penetration Testing

Most pen tests sold in the UAE are just scanner reports. An OSCP-certified buyer guide: why you are buying one, the types, how to scope it, what a real engagement looks like, how to read the report, and the red flags when choosing a tester.

Nelson Durairaj May 27, 2026
Compliance 5 min

UAE PDPL Compliance: A Practical Guide to Federal Decree-Law 45 of 2021

The UAE PDPL is its own law, not a GDPR copy. A practical walkthrough: which regime applies to you (PDPL vs DIFC vs ADGM), the core obligations, the implementation journey from data map to training, and the mistakes most UAE businesses make.

Manoj Prabhakaran May 27, 2026
Compliance 5 min

ISO 27001 Certification in the UAE: The Complete Implementation Guide

ISO 27001 is a management system, not a checklist. A Lead-Auditor walkthrough of the 2022 standard: the mandatory clauses, the Statement of Applicability, how Stage 1 and Stage 2 certification actually work, the implementation journey, and the mistakes that fail first attempts.

Manoj Prabhakaran May 27, 2026
Compliance 5 min

ADHICS v2 Compliance: A Practical Guide for Abu Dhabi Healthcare Providers

ADHICS is mandatory for DoH-licensed healthcare entities in Abu Dhabi. A practical Lead-Auditor walkthrough: what it covers, the compliance journey stage by stage, the mistakes we see most, and how to start.

Manoj Prabhakaran May 27, 2026
Compliance 3 min

The real cost of ISO 27001 in the UAE — broken down by company size

AED 36K to 250K+. Why the range is so wide, what drives the cost up, and what an honest scoping conversation looks like.

Manoj Prabhakaran May 2, 2026
Compliance 4 min

Building an ISO 27005-Aligned Risk Register — A UAE SME Playbook

How to build a defensible cybersecurity risk register that satisfies ISO 27001, NESA, and PDPL — with a scoring rubric, template, and common UAE-sector risks.

Manoj Prabhakaran Apr 15, 2026
Penetration Testing vs Vulnerability Assessment — What's the Difference and Which Do You Need?
Penetration Testing 4 min

Penetration Testing vs Vulnerability Assessment — What's the Difference and Which Do You Need?

Pen test vs vulnerability assessment — what you're paying for, what each produces, and which one actually satisfies your ISO 27001 or enterprise client demand.

Nelson Durairaj Apr 15, 2026
Phishing Simulation vs Security Awareness Training — Which Should UAE SMEs Start With?
Training 3 min

Phishing Simulation vs Security Awareness Training — Which Should UAE SMEs Start With?

Most UAE SMEs ask us this: do we run a phishing simulation first, or do awareness training first? Here's the honest answer based on 90-day behaviour data.

Nelson Durairaj Apr 15, 2026
The 7 Azure Misconfigurations We See in Every UAE Assessment
Cybersecurity 3 min

The 7 Azure Misconfigurations We See in Every UAE Assessment

Every UAE Azure tenant we've reviewed shares the same 7 misconfigurations. Here's what they are, why they happen, and how to fix them in an afternoon.

Manoj Prabhakaran Apr 15, 2026
NESA / UAE IA V2 in Plain English — What Every UAE Business Needs to Know
Compliance 3 min

NESA / UAE IA V2 in Plain English — What Every UAE Business Needs to Know

NESA and UAE IA V2 compliance explained without the jargon — what it covers, who it applies to, how it differs from ISO 27001, and what a realistic gap assessment costs.

Manoj Prabhakaran Apr 15, 2026
Why UAE Businesses Can't Afford to Ignore ISO 27001 in 2026
Compliance 4 min

Why UAE Businesses Can't Afford to Ignore ISO 27001 in 2026

With the UAE tightening data protection laws and clients demanding proof of security, ISO 27001 certification is no longer optional — it is a business necessity. Here is what you need to know.

Underwings Team Apr 11, 2026