Home
VAPT Web Application PentestAPI PentestMobile App PentestInfrastructure PentestAI & LLM PentestOT / ICS PentestIoT PentestPenetration TestingAll VAPT services
Red Team Red Team EngagementAdversary SimulationAssumed BreachPurple TeamingSocial Engineering
CompanyResourcesBlogFree Consultation

Authorising a Red Team under UAE law: the letter, and what it cannot cover

Every step of a Red Team is an offence without consent. What the authorisation letter has to say under UAE law, who can sign it, and what no client can authorise.

Joel Aviad OssiJoel Aviad OssiRed Team Lead, RedTeam Security
7 min read
A folded letter under a red wax seal on a dark desk, a fountain pen laid across it, a brass key and a blank access card beside it, and a red thread running from the seal to a small steel door standing at the desk's edge.

Key takeaways

  • Unauthorised access, a message under a false identity and entry by deception are all offences in the UAE. The authorisation letter is the consent that takes a Red Team outside them, and nothing else does.
  • Consent reaches only what the signatory owns. Your systems, premises and staff can be authorised; a supplier's systems need the supplier's letter; and nobody can authorise imitating a real bank, regulator or ministry.
  • The letter names the objective, the exclusions, the hours, the pretext limits, the white team and an expiry date. What it does not name is not authorised, and the operators ask rather than interpret.
  • Records reached during the exercise are still personal data. The contract makes the provider a processor, evidence stays in the country unless the contract says otherwise, and proof of reach is never a copy of the record.
  • Physical work runs on the letter in the operator's pocket and a number that answers at three in the morning. A guard who ends the exercise with one call has done the job correctly.

Described in legal terms rather than in ours, a Red Team engagement is a list of things that are crimes when done without permission. Accessing an information system without authorisation, obtaining data from it, sending a message under an identity that is not yours: Federal Decree-Law No. 34 of 2021 on Countering Rumours and Cybercrimes covers each of those. Entering a building by deception is not a cyber matter at all. It is trespass, unless the occupier consented. What takes the exercise outside those offences is the written consent of the person entitled to give it, dated before the first action. The authorisation letter is that consent. It is not paperwork attached to the engagement; it is the engagement's legal existence.

This weighs more heavily on a Red Team than on a penetration test. A penetration test is announced, windowed and scoped to named systems, so the consent lives in the scope table and everyone who might see the traffic has been told. A Red Team runs unannounced, and the people who notice it have not been told. The analyst who sees a beacon, as the piece on what your SOC should catch describes, the guard who sees a stranger on the third floor, the clerk who receives the email: each is entitled to treat it as real, and each is entitled to call the police. The letter is the only document that can end that call correctly.

This article names instruments and not article numbers, on purpose. Numbering moves between amendments, and a letter that quotes an article is no more valid than one that does not. Read the decree-law in the version in force.

What you can authorise, and what nobody can

Consent reaches only what the signatory has authority over. Your systems, your accounts, your buildings and your staff in their working capacity can all be authorised by a person with the standing to do it. A supplier's systems are not yours to authorise, even where they hold your data, and a supplier path into your estate, one of the realistic routes an operator takes, needs the supplier's own written consent or it is excluded. Hosted infrastructure is the same in a quieter form: the hosting provider's testing policy sits on top of your letter, and where it asks for notice, notice is given first.

Impersonation is the harder line. Your own IT desk, your HR process and your visitor procedure can be imitated, because you can consent to it. A real bank, a regulator, a ministry or another company cannot be, because their identity is not yours to lend, and the cybercrime law treats a message or a site falsely attributed to another entity as an offence in its own right. The social engineering rules published on this site exclude it outright, and a provider offering a pretext dressed as a supervisor's notice is offering you an offence with a report attached. The matrix draws the four cases, and the excluded corner is where the most convincing pretexts live. Realism is the argument for a Red Team, and the letter is where realism meets its limit.

Where a client's consent runs out. The bottom-right cell is the one a realistic pretext drifts towards, and the letter cannot follow it there.

What the authorisation letter has to say

The letter is short and specific. It names the objective in the language of the business, the systems and people excluded, the hours, the techniques permitted and refused, the limits on pretexts, the white team by name and telephone number, and the date it expires. What it does not name is not authorised. Operators do not read silence as permission; they ask the white team, and the answer is countersigned onto the letter. NIST SP 800-115 places the rules of engagement and the written authorisation in the planning phase, before any technical work, and nothing about a Red Team changes that order.

Written generically, as an example, the first two clauses read like this. Objective: demonstrate the ability to submit a payment for approval in the treasury system, without submitting one; proof of reach is a screenshot of the approval queue showing the operator's session and a record identifier, nothing more. Excluded: the core ledger, the trading platform, and any system operated by the payments supplier, which has not consented. Those two lines settle what a screenshot may contain and which route is closed, before the first email is sent.

The table sets out the rest of the clauses and the reason the law needs each. A letter that skips a row is not shorter. It is silent on something the operators will meet.

The clauses a Red Team authorisation letter carries, what each one says, and the legal reason it has to be there.
ClauseWhat it saysWhy the law needs it
SignatoryName, title, and the authority held over every system and premises namedConsent is valid only from someone entitled to give it
Objective and proofThe asset in business language, and exactly what counts as proof of reachProof of reach is access; a copy of the record is data taken without cause
ExclusionsSystems, people, suppliers and locations the operators may not touchWhat is outside the signatory's authority cannot be authorised by them
Techniques and pretextsPhishing, calls, physical entry, each yes or no, with the pretext limitsImitation has to be consented to, and some of it cannot be
Hours and expiryThe working windows, the end date, and how an extension is signedAn expired letter authorises nothing
White teamTwo to four named people, their numbers, and the authority to haltThe number a guard or an analyst calls has to be answered
Data handlingWhat evidence is kept, where it is stored, and when it is destroyedA record reached in the exercise is still personal data

From scoping to a letter in the operator's pocket

The letter is the last thing signed, not the first thing drafted. The objective and the exclusions come out of the scoping session, third-party consents are requested as soon as a supplier or a hosting path is in the picture, and only then is the signatory confirmed against everything the draft names. The order matters because a signatory found first tends to be senior rather than entitled: a board member can authorise a great deal and still cannot authorise a supplier's network. The white team is named and the attribution channel tested before signature.

During the run, the letter is a living document in one narrow sense. A new pretext, a host that turns out to be in scope, or a week's extension is a new consent, countersigned onto the letter rather than agreed on a call. An assumed breach exercise needs the same letter with a shorter first phase, because the foothold is granted rather than earned and there is no route in to authorise.

The signatory is confirmed last, against the finished draft, because a signatory chosen first is usually senior rather than entitled.

The data the operators reach is still personal data

Reaching the objective usually means reaching records: a customer list, a patient index, an approval queue. The proof the engagement needs is that the operators could act, not a copy of what they could act on: a record identifier, a row count, a hash of a file never opened. Nothing is exfiltrated in earnest, and a credential captured on the way is recorded as a fact and discarded. Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data applies on the mainland and in free zones without a data protection law of their own; the DIFC and ADGM have theirs, and government and health data sit under separate instruments, as the federal summary of the data protection laws sets out. Under every one of them, a provider holding evidence that identifies a person is processing personal data on your behalf, and the contract has to say so.

Two clauses follow. Evidence stays in the country unless the contract names where else it may go, because moving it is a transfer and each regime restricts transfers. And retention is written down: how long the evidence is held, where, and when it is destroyed. The evidence pack an examiner reads, described in the UAE rules that expect a Red Team, is built from this material, so the retention clause decides what can still be shown a year later.

When a guard stops an operator

Physical entry is where the letter stops being a file and becomes an object. Every operator carries it on every physical task, and the number printed on it rings a line that passes through nothing being tested. The figure draws the encounter the letter exists for. A guard challenges someone on a floor they should not be on, the operator produces the letter, the guard calls the number, and the white team confirms the exercise and decides whether it continues. The guard has done the job correctly at every step, including the one that ended the exercise, and the report says so.

What must not happen is a negotiation at the door. An operator who argues, or a guard persuaded by the letter alone without making the call, has turned a control into a conversation. The white team's answer is timestamped and scored as a detection, as an analyst's ticket is, which is why the white team is chosen for being reachable rather than senior. If the call goes to the police instead, the letter and the same number resolve it, and the exercise pauses until it is resolved.

The letter is written for this call. Security ends the exercise with one call and is right to, and the white team's answer is scored as a detection.

Signing in Dubai and Abu Dhabi: whose authority, and whose data

In Dubai, the entities held to the DESC Information Security Regulation are government and semi-government bodies and the suppliers holding their data, and the signatory question is sharper there than in a private company: a government entity's consent comes from its head or a delegated authority, and a supplier in a Dubai free zone cannot authorise testing of the government systems it connects to. Since 2024 a provider delivering penetration testing or incident response to a Dubai government entity has to be accredited under DESC's Cyber Force programme, and we are not. Personal data reached in the exercise falls under the federal PDPL for a mainland entity or a free zone without its own law, and under the DIFC's own law inside the DIFC, so the data handling clause names which regime the evidence sits under.

In Abu Dhabi, healthcare providers under ADHICS hold patient data that sits outside the PDPL in its own instrument, and an authorisation that reaches a clinical system has to say what proof of reach means for a patient record: an identifier and nothing more. Entities inside the ADGM answer to its data protection regulations. Federal entities and critical infrastructure in both emirates answering to the UAE Information Assurance Standards carry the same consent question up to whoever holds authority over the designated systems. For a bank supervised by CBUAE, the licence follows the institution rather than the office, so the letter looks the same in either emirate. For UAE buyers the practical step is the same everywhere: find the signatory by reading the draft, not the org chart. The UAE regulation explainer on this site sets out which regime the evidence answers to.

Frequently asked questions

Is Red Teaming legal in the UAE?

Yes, with written consent from a person entitled to give it, dated before the first action. Without that consent the individual steps of a Red Team, unauthorised access, obtaining data and messages sent under a false identity, are offences under Federal Decree-Law No. 34 of 2021 on Countering Rumours and Cybercrimes, and entry to premises by deception is trespass. The authorisation letter is the consent, and it has to name what is authorised, because what it does not name is not.

Who should sign a Red Team authorisation letter?

Someone whose authority covers everything the letter names: the systems, the premises and the staff in their working capacity. Seniority is not the test; entitlement is. A board member can authorise a great deal and still cannot authorise a supplier's network, which needs the supplier's own written consent. Confirm the signatory against the finished draft rather than choosing one first.

Can a Red Team phishing pretext impersonate a bank or a government entity?

No. Your consent reaches your own identity, so your IT desk or HR process can be imitated with the pretext approved in advance. A real bank, a regulator, a ministry or another company cannot be, because their identity is not yours to lend, and a message or a site falsely attributed to another entity is an offence in its own right under the UAE cybercrime law. A provider offering that pretext is offering an offence.

Do we need to tell the regulator before a Red Team engagement in the UAE?

We are not aware of a UAE instrument that requires notifying a supervisor before an exercise, and the European programmes that put the regulator in the loop are not in force here. Treat it as a question for your supervisory contact rather than for the provider, and ask it before scoping. Whatever the answer, the scope rationale and the signed authorisation are what the examiner reads afterwards.

What happens if security stops a Red Team operator during physical testing?

The operator produces the authorisation letter, the guard calls the number printed on it, and a member of the white team confirms the exercise and decides whether it continues. The guard has done the job correctly, the answer is timestamped and scored as a detection, and if the call went to the police the same letter and number resolve it. Operators do not attempt physical entry without the letter and a reachable contact in place.

The engagements this applies to

Joel Aviad Ossi, Red Team Lead at RedTeam Security
Joel Aviad OssiRed Team Lead, RedTeam Security

Joel Aviad Ossi is Red Team Lead at RedTeam Security, the Dubai-licensed trading brand of WebSec FZCO. He scopes and runs objective-based engagements across the UAE.

Let's talk about your security

Tell us the objective you want tested. We will come back with a scope, a timeline and a quote, under NDA from the first conversation.

Email [email protected]
IFZA Business Park, Building A2
Nadd Hessa, Dubai Silicon Oasis
Dubai, United Arab Emirates