Key takeaways
- Unauthorised access, a message under a false identity and entry by deception are all offences in the UAE. The authorisation letter is the consent that takes a Red Team outside them, and nothing else does.
- Consent reaches only what the signatory owns. Your systems, premises and staff can be authorised; a supplier's systems need the supplier's letter; and nobody can authorise imitating a real bank, regulator or ministry.
- The letter names the objective, the exclusions, the hours, the pretext limits, the white team and an expiry date. What it does not name is not authorised, and the operators ask rather than interpret.
- Records reached during the exercise are still personal data. The contract makes the provider a processor, evidence stays in the country unless the contract says otherwise, and proof of reach is never a copy of the record.
- Physical work runs on the letter in the operator's pocket and a number that answers at three in the morning. A guard who ends the exercise with one call has done the job correctly.
Without consent, every step of a Red Team is an offence
Described in legal terms rather than in ours, a Red Team engagement is a list of things that are crimes when done without permission. Accessing an information system without authorisation, obtaining data from it, sending a message under an identity that is not yours: Federal Decree-Law No. 34 of 2021 on Countering Rumours and Cybercrimes covers each of those. Entering a building by deception is not a cyber matter at all. It is trespass, unless the occupier consented. What takes the exercise outside those offences is the written consent of the person entitled to give it, dated before the first action. The authorisation letter is that consent. It is not paperwork attached to the engagement; it is the engagement's legal existence.
This weighs more heavily on a Red Team than on a penetration test. A penetration test is announced, windowed and scoped to named systems, so the consent lives in the scope table and everyone who might see the traffic has been told. A Red Team runs unannounced, and the people who notice it have not been told. The analyst who sees a beacon, as the piece on what your SOC should catch describes, the guard who sees a stranger on the third floor, the clerk who receives the email: each is entitled to treat it as real, and each is entitled to call the police. The letter is the only document that can end that call correctly.
This article names instruments and not article numbers, on purpose. Numbering moves between amendments, and a letter that quotes an article is no more valid than one that does not. Read the decree-law in the version in force.
What you can authorise, and what nobody can
Consent reaches only what the signatory has authority over. Your systems, your accounts, your buildings and your staff in their working capacity can all be authorised by a person with the standing to do it. A supplier's systems are not yours to authorise, even where they hold your data, and a supplier path into your estate, one of the realistic routes an operator takes, needs the supplier's own written consent or it is excluded. Hosted infrastructure is the same in a quieter form: the hosting provider's testing policy sits on top of your letter, and where it asks for notice, notice is given first.
Impersonation is the harder line. Your own IT desk, your HR process and your visitor procedure can be imitated, because you can consent to it. A real bank, a regulator, a ministry or another company cannot be, because their identity is not yours to lend, and the cybercrime law treats a message or a site falsely attributed to another entity as an offence in its own right. The social engineering rules published on this site exclude it outright, and a provider offering a pretext dressed as a supervisor's notice is offering you an offence with a report attached. The matrix draws the four cases, and the excluded corner is where the most convincing pretexts live. Realism is the argument for a Red Team, and the letter is where realism meets its limit.
Whose system or identity
Authorise in the letter
Named systems, accounts, premises and staff in their working capacity
Authorise, with pretext limits
Your IT desk or HR process, each pretext approved by the white team first
Their written consent, or excluded
Suppliers and hosting providers; a supplier path needs the supplier's letter
Nobody can authorise it
A real bank, regulator, ministry or company. An offence with or without your letter
What the operators do
What the authorisation letter has to say
The letter is short and specific. It names the objective in the language of the business, the systems and people excluded, the hours, the techniques permitted and refused, the limits on pretexts, the white team by name and telephone number, and the date it expires. What it does not name is not authorised. Operators do not read silence as permission; they ask the white team, and the answer is countersigned onto the letter. NIST SP 800-115 places the rules of engagement and the written authorisation in the planning phase, before any technical work, and nothing about a Red Team changes that order.
Written generically, as an example, the first two clauses read like this. Objective: demonstrate the ability to submit a payment for approval in the treasury system, without submitting one; proof of reach is a screenshot of the approval queue showing the operator's session and a record identifier, nothing more. Excluded: the core ledger, the trading platform, and any system operated by the payments supplier, which has not consented. Those two lines settle what a screenshot may contain and which route is closed, before the first email is sent.
The table sets out the rest of the clauses and the reason the law needs each. A letter that skips a row is not shorter. It is silent on something the operators will meet.
| Clause | What it says | Why the law needs it |
|---|---|---|
| Signatory | Name, title, and the authority held over every system and premises named | Consent is valid only from someone entitled to give it |
| Objective and proof | The asset in business language, and exactly what counts as proof of reach | Proof of reach is access; a copy of the record is data taken without cause |
| Exclusions | Systems, people, suppliers and locations the operators may not touch | What is outside the signatory's authority cannot be authorised by them |
| Techniques and pretexts | Phishing, calls, physical entry, each yes or no, with the pretext limits | Imitation has to be consented to, and some of it cannot be |
| Hours and expiry | The working windows, the end date, and how an extension is signed | An expired letter authorises nothing |
| White team | Two to four named people, their numbers, and the authority to halt | The number a guard or an analyst calls has to be answered |
| Data handling | What evidence is kept, where it is stored, and when it is destroyed | A record reached in the exercise is still personal data |
From scoping to a letter in the operator's pocket
The letter is the last thing signed, not the first thing drafted. The objective and the exclusions come out of the scoping session, third-party consents are requested as soon as a supplier or a hosting path is in the picture, and only then is the signatory confirmed against everything the draft names. The order matters because a signatory found first tends to be senior rather than entitled: a board member can authorise a great deal and still cannot authorise a supplier's network. The white team is named and the attribution channel tested before signature.
During the run, the letter is a living document in one narrow sense. A new pretext, a host that turns out to be in scope, or a week's extension is a new consent, countersigned onto the letter rather than agreed on a call. An assumed breach exercise needs the same letter with a shorter first phase, because the foothold is granted rather than earned and there is no route in to authorise.
Draft
Objective agreed
In business language, with what counts as proof of reach
Exclusions listed
Systems, people, suppliers and hours; silence is not consent
Third parties asked
Supplier and hosting consents requested, or the path is excluded
Sign
Signatory confirmed
Someone whose authority covers everything the draft names
White team named
Two to four reachable people, with the authority to halt
Channel tested
The attribution line answers before anything is pointed at anything
Run
Letter carried
On every operator, on every physical task
Changes countersigned
A new pretext or a new host is a new consent
Expiry watched
An expired letter authorises nothing
The data the operators reach is still personal data
Reaching the objective usually means reaching records: a customer list, a patient index, an approval queue. The proof the engagement needs is that the operators could act, not a copy of what they could act on: a record identifier, a row count, a hash of a file never opened. Nothing is exfiltrated in earnest, and a credential captured on the way is recorded as a fact and discarded. Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data applies on the mainland and in free zones without a data protection law of their own; the DIFC and ADGM have theirs, and government and health data sit under separate instruments, as the federal summary of the data protection laws sets out. Under every one of them, a provider holding evidence that identifies a person is processing personal data on your behalf, and the contract has to say so.
Two clauses follow. Evidence stays in the country unless the contract names where else it may go, because moving it is a transfer and each regime restricts transfers. And retention is written down: how long the evidence is held, where, and when it is destroyed. The evidence pack an examiner reads, described in the UAE rules that expect a Red Team, is built from this material, so the retention clause decides what can still be shown a year later.
When a guard stops an operator
Physical entry is where the letter stops being a file and becomes an object. Every operator carries it on every physical task, and the number printed on it rings a line that passes through nothing being tested. The figure draws the encounter the letter exists for. A guard challenges someone on a floor they should not be on, the operator produces the letter, the guard calls the number, and the white team confirms the exercise and decides whether it continues. The guard has done the job correctly at every step, including the one that ended the exercise, and the report says so.
What must not happen is a negotiation at the door. An operator who argues, or a guard persuaded by the letter alone without making the call, has turned a control into a conversation. The white team's answer is timestamped and scored as a detection, as an analyst's ticket is, which is why the white team is chosen for being reachable rather than senior. If the call goes to the police instead, the letter and the same number resolve it, and the exercise pauses until it is resolved.
- Operator
Follows a staff member through a controlled door
In scope only by explicit written agreement
- Site security → Operator
Challenges the operator on the third floor
The guard is doing the job correctly
- Operator → Site security
Hands over the authorisation letter
Carried on every physical task, never left behind
- Site security → White team
Calls the number printed on the letter
A line that runs through nothing being tested
- White team → Site security
Confirms the exercise and decides: stop or continue
Timestamped, and scored as detected
- Site security → Operator
Escorts the operator out, or stands down
Signing in Dubai and Abu Dhabi: whose authority, and whose data
In Dubai, the entities held to the DESC Information Security Regulation are government and semi-government bodies and the suppliers holding their data, and the signatory question is sharper there than in a private company: a government entity's consent comes from its head or a delegated authority, and a supplier in a Dubai free zone cannot authorise testing of the government systems it connects to. Since 2024 a provider delivering penetration testing or incident response to a Dubai government entity has to be accredited under DESC's Cyber Force programme, and we are not. Personal data reached in the exercise falls under the federal PDPL for a mainland entity or a free zone without its own law, and under the DIFC's own law inside the DIFC, so the data handling clause names which regime the evidence sits under.
In Abu Dhabi, healthcare providers under ADHICS hold patient data that sits outside the PDPL in its own instrument, and an authorisation that reaches a clinical system has to say what proof of reach means for a patient record: an identifier and nothing more. Entities inside the ADGM answer to its data protection regulations. Federal entities and critical infrastructure in both emirates answering to the UAE Information Assurance Standards carry the same consent question up to whoever holds authority over the designated systems. For a bank supervised by CBUAE, the licence follows the institution rather than the office, so the letter looks the same in either emirate. For UAE buyers the practical step is the same everywhere: find the signatory by reading the draft, not the org chart. The UAE regulation explainer on this site sets out which regime the evidence answers to.
Frequently asked questions
Is Red Teaming legal in the UAE?
Yes, with written consent from a person entitled to give it, dated before the first action. Without that consent the individual steps of a Red Team, unauthorised access, obtaining data and messages sent under a false identity, are offences under Federal Decree-Law No. 34 of 2021 on Countering Rumours and Cybercrimes, and entry to premises by deception is trespass. The authorisation letter is the consent, and it has to name what is authorised, because what it does not name is not.
Who should sign a Red Team authorisation letter?
Someone whose authority covers everything the letter names: the systems, the premises and the staff in their working capacity. Seniority is not the test; entitlement is. A board member can authorise a great deal and still cannot authorise a supplier's network, which needs the supplier's own written consent. Confirm the signatory against the finished draft rather than choosing one first.
Can a Red Team phishing pretext impersonate a bank or a government entity?
No. Your consent reaches your own identity, so your IT desk or HR process can be imitated with the pretext approved in advance. A real bank, a regulator, a ministry or another company cannot be, because their identity is not yours to lend, and a message or a site falsely attributed to another entity is an offence in its own right under the UAE cybercrime law. A provider offering that pretext is offering an offence.
Do we need to tell the regulator before a Red Team engagement in the UAE?
We are not aware of a UAE instrument that requires notifying a supervisor before an exercise, and the European programmes that put the regulator in the loop are not in force here. Treat it as a question for your supervisory contact rather than for the provider, and ask it before scoping. Whatever the answer, the scope rationale and the signed authorisation are what the examiner reads afterwards.
What happens if security stops a Red Team operator during physical testing?
The operator produces the authorisation letter, the guard calls the number printed on it, and a member of the white team confirms the exercise and decides whether it continues. The guard has done the job correctly, the answer is timestamped and scored as a detection, and if the call went to the police the same letter and number resolve it. Operators do not attempt physical entry without the letter and a reachable contact in place.






