Home
VAPT Web Application PentestAPI PentestMobile App PentestInfrastructure PentestAI & LLM PentestOT / ICS PentestIoT PentestPenetration TestingAll VAPT services
Red Team Red Team EngagementAdversary SimulationAssumed BreachPurple TeamingSocial Engineering
CompanyResourcesBlogFree Consultation

Does a detected Red Team start the UAE incident reporting clock? What to settle before day one

Your SOC catches the operators and the incident process starts. Whether a regulator hears about it is a decision made before the engagement, not during it.

Joel Aviad OssiJoel Aviad OssiRed Team Lead, RedTeam Security
7 min read
A brass clock with a red second hand mounted above a heavy steel door, and beneath it a dark desk holding a sealed red envelope and a telephone handset lifted off its cradle.

Key takeaways

  • Each of the four UAE regimes that names security testing also tells the entities it binds to report incidents to a regulator inside a set period, and none of them carves out an exception for a test.
  • An alert on the operators is an alert on authorised activity. Once the white team confirms the source there is no unauthorised access to report, and the notification step in the incident procedure does not run.
  • Three things change that answer: real impact caused by the operators, an unknown actor found during the exercise, and evidence that actually leaves the agreed boundary. Each is reported inside the instrument's clock, and the report says a test was running.
  • During the engagement window the notification step carries a gate: the incident manager confirms the source with a named white team member, by the number in the rules of engagement, and records the answer with a time.
  • No UAE instrument requires advance notice of a Red Team to the supervisor. Decide whether to give it anyway, on paper, and put the page in the evidence pack.

Every UAE regime that names testing also sets an incident clock

Four regimes in the UAE name security testing, and each of the four also tells the entities it binds to report security incidents, to a regulator and inside a period the instrument sets. That is the tension a Red Team creates. The exercise is built to look like the thing the clock exists for. The UAE rules that expect a Red Team set out what a supervisor expects to read afterwards. This article is about the obligation that can fire during the exercise: the point at which a detection by your SOC becomes a notification to a regulator, and how to make sure that happens only when it should.

The instruments differ in who receives the report and how the period is expressed. A bank supervised by CBUAE reports to the Central Bank under the instrument that binds its licence. A Dubai government entity, or a supplier holding its data, reports to DESC under the Information Security Regulation. An Abu Dhabi healthcare provider under ADHICS reports through the Department of Health. A federal entity under the UAE Information Assurance Regulation reports along the path its sector regulator names. The thresholds and the hours are not reproduced here on purpose. Read them in the version in force, because an examiner holds you to the instrument and not to a number quoted in a proposal.

What the regimes share is the shape. Something is detected, someone decides it meets the threshold, and a period starts running from that decision or from the detection, depending on the wording. A Red Team detection enters that shape at the first step and, until the white team says otherwise, it is the real thing to everyone in the incident process. The table sets out where each regime places the report.

The four UAE testing regimes and the personal data law, with where an incident report goes and what a detection of the operators is until the white team has confirmed the source.
InstrumentWho it bindsAn incident report goes toA detection of the operators is
CBUAE regulations and standardsLicensed financial institutionsThe Central Bank of the UAEAn incident until deconflicted; the period is the instrument's, not the SOC's
DESC Information Security RegulationDubai government entities and their suppliersDESCAn incident until deconflicted; a supplier's client entity carries its own duty
ADHICSAbu Dhabi healthcare entities and their vendorsThe Department of Health Abu DhabiAn incident until deconflicted; a reached patient record lowers the bar for real impact
UAE Information Assurance RegulationFederal entities and critical infrastructureThe sector regulator's named reporting pathAn incident until deconflicted; the sector regulator's wording governs
Federal Decree-Law 45 of 2021 (PDPL)Controllers of personal data, with sectoral exclusionsThe UAE Data OfficeNothing, unless personal data is exposed in earnest

The exercise is not an incident, until one of three things happens

The access the operators take is authorised, by the letter described in Authorising a Red Team under UAE law, so an alert on the operators is an alert on permitted activity. Once the white team has confirmed the source there is no unauthorised access to report, and the notification step in your incident procedure does not run. That is the ordinary case, and it is the point of a Red Team engagement: the SOC treated the alert as real, escalation ran to the top of the process, and the time it took was measured.

Three things change the answer. The first is real impact: an outage, a production change, a wave of locked-out users, anything the letter's exclusions were written to prevent. Consent covers intent, not consequence, and an instrument's threshold is written in terms of effect. The second is an unknown actor. The operators find a web shell they did not place, a persistence mechanism nobody owns, or the SOC's alert turns out to match nothing in the attribution log. That is an intrusion discovered by the exercise, and the period runs from the moment it is recognised. The third is evidence leaving the boundary: personal data actually copied out, a captured credential stored outside the country, a record opened rather than counted. Each is a breach of the engagement's own rules and, depending on the regime, of the instrument.

The matrix is the decision, and it is made by the white team in minutes rather than by counsel in days. Where the activity is the exercise and the impact is contained, deconflict and record. Anywhere else, the incident process runs to its end, and the exercise is the thing that pauses.

The white team's decision when an alert reaches them: only one cell ends without a report, and it is the one the engagement was bought to produce.

Putting the white team in front of the regulator, not behind

What your SOC should catch during a Red Team set out the three answers the white team can give when analysts catch the operators. The question here is where the regulatory notification step sits relative to that call. In an incident procedure written without an exercise in mind, notification is a step the incident manager takes once severity has been assessed, and nothing in that step pauses to ask whether the activity is a test. During the engagement window it needs to. Before any external report, the incident manager confirms the source with a named white team member, by the number in the rules of engagement, and records the answer with a time. The gate costs minutes. A report sent and then withdrawn costs a file entry an examiner will read for years.

Two escalation paths run outside your building and both need the same gate. A managed SOC provider has its own severity ladder and its own contractual duty to report, and unless its runbook for your account names your white team it will do what the contract says. A hosting or cloud provider that notices the traffic reports to you as a customer and may suspend the resource, which is a real impact in its own right. Both appear in the rules of engagement as a contact and a path.

The record of the call is part of the evidence pack. A deconfliction that happened but was not timestamped looks, a year later, exactly like one that did not.

Where the deconfliction call sits: between the analyst's escalation and any external report, so the regulator hears only about what is really an incident.

Telling the supervisor beforehand: not required, and still a decision

No UAE instrument we can point to requires an entity to give its regulator notice of a Red Team before it runs. The regulator-run programmes work differently. TIBER-EU and the Dutch Advanced Red Teaming framework build the authority into the process from the first meeting, which is one reason an adversary simulation run in their shape carries a threat intelligence phase and a named authority contact. That structure does not exist in the UAE, so the choice is the institution's, and it should be made on paper.

The case for a short note to the supervisory contact is the file. The note names the window, the class of objective, and the name and number of the white team, and says nothing about technique. If a report goes out by mistake, the correction lands against a note already held, and the examiner reading the pack later sees a decision rather than an omission. The case against is the one that always applies to secrecy: the fewer people who know, the truer the measurement. That argument is about the SOC, not the supervisor. Where an instrument or a supervisory relationship expects material testing to be discussed, that expectation settles it. Where nothing does, write down which way you chose and why, and put the page in the pack.

When a real incident happens inside the exercise

The moment the white team lands in any cell but one, the order of events is fixed and rehearsed. The operators stop and hold their access without using it, so the responders are not chasing two sets of activity. The attribution log goes to the incident team in full, so that every artefact of ours can be subtracted from what they find: the hosts touched, the accounts used, the tooling and its hashes, each mapped to an ATT&CK identifier. Incident handling of the kind NIST SP 800-61 describes depends on knowing what the adversary did, and an exercise left running is noise laid over that signal.

The notification then goes out inside the instrument's period and says that a test was running. Leaving that out would make the report incomplete, and the regulator learns of the exercise at the next examination in any case, from a pack that describes it. The letter's evidence rules apply to the real incident as much as to the exercise: what was reached is counted, not copied. When the incident is closed the exercise can resume from where it stopped, as an assumed breach from a granted foothold rather than from reconnaissance again, and the report records the pause with both timestamps.

If the impact was ours, the report is still a report, and the engagement's own root cause goes into it: which exclusion was missing from the letter, or which one was crossed, and what changed as a result. An examiner reads that as a control that worked late. Silence reads as a control that did not exist.

Reporting lines in Dubai and Abu Dhabi, and where a free-zone supplier sits

In Dubai, DESC's regulation reaches government entities directly and their suppliers by contract, so a detection on the supplier's side of a shared connection produces two potential reports: the supplier's to its client entity, and the entity's to DESC. A Red Team of a Dubai free-zone supplier with a government connection in scope needs that entity's white team contact in the rules of engagement, or the entity's SOC will do what its own procedure says. A bank in Dubai supervised by the Central Bank runs the same gate with a different recipient, and its incident manager needs the instrument's threshold in front of them when the white team calls. Entities inside the DIFC and the ADGM carry their own data protection regimes with their own breach notification duties, alongside whatever their sector regulator asks.

In Abu Dhabi, a healthcare provider under ADHICS has a reporting line to the Department of Health and a patient data instrument that treats a reached clinical record differently from a reached file share, so the real impact row of the matrix begins lower than it does elsewhere. Federal entities and designated critical infrastructure in both emirates answer to the UAE Information Assurance Regulation and report along the path it names. Across the UAE the shape is the same: an authorised detection is scored, an unauthorised one is reported, and the person who tells them apart is named before the engagement starts. Where the exercise ends with more missed detections than caught ones, the purple team session that follows is where the replay happens, and that record is what closes the file in either emirate.

Frequently asked questions

Does a Red Team detection have to be reported to the regulator in the UAE?

Not when the activity was the exercise and no real impact occurred. The access was authorised, so once the white team confirms the source there is no unauthorised access to report and the notification step does not run. It becomes reportable if the operators caused real effect, if the activity belongs to an unknown actor, or if data actually left the agreed boundary. The threshold and the period are in the instrument that binds your licence.

Should we tell CBUAE or DESC before running a Red Team?

No UAE instrument requires advance notice of a test. Regulator-run programmes such as TIBER-EU build the authority into the process, and the UAE has no equivalent structure, so the decision is yours. A short note of the window and the white team contact, with nothing about technique, protects the file if a report goes out by mistake. Record the decision either way and keep it with the evidence pack.

What happens if the Red Team finds a real attacker?

The exercise pauses. The operators hold their access without using it, and the attribution log goes to the incident team so that every artefact of the exercise can be subtracted from what the responders find. The intrusion is reported inside the instrument's period and the report says a test was running. The exercise resumes when the incident is closed, from a granted foothold.

Who decides whether an alert is the exercise or a real incident?

The white team: the small group named in the rules of engagement who know the exercise is running. During the engagement window the incident manager confirms the source with them, by the number in the rules, before any external report, and records the answer with a time. The check takes minutes and sits ahead of notification in the procedure.

The engagements this applies to

Joel Aviad Ossi, Red Team Lead at RedTeam Security
Joel Aviad OssiRed Team Lead, RedTeam Security

Joel Aviad Ossi is Red Team Lead at RedTeam Security, the Dubai-licensed trading brand of WebSec FZCO. He scopes and runs objective-based engagements across the UAE.

Let's talk about your security

Tell us the objective you want tested. We will come back with a scope, a timeline and a quote, under NDA from the first conversation.

Email [email protected]
IFZA Business Park, Building A2
Nadd Hessa, Dubai Silicon Oasis
Dubai, United Arab Emirates