Home
VAPT Web Application PentestAPI PentestMobile App PentestInfrastructure PentestAI & LLM PentestOT / ICS PentestIoT PentestPenetration TestingAll VAPT services
Red Team Red Team EngagementAdversary SimulationAssumed BreachPurple TeamingSocial Engineering
CompanyResourcesBlogFree Consultation

The UAE rules that expect a Red Team, and the evidence they read

No UAE instrument says the words Red Team, yet one supervisor expects one. Which regime asks, what the expectation means, and the evidence an examiner reads.

Joel Aviad OssiJoel Aviad OssiRed Team Lead, RedTeam Security
7 min read
A leather-bound ledger open on a dark desk beside a wax-sealed envelope and a brass drafting compass, with a red thread pinned across a folded floor plan leading to a small steel vault at its centre.

Key takeaways

  • No UAE instrument names a Red Team engagement. CBUAE expects intelligence-led adversary simulation of its larger institutions; DESC, ADHICS and the UAE IAS leave a full exercise to the entity and the assessor.
  • An expectation is not a mandate, and it is harder to satisfy: the file has to show why this scenario and not another, which is what the intelligence phase exists to answer.
  • Two documents in a Red Team pack have no counterpart in a penetration test: the ATT&CK-mapped attack path and the detection gap analysis. The second is the one a controls examiner reads.
  • Under a controls framework, or on an estate with nothing watching yet, a Red Team is often the wrong evidence. A purple team session or an assumed breach exercise evidences the control directly.

No UAE instrument uses the words Red Team

Four regimes in the UAE name security testing, and none of them defines a Red Team engagement. What the instruments say is that entities in scope test their systems, remediate what is found and keep the record. CBUAE supervises licensed financial institutions and asks for independent penetration testing of critical and internet-facing systems at least annually, with larger institutions increasingly asked for intelligence-led adversary simulation on top. DESC publishes the standard that Dubai government entities and their suppliers are held to. ADHICS, published through the Department of Health, is a control catalogue for healthcare in Abu Dhabi. The UAE Information Assurance Standards are a controls framework for the federally designated critical sectors, not a testing mandate.

So the question is rarely whether a clause names the exercise. It is whether the supervisor reading your file expects one, and what they will accept as proof that it was run for a reason. The table sets out where a full Red Team lands under each regime, in the same terms as the UAE regulation explainer on this site. Where it says case by case, the instrument leaves the decision to the entity and the assessor, and the argument for buying one has to be written down before it is bought.

Read the instrument that binds your licence rather than a paraphrase of it. Clause wording changes between versions, and a proposal quoting an article number is not evidence of anything.

Where a full Red Team engagement lands under each of the four UAE regimes, and what each regime asks for instead when it does not ask for one.
RegimeWho it bindsDoes it expect a Red TeamWhat it does ask for
CBUAEBanks, finance companies, payment service providers and stored-value facilities it licensesExpected of larger institutions, as intelligence-led adversary simulationIndependent penetration testing at least annually, scanning more often, and evidence that findings were closed
DESC ISRDubai government and semi-government entities, and suppliers holding their data or connecting to their networksCase by caseAssessment on a cycle set by the criticality of the system, from a provider the entity can accept
ADHICSHealthcare providers, payers and health information exchanges in Abu DhabiRarely the first buyTesting that evidences the technical control families across clinical systems and patient data
UAE IASFederal entities and operators designated as critical national infrastructureCase by caseEvidence that segmentation holds, privileged access is constrained and monitoring reaches a person

What a supervisory expectation means in practice

A mandate is a sentence in an instrument with a cadence attached. An expectation is different: nothing tells you to run the exercise, and an examiner still asks why you have not. That is where a Red Team sits under CBUAE for the larger institutions, and the shape supervisors have in mind is the intelligence-led one, because it shows the scenario was chosen for a reason rather than lifted from a template. The sequence those frameworks fix is a generic threat landscape first, targeted intelligence second, a scenario agreed in writing, execution against it, and a closure phase with the defenders in the room.

That sequence comes from TIBER-EU, run by the European Central Bank for financial entities, and from Advanced Red Teaming, published by De Nederlandsche Bank in 2024. Both are regulator-run programmes, and being accredited under either means a central bank accredited you. No provider earns that by doing the work in the UAE, and we are not accredited under either. What can honestly be claimed is that an adversary simulation follows the sequence and that the file shows it. Ask any provider quoting TIBER in a proposal which regulator accredited them.

The consequence for a buyer is that the intelligence phase is not optional trimming. A supervisor who expects intelligence-led testing reads the threat assessment before the attack narrative, and an engagement that went straight to execution has no answer to the first question asked.

The sequence a supervisor expecting intelligence-led testing looks for. The phase most often skipped is the first one, and it is the one they read first.

The evidence pack an examiner reads afterwards

An examiner does not read the engagement. They read the pack it produced, and for a Red Team the pack carries two documents a penetration test report does not. The first is the attack path: the ordered chain of steps that reached the objective, with every technique recorded against its MITRE ATT&CK identifier so this year can be compared with last. The second is the detection gap analysis, which sets that path beside your own telemetry and marks each step detected, logged only, or missed, with the reason it went that way. Under a controls framework that is the document that evidences whether monitoring produces something a person acts on. Nothing else in the pack does.

Around those two sit the artefacts every regime wants: the scope rationale, the signed authorisation, findings with named owners, the remediation record and the retest. Written generically, as an example, the front of the pack reads like this. Objective: reach the payment approval path and prove the ability to release a transfer, without releasing one. Rationale: the intelligence phase placed financially motivated groups targeting regional banks at the top of the threat assessment, and the approval path is the asset they would go for. An examiner who reads those two lines knows why this exercise and not another before reaching the narrative. The findings underneath follow the same discipline as what a penetration test report has to contain.

Keep the attribution log with the pack. A Red Team engagement runs without the defenders knowing, so the log of what the operators did and when is what your SOC's tickets are reconciled against, and that reconciliation is the detection gap analysis in raw form. Lose it and the central document cannot be rebuilt.

Two layers here have no counterpart in a penetration test pack, and the detection gap analysis is the one a controls examiner reads.

When a Red Team is the wrong evidence to bring

Two of the four regimes are controls frameworks, and a controls framework is answered control by control. The IAS families that testing can evidence are that segmentation holds, that privileged access is constrained in practice, and that monitoring produces something a person acts on. A purple team session evidences each of those directly, technique by technique, with the defenders watching, and it leaves detection content your own team wrote. A Red Team evidences them indirectly, through one path taken once. Under the IAS, and often under ADHICS, the session is the better buy.

The other case is an estate with nothing watching yet. The product of a Red Team is a measurement of detection and response, and against an estate with no central logging or incident process it returns an answer you could have written in advance: the operators reached the objective and nobody noticed. An examiner reads that as absence, not capability. The detection you need before a Red Team is worth buying sets out the floor. Reach it first, keep the record of having reached it, and buy the exercise when the answer is genuinely uncertain.

Which exercise to bring an examiner, decided by what the regime expects and what your estate can currently measure.

How often, and what closes it

Once a year is the cadence testing obligations are written around, and it is the cadence the Red Team page on this site assumes too. Two things argue against the calendar. A material change to the estate argues for sooner. Detection work from the last exercise that has not landed argues for waiting, because running again before the fixes are in measures the same gaps twice and produces a second pack that says what the first did. Penetration tests carry the load in between, and under CBUAE they are the baseline the Red Team sits on top of, not a substitute for it.

What closes the exercise in an examiner's file is not the report. It is the retest of the findings and the replay of the missed detections, recorded against the same ATT&CK identifiers as the original path, so the missed column in this year's analysis is visibly shorter than last year's. A pack that stops at the report shows that an exercise happened. The retest record shows that something changed because of it, which is the part a controls examiner can credit. NIST SP 800-115 sets out that closing discipline for technical testing in general, and it applies unchanged here.

What this looks like in Dubai and Abu Dhabi

In Dubai, the regime that reaches the widest range of organisations is DESC's, and it reaches them through contract as often as through licence. A supplier in a Dubai free zone that holds a government entity's data or connects to its network inherits that entity's testing expectations, and since 2024 a provider delivering penetration testing or incident response to a Dubai government entity has to be accredited under DESC's Cyber Force programme. We are not Cyber Force accredited. If the engagement you are scoping needs a provider who is, say so at the first conversation and we will tell you plainly that we are not the right firm for it. A bank supervised by CBUAE carries the same expectation in either emirate, because the licence follows the institution rather than the office.

In Abu Dhabi, healthcare entities and the vendors working inside their environments answer to ADHICS, where a full Red Team is rarely the first buy and testing that evidences the control families is what the file needs. Federal entities and designated critical infrastructure in both emirates answer to the UAE IAS, which is where a purple team session or an assumed breach exercise usually evidences the controls more directly for less. Mainland or free-zone status changes your licensing and your contracting, not the security expectation attached to the data you hold. For UAE buyers the practical difference between the emirates shows up in procurement: what a tender asks you to attach, whether the provider's accreditation is checked, and how recent the evidence has to be.

Frequently asked questions

Does any UAE regulator require a Red Team engagement?

No UAE instrument names a Red Team as a mandate with a cadence attached. CBUAE asks its licensed institutions for independent penetration testing at least annually, and larger institutions are increasingly expected to run intelligence-led adversary simulation on top of that. DESC, ADHICS and the UAE Information Assurance Standards leave a full Red Team to the entity and the assessor, case by case. Read the instrument that binds your licence rather than a summary of it.

Is a TIBER-EU or ART accredited provider required in the UAE?

No, and no provider working in the UAE holds that accreditation by virtue of the work. TIBER-EU and Advanced Red Teaming are run by central banks in Europe with the regulator in the loop. What a UAE supervisor looks for is the shape those frameworks fix: threat intelligence first, a scenario agreed in writing, execution, and closure with the defenders. Ask a provider quoting either framework which regulator accredited them.

What evidence does an examiner want from a Red Team engagement?

The objective and scope rationale, the signed authorisation and rules of engagement, the attack path with each technique mapped to MITRE ATT&CK, the detection gap analysis marking every step detected, logged only or missed, and the remediation record with the retest that closed each finding. The detection gap analysis has no counterpart in a penetration test, and under a controls framework it is the document that evidences monitoring.

Should we run a Red Team or a purple team session for the UAE IAS?

For a controls framework, usually the purple team session. The IAS families that testing can evidence, segmentation, constrained privileged access and monitoring that reaches a person, are evidenced directly, technique by technique, with your defenders watching, and the session leaves detection content your team owns. A Red Team evidences the same families through one path taken once. Run the Red Team when the open question is whether anyone would notice, and you have the telemetry to answer it.

The engagements this applies to

Joel Aviad Ossi, Red Team Lead at RedTeam Security
Joel Aviad OssiRed Team Lead, RedTeam Security

Joel Aviad Ossi is Red Team Lead at RedTeam Security, the Dubai-licensed trading brand of WebSec FZCO. He scopes and runs objective-based engagements across the UAE.

Let's talk about your security

Tell us the objective you want tested. We will come back with a scope, a timeline and a quote, under NDA from the first conversation.

Email [email protected]
IFZA Business Park, Building A2
Nadd Hessa, Dubai Silicon Oasis
Dubai, United Arab Emirates