Cybersecurity
The 90-day compliance runway
The exact sequence we use to take an SME from zero to a defensible security baseline — mapped against the UAE PDPL and sector rules.
- Map every system that stores personal data — CRM, HR files, email lists, spreadsheets
- Run a gap assessment against the PDPL basics and your sector’s rules
- Turn on MFA everywhere — email, admin panels, VPNs, cloud consoles
- Establish a patching cycle with same-week turnaround for critical fixes
- Test a full backup restore — a backup you have never restored is a hope
- Write the privacy notice, retention schedule and a one-page incident plan
- Train the team and schedule a penetration test to validate the work