DFSA Cyber Risk Rules: A Practical GEN 5.5 Guide

Cybersecurity for a DFSA-regulated firm is not a topic that you can deprioritize.
Under section 5.5 of the DFSA General Module, or GEN, cyber risk must be managed through a documented framework connected to governance, risk management, technology controls, third-party oversight, monitoring, and incident response.
The rules came into force on January 1, 2024. In June 2026, the DFSA again reminded firms that compliance is mandatory for Authorised Persons.
For smaller DIFC firms, the main challenge is rarely understanding that cybersecurity matters. The challenge is turning regulatory requirements into controls that work every day and producing evidence that those controls are operating without impacting the focus on the core business.
This guide explains the principal requirements and how firms can approach them practically.
First: do the DFSA cyber-risk rules apply to every DIFC company?
Not automatically.
Being incorporated or located in the DIFC does not, by itself, make every business subject to GEN 5.5. The rules apply to an “Authorised Person” as defined in the DFSA regulatory framework.
A firm should confirm its exact status, permissions, applicable modules, and any additional requirements with its compliance and legal advisers.
However, even non-regulated DIFC businesses may use the rules as a useful security benchmark, particularly when handling financial, personal, or confidential client information since it gathers the best practices.
What does GEN 5.5 require?
At a high level, an Authorised Person must be able to:
- Identify and assess its cyber risks.
- Protect its information and communications technology assets.
- Manage cyber risk created by third parties.
- Detect potential and actual cyber incidents.
- Respond to and recover from incidents.
- Notify the DFSA when a material cyber incident occurs.
- Demonstrate appropriate governance and senior-management oversight.
These are connected requirements. A firewall, antivirus subscription, or collection of security policies is not a complete Cyber Risk Management Framework.
1. Establish a written Cyber Risk Management Framework
GEN 5.5.2 requires an Authorised Person to establish and maintain a Cyber Risk Management Framework.
The framework must be:
- Documented in writing
- Approved by the firm’s Governing Body
- Appropriate to the nature, scale, and complexity of the business
- Clear about roles, responsibilities, and decision-making authority
- Integrated with the firm’s wider risk-management framework
- Reviewed periodically and at least annually
A practical framework should explain how the firm identifies risks, protects systems, manages incidents, supervises technology providers, reports to management, and retains evidence.
Swyt’s DFSA compliance and certification support can help connect written policies with the technical controls and operational records needed to demonstrate implementation.
2. Make governance more than an annual routine
The Governing Body and senior management remain ultimately responsible for the effective management of cyber risk.
Their responsibilities include:
- Ensuring cyber risks are identified, assessed, and managed
- Establishing an appropriate senior-management structure
- Defining the firm’s cyber-risk tolerance
- Ensuring relevant personnel have suitable experience
- Receiving understandable information on risks and control performance
- Allocating sufficient attention and resources to material weaknesses
A board should not receive only a technical list of antivirus alerts.
Useful management information may include:
- Critical vulnerabilities and remediation status
- Percentage of devices meeting security policies
- Privileged and dormant accounts
- Material third-party risks
- Security incidents and lessons learned
- Patch and update status
- Testing results
- Exceptions approaching or exceeding risk tolerance
The objective is to let decision-makers understand exposure, ownership, and required action.
3. Maintain a current ICT asset inventory
A firm cannot assess cyber risk if it does not know what technology and information it depends on.
GEN 5.5.5 requires a current inventory of ICT assets. Assets must be classified by confidentiality and by how critical they are to business functions and processes.
The inventory may cover:
- Laptops, desktops, phones, and tablets
- Servers and network equipment
- Cloud environments
- Business applications
- Databases and information repositories
- Software, firmware, and end-user tools
- Critical integrations and dependencies
- Systems operated by third parties
An asset register should identify more than the product name. Depending on the asset, it may record its owner, administrator, location, users, criticality, information classification, support status, dependencies, and recovery requirements.
A central device and IT asset-management process can provide evidence of ownership, enrollment, security status, and lifecycle changes rather than relying on a spreadsheet updated once before an audit.
4. Assess cyber risk regularly
The firm must regularly assess the cyber risk associated with its ICT assets.
The assessment must consider:
- Relevant cyber threats
- The effectiveness of existing controls
- Residual risk after those controls
- Potential consequences for the firm’s operations
- Dependencies between technology and business processes
- Risks created by third parties
A useful risk assessment connects each material risk to an asset, business impact, control, owner, treatment plan, and target date.
For example, “phishing” is too broad to be a complete risk entry. A more useful assessment would explain which users and applications are exposed, which controls are operating, how an account compromise would affect the business, and what additional action is required.
5. Control access throughout the user lifecycle
GEN 5.5 requires firms to manage access rights and permissions, apply least privilege, revoke access when approval conditions no longer exist, and review access regularly.
It also requires appropriate authentication controls, including MFA or equivalent protection for internet-accessible systems and privileged access.
In practice, firms should be able to show:
- Who approved a user’s access
- Why the user needs it
- Which privileged accounts exist
- When access was last reviewed
- Whether MFA is enforced
- When access was removed after a role change or departure
- How dormant, shared, and unnecessary accounts are identified
Connecting access control to employee IT onboarding and offboarding reduces the risk that application, device, or administrator access remains active after an employee or contractor leaves.
6. Implement the required protective controls
GEN 5.5 sets out several practical security requirements.
These include:
- Up-to-date anti-malware protection
- Appropriate network architecture and perimeter protection
- Network-security monitoring
- Properly managed access rights
- Strong authentication and MFA
- Controlled change management
- Prioritised security updates
- Encryption appropriate to information sensitivity
- Physical controls for server rooms and data centres, where applicable
- Cybersecurity training
- Regular security testing
Internet-facing systems must be tested at least annually. The appropriate frequency and depth for other testing depends on the nature, scale, and complexity of the firm.
A firm may use vulnerability assessments, penetration testing, scenario exercises, and other methods according to its risk profile.
These controls should work as one system. Managed network security, for example, should connect firewall configuration and monitoring with access controls, endpoint protection, patching, and incident escalation.
7. Manage cloud and third-party cyber risk
Outsourcing technology does not outsource regulatory responsibility.
Under GEN 5.5.3, third-party cyber risk must form part of the firm’s overall Cyber Risk Management Framework. The firm remains responsible for compliance when it relies on an external ICT provider.
Required measures include:
- Appropriate due diligence before appointing the provider
- Contractual cybersecurity requirements
- Obligations for the provider to notify the firm of relevant incidents
- Cooperation with remediation
- The firm’s ability to verify continued compliance
- Effective ongoing supervision
This can apply to providers such as cloud platforms, managed IT providers, hosting companies, software vendors, data processors, and technology subcontractors.
A provider saying “we are secure” is not enough. Firms should collect proportionate evidence based on the sensitivity of the information and the criticality of the service.
This is particularly important when reviewing cloud security controls, because responsibility is normally shared between the platform provider, the firm, and any company administering the environment.
8. Monitor continuously and prepare for incidents
GEN 5.5.16 requires continuous monitoring of IT systems and networks to detect incidents, anomalies, and events that may indicate an incident.
The firm also needs an escalation process.
Monitoring should answer practical questions:
- Which systems and events are monitored?
- Who reviews the alerts?
- What creates an escalation?
- Who makes containment decisions?
- How are actions recorded?
- What happens outside normal office hours?
- How does management learn about a serious event?
The purpose of ongoing cybersecurity monitoring is not to collect more alerts. It is to turn relevant events into timely investigation and action.
9. Maintain and test a Cyber Incident Response Plan
A firm must maintain a written Cyber Incident Response Plan.
The plan should cover:
- Incident identification and classification
- Roles and decision-making authority
- Technical containment
- Investigation and evidence preservation
- Recovery of affected systems and data
- Internal and external communications
- Regulatory assessment and notification
- Coordination with third parties
- Post-incident review
The plan must be tested regularly, reviewed at least annually, and reviewed after a major cyber incident.
A tabletop exercise is often a useful starting point. It allows management, compliance, IT, communications, and external providers to work through a realistic scenario before a real incident forces them to make decisions under pressure.
10. Understand the 72-hour notification requirement
GEN 5.5.19 requires an Authorised Person to notify the DFSA as soon as reasonably practicable and no later than 72 hours after becoming aware, or receiving information reasonably suggesting, that a material cyber incident has occurred.
Materiality may involve factors such as:
- Effects on customer information or Client Assets
- Leakage or corruption of sensitive information
- Disruption of critical functions or systems
- Material financial loss
- Effects on external stakeholders
The rule does not mean a firm should wait until hour 71 to decide whether to report.
The response process should quickly involve the appropriate compliance, legal, executive, and technical decision-makers. The firm may also need to consider notification to other authorities, including the DIFC Data Protection Commissioner, depending on the circumstances.
What evidence should a firm maintain?
Implementation must be demonstrable.
A practical evidence set may include:
- Approved Cyber Risk Management Framework
- Governing Body minutes and cyber-risk reporting
- Current ICT asset inventory
- Cyber-risk register and treatment plans
- Access approvals and review records
- MFA and security-policy reports
- Patch and vulnerability records
- Network and security-monitoring evidence
- Training attendance and materials
- Security-test reports and remediation tracking
- Third-party due-diligence records and contracts
- Incident logs and response exercises
- Annual framework and plan reviews
The evidence should arise from normal operations. Reconstructing it immediately before a supervisory review is slower, less reliable, and more likely to expose gaps.
A practical implementation sequence
For a growing DIFC firm, the work can be organised into five stages:
- Scope: Confirm regulatory applicability, systems, data, providers, and business processes.
- Assess: Build the asset inventory and identify control gaps and residual risks.
- Design: Document the framework, responsibilities, policies, risk tolerance, and incident plan.
- Implement: Deploy and configure the necessary identity, endpoint, network, cloud, monitoring, and training controls.
- Operate: Review alerts, evidence, vendors, vulnerabilities, access, incidents, and management reporting continuously.
The goal is not to create a large compliance folder. It is to make secure and accountable IT operations repeatable.
Frequently asked questions
What is DFSA GEN 5.5?
GEN 5.5 is the cyber-risk management section of the DFSA General Module. It covers governance, risk assessment, ICT assets, protective controls, third parties, monitoring, incident response, recovery, and regulatory notification.
Does GEN 5.5 apply to every company in DIFC?
No. Its mandatory requirements apply to DFSA Authorised Persons. A DIFC company should confirm its regulatory status and applicable obligations with qualified compliance or legal advisers.
Does ISO 27001 certification satisfy DFSA GEN 5.5?
Not automatically. ISO 27001 can support a firm’s control environment and evidence, but the DFSA rules contain specific governance, operational, third-party, and incident-notification requirements. Certification does not replace regulatory compliance.
How often must the Cyber Risk Management Framework be reviewed?
GEN 5.5.2 requires periodic review and review at least annually. Reviews may also be needed after significant business, technology, risk, or regulatory changes.
How quickly must a material cyber incident be reported?
The DFSA must be notified as soon as reasonably practicable and no later than 72 hours after the firm becomes aware—or has information reasonably suggesting—that a material cyber incident has occurred.
Is a cloud provider responsible for the firm’s compliance?
No. A regulated firm remains responsible for its obligations when it uses a third-party ICT provider. It must conduct due diligence, establish suitable contractual protections, verify compliance, and supervise the provider.
Does a small Authorised Firm need the same systems as a bank?
Not necessarily. Controls must be appropriate to the nature, scale, and complexity of the firm. The core obligations still apply, but the implementation should be proportionate to the firm’s activities, assets, information, dependencies, and exposure.
Can Swyt help with an existing DFSA compliance programme?
Yes. Swyt can assess the technical environment, map assets and controls, identify gaps, implement security measures, improve monitoring and evidence, and support the ongoing operation of the firm’s cyber-risk programme. Legal interpretations and regulatory decisions should remain with the firm’s qualified advisers.

.png)











































