All case studies
Justice — Dubai International Financial Centre · 2024 · 5 months
DIFC Courts
Cyber Resilience and Regulatory Compliance Uplift
Independent cybersecurity posture review against ISR v2 and NESA, with a 12-month resilience programme covering governance, controls and recovery.
92%
ISR v2 compliance
-83%
Tier-1 RTO
12 mo
Remediation programme
0
Critical findings open at exit
The challenge
As a court of international standing, DIFC Courts required assurance over its cyber posture, regulatory compliance and ability to recover critical case-management services within agreed RTOs.
Our approach
- Gap assessment against ISR v2, NESA and ISO 27001 control sets
- Tabletop exercises with executive and technical teams
- Re-baselined RTO/RPO for tier-1 case-management services
- Designed a 12-month remediation programme with owners
Outcomes
- 92% compliance achieved against ISR v2 mandatory controls
- Tier-1 RTO reduced from 24h to 4h
- Cyber governance committee operating monthly
