All case studies
Justice — Dubai International Financial Centre · 2024 · 5 months

DIFC Courts

Cyber Resilience and Regulatory Compliance Uplift

Independent cybersecurity posture review against ISR v2 and NESA, with a 12-month resilience programme covering governance, controls and recovery.

92%
ISR v2 compliance
-83%
Tier-1 RTO
12 mo
Remediation programme
0
Critical findings open at exit

The challenge

As a court of international standing, DIFC Courts required assurance over its cyber posture, regulatory compliance and ability to recover critical case-management services within agreed RTOs.

Our approach

  • Gap assessment against ISR v2, NESA and ISO 27001 control sets
  • Tabletop exercises with executive and technical teams
  • Re-baselined RTO/RPO for tier-1 case-management services
  • Designed a 12-month remediation programme with owners

Outcomes

  • 92% compliance achieved against ISR v2 mandatory controls
  • Tier-1 RTO reduced from 24h to 4h
  • Cyber governance committee operating monthly