Microsoft 365 security checklist for small businesses in Dubai and the UAE
The Microsoft 365 settings a small UAE business should check first, based on Microsoft's own guidance, with what each one does.
Read the articleIT Services
What a penetration test actually is, how it differs from a vulnerability scan, what belongs in a scope document and a rules of engagement letter, what a report should contain, and why authorisation in writing matters under UAE law.

A penetration test is a manual, scoped attempt by a skilled tester to break into a named system the way a real attacker would, carried out with written permission and ending in a report a technical team can act on. It is not the same as a vulnerability scan, it does not cover systems outside its written scope, and it does not promise a system is secure forever afterwards. In the UAE, penetration testing carries an extra layer most other IT work does not: accessing a system without clear written authorisation is an offence under federal law, which is why the scope document matters as much as the technical work itself.
This guide works through what a penetration test actually is and is not, how scanning differs from testing, what belongs in a scope and a rules of engagement letter, what a usable report contains, how often testing should happen, and the UAE legal point every business commissioning a test should understand before work begins.
Key points
This article explains penetration testing practice and public legal material in general terms. It is not legal advice. Confirm how UAE federal law applies to your specific engagement with a qualified adviser before commissioning or carrying out a penetration test.
Penetration testing is a defined, time boxed exercise in which a tester attempts to achieve a specific goal against a named system, such as gaining access to a database or an admin panel, using the same techniques a real attacker would use. NIST’s own technical guide to security testing describes this kind of assessment as one that uses the same methods a genuine adversary would, to demonstrate the practical impact of security weaknesses rather than simply listing them. That practical, demonstrated impact is what separates penetration testing from most other security work a UAE business commissions.
A penetration test in the UAE, or anywhere else, is not an open ended search for every possible problem. It is bounded to what is written into the scope, run over an agreed window, and it stops the moment the agreed goals are met or the time runs out. Anything discovered outside that boundary is reported, not exploited further, without going back to the client first.
A vulnerability scan and a penetration test are often confused, and the confusion is expensive when a business buys one expecting the other.
| Vulnerability scan | Penetration test | |
|---|---|---|
| Method | Automated tool, run against a target | Manual, human led work following a methodology |
| Question answered | What might be wrong here | What can actually be exploited, and how far does it reach |
| Output | A list of flagged issues, including false positives | A ranked report with evidence, impact and a fix for each real finding |
| Typical use | Frequent, routine checking | Periodic, deeper assessment or a specific compliance need |
Neither replaces the other. A scan run every week catches new, obvious exposures quickly and with little effort. A penetration test, run less often, chains smaller findings together the way an attacker actually would, which a scan cannot do on its own. A UAE business asking for penetration testing but budgeting for a scan, or the other way round, is usually the source of a disappointing engagement.
A scan tells you what a tool noticed. A penetration test tells you what a person could actually do with it.
Scope is the single most important document in a penetration test, because it is what turns access to a system from an offence into an agreed, lawful service. NIST’s guide places planning, including defining scope and objectives, as the first phase of any technical security assessment, before any discovery work begins. A written scope for penetration testing in the UAE should name:
A tester should never touch a system without this document signed by someone with the authority to grant that access.
Rules of engagement sit alongside scope and cover how the work is carried out, not just what is included. This usually covers which techniques are permitted, such as whether social engineering or physical access attempts are in scope, how the tester should communicate a critical finding discovered mid test, an emergency contact if something behaves unexpectedly, and how any data accessed during testing is handled and later deleted. A UAE business handling customer data during a test still has obligations under the country’s separate data protection law once that data is touched, so retention and deletion terms belong in the rules of engagement, not left as an assumption.
Agreeing rules of engagement before testing starts also protects the business commissioning the work. A tester who strays outside agreed techniques, or who cannot show what was agreed, leaves a UAE business unable to demonstrate the test was properly authorised if a system is affected in an unexpected way.
The report is the actual deliverable of a penetration test, and a weak report can waste a technically strong engagement. A usable report, for a UAE business acting on the findings, includes:
A short, non technical account of overall risk, written for someone who will never read the technical detail underneath.
Screenshots, request and response data, or another form of proof, not just a claim that something is vulnerable.
Findings ranked so a small technical team knows what to fix first, rather than a flat, unordered list.
What an attacker could actually do with the finding, described in terms a non specialist can understand.
A concrete remediation step for each finding, not a generic instruction to improve security.
NIST’s guide describes reporting as a distinct phase that includes analysing results and recommending mitigation, not simply exporting whatever a tool produced during testing. A report without that structure is closer to a scan output than genuine penetration testing.
There is no single legal requirement setting testing frequency for every UAE business, so this is a risk judgement rather than a fixed rule. A common, defensible pattern is testing at least once a year, plus an additional test after any significant change, such as a new payment integration, a new customer facing application, or a move to new hosting infrastructure. A business handling sensitive personal or financial data, or one bound by a client contract that specifies testing, should treat that as the floor rather than the ceiling. Penetration testing tied only to a calendar date, and never to what actually changed on the system, tends to miss the moments risk genuinely increased.
This is the point most guides on penetration testing skip, and it matters specifically for the UAE. Federal Decree Law No. 34 of 2021 on Countering Rumours and Cybercrimes, in force since 2 January 2022, sets out hacking offences directly. Article 2 of the law states that whoever hacks a website, an electronic information system, an information network or a piece of information technology equipment is subject to imprisonment, a fine, or both, with heavier penalties where the hacking causes damage or is carried out to obtain data for an unlawful purpose.
None of that changes for a security professional carrying out a legitimate, agreed test. The law does not create an exemption for penetration testing by title, so the protection a UAE business and its tester rely on is the written scope and authorisation itself, signed by someone with the authority to grant access to the system being tested. Commissioning penetration testing in the UAE without that written authorisation in place, even with good intentions, is a genuine legal exposure for both sides, not just a procedural gap.
We treat scope and written authorisation as the starting point for every engagement, not paperwork to complete afterwards. Our penetration testing service scopes the work against a named system before anything is touched, our penetration tester page covers hiring a specialist for project, recruitment or dedicated work, and our wider cyber security service covers the practical basics, such as patching and multifactor authentication, that a test’s findings often point back to. This work sits in our IT services category, alongside the cybersecurity specialists who carry out and act on the testing described here. If your business is preparing for a client or compliance requirement, tell us which standard is driving the request so the scope and report can be shaped to match what your auditor expects.
For the wider IT hygiene that often sits behind a test’s findings, our guide to a Microsoft 365 security checklist for small businesses covers the everyday controls worth having in place before you commission penetration testing in the UAE at all.
Straight answers
A scan runs automated tools against a target and lists whatever they flag, including a fair number of false positives. A penetration test is a manual, human led exercise that tries to chain those findings together the way a real attacker would, to show what is actually exploitable rather than just what a tool noticed.
No test can promise that. A penetration test reports on what a skilled tester found exploitable within an agreed scope and time window. It reduces risk and provides evidence of testing, but new weaknesses can appear the day after a report is delivered, which is why testing is repeated rather than done once.
Whoever owns or is legally responsible for the system being tested, in writing, before any tool touches it. This is not a formality. Unauthorised access to a website or information system is an offence under UAE federal law, discussed below, so the signed scope and authorisation letter is what makes the engagement lawful.
There is no single rule that fits every business. A common pattern is at least once a year, plus after any significant change to the system, such as a major new feature, a new integration, or a move to new infrastructure. A business handling sensitive customer data usually tests more often than a simple brochure site.
Each finding with evidence, a severity rating, the business impact and a specific fix, ordered so a technical team knows what to close first. A report that is only a list of raw tool output, without that structure, is closer to a scan result than a usable penetration test report.
Sources
Fixed price, in writing
Got it. Your quote is being written now.
In business hours you will have it within 45 minutes. Check your inbox for the confirmation.
Keep reading

The Microsoft 365 settings a small UAE business should check first, based on Microsoft's own guidance, with what each one does.
Read the article
Cloud API versus a click to chat link, message templates, opt in, the 24 hour window and human handover, for a UAE business building WhatsApp into its site.
Read the article
How a UAE business should decide whether to build or buy enterprise software, and what each path actually costs over time.
Read the article