Rootsec is an independent cybersecurity firm based in Business Bay, Dubai. We are offensive-security specialists: we attack your environment the way a real adversary would, show you exactly what we found, and help you close it. No resold dashboards, no generic reports — expert-led testing, with findings you can act on.
Testing is not optional in the UAE
Vulnerability assessment and penetration testing is a regulatory requirement here, not a nice-to-have. Depending on your sector, testing obligations flow from:
- NESA / UAE IA Standards — federal entities and critical infrastructure operators, typically at least annually and after major system changes
- DESC (Dubai Electronic Security Center) — Dubai government entities and their suppliers
- CBUAE — banks, finance companies and payment providers
- TDRA — telecom and digital service providers
- UAE PDPL — organisations processing personal data
Our work is benchmarked against the frameworks these regimes expect: OWASP, PTES, NIST CSF, MITRE ATT&CK, CIS Benchmarks and ISO/IEC 27001. If you need evidence for an audit, you get a report written to stand up to one.
Read the full UAE compliance guide — NESA, DESC, CBUAE & PDPL →
Offensive security: testing & simulation
Manual, expert-led testing that shows you how a real adversary would get in — and exactly how to close it.
- Penetration TestingManual, expert-led testing of applications, networks and cloud environments. Certified ethical hackers, not a scan with a logo on it.Learn more →
- Vulnerability Assessment & Penetration Testing (VAPT)Combined scanning and hands-on verification, so you know which findings are genuinely exploitable and which are noise.Learn more →
- Red Team OperationsFull-scope adversary simulation across people, process and technology — recon, initial compromise, lateral movement, and a debrief your SOC learns from.Learn more →
- Social Engineering AssessmentTesting the human layer directly: phone, physical and digital pretexts.Learn more →
- Phishing SimulationRealistic campaigns plus targeted awareness training, so your people have seen a convincing attempt before it counts.Learn more →
- AI SecurityTesting LLMs, RAG pipelines and AI agents for prompt injection, data leakage and tool-calling abuse, with working proof-of-concepts.Learn more →
- Comprehensive Security AssessmentNot sure whether you need a scan or a full pentest? This maps where you actually stand first.Learn more →
Detection & protection
Detection only works when someone is watching — around the clock.
When it has already gone wrong
A live incident is a phone call, not a form. Containment first, then recovery, then the honest post-mortem.
Where should you start?
Most organisations arrive at one of these three. New to this? Read how to choose a penetration testing partner in the UAE. Not sure which is you? That is a fine place to begin.
- You need testing for a regulator or a client questionnaire.Start with VAPT — it produces the evidence, and it tells you what is real.
- You want to know whether your defences would actually hold.Start with a red team operation. Testing one application tells you about that application; a red team tells you about your organisation.
- Something is happening right now.Go straight to incident response and call +971 55 468 3363.