Rootsec is an independent cybersecurity firm based in Business Bay, Dubai. We are offensive-security specialists: we attack your environment the way a real adversary would, show you exactly what we found, and help you close it. No resold dashboards, no generic reports — expert-led testing, with findings you can act on.

Testing is not optional in the UAE

Vulnerability assessment and penetration testing is a regulatory requirement here, not a nice-to-have. Depending on your sector, testing obligations flow from:

  • NESA / UAE IA Standards — federal entities and critical infrastructure operators, typically at least annually and after major system changes
  • DESC (Dubai Electronic Security Center) — Dubai government entities and their suppliers
  • CBUAE — banks, finance companies and payment providers
  • TDRA — telecom and digital service providers
  • UAE PDPL — organisations processing personal data

Our work is benchmarked against the frameworks these regimes expect: OWASP, PTES, NIST CSF, MITRE ATT&CK, CIS Benchmarks and ISO/IEC 27001. If you need evidence for an audit, you get a report written to stand up to one.

Read the full UAE compliance guide — NESA, DESC, CBUAE & PDPL →

Where should you start?

Most organisations arrive at one of these three. New to this? Read how to choose a penetration testing partner in the UAE. Not sure which is you? That is a fine place to begin.

  • You need testing for a regulator or a client questionnaire.Start with VAPT — it produces the evidence, and it tells you what is real.
  • You want to know whether your defences would actually hold.Start with a red team operation. Testing one application tells you about that application; a red team tells you about your organisation.
  • Something is happening right now.Go straight to incident response and call +971 55 468 3363.