Ransomware incidents in the Gulf are up materially year-on-year. What has changed most for advisors is not the frequency but the regulatory choreography of the response — the number of parallel notifications, and the window in which they must be sequenced, has narrowed to something close to 72 hours.
The primary obligations are three. Under the PDPL, controllers must notify the UAE Data Office 'without undue delay' of any breach 'likely to result in a risk to the privacy, confidentiality or security' of the personal data. Practically, this is a 72-hour window. Data subjects must be notified where the risk is high.
For regulated financial institutions, the CBUAE's Consumer Protection Regulation and the Standards for the Cyber Resilience of the UAE Banking Sector impose additional notification obligations to the CBUAE within an even shorter timeframe.
Under the UAE Cybercrime Law (Federal Decree-Law No. 34 of 2021), the payment of ransom is not, in itself, criminalised — but concealment of the underlying offence is. Any strategy that involves quiet resolution without regulator engagement is not viable.
In practice, the first four hours of any credible incident should be spent on three tasks in parallel: (i) containment and forensic imaging, (ii) legal privilege scoping — engage external counsel and have forensic vendors contracted under counsel; and (iii) regulator engagement strategy — the sequence of notifications matters, and it is easier to lead the conversation than to catch up to it.