Cybersecurity Companies in Abu Dhabi: 8 Firms Compared for 2026
Founder and Principal Security Consultant - CISSP, CEH, CHFI, Mandiant

Abu Dhabi is not a smaller Dubai. The capital’s security market is shaped by government, energy and sovereign technology rather than by trade and tourism, and the obligations that come with that are different in kind. This guide compares eight firms serving Abu Dhabi on what they charge, how big they are, and which of them fits the kind of organisation you actually run.
Disclosure: this guide is published by Atlant Security, which appears at number 4 of 8 below. We are not a reseller or partner of any firm listed, none paid for placement, and none saw this before publication. Every company here was checked against its own live website on 14 September 2026. Strengths and weaknesses are our editorial judgement; each quoted line is taken verbatim from the firm’s own site.
What changed in this edition: This edition was rebuilt and corrects several errors. DarkMatter was ranked second in the previous version; darkmatter.ae does not resolve on any DNS resolver we tested, and given the firm’s reporting history it is not a vendor we would recommend regardless. Paladion has been removed because paladion.net now redirects to eviden.com: the business was absorbed into Atos and the brand no longer operates independently. The CPX link was corrected to cpx.net, since cpx.ae belongs to an unrelated affiliate marketing network. One further Abu Dhabi candidate was dropped because its site shows only a "Coming Soon" placeholder. Finally, Atlant Security was ranked first in the previous edition, which is not a defensible thing for us to do in our own comparison; we now place ourselves fourth and say why.
Start Here: the 30 Second Version
If you read nothing else on this page, read the row that describes you. Every provider is compared in detail further down, but choosing the right category of firm matters far more than choosing between two firms in the same category.
| If this is you | Buy this first | Because |
|---|---|---|
| A DoH-regulated clinic, hospital or health business | An ADHICS gap assessment | It is mandatory, and the licence is what is at stake. |
| A government or critical infrastructure entity | A UAE IA Standard assessment against all 188 controls | Three firms below are built for exactly this buyer and priced accordingly. |
| A 20 to 80 person commercial business | A fixed-price assessment from a smaller firm | The national providers are not aimed at you and will price accordingly. |
| You need monitoring without an enterprise contract | Managed detection and response from a smaller firm | Ask how round-the-clock coverage is genuinely staffed at a small team size. |
| You do not know which of these you are | A scoped, fixed-price audit | The cheapest thing to buy first is the ordering. |
Atlant Security editorial assessment, September 2026. This is our reading of the market, not a figure taken from any published source.
Does a Abu Dhabi Cybersecurity Company Need to Be in Abu Dhabi?
In Abu Dhabi, more than in Dubai, yes. A large share of the serious security work in the capital touches government entities, critical national infrastructure or the energy sector, and those engagements carry requirements around nationality, clearance, data residency and physical presence that simply cannot be met remotely. If your work falls into that category, the question is not which firm is best but which firms are eligible.
For ordinary commercial businesses in the capital, the calculation is the same as anywhere: judge on specialism and on who is actually assigned. Several of the firms below are headquartered in Dubai and serve Abu Dhabi clients perfectly well, which is a ninety minute drive rather than a different market.
Where Abu Dhabi does differ commercially is expectation. Procurement here tends to be more formal, timelines longer, and in-person meetings more important to closing than they are in the faster-moving Dubai market. Budget for that in your project plan.
What Drives Security Spending in Abu Dhabi
The capital’s security market is dominated by the public sector and by critical national infrastructure. Government entities, the energy sector and sovereign technology investments generate requirements that are set by national policy rather than by commercial risk appetite, and the firms that serve them are structured accordingly, with local delivery, local data residency and staff who can hold the necessary clearances.
Healthcare is the second pillar and comes with its own named framework. Abu Dhabi’s health sector operates under sector-specific information security requirements covering how patient data is handled by providers and payers in the emirate. If you run a clinic, a hospital, a health insurer or a health technology platform serving Abu Dhabi patients, that is a distinct obligation from the general federal data protection regime, and we cover it in detail on our ADHICS compliance page.
The ADGM free zone adds a third regime. A company licensed in Abu Dhabi Global Market operates under that jurisdiction’s own data protection framework rather than the federal one, in the same way DIFC companies do in Dubai. Which applies to you depends on where you are licensed, not on where your office happens to be, and it is a question for counsel before you scope a compliance programme around an assumption.
Layered across all of this is the national information assurance framework applying to entities designated as critical, which sets control requirements considerably more prescriptive than a general good-practice standard. Our NESA and UAE Information Assurance page goes through what that actually requires.
For the ordinary Abu Dhabi business that is none of the above, a trading company, a consultancy, a contractor, the real threat is the same as it is across the Gulf: business email compromise against invoiced cross-border payments, and accounts that outlive departing staff in a workforce with high turnover. Neither is solved by buying a platform.
Work out which one you are
Which rulebook binds you in Abu Dhabi?
Abu Dhabi adds an emirate-level healthcare standard on top of the federal frameworks, and it is mandatory rather than advisory for the entities it covers.
You are a DoH-regulated healthcare entity
ADHICS, the Abu Dhabi Healthcare Information and Cyber Security Standard, aligned with ISO 27001
Enforced by the Department of Health Abu Dhabi
You operate critical national infrastructure, or supply government
The UAE Information Assurance Standard: 188 controls across 4 domains
Enforced by the authority that issued it, now under the Signals Intelligence Agency
You hold personal data in the UAE
UAE personal data protection law, with fines of up to AED 5 million for violations
Enforced by the federal data office
The three most common situations. The full table below adds a fourth and gives the sourcing for each row.
| Your situation | What applies | Who enforces it | What it changes when you buy |
|---|---|---|---|
| You are a DoH-regulated healthcare entity | ADHICS, the Abu Dhabi Healthcare Information and Cyber Security Standard, aligned with ISO 27001 | The Department of Health Abu Dhabi | Mandatory, not voluntary, and a failed assessment puts your DoH licence at risk. See ADHICS compliance. |
| You operate critical national infrastructure, or supply government | The UAE Information Assurance Standard: 188 controls across 4 domains | The authority that issued it, now under the Signals Intelligence Agency | Tenders increasingly require proof of alignment. See NESA and UAE IA compliance. |
| You hold personal data in the UAE | UAE personal data protection law, with fines of up to AED 5 million for violations | The federal data office | Applies far more broadly than the government-facing frameworks. |
| You are the Gulf arm of a foreign parent | Local law, plus group standards and any GDPR flowing down by contract | Your head office, your auditors and your customers | Usually both apply at once. Scope it explicitly. |
Framework scope and control counts are as published on Atlant Security’s own compliance pages, linked from each row. Confirm your own position with counsel. This is not legal advice.
Cybersecurity Companies in Abu Dhabi: Side-by-Side Comparison
All 8 firms below have a real presence in the Abu Dhabi area. The table is sorted in the same order as the reviews that follow.
| Provider | Based | Team size | Hourly rate | Best for |
|---|---|---|---|---|
| CPX | Abu Dhabi, UAE | 500+ | Not published | Government and critical national infrastructure operators in the Emirates |
| Help AG | Dubai, UAE | 500+ | Not published | Large UAE enterprises and government entities needing a full managed SOC |
| Paramount | Dubai, UAE | 250-999 | Not published | Regional enterprises wanting long-established Middle East consulting and compliance work |
| Atlant Security | Remote, serving 14 countries | Small senior team | Fixed price, not hourly | Companies that need someone to decide what to do and then implement it |
| Truscova | Abu Dhabi, UAE | 2-9 | $200-$300 | Abu Dhabi organisations wanting a small senior team rather than an account manager |
| CyberSec Consulting | Dubai, UAE | 10-49 | $100-$149 | Dubai businesses wanting advisory and compliance support at mid-market rates |
| Azpirantz | Dubai, UAE | 10-49 | $100-$149 | Companies whose driver is data privacy obligations as much as security |
| CyberQuell | Dubai, UAE | 2-9 | $50-$99 | Dubai SMEs that want monitored detection without an enterprise contract |
Team size, hourly rate and minimum engagement are as published by each firm on the Clutch directory, checked 14 September 2026. They are the firms’ own figures, not our measurements. “Best for” is Atlant Security’s editorial assessment.
What kind of firm each one actually is
The table above compares them on price and location. This one compares them on what they are, which is the comparison that decides whether the engagement works. Most bad purchases in this market are the right firm in the wrong category.
| Provider | What kind of firm it is | What the engagement ends with | The limitation this guide flags |
|---|---|---|---|
| CPX | Managed security (MSSP) | A monitored service, and an alert somebody acts on | Public sector and large enterprise focus rather than commercial SMEs |
| Help AG | Managed security (MSSP) | A monitored service, and an alert somebody acts on | Enterprise oriented; a thirty-person Dubai company is not the target client |
| Paramount | Consultancy | A prioritised plan, and with some firms the fixes as well | Consulting led, so continuous monitoring comes from a partner or a separate tier |
| Atlant Security | Consultancy | A prioritised plan, and with some firms the fixes as well | No help desk, so day-to-day IT support still needs a local provider |
| Truscova | Consultancy | A prioritised plan, and with some firms the fixes as well | At 2-9 people, capacity and cover need a written answer before you sign |
| CyberSec Consulting | Consultancy | A prioritised plan, and with some firms the fixes as well | Consulting rather than managed monitoring or offensive testing |
| Azpirantz | Consultancy | A prioritised plan, and with some firms the fixes as well | Advisory focused; monitoring and testing are not the core offering |
| CyberQuell | Managed security (MSSP) | A monitored service, and an alert somebody acts on | Very small team, so ask precisely how 24/7 coverage is staffed |
Category is our reading of each firm’s own published description, quoted in its entry below. The limitation column is taken verbatim from the same entry. Checked against each firm’s live site in September 2026.
Read the Atlant Security row the same way you read the others. We are a consultancy. There is no help desk, no monitoring platform and nothing to resell, and that is a limitation as much as a position. If what you need is somebody to answer the phone when a laptop dies, buy from one of the managed providers on this page instead. We are here because deciding what to fix and in what order is a separate purchase from keeping the estate running.
The 8 Best Cybersecurity Companies in Abu Dhabi for 2026
Ordered by fit for an Abu Dhabi buyer. The first is the capital’s own government-oriented provider; the rest serve the emirate from across the UAE.
1. CPX
Abu Dhabi, UAE · Website: cpx.net

Best for: Government and critical national infrastructure operators in the Emirates
CPX is an Abu Dhabi cybersecurity group oriented toward government and critical national infrastructure, with managed services, consulting and incident response delivered from the UAE. For entities whose requirements include national data residency and security clearance considerations, a home-grown provider matters in a way it does not elsewhere, because the question of where your telemetry physically sits is a live one. Note the domain carefully: the company is at cpx.net, while cpx.ae belongs to an unrelated affiliate marketing network.
Leading Cybersecurity Company in UAE
How CPX describes itself on cpx.net, September 2026
Strengths
- UAE-native provider oriented to government and critical infrastructure
- Local delivery and data residency, which matters for sovereign requirements
Watch out for
- Public sector and large enterprise focus rather than commercial SMEs
- No published pricing; expect formal procurement
Team size: 500+ · Rate: Not published · Minimum engagement: Enterprise engagement
2. Help AG
Dubai, UAE · Website: helpag.com

Best for: Large UAE enterprises and government entities needing a full managed SOC
Help AG is the largest and best-established cybersecurity firm in the UAE, now part of the e& enterprise group, and it is the default answer for a large Emirati organisation buying security services. It runs regional security operations centres, has a substantial consulting and incident response practice, and has been embedded in the UAE market long enough to know how the regulators actually behave rather than only what the published standards say. For an enterprise buyer this is the safe, obvious and expensive choice.
Leading Cybersecurity Firm in the Middle East
How Help AG describes itself on helpag.com, September 2026
Strengths
- The most established security firm in the UAE, with regional SOCs of its own
- Deep familiarity with UAE regulators and how requirements are applied in practice
- Backed by e& enterprise, so continuity is not a concern
Watch out for
- Enterprise oriented; a thirty-person Dubai company is not the target client
- No published pricing, and procurement is a formal process
Team size: 500+ · Rate: Not published · Minimum engagement: Enterprise engagement
3. Paramount
Dubai, UAE · Website: paramountassure.com

Best for: Regional enterprises wanting long-established Middle East consulting and compliance work
Paramount is one of the longer-established cybersecurity consultancies in the Gulf, with a practice weighted toward governance, risk and compliance alongside technical services. In a market where a great deal of security spending is driven by regulatory requirement rather than by incident, a firm whose centre of gravity is compliance is well matched to what buyers actually need. For a UAE business facing a specific regulatory deadline, this is a sensible shortlist entry.
CyberSecurity Solutions & Services in Middle east
How Paramount describes itself on paramountassure.com, September 2026
Strengths
- Long regional track record with governance, risk and compliance depth
- Well matched to the compliance-driven nature of Gulf security spending
Watch out for
- Consulting led, so continuous monitoring comes from a partner or a separate tier
- No published rate card
Team size: 250-999 · Rate: Not published · Minimum engagement: Enterprise engagement
4. Atlant Security
Remote, serving 14 countries · Website: atlantsecurity.com

Best for: Companies that need someone to decide what to do and then implement it
Atlant Security is a consultancy rather than a managed services provider or a product vendor, and the distinction is the reason it is on this list at all. There is no help desk, no monitoring platform and nothing to resell. What it does is the part most local providers leave to you: an audit that produces a prioritised remediation plan with named owners and effort estimates, and the same engineers then implementing the fixes. The firm has run 200+ security assessments across 14 countries since 2013, works to fixed prices rather than hourly billing, and is vendor-independent, so the recommendation carries no resale commission. For a company that does not yet know whether it needs an MSP, a penetration test or a compliance programme, that ordering is the useful thing to buy first.
Strengths
- Fixed price, so scope and invoice are agreed before work starts
- Implements the fixes rather than stopping at a findings report
- Vendor-independent, with no product resale margin behind the advice
Watch out for
- No help desk, so day-to-day IT support still needs a local provider
- No 24/7 monitoring platform of its own; continuous detection goes to a partner
- Remote-first, so regular on-site presence is not the model
Team size: Small senior team · Rate: Fixed price, not hourly · Minimum engagement: $8,000+
5. Truscova
Abu Dhabi, UAE · Website: truscova.com

Best for: Abu Dhabi organisations wanting a small senior team rather than an account manager
Truscova is a very small Abu Dhabi security firm, in the 2 to 9 employee band, publishing a rate at the top of the local range. That combination normally signals senior practitioners doing the work themselves rather than a sales layer in front of junior delivery, which for security is usually the right trade. The limits of a team this size are the obvious ones and should be planned around rather than discovered: capacity, holiday cover, and no independent round-the-clock capability.
Strengths
- Small senior team, so the people you meet are the people who deliver
- Abu Dhabi based rather than serving the capital from Dubai
Watch out for
- At 2-9 people, capacity and cover need a written answer before you sign
- Top-of-band rate with no published detail on specialisms
Team size: 2-9 · Rate: $200-$300 · Minimum engagement: $5,000+
6. CyberSec Consulting
Dubai, UAE · Website: cybersecit.net

Best for: Dubai businesses wanting advisory and compliance support at mid-market rates
CyberSec Consulting is a mid-sized Dubai consultancy positioning on strategic advisory rather than product delivery, at a published band of $100 to $149 per hour. That is the sensible middle of the Dubai market: more capability than a two-person shop, considerably less cost and ceremony than the regional enterprise providers. For a Dubai company that needs someone to work out which of the several applicable UAE frameworks it must actually satisfy, this tier is usually the right place to start.
CyberSec Consulting | Strategic Services Partner
How CyberSec Consulting describes itself on cybersecit.net, September 2026
Strengths
- Advisory-led positioning at accessible mid-market rates
- Sized appropriately for Dubai mid-market businesses
Watch out for
- Consulting rather than managed monitoring or offensive testing
- Confirm which named consultant is assigned before signing
Team size: 10-49 · Rate: $100-$149 · Minimum engagement: $1,000+
7. Azpirantz
Dubai, UAE · Website: azpirantz.com

Best for: Companies whose driver is data privacy obligations as much as security
Azpirantz names data privacy alongside cybersecurity in its own positioning, which is a more useful distinction in the UAE than it might appear. The Emirates now has a federal personal data protection regime layered over the separate frameworks operating inside the DIFC and ADGM financial free zones, and privacy obligations frequently arrive before security ones in a company’s attention. A firm that treats both as one practice fits that reality better than one that treats privacy as a legal afterthought.
Azpirantz - Cyber Security and Data Privacy Consulting Services
How Azpirantz describes itself on azpirantz.com, September 2026
Strengths
- Treats data privacy and security as a single practice, which suits UAE obligations
- Mid-market rate band with a low entry point
Watch out for
- Advisory focused; monitoring and testing are not the core offering
- Smaller team than the regional enterprise providers
Team size: 10-49 · Rate: $100-$149 · Minimum engagement: $1,000+
8. CyberQuell
Dubai, UAE · Website: cyberquell.com

Best for: Dubai SMEs that want monitored detection without an enterprise contract
CyberQuell is a small Dubai firm selling managed detection and round-the-clock monitoring, which is the service most mid-sized Dubai businesses need and almost none of them buy, because the large regional providers are priced for enterprises. A published band of $50 to $99 per hour with a $1,000 minimum puts monitored detection within reach of a company that would never get through Help AG’s procurement process. Verify what "24/7" means contractually and who is actually watching.
Managed SOC & XDR Services | 24/7 Monitoring
How CyberQuell describes itself on cyberquell.com, September 2026
Strengths
- Managed detection at a price point Dubai SMEs can actually reach
- Low minimum engagement makes a bounded trial realistic
Watch out for
- Very small team, so ask precisely how 24/7 coverage is staffed
- Limited depth for compliance or specialist testing work
Team size: 2-9 · Rate: $50-$99 · Minimum engagement: $1,000+
How to Choose a Cybersecurity Company in Abu Dhabi
The providers below fall into several quite different categories, which makes the selection process matter more than the shortlist. Work through these five steps in order.
- Work out which of the things below you are buying
A managed provider keeps your estate running day to day. A testing firm tries to break in and reports how it went. A consultancy decides what you should do and in what order. A product vendor sells you a platform somebody then has to operate. The table above says which is which.
- Ask who fixes the problem after it is found
A scan, an audit and a penetration test all end with a document. Somebody then has to change firewall rules, rebuild permissions, roll out multi-factor authentication and argue with a vendor about a legacy application. Ask in writing whether remediation is included, excluded, or billed separately.
- Get the scope and the price in writing before anyone starts
A proposal that prices security services without listing what is monitored, tested or documented is not a proposal you can hold anyone to. Ask for a fixed or capped price and an explicit list of exclusions. The price transparency panel further down shows how many of these firms publish anything at all.
- Check whether ADHICS or the UAE IA Standard reaches you
Both extend beyond the obvious in-scope entities. ADHICS covers DoH-regulated healthcare entities including professionals and support staff who access patient information. The UAE IA Standard reaches government suppliers through tender conditions. If either applies, it sets your baseline and your shortlist narrows considerably.
- Ask what you keep if you leave after twelve months
Documentation, configurations, log history, tenancy ownership. If the answer is that you keep nothing, you are not buying a security programme, you are renting one, and the renewal conversation will reflect that.
Good signs
- They name the engineer who will do the work, and you can check that person exists
- They tell you what is out of scope before you ask
- They are willing to quote a fixed price for a bounded piece of work
- They ask about your customers and your parent company, not just your firewall
- They can say plainly which parts of the job they would subcontract
Walk away if
- Security is one of a dozen services listed and nobody on the team does it full time
- The proposal prices security services as a single line with no itemised scope
- The recommendation happens to be the product they resell
- They will not put the remediation position in writing
- They treat ADHICS as optional or as a nice-to-have
Five questions worth putting in the RFP
| Ask this | Why it matters | What a good answer sounds like |
|---|---|---|
| What proportion of your revenue is security work? | A directory search returns many firms listing cybersecurity among a dozen services. | A number, followed by the names of the people who do it full time. |
| Who specifically will be assigned, and what is their background? | Small teams sell with a senior and deliver with a junior. It is the most common complaint. | A name, a history you can verify, and a willingness to put it in the contract. |
| What does your managed security tier actually monitor, and during which hours? | MSSP is a marketing term as often as it is an operating model. | Named data sources, named hours, and who reads an alert at 03:00. |
| Is remediation included, excluded, or billed separately? | This is where the budget you did not plan for appears. | One of the three words, in writing, before you sign. |
| What happens contractually if we are breached during the engagement? | It reveals how much of the risk the provider is genuinely taking on. | A clear, unembarrassed answer. Whether they have thought about it matters most. |
Atlant Security editorial, September 2026. These are the questions we would ask, based on what goes wrong in engagements we are called in to rescue.
What Cybersecurity Costs in Abu Dhabi
Abu Dhabi splits the same way Dubai does, but more sharply. The providers serving government and critical infrastructure do not publish pricing and run formal, lengthy procurement. The smaller commercial firms publish bands from roughly $50 to $300 per hour with minimum engagements from $1,000, and that is where a normal private business should be shopping.
If your requirement is driven by a named framework rather than by a general wish to be more secure, expect the documentation and evidence work to cost more than the technical remediation. That is not padding. Demonstrating a control to an assessor is genuinely more laborious than implementing it, and budgets that ignore this run out halfway through.
A fixed-price independent security audit generally runs $8,000 to $35,000 depending on scope and headcount. In a market with a federal regime, a free-zone regime and sector frameworks all in play, establishing which obligations actually bind you is frequently worth more than the technical findings that come with it.
The practical problem with buying here
Price transparency among these providers
What each firm publishes about what it charges, before you have spoken to anyone.
| Provider | Hourly rate published | Minimum engagement published | Fixed price offered |
|---|---|---|---|
| CPX | |||
| Help AG | |||
| Paramount | |||
| Atlant Security | |||
| Truscova | |||
| CyberSec Consulting | |||
| Azpirantz | |||
| CyberQuell |
4 of the 8 publish an hourly rate. 5 publish a minimum engagement. Expect to ask, and expect to get the answer in writing before anyone starts.
Rates and minimums as published by each firm on the Clutch directory, checked 14 September 2026. A cross means the figure is not published. It is not a finding that the firm refuses to quote.
| What you are buying | Price | Where this number comes from |
|---|---|---|
| Hourly rate, published bands | $100-$149 · $200-$300 · $50-$99 | Published by 4 of the 8 firms above on the Clutch directory. |
| Minimum engagement, published | $1,000+ to $8,000+ | Published by 5 of the 8 firms above. |
| Fixed-price independent security audit | US$8,000 to US$35,000 | Atlant Security estimate, based on our own engagements. Not a published figure. |
| Penetration test, bounded scope | US$8,000 to US$20,000 | Atlant Security estimate. Varies more with scope than with provider. |
| Managed detection and response, per year | From US$30,000 | Atlant Security estimate. The variable is who reads the alerts, not the platform licence. |
| Gap assessment against ADHICS compliance | Quoted per organisation | Scope depends on which framework applies. See our ADHICS compliance page. |
Rows marked as published are the firms’ own figures, checked 14 September 2026. Rows marked as an estimate are Atlant Security’s, are labelled as such, and should be treated as a planning range rather than a quotation.
Frequently Asked Questions: Cybersecurity Companies in Abu Dhabi
Is DarkMatter still operating in Abu Dhabi?
darkmatter.ae does not resolve on any DNS resolver we tested, which indicates the domain is no longer active. The firm was also the subject of significant reporting regarding former US intelligence personnel it employed. It was ranked second in the previous version of this article; we do not list or recommend it now.
What happened to Paladion?
Paladion was acquired by Atos and the brand no longer operates independently. paladion.net now redirects to eviden.com, Atos’ cybersecurity arm. It has been removed from this edition for that reason.
Which cybersecurity company is actually headquartered in Abu Dhabi?
CPX is the significant Abu Dhabi headquartered provider, at cpx.net, oriented toward government and critical national infrastructure. Truscova is a much smaller Abu Dhabi firm. Help AG, Paramount and the other firms listed are based in Dubai and serve the capital from there.
Does ADGM have different data protection rules from mainland Abu Dhabi?
Yes. Abu Dhabi Global Market operates its own data protection framework, separate from the UAE federal regime that applies to mainland companies. Which one binds you depends on where your entity is licensed. Confirm it with counsel before scoping any compliance work.
What does a cybersecurity company cost in Abu Dhabi?
The commercial firms publish hourly bands from roughly $50 to $300 with minimum engagements from $1,000. Providers serving government and critical infrastructure do not publish pricing and run formal procurement. A fixed-price independent audit generally runs $8,000 to $35,000.
Why is Atlant Security not ranked first here?
Because we publish this comparison, and ranking ourselves first in our own guide would not be credible. An earlier version of this page did exactly that, which was a mistake. We are a remote consultancy with no help desk and no monitoring platform, so for an Abu Dhabi government entity or a business needing on-site presence, several firms above are a better fit than we are. We say where we do fit in our entry.
Is ADHICS mandatory?
Yes. ADHICS is mandatory for all DoH-regulated healthcare entities in the Emirate of Abu Dhabi, including healthcare and medical facilities, healthcare professionals and support staff who access patient health, diagnostic or personal information. It is not a voluntary framework, and a failed assessment puts your DoH licence and your ability to contract at risk. See our ADHICS page.
We are in scope for both ADHICS and the UAE IA Standard. Two projects?
It should not be. Both align substantially with ISO 27001 as a shared control base, which means the overlapping controls can be assessed and implemented once and evidenced against both. Running them as two separate programmes duplicates the gap assessment, the policy work and the evidence collection, which is where most of the cost sits.
Not sure which of these you actually need?
That is the question a fixed-price security audit answers. We assess what you have, tell you what to fix and in what order, and give you a plan you can hand to any provider on this page, including one of our competitors. 200+ assessments across 14 countries since 2013, fixed price agreed before we start.
See what a fixed-price audit coversRelated reading: the 15 largest computer security companies compared, our fixed-price IT security audit, and virtual CISO services.
Looking wider than this list? cybersecuritycompanies.io is a free directory of cybersecurity companies worldwide, filterable by category, location and credentials.

Alexander Sverdlov
Founder of Atlant Security. CISSP, CEH, CHFI and Mandiant certified. Author of 2 information security books, cybersecurity speaker at the largest cybersecurity conferences in Asia and a United Nations conference panelist. Former Microsoft security consulting team member, external cybersecurity consultant at the Emirates Nuclear Energy Corporation.
Connect on LinkedIn