FSRA's New Cyber Risk Management Framework and 24-Hour Incident Reporting Requirements
On January 31, 2026, financial services firms operating in the Abu Dhabi Global Market crossed a critical compliance threshold. The Financial Services Regulatory Authority’s new Cyber Risk Management Framework became mandatory, fundamentally reshaping cybersecurity obligations for every authorized person and recognized body under FSRA supervision. For firms accustomed to treating cybersecurity as an IT function, this marks a decisive shift toward board-level accountability, third-party oversight, and real-time incident disclosure.
What makes this framework particularly significant is its integration of cybersecurity into core financial audit and regulatory compliance structures. ADGM entities can no longer maintain separate cybersecurity and financial control environments—the new requirements demand convergence, creating both compliance challenges and strategic opportunities for firms willing to embrace integrated assurance models.
FSRA Cyber Risk Framework 2026: Understanding the New Baseline Requirements
The framework requires firms to integrate cyber risk management into existing risk frameworks, building on previous FSRA guidance while establishing binding obligations with a six-month transition period from July 2025 through January 31, 2026. Unlike voluntary best practices, these are enforceable regulatory requirements carrying supervisory consequences for non-compliance.
At the foundation sits a mandatory Cyber Risk Management Framework that must be documented, board-approved, and proportionate to each firm’s size, nature, and complexity. This framework must address governance structures, technical controls, third-party risk oversight, monitoring and testing systems, and incident response plans integrated with overall crisis management.
The proportionality principle provides important flexibility—a boutique investment advisory firm with ten employees faces different expectations than a major clearing house. However, proportionality does not mean exemption. Every ADGM-regulated entity must establish cyber risk management systems appropriate to their operations, and FSRA maintains supervisory discretion to assess adequacy.
Board and Senior Management Accountability: Cybersecurity as Governance Imperative
One of the framework’s most significant departures from previous guidance involves explicit accountability at the highest organizational levels. Governing bodies and senior management bear ultimate responsibility for framework implementation and must receive regular updates on global cyber threats while participating in mandatory cybersecurity training.
This creates personal accountability for directors and executives, moving cybersecurity from technical management to fiduciary duty. Board members can no longer delegate cyber oversight entirely to IT departments—they must demonstrate active engagement, informed decision-making, and strategic prioritization of cyber resilience as a core governance function.
Practical implementation might include establishing a dedicated board-level cyber risk committee, requiring quarterly cyber risk reporting to full boards, mandating annual cybersecurity competency assessments for directors, and integrating cyber metrics into enterprise risk dashboards alongside traditional financial and operational indicators.
24-Hour Cyber Incident Reporting: FSRA's Strict Notification Timeline
Perhaps the framework’s most operationally demanding requirement involves material cyber incident notification. Firms must notify FSRA immediately and no later than 24 hours after becoming aware that a material cyber incident has occurred or having information reasonably suggesting this is the case.
This 24-hour window operates continuously—weekends, public holidays, and after-hours incidents all trigger the same urgent reporting obligation. The requirement deliberately creates time pressure to force rapid incident detection, assessment, and escalation protocols.
Determining Materiality: When Incidents Require FSRA Notification
FSRA guidance identifies several materiality factors: financial, operational, and reputational impact on the firm and its customers; whether the incident requires reporting to other regulators; and whether the incident could result in serious adverse consequences to the ADGM financial system or other regulated firms.
Importantly, there’s no bright-line materiality threshold. Firms must exercise judgment based on incident characteristics and potential consequences. A ransomware attack encrypting backup systems might be immediately material even without data exfiltration. A phishing incident compromising a single employee email account might not be material unless that account provided access to customer funds or sensitive regulatory filings.
The prudent approach involves establishing clear materiality assessment protocols with documented decision criteria, pre-approved incident response teams authorized to make notification decisions, and escalation pathways ensuring senior management and boards receive concurrent notification when FSRA is informed.
Third-Party Cyber Risk Management: Extending Compliance Beyond Your Walls
The framework applies broadly to ICT Services, defined as any information and communication technology service involving hosting, maintenance, repair, or any service accessing a firm’s IT systems, networks, or data. This extends well beyond traditional technology outsourcing to encompass virtually any vendor relationship with system or data access.
Mandatory Third-Party Controls and Due Diligence
Firms must implement robust controls and due diligence processes for third-party ICT service providers. This includes conducting due diligence to select providers meeting cybersecurity standards, establishing appropriate contractual arrangements, and verification through control environment reviews, independent audit reports, or other suitable methods.
Critically, firms must maintain adequate controls over providers’ use of subcontractors, maintain current inventories of ICT assets including third-party systems, and require providers to notify firms of material cyber incidents impacting or likely to impact the firm’s operations. Firms must then notify FSRA within 24 hours of becoming aware of such third-party incidents.
This creates cascading notification obligations—providers must notify clients, clients must notify FSRA, all within compressed timeframes. Contractual provisions must address incident notification mechanics, remediation cooperation, and information sharing protocols to enable firms to meet their regulatory obligations.
The practical implication: every cloud service agreement, every software-as-a-service arrangement, every managed security service contract requires cybersecurity provisions aligned with FSRA expectations. Vendors unwilling or unable to commit to these standards present compliance risk that firms must either remediate or avoid.
Technical Controls and Operational Requirements: Beyond Policy Documentation
While the framework emphasizes governance and oversight, it also establishes specific technical control expectations. These include multi-factor authentication for internet-facing systems and privileged accounts, encryption of user-system communication, comprehensive change management processes assessing cyber risks before, during, and after system changes, and separate development, testing, and production environments.
Firms must implement software update management processes identifying and classifying updates by criticality with timely application prioritizing critical security patches. Vulnerability management processes should maintain current understanding of security vulnerabilities, potentially using automated scanning tools. Monitoring and testing systems must conduct ongoing assessment through vulnerability scanning, penetration testing, and scenario-based exercises proportionate to business risk.
Incident Response Planning and Recovery Capabilities
Every firm must establish, maintain, and regularly test robust cyber incident response plans ensuring timely recovery, mitigation of consequences, and compliance with notification requirements. Plans should integrate with overall crisis management and disaster recovery frameworks, creating unified organizational responses to severe incidents.
Testing requirements deserve particular emphasis. Tabletop exercises, simulated incident scenarios, and recovery drills should occur regularly with documented outcomes, identified gaps, and remediation plans. Firms failing to test response plans discover deficiencies during actual incidents when rapid, coordinated response is most critical.
The Audit Integration Opportunity: Combining Cyber and Financial Assurance
For ADGM firms already subject to financial statement audits, the new cyber requirements create an opportunity few have yet recognized: integrated cyber-financial assurance engagements that address both regulatory frameworks in coordinated examinations.
Traditional financial audits assess internal controls over financial reporting. The new FSRA framework requires assessment of cyber risk management systems. These domains increasingly overlap—cybersecurity weaknesses create financial reporting risks, particularly for firms relying on IT systems for transaction processing, record-keeping, and financial close processes.
Forward-looking firms are exploring combined assurance models where external auditors conduct integrated examinations addressing both financial statement audit requirements and cyber risk management framework effectiveness. This approach offers several advantages: reduced duplicative testing of IT general controls, unified remediation priorities addressing both financial and cyber gaps, streamlined evidence gathering reducing management burden, and holistic risk assessment connecting cyber vulnerabilities to financial reporting implications.
For firms subject to SOC 2 requirements alongside ADGM financial audits, the integration opportunities become even more compelling. SOC 2 Trust Services Criteria address security, availability, processing integrity, confidentiality, and privacy—domains directly aligned with FSRA’s cyber framework. A well-designed integrated audit can simultaneously satisfy financial audit requirements, FSRA cyber framework expectations, and SOC 2 attestation needs through a unified examination methodology.
Practical Compliance Roadmap for ADGM Entities
With the January 31 implementation deadline now passed, firms in early 2026 should focus on several critical actions to achieve and demonstrate compliance:
Immediate Priorities (February-March 2026):
Conduct comprehensive gap assessments comparing current practices against FSRA requirements across all framework elements—governance, technical controls, third-party oversight, monitoring, and incident response. Document existing cyber risk management frameworks, identifying areas requiring enhancement or formalization. Establish board-level cyber risk oversight mechanisms if not already in place, including reporting protocols and training programs.
Ongoing Compliance Implementation:
Review and update all third-party ICT service agreements to incorporate required cybersecurity provisions, incident notification obligations, and audit rights. Implement or enhance multi-factor authentication across internet-facing and privileged access systems. Establish formalized change management processes with documented cyber risk assessment gates. Deploy vulnerability management programs with regular scanning, assessment, and remediation tracking.
Incident Response Readiness:
Develop or refine 24-hour incident notification protocols ensuring continuous assessment and escalation capability. Create materiality assessment criteria with documented examples and decision frameworks. Conduct tabletop exercises testing incident detection, assessment, notification, and recovery procedures. Establish incident notification templates and FSRA contact procedures enabling rapid compliance.
Documentation and Demonstration:
Maintain current cyber risk management framework documentation accessible to boards, management, and supervisors. Create evidence files demonstrating compliance across framework requirements—meeting minutes, training records, test results, vendor assessments, and incident response exercises. Prepare for FSRA supervisory examinations by organizing documentation, identifying subject matter experts, and understanding framework interpretation.
Looking Ahead: FSRA's Risk-Based Supervision and Future Expectations
The January 2026 implementation marks the beginning, not the conclusion, of FSRA’s cyber risk supervision evolution. The authority has indicated intentions to conduct thematic reviews assessing framework adherence and potentially introduce annual Cyber Risk Management Returns providing ongoing supervisory visibility into firms’ cyber maturity.
potentially remedial actions.
The framework also positions ADGM within broader UAE cybersecurity initiatives. The country’s preparation for Financial Action Task Force mutual evaluation in 2026 includes significant focus on cybercrime prevention and financial sector resilience. FSRA’s framework aligns with national objectives while maintaining ADGM’s role as a leading international financial center attracting global firms through robust, credible regulatory standards.
For financial services firms operating in ADGM, cybersecurity has permanently transitioned from IT management to strategic governance imperative. The January 2026 framework implementation creates clear expectations, accountability structures, and supervisory mechanisms ensuring cyber resilience receives appropriate priority alongside traditional prudential and conduct obligations.
Firms treating this as mere compliance exercise risk missing the strategic opportunity: building integrated cyber-financial risk management capabilities that simultaneously satisfy regulatory requirements, enhance operational resilience, reduce incident probability and impact, and demonstrate to clients and counterparties the robust governance frameworks essential for trust in digital financial services.
About NR Doshi & Partners
NR Doshi & Partners provides integrated cybersecurity, financial audit, transfer pricing, and excise compliance services to ADGM-regulated entities and financial services firms across the UAE. Our unique capability to deliver combined cyber-financial assurance engagements helps clients efficiently address FSRA framework requirements while maintaining financial audit compliance through unified examinations.
ADGM Cyber Risk Advisory Services :
- FSRA Framework Gap Assessments & Remediation Planning
- Integrated Cyber-Financial Audit Engagements
- Third-Party ICT Risk Assessment & Contract Review
- 24-Hour Incident Notification Protocol Development
- Board-Level Cyber Governance Program Design
- SOC 2 + FSRA Framework Combined Attestation
Contact our ADGM Cybersecurity Team:
📞 +971 4 352 8001
This article provides general information and does not constitute professional cybersecurity or legal advice. ADGM-regulated entities should consult qualified advisors familiar with their specific circumstances and regulatory obligations.





