Dubai · Chief Information Security Officer
Fractional CISO in Dubai
The second most-established fractional role after CFO, and for the same reason: the need is compliance-triggered and finite. An enterprise customer conditions a contract on ISO 27001, a regulator names a required officer, an insurer asks for MFA and offline backup attestations before renewal — and a company of eighty people discovers it needs security judgment it cannot justify hiring full-time.
Corporate tax and the audit and transfer-pricing wave behind it created acute demand for a real CFO among owner-managed firms that have never had one — a compliance-triggered, time-boxed need.
What they deliver
- Security programme and a costed 12–18 month roadmap
- ISO 27001 or SOC 2 readiness, through to managing the external auditor
- Incident response plan mapped to each regulator’s notification clock, and the tabletop exercises to test it
- Enterprise customer security questionnaires — often the highest-return work on the whole mandate
- Third-party and vendor risk: tiering, diligence, contract security schedules
- Board and regulator reporting, and managing the MSSP or a small internal team
Signals you need one
- A customer has made ISO 27001 or a security questionnaire a condition of the contract
- You have had a breach, a ransomware scare, or a near-miss nobody formally closed out
- Cyber insurance renewal came back loaded, or declined
- A buyer or investor has commissioned technical due diligence
- Security has been the CTO’s side job and headcount is now past fifty
- You have security engineers but nobody senior enough to set the direction
Saudi Arabia and South Korea both require the named security officer to be an internal, full-time appointment — Saudi under NCA Essential Cybersecurity Controls 1-2-2, which requires cybersecurity roles to be filled by full-time Saudi nationals, and Korea under the Network Act, where the CISO is designated and reported to the Ministry of Science and ICT, with larger companies barred from letting that person hold unrelated duties. In both, a fractional CISO can advise the designated officer but cannot be them. Hong Kong is the opposite case: its critical infrastructure regime expressly allows the security management unit and its supervisor to sit outside Hong Kong, which makes it the most fractional-friendly regime in the region.
The Dubai numbers
The full Dubai picture — tax, regulation and market context →
What governs this in United Arab Emirates
UAE corporate tax and the Qualifying Free Zone Person rules
Determines whether the entity you contract with pays 0% or 9%, and whether your payment is deductible with a proper tax invoice. Payments to a connected person must be at market value and wholly for business purposes or they are disallowed.
DIFC versus mainland employment law
DIFC Employment Law No. 2 of 2019 brings common law, English-language courts, the DEWS scheme and a six-month limitation period on employment claims against two years on the mainland. Emiratisation and the Wage Protection System do not apply inside DIFC.
MOHRE part-time work permit
Introduced in 2022, it lets a resident work for more than one employer below full-time hours, valid for a year and free through the MOHRE portal. This is the compliant route for a resident executive splitting time across several UAE companies.
Emiratisation and Nafis
Mainland firms with 50 or more employees face rising Emirati quotas in skilled roles, with monthly penalties per unfilled place. Free zones, DIFC and ADGM sit outside it — and a fractional executive on a services contract does not add to the headcount that triggers or worsens quota exposure.