What incident response actually covers
Incident response is the set of arrangements that decide how well an organisation copes once prevention has failed: who takes charge, what is isolated, how evidence is preserved, and who has to be told. Almost all of it has to exist before the incident. A team assembled during one spends its first hours deciding who is in charge, and those are the hours that matter most.
The clock starts when you became aware
A single incident in the UAE can create notification duties to more than one authority. Where personal data is involved that includes the UAE Data Office under the Personal Data Protection Law, alongside the sector regulator and, for entities in scope of the NESA Information Assurance Standards, reporting through aeCERT to the UAE Cybersecurity Council. Every window runs from the moment of awareness, and most organisations cannot evidence when that moment was. Reconstructing it afterwards from logs that may no longer exist is where notification failures begin.
How CLA Emirates prepares and responds
We start with the plan you would actually reach for: named roles, a severity scale tied to decisions rather than adjectives, evidence handling that survives later scrutiny, and a notification map setting out which authority is owed what. Then we test it against a scenario your sector has already seen. Where the arrangement is a retainer, response times and escalation are agreed in writing beforehand, because the middle of an incident is the worst moment to negotiate them.
What we put in place, or run for you
- Incident response plan and playbooks
- Tabletop and simulation exercises
- Retained response capability
- Security operations centre advisory and build
- Regulatory notification support
- Post-incident review and root cause
Questions we are asked most often
What is a cyber incident response plan?
A cyber incident response plan sets out who takes charge during an attack, how severity is decided, what is isolated or preserved, and which authorities must be notified. It is written before an incident because there is no time to write one during it.
Who must a UAE organisation notify after a data breach?
Where personal data is involved, the UAE Data Office under the Personal Data Protection Law, and affected individuals where risk to them is high. Entities under the NESA Information Assurance Standards report through aeCERT, and regulated financial institutions notify the Central Bank of the UAE.
What is the difference between a SOC and incident response?
A security operations centre monitors continuously and detects events as they happen. Incident response is what follows once something is confirmed: containment, evidence, notification and recovery. A SOC without a response plan finds problems it has no agreed way to act on.
