Frameworks · Middle East
DFSA GEN 5.5 Cyber Risk
GEN 5.5 Cyber Risk Management is a section of the Dubai Financial Services Authority's General Module. It requires Authorised Persons in the DIFC to establish and maintain a written, board-approved cyber risk management framework. DFSA rule-making instrument RMI361/2023 added it, and it came into force on 1 January 2024.
Who it applies to
It applies to Authorised Persons regulated by the DFSA in the Dubai International Financial Centre, including banking, asset management, insurance intermediation, fintech and advisory firms. Expectations are proportionate to each firm's size and risk profile.
Main requirements
Framework & governance
The Governing Body approves a written cyber risk management framework that sets out roles, risk appetite and review.
Identification & protection
Firms keep an ICT asset inventory and manage access control, vulnerabilities, and third-party and outsourcing risk.
Detection, response & recovery
Firms monitor their systems and maintain incident response and recovery plans, which they test regularly.
Notification
Firms report material cyber incidents to the DFSA through the DFSA portal as soon as reasonably practicable, and no later than 72 hours after becoming aware.
How xmodo supports it
- 1
Each rule is set up as a control with an owner, evidence and a calculated compliance status, so the board can see the framework it approves in operation.
- 2
The 72-hour DFSA reporting deadline starts in the incident workflow at the point of awareness. The notification is filed against the incident as evidence.
- 3
ICT assets, vulnerabilities and third parties are kept in registers linked to the controls that reference them.
- 4
Mapping from ISO/IEC 27001 and NIST CSF 2.0 shows how much you already cover. The DIFC Data Protection Law can run alongside it for the same entity.
Related frameworks
DFSA GEN 5.5 Cyber Risk shares requirements with the frameworks below. Controls you already run for any of them count towards DFSA GEN 5.5 Cyber Risk as well.
Frequently asked questions
Is this what people call "DFSA TRM"?
The rules are GEN 5.5 Cyber Risk Management in the General Module of the DFSA Rulebook. xmodo uses the rulebook title and keeps "DFSA TRM" as an alternative name, so the page can be found under either.
What must be reported, and when?
Firms must report material cyber incidents as soon as reasonably practicable. The report is due no later than 72 hours after the firm becomes aware, or has information that reasonably suggests one has occurred. The incident record holds the awareness timestamp, the materiality assessment and the submission.
Does our ISO 27001 programme cover it?
It covers a large part of the identification, protection and detection expectations. The remaining DFSA-specific work is Governing Body approval, the DIFC notification process and the reasoning on proportionality. The mapping shows how much is already covered for your firm.