VARA’s cyber rules require a defensible security programme matched to the VASP’s systems and risks. They do not prescribe every password setting, withdrawal threshold or encryption product that appears in online checklists.
What must a licensed VASP organise?
The VARA Technology and Information Rulebook addresses governance, a cybersecurity policy, the CISO role, testing, access control, key management and business continuity. The policy is part of licensing and is reviewed at least annually by the CISO. The firm must be able to explain why its controls fit its business, not merely display a generic checklist.
For example, the rulebook calls for consideration of multi-factor authentication for transactions exceeding client-set limits. It does not impose a universal AED 10,000 withdrawal trigger. Specific values such as a 90-day password rotation, three-to-five failed attempts, AES-256 for every system, a fixed CISO salary or a fixed security budget should not be presented as VARA legal minimums without an exact rule.
When must a material cyber event be reported?
Under the Technology and Information Rulebook’s notification provision, a material cybersecurity event or a business-continuity event materially affecting operations must be reported to VARA as soon as reasonably practicable and no later than 72 hours from detection. The report includes the nature, scope, impact and response. This is not a blanket 24-hour rule for every event.
Personal-data incidents have a separate notice sequence under VARA’s provision-of-information rules, and other data-protection or AML obligations may apply. An incident plan should identify each trigger and recipient rather than using one clock for all events.
What should the security file contain?
Keep a current asset and access inventory, risk assessment, policy ownership, evidence of testing, incident playbooks, backup and recovery evidence, vendor oversight, and a log of decisions on key custody and transaction controls. Test the plan with the actual people who would have to report an incident.
Sources and notes
- VARA, Technology and Information Rulebook: VASP governance and proportionate technical-control requirements.
- VARA, Notification to VARA: material cyber and continuity events, with the event-specific 72-hour outer limit.
- VARA, Provision of Information to VARA: separate personal-data notice sequence.
Updated 24 September 2026. This guide is general information; an incident response needs advice on its exact facts and governing rules.



