vCISO With an In-House Security Team: The InsuranceMarket.ae Case Study

vCISO With an In-House Security Team: The InsuranceMarket.ae Case Study

vCISO With an In-House Security Team: The InsuranceMarket.ae Case Study

vCISO With an In-House Security Team: The InsuranceMarket.ae Case Study

Alfred Holdings employs full-time security staff and still retains a vCISO. That pairing sounds redundant if you assume a vCISO is what a company buys when it cannot afford a security team. At this size the role does something else, and this case study sets out what: who decides what, how the internal team gets direction, what the CEO, the CTO and the Information Security Committee actually receive, and how three regulatory regimes plus the group's privacy obligations run through one programme.

Your vCISO in the UAE and Middle East
A named security leader of record, backed by a delivery team that builds the programme, not just advises. From $2,500 / mo

Your vCISO in the UAE and Middle East
A named security leader of record, backed by a delivery team that builds the programme, not just advises. From $2,500 / mo

The client and why its regulatory position is unusual

InsuranceMarket.ae is the registered trademark of AFIA Insurance Brokerage Services LLC, an Alfred Holdings company. The business says one in ten cars in the UAE is insured through it. It is licensed and regulated by the Central Bank of the UAE under registration number 85, and it holds broker permits from the Dubai Health Authority and the Abu Dhabi Department of Health. Alongside it the group operates other consumer brands, including CreditMarket.ae, InvestmentMarket.ae and HolidayMarket.ae, each with its own controller position over customer data.

That licence set puts several supervisory expectations on one estate at the same time.

The Central Bank is the prudential and conduct regulator. The Insurance Brokers' Regulation (C 1/2024, effective 15 February 2025) sets the record keeping, governance and outsourcing expectations the broker is measured against, and Article 15.1 alone shapes how the group is allowed to treat customer data. Where the group participates in Open Finance, Article 31 of the Open Finance Regulation (Circular No. C 03/2025, issued 10 July 2025) adds a technology and cyber security risk management framework requirement. Our CBUAE cybersecurity requirements guide covers how those instruments fit together.

Underneath the Central Bank's expectations sits the UAE Information Assurance Regulation. Version 2 of the standards, published in September 2025 and rebased onto ISO 27001:2022, is the baseline that licensees are assessed against, and an independent external assessment is what a regulator accepts as evidence. The UAE IAR compliance guide explains the assessment mechanics.

Then there is health data. Because the group places health cover and holds an Abu Dhabi Department of Health licence, it falls inside the Department's remit and is assessed against ADHICS v2 (DOH/SD/ICSO/ADHICS/V2/2024, published May 2024, effective August 2024): 131 controls, a Statement of Applicability, and a minimum of 70 percent compliance in every domain rather than on average. Most brokers do not expect a healthcare cyber security standard to apply to them. Our ADHICS v2 compliance guide sets out who is in scope.

Finally, a set of consumer brands collecting UAE residents' personal data brings Federal Decree-Law No. 45 of 2021 (the UAE PDPL) into every marketing, retention and deletion decision.

One security programme has to satisfy all of that without producing four contradictory descriptions of the same estate.

InsuranceMarket.ae Metro Station

Why a group with its own security staff retains a vCISO

The internal team was never the constraint. Alfred Holdings has an information security manager, application security capability, and an IT function that runs identity, endpoints and infrastructure. What a structure like that lacks is not hands.

Four things drove the decision.

Accountability that survives a regulator's question. Supervisors and boards want a named senior individual who owns the security position and can defend it. An information security manager operating controls is doing necessary work, and it is not the same as a head of function who signs an assessment, states a risk position in front of a committee, and answers for it afterwards.

Regulatory judgment is episodic, not daily. Reading C 1/2024, the Information Assurance Standards, ADHICS v2 and the PDPL against one real estate, then deciding what genuinely applies and what does not, is senior work that arrives in bursts around submissions, audits and new regulatory notices. It does not fill a full-time role at this size.

Market rate for the alternative. A full-time CISO with UAE regulated-sector experience costs a multiple of a vCISO retainer, before the cost of the analysts that person would immediately ask for. We compare the two models in virtual CISO vs full-time CISO cost.

Elastic delivery capacity. Submission periods need documentation produced quickly: assessment reports, a Statement of Applicability, evidence packs, policy revisions. Our own compliance manager works inside the engagement during those periods, so the internal team is not the bottleneck when a deadline is fixed by a regulator.

Who owns what

The split matters more than the title. This is how it works in practice.

The in-house team owns

The vCISO owns

Day-to-day operation of controls: identity, endpoints, logging, patching, access provisioning

The security strategy, the control roadmap and the order in which gaps get closed

Internal application security testing and remediation tracking with engineering

Interpretation of CBUAE, UAE IAR, ADHICS and PDPL requirements against the actual estate

Ticket-level incident handling and first-line triage

Risk assessment, risk ratings, and what gets accepted, mitigated or funded

Evidence collection from the systems they administer

Sign-off on anything that leaves the group for a regulator, auditor, bank or insurer

Vendor and tool administration

Papers, options and recommendations for the Information Security Committee and the CEO

Escalation when something looks wrong

Accountability for the programme as a whole, including where it is behind

Nothing in the right-hand column can be delegated to a platform, and nothing in the left-hand column should be sold to a client as consulting.

How an external CISO directs an internal team

Direction is functional, not administrative. The security staff remain Alfred Holdings employees with the group's reporting lines and the group's HR accountability. What changes is where the security agenda comes from.

The retainer is a fixed weekly allocation, currently eight hours, structured as a working rhythm rather than an on-demand advisory line. Priorities for the internal team are set against the control roadmap, so the information security manager starts a week knowing which gap is being closed and what evidence that gap needs to produce. Work comes back for technical review before it becomes a finished artefact, which is where most of the quality is gained: an assessment narrative that overstates maturity, or a policy that promises a process nobody runs, fails at exactly the wrong moment.

Anything leaving the group goes through one gate. Regulatory submissions, audit responses and due diligence answers are reviewed as a set, because the fastest way to lose credibility with a supervisor is to describe the same control differently in two filings.

The CTO holds the escalation path. When a decision needs money, a change in engineering priority, or an executive to accept a risk, it goes there and then to the committee rather than sitting in a security backlog.

Capability decisions run the same way. Which roles the group should hire internally, which work is better kept external, and what a new security hire should actually be responsible for are all part of the remit, because a team built around the wrong skills produces activity and no assurance.

What the executives and the committee receive

The Information Security Committee is where the programme becomes governance rather than activity. Executives chair it, minutes record decisions with owners and dates, and the security position is presented to the people who can actually fund or reject it.

Papers follow the same shape every time. Current state in plain language. The regulatory driver, named precisely, including the article or control if one applies. Options with real cost attached, including the option of doing nothing. A recommendation. What happens if the decision is deferred to the next cycle.

Two habits do most of the work here. The first is separating likelihood from impact and refusing to call everything critical, because a committee that has been told five times that something is critical stops funding anything. The second is bringing the honest version of cost, including the operational drag a control creates for a business with hundreds of staff and a sales floor that measures itself in minutes.

Risk acceptance is recorded, not implied. When the committee decides to live with something for a quarter, that is written down with a date and an owner, which is also what a supervisor expects to see when it asks how the board oversees technology risk.

Working across compliance, IT and the business

Security owns almost none of the systems it is accountable for, which makes stakeholder work most of the job. Compliance holds the regulator relationship and coordinates what gets filed, so the security content has to arrive in the format and on the date compliance needs it. Internal audit cross-checks what security submits, and that challenge is useful: a narrative that says a document does not exist while another workbook already contains it is exactly the kind of inconsistency a supervisor finds.

IT runs identity, endpoints and infrastructure. Engineering owns the code and the release pipeline. Legal and HR own the contracts, the processor clauses and the policy acknowledgements. Every control therefore lands as somebody else's work, on top of a roadmap that department already has.

That is where an external security leader earns the retainer or fails at it. Sequencing the asks, attaching each one to a named regulatory driver, and taking the unresolved ones to the committee rather than escalating by email volume is what turns a control roadmap into something that actually gets built.

Risk assessment, and where the money goes

The risk register drives spend, not the other way round. Ratings separate likelihood from impact, assumptions are written next to the rating, and the register is reviewed rather than refreshed once a year for an auditor.

Proportionate control choices come out of that. Where a legacy business application cannot support modern authentication, putting a strong authentication layer in front of it using infrastructure the group already owns beats buying another platform, and it closes the same finding. Where testing is needed, scoping by system criticality produces a defensible programme: a high-level view of the external perimeter plus a deep test of the systems that actually carry customer data, rather than one flat annual number that satisfies nobody.

Compensating controls are documented as compensating controls, with the residual risk stated. Auditors accept that. What they do not accept is a control described as fully implemented when the evidence shows otherwise, which is the most common reason remediation plans fail on re-verification.

The DPO role for the group

The same engagement carries the data protection officer role across the group's entities. For a business whose brands run motor, health, life, credit, investment and travel enquiries, privacy is not a document exercise.

Four streams run continuously. Privacy notices are drafted per brand and per controller, because the controller for a travel brand is not the controller for the brokerage and the notices cannot pretend otherwise. Records of processing and the data inventory have to match what the systems actually do, including marketing platforms hosted outside the UAE. Data subject requests are handled inside the statutory window with identity verification first, since a request to delete or export someone else's record is a pretexting opportunity. And retention rules are applied per category rather than per request.

Retention is where the interesting conflicts live. A customer asks for erasure, the PDPL gives that right, and Article 15.1 of C 1/2024 requires an insurance broker to keep personal data records for ten years from the date of receipt. The right answer is not to pick a side. Marketing stops immediately, processing is restricted to what the retention obligation requires, the record is kept for the statutory period, and the data subject is told the legal basis and the end date in writing. That position is defensible to both the Central Bank and the UAE Data Office, which is the only test that matters.

Handling these case by case does not scale, so the group is moving to approved procedures for deletion and request handling, with a register that shows every request, decision and basis. Note also that the PDPL's executive regulations still had not been published at the time of writing, which changes how conservatively some of these positions are taken. We track that in the status of the UAE PDPL executive regulations, and our PDPL and DPO guide covers the role itself.

Due diligence: answering other people's questionnaires

Regulated firms get assessed constantly by parties that are not their regulator. Banks send security questionnaires before onboarding. Insurers and partners ask about data handling before a distribution agreement. Open Finance participation brings its own assessment expectations, which we cover in the UAE Open Finance regulation guide.

The vCISO owns those answers for one reason: consistency. Every questionnaire response has to match the assessment filed with the regulator, the Statement of Applicability, and the policies that exist in the document set. Overstating maturity to win an onboarding creates a contradiction that surfaces later in an audit, and an internal team under commercial pressure from a business unit should not be the last line of defence against that.

The same discipline runs outward. Third parties handling group data are assessed before they are onboarded, and the assessment is written down, because a supplier register with no assessments behind it is a finding waiting to happen.

What this model does not do

A vCISO does not replace headcount. If a group needs round-the-clock monitoring, it needs a SOC, whether internal or managed. If the estate needs engineering work, it needs engineers. The retainer buys leadership and judgment, plus the capacity to produce regulatory work properly, and pretending otherwise sets up a failure that nobody enjoys explaining to a committee.

The model also has a real dependency. An external leader sees less of the informal signal than someone sitting in the office every day, so the arrangement works when the internal team reports problems honestly and when the escalation path to the CTO is genuinely open. Where a security team has learned to hide bad news, a vCISO will be the last person to hear it, and no contract fixes that.

At a certain scale the split stops making sense. When a group runs several regulated entities in different jurisdictions with a security organisation of twenty or more, the leadership work becomes a full-time job and the right move is to hire.

When this arrangement fits a UAE company

The pattern fits when four things are true at once. The company is regulated, ideally by more than one authority. It already employs people who can execute security work. It needs an accountable, senior security owner for regulators, partners and the board. And the volume of genuinely senior work does not justify a full-time CISO salary at UAE market rates, which we break down in the vCISO cost guide.

If that describes your business, our vCISO services for regulated firms in the UAE are built around exactly this division of labour. For a contrasting engagement where the client had no internal security function at all, see OGold's ISO 27001 case study.

Frequently asked questions

Can a vCISO be the accountable security leader for a CBUAE-regulated firm? In practice yes, when the appointment is documented, the individual is named and senior, the time commitment is real, and the reporting line reaches the board or a board committee. The Information Assurance Standards require a security leadership role rather than a specific employment contract. Confirm the expectation with your own supervisor before you rely on it, because CBUAE applies its requirements by licence type.

What happens to the in-house security team? It stays and it keeps operating the controls. The change is that the team receives a roadmap, gets its work reviewed before it becomes an artefact, and has an escalation path that reaches executives. Most internal security managers welcome that, because the alternative is defending a programme they were never resourced to own.

Does the vCISO manage employees directly? Functionally, not administratively. The security agenda, priorities and technical review come from the vCISO. Employment, performance management and HR accountability stay with the group. The arrangement needs to be written down, or you get two people believing they set priorities.

Can the same provider be both vCISO and DPO? It works when the DPO position reports to the board rather than into IT, and when the record shows privacy positions taken independently of the security budget. It stops working when a privacy objection would embarrass the same person's security decision. Document the reporting line, and split the roles once the volume of data subject requests or the number of controllers makes independence hard to demonstrate.

Does ADHICS really apply to an insurance broker? It applies where the entity holds a Department of Health licence or handles health information inside the Abu Dhabi health sector, which covers payers and intermediaries as well as clinics and hospitals. The assessment is against 131 controls with a Statement of Applicability, and the Department expects a minimum of 70 percent in each domain.

How many hours a week does this take? This engagement runs on a fixed weekly allocation, currently eight hours, plus additional delivery capacity from our side during submission and audit periods. A group with no internal team needs considerably more, and a company that only needs an annual assessment needs less.

How quickly does a new arrangement like this produce something a regulator accepts? If the document set already exists, a credible assessment and Statement of Applicability take weeks. Building an ISMS baseline from nothing takes months, and any provider promising a regulator-ready position in days is describing paperwork, not a control environment.

Closing

The credit for the security position at Alfred Holdings belongs to its own team and its executives, who fund the work and accept the risks. Our part is the leadership layer: the regulatory judgment, the risk decisions, the committee papers, the DPO role, and the assurance that what the group tells a regulator is what the group actually does.

If you have a security team and no accountable security leader, or a regulator asking who owns information security at your firm, get in touch and we will tell you honestly whether this model fits.

Case Studies

Get started

Don’t scale security harder. Scale smarter.

Dynova provides virtual CISO services and fractional CISO services in Dubai and across the UAE: security strategy, CBUAE, VARA, ISO 27001, PCI DSS and SOC 2 compliance, hands-on execution, penetration testing and code review, all under one named CISO.

info@business-ciso.com

+971 54 458 8631


Report incident:

soc@business-ciso.com


Dynova Services LLC-FZ, License 2644102.01, Issued by Meydan Free Zone, Dubai, UAE

Get started

Don’t scale security harder. Scale smarter.

Dynova provides virtual CISO services and fractional CISO services in Dubai and across the UAE: security strategy, CBUAE, VARA, ISO 27001, PCI DSS and SOC 2 compliance, hands-on execution, penetration testing and code review, all under one named CISO.

info@business-ciso.com

+971 54 458 8631


Report incident:

soc@business-ciso.com


Dynova Services LLC-FZ,

License 2644102.01,

Issued by Meydan Free Zone, Dubai, UAE

Get started

Don’t scale security harder. Scale smarter.

Dynova provides virtual CISO services and fractional CISO services in Dubai and across the UAE: security strategy, CBUAE, VARA, ISO 27001, PCI DSS and SOC 2 compliance, hands-on execution, penetration testing and code review, all under one named CISO.

info@business-ciso.com

+971 54 458 8631


Report incident:

soc@business-ciso.com


Dynova Services LLC-FZ, License 2644102.01,

Issued by Meydan Free Zone, Dubai, UAE