
Cybersecurity for Real Estate Companies in the UAE: The Forum Case Study
No regulator tells a property developer in the UAE to appoint a CISO, run a penetration test, or put endpoint protection on its laptops. That is precisely why most real estate businesses build nothing until money leaves the company. Forum decided not to wait, and this case study describes what was actually built, in what order, and what we would tell any developer or brokerage to do first.
Real estate is a target that does not feel like one
The sector has an unusual risk shape. Large payments move on the strength of an email. Deal flow runs through WhatsApp, brokers and agents who sit outside the company. Buyer files hold passport copies, proof of funds, bank statements and source-of-wealth documents, which is a richer set of personal data than most banks hold on a retail customer. Sales staff work from phones and personal laptops. Finance runs on accounting software installed on a handful of machines, and the person who approves a transfer is often two desks away from the person who typed the bank details.
The FBI's Internet Crime Complaint Center recorded 12,368 real estate related complaints in 2025 with 275.1 million dollars in reported losses, inside a total of 3.04 billion dollars lost to business email compromise across all sectors. That is United States reporting, so treat it as a pattern rather than a UAE number. The pattern matches Dubai exactly: off-plan payments go to a Land Department escrow account on written instructions, and a fraudster who can read a sales mailbox for two weeks knows the amount, the date, and the buyer's name before anybody notices.
Compare that with the compliance drivers a developer is aware of. Anti-money laundering obligations for the sector are real and specific. Data protection applies from the first customer form. Nothing in either regime mentions phishing-resistant authentication or device management, so those decisions stay with whoever happens to run IT.
The client and the starting point
Forum Real Estate Development LLC describes itself as an international investment group with full-cycle property development expertise, active in Dubai and investing across the CIS, EU and Middle East. More than 35 projects delivered, over 300,000 square metres developed, with a Dubai portfolio that includes XXII Carat on Palm Jumeirah, FH Residency in Jumeirah Village Triangle and Metropoint in Downtown Jebel Ali.
The security starting point was zero, which is the normal condition for a developer of this size rather than a failing. No security function, no policies that described what people actually did, no standard build for a laptop, no agreed process for verifying a payment instruction, and IT support handled as needed. The group also operates from more than one jurisdiction, so any answer had to work for a Dubai head office and a European office at the same time.
We were brought in as vCISO to own the security position and build the programme. Everything below was produced from that engagement.
Phase one: assessment before any purchase
The first piece of work was a risk assessment across the whole business, not a tool evaluation. Scope covered the payment and approval process, the CRM holding buyer data, employee devices, the cloud tenancy and identity setup, the brokerage and contractor relationships, and the second office.
That produced a register of 29 risks. Seven were prioritised as critical or high. Every rating separated likelihood from impact, and the assumptions behind each rating were written next to it, because a risk score with no stated assumption cannot be argued with later.
The four themes that dominated the top of the register are the same four that dominate this sector: fraudulent payment instructions sent from a compromised or spoofed mailbox, theft of banking credentials from unmanaged personal devices, interception of one-time codes, and exposure of buyer personal data held in the CRM. A developer who fixes those four is in a better position than one holding a certificate and none of them.
Phase two: a strategy the board could approve
The roadmap was built from the prioritised risks, not from a control framework adopted wholesale. Adopting ISO 27001:2022 in full as a first move would have produced a year of documentation and left the payment process untouched, and we said so.
So the plan was sequenced by risk reduction per dirham. Controls that removed a critical risk went first, controls that produced evidence for a future certification went later, and medium and low risks stayed in the register with a review date rather than a project. The board saw the cost, the order, and what was deliberately not being done this cycle. Deferral was recorded as a decision with an owner and a date, which is the part most companies skip and then cannot explain when something happens.
Phase three: penetration testing, then verification
Testing came after the obvious gaps were understood, not before. Scope was the external perimeter and the systems carrying buyer and payment data, because those are the paths that turn into a loss rather than a finding.
A report is only useful if it shows an exploitable path, the business consequence of that path, and a fix that has been retested. A scanner output with severity labels and no exploitation attempt is not a penetration test, whatever the invoice says, and remediation that is never re-verified quietly becomes a spreadsheet of good intentions. Retesting was part of the scope from the start.
Phase four: managed devices and endpoint protection for every employee
This was the single highest-value block of work, and it is the one most real estate companies avoid because it touches everybody.
Work had been happening on a mix of personal and unmanaged machines, which is where most companies of this size start: no consistent protection, no central visibility, and no way to remove company access from a device after somebody left. Endpoint protection now runs on every employee machine with central visibility, and the group has an approved corporate device standard that is being rolled out office by office. The standard is written down rather than assumed: company-owned laptops with a documented build, device management enrolment so configuration and encryption are enforced centrally rather than requested politely, single sign-on against the corporate identity provider, and a password manager issued to every employee so credentials stop living in browsers and notebooks.
Two details from this phase are worth copying. First, we surveyed staff on the software they actually use before specifying anything, and the finance team's accounting package runs on Windows only, which settled a platform argument on facts instead of preference. Second, the device specification was written as a document with pricing, so the group approved a standard rather than buying laptops one at a time and inheriting five different configurations.
Phase five: governance and compliance that matches practice
Policies came after the controls existed, which is the opposite of the usual order and produces documents people can pass an audit with.
Data protection did most of the work here. The UAE PDPL (Federal Decree-Law No. 45 of 2021) governs the buyer data in the CRM, the marketing lists, the retention period for enquiries that never became sales, and the disclosure of customer files to brokers, banks and agents. Data processing agreements were drafted for the processors handling that data, since a developer that hands buyer files to an outsourced marketing agency or CRM vendor with no written terms is the controller carrying the whole exposure. Our PDPL and DPO guide covers the obligations, and the executive regulations are still not published, which is why some positions are taken conservatively.
The group's European operation brings the GDPR into the same conversation, so the privacy work was written once in a form that satisfies both regimes rather than twice in conflicting language.
Anti-money laundering obligations run alongside. Federal Decree-Law No. 20 of 2018, Cabinet Decision No. 10 of 2019 and Cabinet Decision No. 74 of 2020 set the framework for designated non-financial businesses and professions, which names real estate brokers and agents explicitly. Reporting runs through the goAML platform, and a real estate activity report is required where a purchase or sale involves physical cash at or above AED 55,000, as a single payment or split across several. A developer selling directly should confirm its own classification with the Ministry of Economy rather than assuming the obligation sits only with brokers, and either way the security programme has to support it: identity documents and source-of-funds evidence have to be collected, stored with access control, retained for the statutory period, and produced on request without somebody emailing a zip file of passports.
The payment control that matters more than any product
The most valuable document we produced for this client was not a policy. It was a payment fraud prevention procedure with the payment flow drawn out, step by step, showing who requests, who verifies, who approves and who releases.
The rules inside it are unglamorous and they work. Bank details are never accepted or changed on the strength of an email, including an email from a colleague. Any instruction that introduces new account details is verified out of band on a number held in a system separate from email, and the verification is recorded. Two people authorise outbound payments above a threshold. Buyers are told at the start of the relationship, in writing, which escrow account their payments go to and that the account will never change by email. Staff know that urgency plus a new account number is the signature of the attack rather than a reason to hurry.
None of that requires a licence, a platform or a consultant. It requires somebody senior to insist on it, which is the actual job.
Reporting to the board twice a year
The programme reports to the board on a semi-annual cycle. Each report covers what changed since the last one, how the risk register moved, what the next half-year plan contains, and which items need money or a decision.
Between reports the work runs on a deliberately lean tracker, maintained by two or three people, scoped only to the risks rated critical or high. A hundred-line task list in a company with no security team is theatre, and everyone stops opening it by week three. Medium and low items live in the register with review dates, which is honest about capacity instead of pretending everything is being worked on.
How this is staffed
There is no internal security team. A vCISO owns the security position, the risk decisions and the board reporting, and our own delivery people produce the documents, run the testing and support the rollouts. For a group this size that is the whole security function, and it costs a fraction of one senior hire. We set out the arithmetic in virtual CISO vs full-time CISO cost and the retainer ranges in the vCISO cost guide. If the role itself is new to you, start with what a virtual CISO actually is.
If you run a real estate business in the UAE, do these first
The order matters more than the length of the list. Based on this engagement and others in the sector:
Write and enforce a payment verification procedure, including out-of-band confirmation of any new bank details and dual authorisation above a threshold.
Put every employee on a company-managed device with endpoint protection and central configuration, and remove work data from personal machines.
Turn on single sign-on with phishing-resistant multi-factor authentication for email, the CRM and anything holding buyer files.
Restrict CRM access by role, set a retention period for enquiries that never converted, and log exports.
Put data processing agreements in place with every processor touching buyer data, and publish a privacy notice that matches what you actually do.
Run a risk assessment that separates likelihood from impact, and take the top items to your board with costs.
Then test, and retest what you fixed.
Certification comes after that, if a partner or an investor asks for it. ISO 27001 in the UAE is a reasonable target once the controls exist, and a poor first project when they do not.
If you want this run for you rather than described to you, our vCISO services for UAE real estate and property groups cover exactly this scope. For comparison, two engagements with very different starting points: a regulated broker with its own in-house security team and a fintech that needed ISO 27001 in under six months.
Frequently asked questions
Does a UAE real estate company legally need a CISO? No specific UAE regulation requires a real estate developer or brokerage to appoint a CISO. Anti-money laundering rules require a compliance officer, and data protection law requires a data protection officer in defined circumstances. Security leadership is therefore a commercial decision, driven by payment fraud exposure and by the buyer data you hold, not by a licence condition.
Which UAE rules actually apply to a real estate business on the security side? The UAE PDPL governs customer personal data. Federal Decree-Law No. 20 of 2018 with Cabinet Decision No. 10 of 2019 and Cabinet Decision No. 74 of 2020 set the anti-money laundering obligations for the sector, including goAML reporting and the real estate activity report for cash at or above AED 55,000. Contractual security requirements also arrive from banks, investors and institutional partners, and those are often stricter than anything in law.
Does the PDPL really apply to a brokerage CRM? Yes. Buyer enquiries, passport copies, proof of funds and marketing lists are all personal data, and the company collecting them is the controller. That brings lawful basis, retention, access control, processor agreements and data subject requests into scope, whether or not anyone has asked about it yet.
What should a penetration test cover for a developer? The external perimeter and the systems that hold buyer or payment data, at minimum: the public website and any portal, the email and identity setup, and the CRM. Ask for evidence of exploitation rather than a scanner rating, and insist that retesting of fixes is in the scope and the price.
Is endpoint protection enough on its own? No, and it is still the control we would install first in this sector. Endpoint protection on a managed device stops the common credential-theft path, gives you visibility, and lets you revoke access when somebody leaves. It does nothing about a fraudulent payment instruction, which is why the payment procedure sits next to it.
How long does a programme like this take to build from nothing? The assessment and the strategy take weeks. Device rollout and identity work take a few months around business schedules, since you are touching everybody's daily tools. Governance documentation follows the controls. Expect a first full cycle of roughly two half-year reporting periods before the programme feels routine.
What does this cost for a company of 50 to 100 people? A vCISO retainer plus delivery capacity, sized to the workload, with the tooling and device costs sitting separately in the IT budget. It is a fraction of a full-time senior security hire, and the device and licence spend is usually the larger line in year one. Our pricing guide gives current ranges.
Closing
Forum's leadership funded security before a regulator or an incident forced the conversation, which is rarer in this sector than it should be, and the results belong to them. Our part was the assessment, the strategy, the testing, the rollouts, the governance and the board reporting: an outside security function for a business that does not need a full-time one.
If you run a developer, a brokerage or a property management business in the UAE and nobody currently owns security, get in touch and we will tell you what your first ninety days should look like.
Case Studies