WhatsApp Us

Protect What You've
Built — Stay Secure

End-to-end cybersecurity for UAE businesses — penetration testing, vulnerability assessments, SOC monitoring and compliance support.

View Plans ↓
Frameworks & Standards
ISO 27001
GDPR / PDPL
NIST CSF
PCI-DSS
UAE IA Standards
SOC 2 Readiness
Free Security Assessment

What we check in your free assessment

Before any proposal we run a structured gap check against your environment. Here is what it covers:

01
External Attack Surface
Open ports, exposed services, subdomains and public-facing assets visible to attackers.
02
Web Application Gaps
Common OWASP Top 10 indicators on your public web properties — injection, auth, exposure.
03
Credential & Access Risks
Password policy, MFA coverage and known credential leaks associated with your domain.
04
Compliance Gap Indicators
Quick alignment check against ISO 27001, PDPL and PCI-DSS controls relevant to your business.
05
Incident Readiness
Whether you have logging, alerting and a response plan in place for a breach scenario.

Our Security Assessment Process

A structured four-phase approach that gives you a clear picture of your risk and a prioritised remediation roadmap.

1

Scoping & Reconnaissance

We map your attack surface — assets, entry points and data flows — and agree on scope before any testing begins.

2

Threat & Vulnerability Analysis

Automated scanning plus manual testing to find misconfigurations, weak credentials, injection points and logic flaws.

3

Exploitation & Proof of Concept

Where agreed, we safely exploit findings to demonstrate real-world impact so you understand the actual business risk.

4

Remediation Report & Re-test

A clear, prioritised report with step-by-step fixes. We re-test after remediation to confirm vulnerabilities are closed.

Plans

Who each engagement suits — and what you receive

Starter Assessment
AED 4,500
One-time project · Delivered within 5 business days
  • Are an SME needing your first security baseline
  • Want to understand your risk before a larger project
  • Need a report to share with board or insurers
  • Need a certificate for a tender or compliance audit
  • Have complex internal network to test
Key Deliverables
  • External vulnerability scan report
  • Web application review (up to 5 pages)
  • Risk-rated findings report (Critical → Low)
  • Step-by-step remediation guidance
  • Executive summary (1 page)
Included Activities
  • 30-day re-scan after remediation
  • 1 debrief call to walk through findings
  • Email support during remediation
Full Pentest
AED 18,000
One-time project · 2–3 week engagement
  • Need to demonstrate security to clients or regulators
  • Have web apps, APIs and internal network to cover
  • Require an executive report and a certificate of testing
  • Process payment data or sensitive customer records
  • Just launched and have no production systems yet
Key Deliverables
  • Executive report (risk, impact, priority)
  • Technical report (full findings with PoC)
  • Internal & external network pentest results
  • OWASP Top 10 web app + API test results
  • Social engineering simulation summary
  • Certificate of penetration testing
Included Activities
  • 20 hours of remediation support
  • Post-remediation re-test
  • Debrief calls (executive + technical)
  • WhatsApp + email support
Managed Security (MSSP)
AED 6,500 / month
12-month contract · 4-hour SLA
  • Need ongoing threat detection without an internal SOC
  • Have regulatory requirements for continuous monitoring
  • Want a retainer for incident response coverage
  • Require quarterly compliance evidence
  • Need only a one-time point-in-time assessment
  • Have an existing 24/7 SOC team in-house
Key Deliverables
  • Monthly vulnerability scan report
  • Alert & incident summary
  • Compliance posture dashboard (PDF)
  • Quarterly security review report
Ongoing Activities
  • 24/7 SOC alert monitoring
  • Endpoint detection & response (EDR)
  • Incident response (up to 8 hrs/mo)
  • Patch advisory & change management
  • Compliance dashboard access
Plan Comparison

Full specification

Feature Starter
AED 4,500
Full Pentest
AED 18,000
MSSP
AED 6,500/mo
External vulnerability scan✓✓Monthly
Internal network pentest✕✓✕
Web app pentest (OWASP Top 10)Basic (5 pages)Full✕
API security testing✕✓✕
Social engineering simulation✕✓✕
Certificate of testing✕✓✕
24/7 SOC monitoring✕✕✓
EDR / endpoint protection✕✕✓
Incident response coverage✕✕8 hrs/mo
Remediation supportEmail guidance20 hrs includedOngoing
Compliance dashboard✕✕✓
Re-test after remediation1 × 30-day scan✓Continuous
Engagement typeOne-timeOne-time12-mo retainer
Onboarding

Your first 30 days (MSSP)

1
Days 1–5
Scoping & Access
Asset inventory, credential handover for monitoring tools and environment documentation.
2
Days 6–15
Deploy & Baseline
EDR agents deployed, SIEM rules tuned to your environment, first baseline scan completed.
3
Days 16–25
Tune & Alert
False positives suppressed, alert thresholds calibrated, on-call escalation paths confirmed.
4
Days 26–30
First Report
Month-one security summary delivered; open risks prioritised with your team.
Results

Client case study

[HUMAN APPROVAL REQUIRED]

A verified client case study with real findings and outcomes will be published here once client approval is obtained.

Sample Output

What your pentest report looks like

Example findings only — not actual vulnerabilities from any real client environment.

Full Pentest · Executive Summary · Example Only
Total Findings
23
Across all surfaces
Critical
2
Immediate action
High
6
Fix within 2 weeks
Medium / Low
15
Planned remediation
FindingSeveritySurfaceStatus
SQL injection in login endpointCriticalWeb appOpen
Exposed admin panel (no MFA)CriticalNetworkOpen
Outdated Apache 2.2 (5 CVEs)HighServerOpen
Weak TLS configuration (SSLv3)MediumNetworkOpen

These are hypothetical example findings for illustration only. No real client data is shown.

FAQ

Common questions

We agree on a testing window upfront — typically during off-peak hours. Exploits are only run with your explicit sign-off. We have not caused downtime on any engagement, but we agree a rollback plan before every test to be safe.
Typically 2–3 weeks from kickoff to final report. The active testing phase is 5–8 days. We send a preliminary findings briefing before the formal report so you can begin remediating critical issues immediately.
24/7 SOC alert monitoring, monthly vulnerability scans, EDR deployment and management, up to 8 hours of incident response per month, a compliance dashboard and quarterly security reviews. Hardware and third-party tool licences are quoted separately based on your environment size.
We provide gap analysis, policy templates and audit-readiness support aligned to ISO 27001. We do not issue certificates ourselves — certification is issued by accredited certification bodies after your external audit. We help you prepare and pass that audit.
It depends on the requirement. For a tender asking for evidence of security testing, the Starter report is often sufficient. For PCI-DSS, ISO 27001 or a formal pentest certificate, you will need the Full Pentest engagement.
Yes. Our assessments include a PDPL gap analysis relevant to UAE data protection requirements. We also cover UAE IA Standards for businesses that interact with federal government systems.
We flag it immediately — we do not wait for the formal report. You get a one-page briefing note with the finding and a recommended immediate action within 24 hours of discovery.
All engagements are covered by an NDA signed before work begins. Findings reports are encrypted and delivered over secure channels. We do not retain copies of client data, credentials or systems access beyond the engagement period.

Ready to Know Your Real Risk?

Book a free assessment — we will tell you where you stand before recommending any engagement.

Step 1

Free 30-min security call to understand your environment and goals.

Step 2

We run your free gap assessment and deliver a findings brief.

Step 3

Choose an engagement — only what your risk profile actually needs.

WhatsApp Us
Get Your Free Security Assessment
Tell us about your environment and we will be in touch within a few hours.

No commitment · Reply within a few hours · Strict NDA on all engagements

✓
Request received.
Our security team will review your details and reply within a few hours with next steps.
Close

Get in Touch

We reply within a few hours

Service interested in (select all that apply)
One Central, Trade Centre 2, Dubai, UAE +971 50 769 8143 info@itcity.ae