UAE Strengthens Banking Rules Against Cyberattacks and Outages

2 Min Read

The United Arab Emirates has introduced stronger banking regulations designed to enhance cybersecurity, operational resilience and the continuity of financial services. The UAE Central Bank’s new Operational Risk Management Regulation came into force on September 14, 2026, replacing the previous framework issued in 2018.

The new framework applies to licensed financial institutions and requires them to establish comprehensive systems for identifying, managing and responding to operational risks. A major focus is ensuring that essential banking services can continue operating during disruptions.

Financial institutions must identify their critical operations, including payment services, transfers and maintaining accurate customer financial records. They are also required to establish business-continuity and disaster-recovery plans and regularly test their ability to respond to major disruptions.

Cybersecurity has been placed at the centre of the new framework. Banks and other regulated institutions must maintain robust ICT and cybersecurity systems covering vulnerability management, incident response, data protection, system recovery and regular testing. These requirements also extend to technology and cloud-service providers used by financial institutions.

The regulation also strengthens incident-management requirements. Institutions must maintain response and recovery plans, regularly test them, investigate the causes of significant incidents and implement measures designed to reduce the likelihood of similar disruptions occurring again.

The UAE’s latest regulatory measures demonstrate its commitment to building a secure, resilient and digitally advanced financial sector. By strengthening cybersecurity, business continuity and risk management, the country is supporting customer confidence while preparing its banking system for an increasingly technology-driven economy.