DESC and Microsoft deploy real-time Zero Trust dashboard for Dubai

Dubai Electronic Security Center and Microsoft have built a live dashboard tracking government entities' compliance with Dubai's Information Security Regulation.

DESC and Microsoft deploy real-time Zero Trust dashboard for Dubai

Dubai Electronic Security Center (DESC) and Microsoft have unveiled a co-developed Zero Trust assurance dashboard that gives DESC a continuously updated view of the cybersecurity posture of Dubai Government entities. Announced at GISEC Global 2026, the tool replaces periodic, self-reported assessments with live telemetry drawn from security signals that participating entities already generate through Microsoft products.

The dashboard maps those signals against the Dubai Information Security Regulation (ISR), the minimum security standard DESC maintains across 13 domains for all Dubai Government bodies. It surfaces 37 distinct finding types covering risky identities, multifactor authentication and Conditional Access posture, privileged access, device compliance, active incidents and open vulnerabilities. Each finding includes plain-language remediation guidance exportable in both Arabic and English.

The deployment

Two Dubai Government entities have completed onboarding following a pilot phase, with rollout planned to more than 80 additional entities across the Emirate. The release did not specify a timeline for full rollout or disclose whether participation is mandatory under the ISR framework.

Amer Sharaf, CEO of the Cybersecurity Systems and Services Sector at DESC, said the initiative "helps us strengthen oversight while giving entity teams clearer guidance on the actions required to address identified gaps," framing it as part of DESC's broader effort to advance Zero Trust and cyber resilience across Dubai Government.

Amr Kamel, General Manager of Microsoft UAE, noted that the system turns signals entities already generate into "a live view of their posture, faster remediation and stronger Zero Trust across Dubai Government." The collaboration builds on an existing relationship: Microsoft Azure, Microsoft 365 and Dynamics 365 have each been certified against DESC's Cloud Service Provider Security Standard, and Microsoft operates local cloud regions in both Abu Dhabi and Dubai.

Market context

Government security operations centres are increasingly moving from annual compliance audits to continuous control monitoring, a shift accelerated by rising ransomware frequency and stricter national cyber frameworks across the Gulf. The UAE's broader cybersecurity regulatory landscape includes the National Information Assurance Policy and sector-specific frameworks for financial services and critical infrastructure, all of which share an emphasis on real-time visibility and zero-trust architecture.

Microsoft's position here reflects a wider pattern: hyperscalers leveraging existing enterprise deployments to upsell or embed governance tooling at the sovereign level. Competitors including Google Cloud and AWS are pursuing similar strategies in the Middle East, with each operating or building dedicated sovereign cloud regions in the Gulf. For DESC, anchoring its assurance framework to Microsoft signals creates measurable compliance evidence but also concentrates oversight infrastructure within a single vendor's telemetry layer, a dependency governments in other markets have begun to scrutinise under digital sovereignty principles.

The dashboard's 37 finding types and ISR-mapped controls represent a more granular compliance surface than most national-level government programmes have published to date in the region, which positions this deployment as a potential reference model for other Gulf states developing their own ISR-equivalent frameworks.