Service Provider and Legal Hold Software User
The company worked with Penta to host a secure collaborative environment for legal hold in compliance with local data jurisdiction requirements.
Read MorePenta has run IT for regulated businesses since 1996. For Authorised Firms and Authorised Market Institutions, we assess where your technology stands against the DFSA's requirements, close the gaps, and operate the controls with independently audited evidence behind them, so your compliance team has something concrete to show a supervisor.
Each service maps to a specific part of the DFSA's General Module (GEN) or Prudential Module (PIB). Firms take the whole set or only the pieces their own teams do not cover.
Each requirement scored as met, partial or missing against the evidence you can actually produce, then turned into a prioritised plan of work.
Supports GEN 5.5.2 and GEN 5.5.5
Your Cyber Risk Management Framework, Operational Risk policy and Cyber Incident Response Plan, written for Governing Body approval and annual review.
Supports GEN 5.5.2, GEN 5.5.17 and PIB 6.2
Access control, multi-factor authentication, encryption and data protection configured in your tenant, with Microsoft Purview for classification and loss prevention.
Supports GEN 5.5.8, 5.5.9 and 5.5.12
Penta Sentinel, our SIEM, watched by a Security Operations Centre around the clock, so a material incident is detected and escalated in time to notify the DFSA within 72 hours.
Supports GEN 5.5.7, 5.5.16 and 5.5.19
Regular vulnerability assessment and penetration testing, with findings tracked through to remediation and kept on file for review.
Supports GEN 5.5.15
Tailored programmes for staff and senior management, run at least annually, with completion records kept by role.
Supports GEN 5.5.14
Managed backup and tested recovery, to your chosen cloud or to Penta's data centres in the UAE and Switzerland.
Supports PIB 6.6 and GEN 5.5.17
Private, hybrid or Azure environments patched, change-controlled and monitored by Penta, with an asset inventory kept current.
Supports GEN 5.5.5, 5.5.10, 5.5.11 and PIB 6.6
Outsourcing IT to Penta leaves the regulatory responsibility with your firm. The DFSA accepts a provider's independent audit reports as the way to oversee it, so what you rely on is our audited evidence, set out plainly.
ISAE 3402 Type 2
An independent auditor's annual opinion on the design and operating effectiveness of our controls over IT and managed services, covering change management, access, network security, monitoring, malware protection, backup and continuity.
ISO/IEC 27001:2022
Certification of the information security management system behind our compliance, consultancy, managed services, infrastructure and Microsoft 365 work.
Contract terms
Incident reporting, verification and audit access written into the service agreement, in line with the DFSA's expectations for third-party ICT providers under GEN 5.5.3.
We also show you which controls our reports leave with your firm, so nothing falls between the two. Our certifications evidence the part Penta operates; your firm's compliance position remains its own.
Ready to talk? The Penta team spans two countries, covering Europe and the Middle East in multiple languages. From a single outsourced application to the most complex private cloud, there’s a solution for you.
The best way to understand Penta is through the clients we work with. These are their stories: the challenge they faced, the thinking we brought to it, and where they landed. Different sectors, different problems, one consistent standard of work.