Information Security Dubai: Full Engagement | Ilia Arestov

Information Security

IT Consulting Dubai — ИТ-консалтинг Services

In most companies information security amounts to an antivirus and the Wi-Fi password shared in a group chat, and the first real incident reveals there are no logs, no owner and no plan. I build the whole perimeter: access, employee devices, data encryption and monitoring that catches a problem before your client reports it. On an open stack and inside your own infrastructure, with no mandatory vendor cloud. That is the scope of an information security engagement as I run it for companies in Dubai and the wider MENA region.

Information security: what the engagement covers

Information security: access, devices, encryption and monitoring

The work closes the four areas where companies actually leak: who gets access and how, what runs on employee devices, where the data sits, and who is looking at the logs. It runs in that order: starting with monitoring is pointless while half the staff share one administrator password.

The deliverable is not a hundred-page report but a working configuration handed to your team, with documentation and a record of what was set and why. Everything I install, you can run without me.

Access and the perimeter

The most common finding at the start is a single provider account three people can log into, with password recovery pointing at a mailbox that lives inside that same account. A setup like that fails all at once.

  • Provider, domain and mail accounts separated so that compromising one does not open the rest.
  • Hardware keys instead of SMS codes for every administrative login.
  • Named accounts instead of shared ones: every action in the log has an author.
  • Access revocation on departure as one procedure, not a walk through ten services from memory.

How this is built on my own infrastructure is set out in Zero Trust in practice.

Employee devices

Device management is usually sold together with a mandatory vendor cloud: staff phones and laptops report outwards, and the company signs up for a per-device subscription. For some companies that is unacceptable: because a client requires it, because of regulation, or simply because the data must not leave the perimeter.

I run device management on your own server: disk encryption, password policy, remote lock and wipe on loss, and a work profile kept separate from personal use on the phone. The reasoning is in A self-hosted MDM instead of Intune and Jamf.

Monitoring and incident handling

Almost everyone has logs, but they sit in ten places and nobody reads them. The point of monitoring is not to collect everything; it is to correlate events so that an alert means a real problem rather than noise.

The stack is open: collection and storage on Wazuh and OpenSearch, with correlation rules written for your specific infrastructure on top. An open core means the bill does not grow with log volume, so you are never pushed to switch off sources to save money, which is exactly how the events you built it for get lost. The trade-offs are in A SIEM on an open core.

Data and encryption

Disk encryption on working machines, separate keys for backups, and a cold copy out of reach of anyone who gets into the live environment. The backup keys sit neither next to the copies nor in the same store as working passwords: ransomware that reaches the environment does not reach the archive.

For higher-risk situations (travel, work in an unfriendly jurisdiction, devices that may be seized) there are separate answers, up to a hidden operating system. It is justified where the device can be seized by someone entitled to demand the password.

Stack

LayerTools
Accounts and keysYubiKey, Vaultwarden
Network and remote accessWireGuard
Employee devicesself-hosted MDM, Ansible
Logs and alertsWazuh, Fluent Bit
Encryption and backupsVeraCrypt, Proxmox Backup Server

What I do not do

This section is not modesty. Stating the limits saves both sides months.

  • I do not read the content of people’s work. Monitoring messages and screens is a deliberate refusal, not a missing feature.
  • I do not pass off a report against a standard as compliance with it. Certification comes from an accredited body; I prepare the infrastructure for audit and tell you where you would fail.
  • I do not stand in for a duty rota: an alert at three in the morning is handled by a roster of people, not by one consultant.
  • I do not hold your keys or your licences: subscriptions and tokens are registered to your own company, so leaving me never means reissuing access.

How the engagement runs

The first two weeks are a survey: an inventory of access, devices and data, and a review of what is already in place. You get a prioritised list of findings with an estimate of what happens if a given one is left open. Sometimes that is where it stops: when the findings turn out cheaper to fix than the full engagement costs.

Then implementation area by area, from access through to monitoring, handing over to your team at each step. It closes with rehearsals: revoking access, losing a laptop, restoring from backup. Anything not rehearsed does not work.

The full engagement costs $35,000 (AED 128,450), a fixed sum for a scope agreed in writing after the survey; after that there are no payments per employee or per device, and over three years the difference sits exactly there.

If the question is wider than technical defence and reaches business continuity, see risk management. If you need an independent view of the whole technology stack rather than security alone, see IT consulting. What running a large estate looks like once it is configured is described in Infrastructure fleet management.

Frequently Asked Questions

How long does the engagement take?

Eight to twelve weeks for a company of 30–150 people. The survey takes two weeks, then implementation runs area by area. What usually moves the dates is not the technical work but getting access approved on the client side.

Does an agent have to go on employees’ personal phones?

Only if work mail is opened on them, and only inside a work profile: it is encrypted and wiped separately, and the personal side of the phone is left alone. The alternative is access from company devices only.

What does the company keep afterwards?

A working configuration on your own infrastructure, the documentation, and every account and key in your people’s hands. An open stack means no lock-in to me: support can continue with me, move to your own team, or go to another contractor.

Does this satisfy UAE regulatory requirements?

The infrastructure is prepared to pass an audit: logs retained to the required depth, access segregated, actions traceable. The compliance opinion itself comes from an accredited body; I prepare the infrastructure for inspection.


Ready to Get Started?

Tell me what is already in place and what worries you: after the conversation it is clear where configuration by your own team is enough and where the full engagement is needed. Discuss the perimeter survey.

Rate article