
SECURITY ARCHITECTURE THAT SURVIVES THE AUDIT.
PRAECEPTA is a specialist security architecture practice based in Dubai. We design Zero Trust, data security and regulatory assurance programmes for organisations across the Middle East and Africa — and we provide architecture capability to the consultancies and integrators who serve them.

MOST SECURITY PROGRAMMES DON'T FAIL AT THE TOOLING LAYER
They fail at the layer above it.
Controls get procured before the target state is defined. Zero Trust programmes stall at identity and never reach data. Sensitive information is classified but never governed. Compliance is achieved on paper and comes apart under inspection.
None of these are product problems. They are architecture problems — and they are decided long before anyone signs a purchase order.
PRAECEPTA works at that layer.
FOUR PRACTICE AREAS
OUR CORE INTEGRATED SERVICES

FRAMEWORKS WE WORK IN
REGIONAL
NCA ECC-2:2024 · NCA CSCC · SAMA Cyber Security Framework · UAE Information Assurance Standard v2 · CBUAE guidance · QCB · CBB · ADHICS
DATA PROTECTION
UAE PDPL (Federal Decree-Law 45/2021) · KSA PDPL & SDAIA transfer regulations · DIFC Data Protection Law 2020 · ADGM Data Protection Regulations 2021 · POPIA · Kenya DPA 2019 · NDPR
INTERNATIONAL
NIST CSF 2.0 · NIST SP 800-207 · ISO/IEC 27001:2022 · ISO/IEC 42001 · CSA CCM v4.1 · IEC 62443 · NCSC CAF v4.0 · MITRE ATT&CK · NIST SP 800-161r1
WHY PRAECEPTA
28 years. Vendor-neutral. Regionally grounded.
We sell no products. No resale margin, no vendor commission, no partner quota. When we recommend a control, the recommendation is the deliverable.
We are regionally resident, not regionally deployed. PRAECEPTA is UAE-licensed and UAE-based. We work in the frameworks GCC regulators actually enforce, in the language they enforce them in — not a global playbook localised after the fact.
We work at architecture grade. Led by a practitioner with 28 years in IT and cybersecurity, certified CISSP, CISM, CCZT, Associate C|CISO and CEH, with Open FAIR and CAISP in progress.
ONE EVIDENCE BASE. FOUR FRAMEWORKS.
Organisations across the GCC run the same assessment repeatedly because each framework demands its own evidence pack. Most of that work is duplicated.
The PRAECEPTA Framework Crosswalk maps NCSC CAF v4.0 to NCA ECC-2:2024, the UAE Information Assurance Regulation v2 and NIST CSF 2.0 — so a single evidence-gathering exercise can serve multiple reporting obligations.






