top of page

SECURITY ARCHITECTURE THAT SURVIVES THE AUDIT.

PRAECEPTA is a specialist security architecture practice based in Dubai. We design Zero Trust, data security and regulatory assurance programmes for organisations across the Middle East and Africa — and we provide architecture capability to the consultancies and integrators who serve them.

MOST SECURITY PROGRAMMES DON'T FAIL AT THE TOOLING LAYER

They fail at the layer above it.
 

Controls get procured before the target state is defined. Zero Trust programmes stall at identity and never reach data. Sensitive information is classified but never governed. Compliance is achieved on paper and comes apart under inspection.

None of these are product problems. They are architecture problems — and they are decided long before anyone signs a purchase order.

PRAECEPTA works at that layer.

FOUR PRACTICE AREAS

OUR CORE INTEGRATED SERVICES

Security Architecture

Current-state assessment, target-state reference architecture, and a roadmap that survives contact with your actual estate. Independent design assurance for architectures produced by others.

Zero Trust Advisory

Maturity assessment against NIST SP 800-207 and the CISA Zero Trust Maturity Model. Target architecture, policy enforcement design, and a first wave scoped to succeed rather than to impress.

Data Security & DSPM

Discovery, classification, and posture management. Where sensitive data actually lives, who can reach it, and whether that arrangement is lawful in every jurisdiction you operate in.

Regulatory Assurance & Cyber Risk

Gap assessment and roadmap against the frameworks GCC regulators enforce — with findings quantified in financial terms your board can act on.

FRAMEWORKS WE WORK IN

REGIONAL

NCA ECC-2:2024 · NCA CSCC · SAMA Cyber Security Framework · UAE Information Assurance Standard v2 · CBUAE guidance · QCB · CBB · ADHICS

DATA PROTECTION

UAE PDPL (Federal Decree-Law 45/2021) · KSA PDPL & SDAIA transfer regulations · DIFC Data Protection Law 2020 · ADGM Data Protection Regulations 2021 · POPIA · Kenya DPA 2019 · NDPR

INTERNATIONAL

NIST CSF 2.0 · NIST SP 800-207 · ISO/IEC 27001:2022 · ISO/IEC 42001 · CSA CCM v4.1 · IEC 62443 · NCSC CAF v4.0 · MITRE ATT&CK · NIST SP 800-161r1

WHY PRAECEPTA

28 years. Vendor-neutral. Regionally grounded.

We sell no products. No resale margin, no vendor commission, no partner quota. When we recommend a control, the recommendation is the deliverable.

We are regionally resident, not regionally deployed. PRAECEPTA is UAE-licensed and UAE-based. We work in the frameworks GCC regulators actually enforce, in the language they enforce them in — not a global playbook localised after the fact.

We work at architecture grade. Led by a practitioner with 28 years in IT and cybersecurity, certified CISSP, CISM, CCZT, Associate C|CISO and CEH, with Open FAIR and CAISP in progress.

ONE EVIDENCE BASE. FOUR FRAMEWORKS.

Organisations across the GCC run the same assessment repeatedly because each framework demands its own evidence pack. Most of that work is duplicated.

The PRAECEPTA Framework Crosswalk maps NCSC CAF v4.0 to NCA ECC-2:2024, the UAE Information Assurance Regulation v2 and NIST CSF 2.0 — so a single evidence-gathering exercise can serve multiple reporting obligations.

CHANNEL PARTNERS

Are you a consultancy, systems integrator or MSSP?
PRAECEPTA provides subcontracted senior architecture capacity under your brand, with a signed non-solicitation undertaking both ways. 

2
bottom of page