Rapid digital transformation in the UAE has led to the rising reliance on third-party service providers, such as cloud platforms, IT contractors, and software vendors, by organizations. This dependency has expanded the cyber threat surface and has become an essential piece of the legal compliance and organizational resiliency puzzle in the world of cyber risk management. The study investigates third-party cyber risk management within the framework of the UAE Personal Data Protection Law (PDPL) and the Cybercrime Law, particularly the third-party data controllers and processors’ obligations. The study pertains to a qualitative literature review of the latest research and international standards, NIST SP 800–161 and ISO/IEC 27036 to provide a list of best practices for governance, risk assessment, contractual controls, monitoring, audit, incident response, and business continuity. The results show that a strong link exists between integrated IT governance, cybersecurity investment and operational resilience in minimizing risks of third-party data breaches. The research extends a framework for UAE organizations to meet the requirements of PDPL, protect personal data, and foster trust within the digital supply chain.
Budair et al. (Mon,) studied this question.