Al Kashif

Al Kashif Managed Vulnerability Assessment and Remediation

A complete managed Al Kashif service for Dubai Government entities — on-time vulnerability assessment of critical servers and services, actionable remediation reporting and disciplined follow-up to protect your DESC DCI score and SLA.

Al Kashif • DESC DCI • Dubai Cyber Index • Managed vulnerability assessment Dubai • VA scanning Dubai Government • Vulnerability remediation UAE
Al Kashif • DESC DCI • Dubai Cyber Index • Managed vulnerability assessment Dubai • VA scanning Dubai Government • Vulnerability remediation UAE
About
Al Kashif

How HexaPrime help you with Al Kashif!

Al Kashif is one of the services under the DESC Dubai Cyber Index (DCI). It covers vulnerability assessment of an entity's critical servers and services, and the entity is measured on how well those findings are scanned, reported and remediated within SLA. HexaPrime delivers this as a complete Managed VA Service: we run the vulnerability assessment scans on schedule, convert the output into a clear remediation report for your technical teams, and follow up until findings are closed and verified — so remediation happens on time and the Al Kashif SLA is met. Entities we manage are maintained at a DCI score above 4.

Key
Features
  • Scope & asset coverage — identify and confirm all critical servers and services in scope for Al Kashif
  • Scheduled vulnerability assessment — run VA scans on the agreed cycle, on time, every time
  • Findings validation & triage — remove false positives and confirm real, exploitable exposure
  • Risk-based prioritisation — rank findings by severity, exploitability and asset criticality
  • Remediation reporting — per-finding fix guidance, affected assets, owners and due dates
  • Remediation support & follow-up — work with technical teams and track every finding to closure
  • Re-scan & closure verification — prove fixes are effective and findings are closed
  • SLA & DCI score reporting — track remediation timeliness and score performance for management
Let’s Connect
Please send your work inquiry here...
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Workflow
The managed Al Kashif VA and remediation cycle
Service Deliverables
Everything the service delivers. Built around measurable outcomes.
01
Scope & Scanning
  • Confirmed scope of critical servers and services, with scan schedule
  • Vulnerability assessment scan on every agreed cycle
02
Remediation Report & Register
  • Remediation report — validated, prioritised findings with fix guidance, owners and SLA due dates
  • Live findings register tracking open, in-progress and closed items
03
Follow-Up & Verification
  • Remediation follow-up with technical teams
  • Re-scan and closure-verification evidence
04
Reporting & Reviews
  • SLA compliance and DCI score performance reporting
  • Periodic service review with improvement recommendations

See what Al Kashif delivers and how it fits your environment.

Talk to an Al Kashif Expert
FAQs
Frequently Asked Questions
What is Al Kashif?

Al Kashif is one of the services under the DESC Dubai Cyber Index (DCI). It covers vulnerability assessment of a Dubai Government entity's critical servers and services, with the entity measured on scanning coverage and on how quickly findings are remediated within SLA.

What does HexaPrime do as part of Al Kashif?

We provide the complete managed VA service: scheduled vulnerability assessment scanning, validation and prioritisation of findings, a remediation report your technical teams can act on, follow-up until fixes are applied, and re-scan verification — all governed against the Al Kashif SLA.

How do you keep the Al Kashif score above 4?

By never missing a scan cycle, issuing the remediation report immediately after each scan, prioritising findings by real risk, and following up with the technical teams until fixes land inside the SLA window. Score performance is reported every cycle.

Which assets are covered?

The entity's critical servers and services as defined in the agreed Al Kashif scope. Scope and asset coverage are validated at onboarding and re-confirmed at each review so new or changed systems are not missed.

How do you prioritise what to fix first?

By risk — combining vulnerability severity, exploitability and the criticality of the affected server or service — so limited engineering time goes first to the exposures that matter most and to findings closest to their SLA deadline.

Will remediation disrupt operations?

Fixes are planned and applied through your agreed change control, sequenced by risk and tested to limit disruption to live services. Re-scans confirm the fix worked without breaking the service.

Ready to Secure Your Business?

Protect your organization with enterprise-grade cybersecurity, cloud, and managed IT solutions tailored to your business needs.