
DESC penetration tests your critical published services under Al Maha. HexaPrime manages everything that happens next — stakeholder engagement, remediation follow-up, independent re-testing, evidence submission to DESC and ticket closure.
Al Maha is the DESC penetration testing service for an entity's critical published services. DESC performs the penetration test and issues the findings report to the entity, and the entity is then measured under the Dubai Cyber Index (DCI) on how those findings are remediated, verified and closed. HexaPrime delivers this as a managed Al Maha service. As soon as the Al Maha report is received from DESC, our offensive security team engages the application stakeholders and owners directly, drives the remediation actions, and once the owner confirms the fix, re-tests the same application to prove the finding is genuinely closed. The re-test result is submitted to DESC against the Al Maha finding and the ticket is closed. Our aim is to keep the Al Maha DCI score at 5, and we drive the follow-up cadence needed to get there — final timelines depend on application team availability and change windows.
Al Maha is the DESC penetration testing service covering a Dubai Government entity's critical published services. DESC carries out the penetration test and issues the findings to the entity, which is then measured under the Dubai Cyber Index on how those findings are remediated, verified and closed.
We manage everything after the DESC report lands. Our offensive security team validates the findings, contacts the application stakeholders directly, drives the remediation, re-tests the application once the owner confirms the fix, submits the re-test evidence to DESC against the Al Maha finding and closes the ticket.
Under Al Maha the penetration test is performed by DESC. HexaPrime performs the remediation-driving and the independent re-test that verifies each finding is closed before the evidence goes back to DESC. We can also deliver separate, entity-commissioned penetration testing outside the Al Maha scope.
By engaging the application owner immediately after the report is received, following up on a fixed cadence until remediation is confirmed, re-testing without delay and submitting closure evidence to DESC promptly. Closure speed also depends on application team availability and change windows, so we drive the follow-up and report anything at risk early.
The application stakeholders and owners for each tested service. Our offensive team works with them directly on the finding, the required fix and the confirmation that remediation has been applied, so your central security team is not left chasing updates.
The finding is not closed. We report the residual issue back to the application owner with the evidence from the re-test, agree a revised fix, and only submit to DESC once the re-test confirms the finding is genuinely remediated.
Protect your organization with enterprise-grade cybersecurity, cloud, and managed IT solutions tailored to your business needs.