Al Maha

Al Maha Managed Penetration Testing Remediation and Re-Test

DESC penetration tests your critical published services under Al Maha. HexaPrime manages everything that happens next — stakeholder engagement, remediation follow-up, independent re-testing, evidence submission to DESC and ticket closure.

Al Maha • DESC penetration testing • DESC DCI • Dubai Cyber Index • Penetration test remediation Dubai • Critical published services • Offensive security UAE
Al Maha • DESC penetration testing • DESC DCI • Dubai Cyber Index • Penetration test remediation Dubai • Critical published services • Offensive security UAE
About
Al Maha

How HexaPrime help you with Al Maha!

Al Maha is the DESC penetration testing service for an entity's critical published services. DESC performs the penetration test and issues the findings report to the entity, and the entity is then measured under the Dubai Cyber Index (DCI) on how those findings are remediated, verified and closed. HexaPrime delivers this as a managed Al Maha service. As soon as the Al Maha report is received from DESC, our offensive security team engages the application stakeholders and owners directly, drives the remediation actions, and once the owner confirms the fix, re-tests the same application to prove the finding is genuinely closed. The re-test result is submitted to DESC against the Al Maha finding and the ticket is closed. Our aim is to keep the Al Maha DCI score at 5, and we drive the follow-up cadence needed to get there — final timelines depend on application team availability and change windows.

Key
Features
  • Report intake & validation — receive the Al Maha penetration test report from DESC and validate findings against the tested application
  • Finding ownership mapping — identify the correct application stakeholder or owner for every finding
  • Direct stakeholder engagement — our offensive team contacts application teams directly to explain the finding, impact and required action
  • Exploitability & risk triage — confirm real exploitability and rank findings by risk to the published service
  • Remediation guidance — practical, developer-level fix guidance rather than generic scanner text
  • Remediation follow-up — structured cadence until the owner confirms the remediation is applied
  • Independent re-test — re-test the same application to verify the finding is closed
  • DESC submission & closure — submit re-test evidence to DESC against the Al Maha finding and close the ticket
  • DCI score governance — track closure timeliness and score performance for management
Let’s Connect
Please send your work inquiry here...
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Workflow
The managed Al Maha remediation and re-test cycle
Service Deliverables
Everything the service delivers. Built around measurable outcomes.
01
Finding Register & Engagement
  • Validated Al Maha finding register mapped to applications and owners
  • Stakeholder engagement record per finding
02
Remediation Guidance & Tracking
  • Risk-based remediation priority list with developer-level fix guidance
  • Remediation follow-up and status tracking to closure
03
Re-Test & DESC Closure
  • Independent re-test report per remediated finding
  • Closure evidence submitted to DESC and ticket closure confirmation
04
Reporting & Reviews
  • Al Maha DCI score and closure-timeliness reporting
  • Periodic review with recurring-issue and secure-development recommendations

See what Al Maha delivers and how it fits your environment.

Talk to an Al Maha Expert
FAQs
Frequently Asked Questions
What is Al Maha?

Al Maha is the DESC penetration testing service covering a Dubai Government entity's critical published services. DESC carries out the penetration test and issues the findings to the entity, which is then measured under the Dubai Cyber Index on how those findings are remediated, verified and closed.

What does HexaPrime do as part of Al Maha?

We manage everything after the DESC report lands. Our offensive security team validates the findings, contacts the application stakeholders directly, drives the remediation, re-tests the application once the owner confirms the fix, submits the re-test evidence to DESC against the Al Maha finding and closes the ticket.

Do you perform the penetration test yourselves?

Under Al Maha the penetration test is performed by DESC. HexaPrime performs the remediation-driving and the independent re-test that verifies each finding is closed before the evidence goes back to DESC. We can also deliver separate, entity-commissioned penetration testing outside the Al Maha scope.

How do you keep the Al Maha score at 5?

By engaging the application owner immediately after the report is received, following up on a fixed cadence until remediation is confirmed, re-testing without delay and submitting closure evidence to DESC promptly. Closure speed also depends on application team availability and change windows, so we drive the follow-up and report anything at risk early.

Who do you deal with inside our organisation?

The application stakeholders and owners for each tested service. Our offensive team works with them directly on the finding, the required fix and the confirmation that remediation has been applied, so your central security team is not left chasing updates.

What happens if a re-test shows the finding is still open?

The finding is not closed. We report the residual issue back to the application owner with the evidence from the re-test, agree a revised fix, and only submit to DESC once the re-test confirms the finding is genuinely remediated.

Ready to Secure Your Business?

Protect your organization with enterprise-grade cybersecurity, cloud, and managed IT solutions tailored to your business needs.