07/09/2026
If your business operates as an Authorised Person under ADGM, its Cyber Risk Management rules aren't optional best practice, they're a binding chapter of the General Rulebook, with specific requirements around access controls, testing, training, and a 24-hour incident notification clock.
We wrote a full breakdown of what Chapter 3.5 actually requires, section by section.
Read it here π https://www.candorme.com/blog/adgm-cyber-risk-management-rules-guide/