Falconry Completes Oman CSA STAR Engagement

Falconry completed a cloud security assurance engagement for Oman’s leading cloud and managed data-centre services provider, supporting its work around the Cloud Security Alliance STAR framework. Cloud service providers operate in an environment where customers, regulators and partners expect clear evidence of security governance and control maturity. CSA STAR provides a recognized mechanism for demonstrating how cloud security practices are structured and assessed against industry expectations. Falconry supported the organization through the professional-services work required for its CSA STAR programme, helping structure the assurance effort and strengthen alignment between cloud security controls, supporting evidence and review requirements. The engagement added another layer to the provider’s existing security and assurance environment and supported a more transparent, evidence-led approach to cloud security maturity. For organizations delivering critical digital infrastructure, that assurance is an important part of building customer confidence and demonstrating disciplined security governance.
Falconry Completes UAE Cybersecurity Assurance Review

Falconry completed an independent cybersecurity posture review for a major UAE environmental services organization, providing a shareholder-level view of governance, control maturity and material cyber risk exposure. The assignment was performed from an ownership and assurance perspective rather than as a detailed technology implementation. This required a concise, decision-focused view of whether cybersecurity governance and controls were sufficiently mature, where material risks existed and which issues required management attention. Falconry assessed cybersecurity governance, control maturity and key risk exposures, considered alignment with UAE national cybersecurity expectations and recognized control frameworks, and translated the findings into executive-level assurance observations and recommendations. The review provided stakeholders with a clearer independent view of the organization’s cyber posture and priority areas for follow-up. It also demonstrated how cybersecurity assessments can be tailored for boards, shareholders and portfolio owners who need assurance over material exposure without losing sight of practical remediation priorities.