What we are watching in this sector, and the research that touches it. This is the research view; the services view is on the industry page.
Whether the corporate and operational estates genuinely fail independently.
Who owns the crossing between them on the org chart.
Whether remediation is sequenced against real maintenance windows.
Every obligation below is dated, named and externally imposed. Read them against what your organisation could evidence this week rather than against what it intends to build.
Lawful basis, DPO appointment, data protection impact assessments; fines AED 100,000 to AED 1,000,000.
39 mandatory Priority One controls; CNI harm penalties from AED 500,000 to AED 3,000,000.
Annual penetration testing, quarterly vulnerability assessment; non-compliance removes you from procurement lists.
That your security and cloud suppliers hold the required accreditation.
A cryptographic inventory across the estate.
Certifiable AI management system, or a defensible path to one.
AI system inventory, risk assessments, human oversight.
Risk classification and conformity documentation.
Reproduced from the Orvix Energy & utilities industry page. Last reviewed 26 August 2026.
The obligation that applies here, and the artefacts most firms in this sector do not hold.
Where organisations in this sector typically sit, and the one artefact that moves them up.
Ten statements. Three minutes. Nothing submitted.
The industry page sets out what we actually do in this sector and who delivers it.