Cybersecurity 2026

UAE Trends and Developments Contributed by: Muthmainur Rahman and Kajen Subramoney, Ankura Consulting Group LLC

these are not generic emails; they are AI-enhanced and tailored to the victim or environment. At a more sophisticated level of phishing, threat actors breach an environment, exfiltrate emails, and use them to gain insights and train AI models to develop an attack plan. These attacks are often sophisticated, multi-channel and use deepfake voice cloning to impersonate trust - ed entities or executive leadership. Microsoft’s Digital Defence Report 2025 notes that 97% of identity attacks globally are password-based. In the UAE, the attack vector has shifted to bypass - ing multi-factor authentication (MFA) through “MFA fatigue” and token theft, facilitated by these AI-driven social engineering campaigns. Many of these attacks involve impersonating Microsoft 365 authentication, with users unknowingly providing their credentials and MFA tokens to an attacker on a spoofed website. The business sabotage anomaly Globally, Palo Alto’s Unit 42 found that 86% of major incidents now involve deliberate “business disruption” or sabotage. In contrast, Microsoft data reveals that 52% of cyber - attacks in the UAE are financially motivated (ransom - ware/extortion), the sabotage threat remains acute for critical infrastructure. Unlike financial firms, which face theft, if left unchecked, UAE energy and utility providers could face state-sponsored attackers tar - geting operational technology assets, mirroring global sabotage trends but with higher geopolitical stakes. Comprehensive Regulatory Environment: 2025- 2026 Legislative Updates If the threat landscape is considered to be evolv - ing, the regulatory landscape can be seen as hav - ing undergone a revolution. The UAE Cyber Security Council made significant progress in 2025 by intro - ducing strict liability and consolidated oversight. The Central Bank of the UAE Federal Decree-Law No 6 of 2025 Effective September 2025, this law represents a con - solidated overhaul of the financial regulatory frame - work.

• Expanded perimeter – The law expands the Central Bank of the UAE’s (CBUAE) supervisory perimeter to explicitly capture emerging technology firms conducting licensed financial activities (Fintechs, payment service providers, crypto-asset firms and others). • Mandatory fraud reporting – Article 149 establishes a statutory obligation to implement “robust fraud prevention and detection mechanisms.” Crucially, it mandates the prompt reporting of confirmed fraud and security breaches to the Central Bank, includ - ing fraud traditionally associated with technology, such as social engineering and identity theft. Strict liability – The law enhances the CBUAE’s super - visory and enforcement capabilities, allowing for sig - nificant administrative penalties and, in severe cases of negligence regarding consumer funds, criminal liability for management. DIFC Data Protection Amendment Law No 1 of 2025 Dubai International Financial Centre (DIFC) enacted this amendment in July 2025, and the law now aligns with the most aggressive aspects of GDPR enforce - ment. • Private right of action – The most notable change for general counsel to consider is that there is now a statutory right for individuals to sue for “financial loss and damage not involving financial loss, such as distress”. This creates an environment in which class-action-style litigation could follow a data breach, significantly increasing the financial risk profile of a cyber incident. • Processor liability – In the past, data processors (vendors) would build indemnity for themselves against regulatory fines into their contracts with data controllers. This is no longer the case: data processors are now directly liable for their own compliance failures and for acting outside the con - troller’s instructions. • Adequacy assessments – New requirements man - date that controllers must conduct and document a transfer impact assessment for high-risk pro - cessing activities even when transferring data to a jurisdiction considered “adequate”. This assess -

436 CHAMBERS.COM

Powered by