UAE Trends and Developments Contributed by: Muthmainur Rahman and Kajen Subramoney, Ankura Consulting Group LLC
Pillar 5: fostering national and international collaboration and partnerships Recognising cybersecurity as a borderless challenge, this pillar emphasises engaging with strategic partners and scaling public-private partnerships. The “Cyber Crystal Ball” platform is a unified AI-pow - ered system for sharing relevant, timely, and action - able threat intelligence with trusted international part - ners and within the UAE ecosystem, to revolutionise real-time intelligence and combat ransomware. The UAE assumes a global leadership role in forums such as the Counter Ransomware Initiative (CRI), underscoring its commitment to collective global action. Kaspersky’s 2025 Financial Threat Report notes a 35.7% increase in ransomware globally, with the Mid - dle East specifically experiencing a 37% increase in spyware and a 26% increase in password stealers. Check Point predicts a “tech tsunami” as AI, Quan - tum and Web 4.0 collide. As a global crypto hub, with Dubai’s Virtual Assets Regulatory Authority (VARA) and Abu Dhabi Global Markets (ADGM) actively enforcing regulations, UAE organisations will need to develop resilience against Web 4.0 threats such as smart con - tract exploits. The CBUAE’s Recovery Planning Regulations place a strong focus on the operational resilience of financial sector entities. For these entities, it is no longer suf - ficient to prevent a breach; they must demonstrate the ability to recover critical services within strict recovery time objectives (RTOs) whilst under attack. Energy & utilities Mandiant identifies the Middle East as a tense region amid operations by the Iran-nexus threat actor. These operations focus on attacking targets of strategic and operational relevance, which include industrial control system (ICS) attacks. The convergence of information technology and operational technology expands the attack surface, Sector-Specific Perspectives Financial services and Web 4.0
requiring even more rigorous integrity checks. The UAE’s CSC has developed a framework of security controls to ensure a unified cybersecurity approach across the UAE. Particularly relevant for energy & utili - ties, the information assurance standards (IAS) and framework must be implemented and audited, with potential fines for non-compliance. Healthcare CNBC previously reported that medical records are highly valuable, selling on the dark web for approxi - mately USD60/record – much more than the price of an identity number or a credit card. For the UAE (and many other nations), data sovereign - ty is paramount. Federal Law No 45 of 2021 (PDPL) establishes the requirements for localisation, transfer restrictions and security measures to support sover - eign data objectives. Healthcare data is effectively “grounded” within the physical borders unless special provisions are arranged. In a cyber breach at a healthcare institute, the most sensitive information in the country is placed in the hands of an unknown third party in an unknown juris - diction, thereby impinging on the rights of data sub - jects. Conclusion: The 2026 Action Plan The UAE has successfully transitioned from a con - sumer of technology to a global innovator. However, the 2025 data shows that the adversary is evolving just as quickly, exploiting legacy gaps and leveraging AI to bypass traditional defences. For the C-Suite and other strategic leaders, 2026 rep - resents a shift in gears. Cybersecurity is no longer just about protecting data; it is about protecting the licence to operate. Strategic recommendations for 2026 • Conduct a legacy audit (immediate) – 50% of UAE exploits use vulnerabilities that are more than five years old, a stark contrast to the global “48-hour” exploit window. Organisations should mandate a specific audit of all assets older than three years and prioritise patching or air-gapping these sys - tems to close the “digital debt.”Enforce AI govern -
438 CHAMBERS.COM
Powered by FlippingBook