Gulf Businesses Must Plan for Weeks. Long Cyberattacks, Warn Regional Security Experts
Gulf businesses are being pushed to rethink continuity plans as ransomware attacks grow capable of taking operations offline for weeks. Leading regional security experts share what resilience now demands from the boardroom to the SOC.

Cybersecurity professionals in a Gulf enterprise operations centre monitoring network threats on large screens
The strategic shift: from recovery to resilience
Across the Gulf Cooperation Council, a fundamental rethinking of cybersecurity strategy is underway. The traditional model of detect a breach, contain it, and recover is being replaced by a more demanding standard: can critical operations continue while an attack is still active?
This is not merely a rebranding of existing practices. It represents a genuine architectural shift in how organisations design their systems, train their people, and govern their risk. Ransomware that once disrupted operations for hours now routinely holds businesses offline for weeks. AI-enabled attacks coordinate across endpoints, identities, and cloud environments simultaneously. The window to respond has narrowed to minutes, not days.
"Cyber resilience has moved from an IT conversation to a boardroom priority. The mandate has shifted toward designing operations that can keep running through an attack. Recovery alone is no longer enough." - Chris Cochran, Field CISO and VP of AI Security, SANS Institute
IBM's 2025 Cost of a Data Breach Report places the global average breach cost at $4.4 million. For Gulf organisations, that figure is compounded by rapid cloud adoption, expanding operational technology (OT) exposure, and supply chain interdependencies that can amplify a single incident across multiple business functions simultaneously. The same report found that 97% of organisations that experienced an AI-related security incident lacked proper AI access controls, and a further 20% of breaches now involve what IBM terms Shadow AI.
The shadow AI problem: an emerging blind spot
Shadow AI refers to employees using unapproved AI tools, including consumer assistants, browser-based writing tools, and code generation services, to process work data without IT or security oversight. An employee drafting a sensitive proposal through an unapproved service may be inadvertently submitting that data to a third-party training pipeline. Governance policies must explicitly address which AI tools are approved, for what data types, and under what conditions, before the AI governance gap becomes an incident.
Critical distinction: resilience does not replace recovery
Organisations that invest in active resilience while neglecting core backup, replication, and restoration capabilities create a dangerous gap. True resilience is built on a solid recovery foundation, not instead of one. Ensure your recovery fundamentals are sound before planning to operate under attack: tested backups, documented runbooks, and validated restoration procedures.
The attack surface has fundamentally changed
Modern attacks are no longer sequential. They are simultaneous. A single threat actor can probe endpoints, harvest credentials, pivot through cloud misconfigurations, and reach OT environments within a single coordinated campaign. Average attacker breakout time, the window between initial access and lateral movement, is now 48 minutes. That is the entire window an organisation has to detect, triage, and contain a breach before it spreads across critical systems.
"Adversaries do not respect your internal org chart. They move across OT and IT in the same campaign, pivot through cloud misconfigurations, and exploit identity the moment they find an unlocked door." - Meriam ElOuazzani, VP META, Censys
Data from the Sophos State of Ransomware 2025 report, drawing on 3,400 professionals across 17 countries including the UAE, found that exploited vulnerabilities remained the top root cause of ransomware attacks. Average ransom payments stood at $1 million, with recovery costs reaching $1.5 million. Google Cloud's Mandiant M-Trends 2025 report confirmed that exploits accounted for 33% of investigated incidents, with stolen credentials rising to 16%.
What this means for continuity planning
Business continuity plans built around static disaster scenarios and perimeter-based controls are no longer adequate. Ezzeldin Hussein, Regional Senior Director at SentinelOne META, describes the new standard:
"Businesses must focus on maintaining processes even during an active attack, making sure that critical services are available while threats are quickly contained. This needs real-time visibility, automated response, and quicker decision-making." - Ezzeldin Hussein, Regional Senior Director, SentinelOne META
For Gulf organisations, this pressure is especially acute. Digital platforms are deeply embedded in aviation, logistics, banking, energy, healthcare, and government services. A single incident can cascade across customer channels, payment flows, supply chains, and physical operations at once. The Colonial Pipeline attack in 2021 remains the clearest illustration: an IT-level breach that disrupted physical fuel distribution across the US Eastern Seaboard.
In the GCC context, the stakes are further elevated by the scale of ongoing infrastructure transformation. Megaprojects such as NEOM are being architected from the ground up around digital systems, AI-driven services, and interconnected operational technology. The resilience of these environments is not a future concern. It is a design requirement that must be embedded now, before the infrastructure is live at scale.
Identity: the most critical and most misunderstood frontier
If there is one theme that dominates expert discussions across the GCC security community, it is identity. Attackers are no longer breaking in. They are logging in. By using valid credentials, threat actors can move laterally through systems for days or weeks before triggering traditional security alerts.
"Attackers today do not take systems down. Instead they log in with valid credentials, move quietly, and leave doubt behind. You can bring your systems back online in hours, but you cannot restore confidence in what they touched." - Keyur Shah, Associate Field CISO, Sophos
Shah is identifying something that goes beyond uptime metrics and recovery time objectives: the erosion of organisational trust in its own data. After a credential-based intrusion, every record the attacker may have touched is suspect. In the Gulf, where institutional reputation is foundational to business relationships across banking, government contracting, and the tightly networked private sector, this erosion of data confidence can outlast the technical incident by months.
The question organisations must be asking is not only how fast can we restore systems, but how do we demonstrate, credibly, to regulators, customers, and partners, that the integrity of our data has been preserved. That requires forensic capability, audit trails, and communications protocols that most business continuity plans do not yet include.
The human and non-human identity gap
While board-level conversations increasingly reference identity security, they often conflate two fundamentally different categories:
Human identities cover employees, contractors, and administrators, the accounts most organisations have some visibility into, governed through Active Directory, SSO, and MFA policies.
Non-Human Identities (NHIs) cover service accounts, API keys, bots, automated pipelines, and machine-to-machine tokens. These are the fastest-growing and least-secured attack surface in modern enterprise environments. NHIs typically outnumber human accounts by a ratio of 10 to 1 or more in cloud-native environments and are rarely subject to the same lifecycle management.
Practitioner priority: start with an NHI inventory
Before investing in advanced identity analytics platforms, conduct a basic Non-Human Identity audit: enumerate all service accounts, API keys, and automation tokens; identify which have excessive permissions; and establish a rotation and revocation policy. This foundational step is often more impactful than sophisticated tooling layered on an unaudited identity estate.
Dependency risk: cloud, OT, and third parties
Cyber incidents today rarely remain isolated to a single system. They cascade. A vulnerability in a cloud platform can expose a logistics provider's shipment system. A compromised contractor account can become an entry point into a bank's core infrastructure. A ransomware hit on a third-party HR platform can lock an energy company out of its payroll systems entirely.
"Business continuity planning can no longer sit apart from cyber strategy. Organisations must identify the services they cannot afford to lose, map the people and suppliers that support them, and rehearse recovery under realistic attack conditions." - Harun Baykal, Head of Cybersecurity Practice MEA, NTT DATA
Walid Natour, Director of Security Engineering at Tenable, adds a critical nuance: the problem is not just the volume of vulnerabilities, it is the inability to prioritise them. Standard CVSS scoring flags roughly 60% of discovered vulnerabilities as critical, creating an unmanageable queue for already-stretched security teams. Effective exposure management narrows the focus to the 1.6% of exposures that represent actual, exploitable business risk.
The regulatory accelerant: NCA ECC and UAE DESC
The shift toward resilience-first security is not only being driven by threat intelligence. It is being mandated by regulators. Saudi Arabia's NCA Essential Cybersecurity Controls (ECC) framework sets baseline requirements across 29 domains including asset management, identity and access, event logging, and resilience. The UAE's Digital Security Regulation (DESC) establishes comparable obligations for entities in Dubai, with explicit requirements around business continuity, incident response, and third-party risk management.
Compliance note for GCC security leaders
NCA ECC and UAE DESC both address business continuity and incident response as distinct control domains, not subsets of IT operations. If your resilience programme is owned entirely by the IT function without board-level oversight and documented governance, you may be meeting the technical controls but failing the governance requirements. Regulators are increasingly examining the quality of governance, not just the presence of tools.
AI in cybersecurity: capability and caution
Artificial intelligence features prominently in nearly every vendor's roadmap for cyber resilience, and for good reason. At scale, AI-driven detection can identify anomalous behaviour patterns faster than any human analyst. Automated response can contain a compromised endpoint in seconds rather than minutes. But the honest picture is more nuanced than vendor briefings typically convey.
The false positive problem
Automated response systems carry a risk that is often underplayed in strategic discussions: false positives. An autonomous system that incorrectly identifies a legitimate business process as malicious and shuts it down can cause the very operational disruption it was designed to prevent. In high-stakes environments, such as a hospital's patient management system or a bank's real-time settlement engine, the cost of an erroneous automated shutdown can rival the cost of the attack itself.
Governance requirement: human-in-the-loop for high-stakes actions
AI-driven security tools should be tiered by action severity. Automated containment of a single suspicious endpoint is acceptable. Automated shutdown of a core business system requires human authorisation. Organisations deploying agentic security AI must define these thresholds explicitly and test them in tabletop exercises before relying on them in production environments.
The talent gap
AI tools do not operate themselves. They require skilled engineers to configure detection logic, tune thresholds, interpret outputs, and override incorrect decisions. The GCC faces a meaningful cybersecurity talent shortage, one that vendor-led narratives of autonomous AI security risk obscuring. IBM's 2025 report found that 63% of organisations lacked AI governance policies. The governance infrastructure for AI in security is still maturing, and organisations that move too fast risk compounding their exposure.
A practical framework for GCC organisations
The strategic principles discussed above must translate into concrete action. The framework below is designed to be applicable across a range of organisational sizes and digital maturity levels.
Tier 1 - Foundations (all organisations)
Conduct a business impact analysis to identify which services cannot be interrupted, and document the technology, data, people, and third parties that underpin each one.
Audit and document all identities, human and non-human, with a focus on permissions, lifecycle status, and rotation practices for service accounts and API keys.
Test your backups: not just whether they exist, but whether they can actually restore critical systems within your recovery time objectives under realistic conditions.
Implement multi-factor authentication across all externally exposed systems and administrative interfaces. This single control addresses the credential theft vector that accounts for 16% of initial access incidents.
Establish a third-party risk register and define minimum security requirements for suppliers with access to your systems or data.
Tier 2 - Maturity (organisations with established security functions)
Integrate cyber scenarios into enterprise risk frameworks alongside financial and operational risk, not as a separate IT annex.
Implement continuous control validation: regularly test whether your security controls actually detect and respond to the threats you have planned for.
Develop and rehearse an assume-compromise playbook: define how critical operations will continue if your primary systems are unavailable or untrusted.
Establish a formal exposure management programme that prioritises remediation by actual exploitability and business impact, not CVSS score alone.
Deploy identity threat detection capabilities with a specific focus on lateral movement indicators and anomalous service account behaviour.
Tier 3 - Advanced (large enterprises and critical infrastructure operators)
Develop an OT/IT convergence security strategy with distinct network segmentation, monitoring, and incident response procedures for operational technology environments.
Evaluate agentic AI security tools with a defined governance framework, including human authorisation thresholds for automated actions affecting core business systems.
Begin quantum readiness assessment: inventory cryptographic dependencies and develop a roadmap for post-quantum cryptography migration on a 3 to 5 year horizon.
Establish a board-level reporting cadence tracking downtime reduction, containment speed, blast radius metrics, and continuity of critical workflows.
Board accountability and the metrics that matter
As cyber disruption becomes a business continuity issue, board accountability is rising accordingly. Executives are increasingly being evaluated not just on whether a breach occurred, but on how effectively the organisation maintained operations through it.
- Mean time to contain
How quickly a threat is isolated after detection.
- Blast radius
The scope of systems, data, and operations affected before containment.
- Recovery confidence
The validated ability to restore critical systems to a trusted state.
- Critical workflow continuity
Whether essential business processes remained operational during an incident.
- Third-party incident notification time
How quickly suppliers are required to notify the organisation of incidents affecting shared infrastructure.
Verizon's 2026 Data Breach Investigations Report identifies the human element, including social engineering, phishing, and stolen credentials, alongside software vulnerability exploitation, as among the most frequent breach causes. These are not exotic attack vectors. They are persistent, well-documented, and preventable with consistent application of established controls.
Conclusion: build to absorb, not just to recover
The message from the GCC security community is consistent: the organisations that will navigate the next phase of cyber risk are those designed to absorb disruption, not merely to recover from it. But absorbing disruption requires a foundation: solid recovery capabilities, well-governed identities, tested controls, and supplier relationships with clearly defined security obligations.
AI and agentic orchestration will reshape the threat landscape on both sides of the equation. So will regulatory pressure, as NCA ECC, UAE DESC, and emerging GCC-wide frameworks raise the floor of what is required. But the organisations that thrive will not be those that simply procure the most sophisticated tools or achieve the minimum compliance score.
They will be those that treat resilience as an operational discipline rather than a procurement exercise, where board governance, CISO strategy, practitioner execution, and supplier accountability are aligned around a single question: if our systems were compromised today, which critical operations would continue, which would not, and what have we done to close that gap?
That question does not require a quantum readiness programme to answer. It requires honesty, clarity of ownership, and the operational rigour to test assumptions under realistic conditions, before an attacker does it for you.
Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA RegionOmar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.