Human Error, Not AI or Cloud, Is UAE’s Biggest Cyber Blind Spot, Experts Say

Date:

Experts Link Most UAE Cyber Breaches to Poor Access Controls and Weak Recovery Plans.

A recent IBM study in the UAE found that 96 per cent of executives lack a complete understanding of their AI dependencies across vendors, models and infrastructure. At the same time, 74 per cent face challenges navigating data residency and sovereignty requirements when information moves across borders.

“As organizations moved rapidly to the cloud, many prioritized speed and scale, assuming security controls could be layered on later,” said Rajeev Nair, Senior Vice President at Special Projects. “At Core42, we see this reflected in growing demand for regulatory requirements to be translated into technical controls that can be continuously monitored and audited.”

Not knowing where your data lives

As GISEC Global 2026 concludes, cybersecurity leaders across the region are highlighting a fundamental challenge: many breaches are linked not simply to failures in traditional security tools, but to gaps in organisations’ understanding of what data and systems need protection and where that data is stored.

“As AI becomes embedded in core operations, organizations need a clear understanding of where their data resides, who can access and operate their infrastructure, how policies are enforced and what dependencies exist across technology providers,” Nair added.

Three cloud security weaknesses continue to surface across organisations, according to Nair: poorly managed secrets and encryption keys, excessive access privileges and inadequate threat prioritisation.

Another major oversight is the assumption that simply backing up data in the cloud is enough to ensure resilience, according to Fady Richmany, Corporate Vice President and General Manager for Emerging Markets at Commvault.

Richmany said organisations need to look beyond data backups and consider whether they can recover critical systems and operations effectively following a cyber incident.

Global research from Absolute Security found that 57 per cent of enterprises took more than four and a half days on average to recover from a cyberattack, highlighting the potential operational and financial impact of inadequate recovery preparedness.

Cloud adoption and common misconceptions

One of the most persistent misconceptions about cloud computing is that the resilience of a cloud provider automatically ensures the resilience of the organisation using its services, according to Richmany.

Cloud adoption is now widespread across Dubai and Abu Dhabi, but Richmany stressed that cloud providers are primarily responsible for maintaining the availability of their platforms. Organisations remain responsible for ensuring that their own critical systems and information can be recovered following an incident.

“Organisations still need to be able to restore their applications, identities, configurations and data cleanly and quickly,” he added.

Which UAE sectors face the most sophisticated cyberattacks?

The growing sophistication of cyber threats is raising questions about which sectors in the UAE face the greatest exposure and what makes them particularly attractive targets for attackers.

Salah Suleiman, Managing Director for South Gulf at TrendAI, said it would be difficult to identify a single sector as facing the most sophisticated cyber threats.

“I would not put one sector at the top of the list,” he said.

Financial services remain an obvious target because of the financial assets and sensitive information they hold. Healthcare faces similarly serious risks, as cyberattacks can compromise confidential data while also disrupting the availability of essential services, Suleiman said. Logistics and critical infrastructure are also among the sectors facing significant exposure.

He added that the UAE’s increasingly connected digital infrastructure means the consequences of a cyberattack can extend well beyond IT systems, potentially disrupting operations, essential services and public trust.

UAE cybersecurity authorities have reported hundreds of thousands of cyberattacks each day, with a growing proportion of threats becoming AI-enhanced.

“That is why I would look at risk based on potential impact rather than simply the number of attacks a sector receives,” Suleiman said.

“The more connected an organization is to critical services and the wider economy, the more attractive and potentially consequential it becomes to an attacker,” Suleiman added.

Are UAE businesses future-ready?

The cyber threat landscape can evolve rapidly, making it difficult to predict what organisations could face even a year from now. Suleiman stressed that a cybersecurity strategy that is effective today cannot simply remain unchanged and be expected to provide the same level of protection in 2027.

Nair said a future-ready cybersecurity strategy will increasingly need to become part of an organisation’s broader infrastructure strategy, with security, resilience and governance built directly into core business systems and operations.

Richmany, meanwhile, said future-readiness also depends on an organisation’s ability to respond when prevention is not enough. Businesses need to be prepared to recover critical systems and data cleanly and quickly from unexpected cyberattacks, helping minimise disruption and restore operations.

“The more connected an organization is to critical services and the wider economy, the more attractive and potentially consequential it becomes to an attacker,” Suleiman added.

The cyber threat landscape can evolve rapidly, making it difficult to predict what organisations could face even a year from now. Suleiman stressed that a cybersecurity strategy that is effective today cannot simply remain unchanged and be expected to provide the same level of protection in 2027.

Nair said a future-ready cybersecurity strategy will increasingly need to become part of an organisation’s broader infrastructure strategy, with security, resilience and governance built directly into core business systems and operations.

Richmany, meanwhile, said future-readiness also depends on an organisation’s ability to respond when prevention is not enough. Businesses need to be prepared to recover critical systems and data cleanly and quickly from unexpected cyberattacks, helping minimise disruption and restore operations.

“I would point UAE enterprises to four priorities,” Richmany said.

These include making isolated, air-gapped recovery the standard rather than the exception; strengthening identity protection for both human employees and AI agents; defining a “minimum viable business” by identifying which operations can and cannot continue during a disruption; and automating and continuously testing recovery procedures in isolated cleanroom environments.

As attackers increasingly use AI to operate faster and deploy more sophisticated techniques, experts say businesses will need to strengthen their defences at a similar pace.

With the UAE already moving rapidly on digital transformation and cybersecurity, many of the technologies needed to improve resilience are available. The next challenge is ensuring they are adopted effectively and integrated across organisations.

Share post:

Subscribe

spot_imgspot_img

Popular

More like this
Related

IIFA 2027 Tickets Go on Sale as Bollywood Stars Prepare to Descend on Abu Dhabi

Bollywood’s Biggest Stars Return to Yas Island for Two-Day...

Dubai Parks and Resorts to Reopen in October: What to Expect This Season

From Hollywood Coasters to Real Madrid World: Family Fun...

AI Education Programme Reaches 170 Private Schools in Abu Dhabi

ADEK Initiative to Develop AI Skills From Kindergarten to...

70% of UAE Workers Use AI, but Microsoft Says the Bigger Challenge Lies Ahead

Microsoft UAE Says Businesses Are Shifting From AI Adoption...