UAE builds new cyber defences as attacks climb rankings
Tech & AI Future

UAE builds new cyber defences as attacks climb rankings

MDASH rollout puts UAE cyber defence delivery to the test

Microsoft’s Digital Defence Report ranked the UAE sixth internationally as a target of cyber attacks, and the country is now rolling out new defensive capability across government entities to keep pace with threats growing in both volume and sophistication.

The ranking drew on cyber crime activity affecting Microsoft’s customers between January and June of this year. The United States topped the list, followed by Israel, Ukraine, Taiwan, the UK and the UAE. India, Japan, Canada, Germany, Australia and the Philippines completed the top 12.

The findings, a summary of which was provided to The National, carry particular weight for the country’s operational landscape. “The findings carry particular relevance for the UAE as the country continues to scale AI adoption across government and industry,” the summary read. The reference analysis is available at https://www.thenationalnews.com/future/technology/2026/10/02/uae-among-top-12-targets-for-cyber-threats-says-microsoft/

On the delivery side, Microsoft, the UAE Cyber Security Council and Core42 have announced plans to deploy MDASH, Microsoft’s AI-powered cybersecurity capability, across UAE government entities. Microsoft said the continuing collaboration would help to “prioritise risk and respond to emerging threats with greater speed and scale”. The company added that the data collected in its threat analysis would serve an important function in bolstering teamwork between the company and the UAE in fighting hacks, cyber crime and other digital-based nefarious activities.

The ranking also reflects a specific geographic threat pattern. The UAE was the third-most targeted country by hackers connected to Iran, behind the US and Israel, according to the US technology giant. Iran’s self-imposed internet blackout, which lasted until May, caused a slight dip in Tehran-sponsored cyber attacks, but Microsoft warned that those attempts had since resumed. The company pointed out that Iranian cyber actors have the most success with relatively simplistic attack methods. “Iranian state-aligned threat actors continue to rely primarily on exploitation of known vulnerabilities, weak authentication and exposed internet-facing systems for initial access, with credential harvesting and phishing as central enablers,” the report read.

For the operators responsible for defending government and industry systems, the challenge is being framed as one of integration rather than reaction. Yazan Khasawneh, director of cybersecurity at Microsoft in the UAE, highlighted the importance of maintaining cybersecurity amid the rapid expansion of AI use. “The UAE is entering a phase in which AI is becoming part of the operating model of government and business,” Mr Khasawneh said. He added that it was important for cybersecurity to be “designed into the way organisations adopt AI, manage identities, protect data and maintain continuity from the outset”.

Dr Mohamed Al Kuwaiti, the UAE’s cybersecurity chief, said last month that the country was continuing to contend with a barrage of daily online threats, with Iran’s Islamic Revolutionary Guard Corps behind many attacks. AI, he explained, was accelerating the pace of cyber attacks. But Dr Al Kuwaiti said the UAE had harnessed cutting-edge technology to “detect, to defend, to disrupt” hacking attempts.

The operational record to date offers some evidence of that capability in practice. In August, the UAE Cyber Security Council said national teams had detected and contained advanced, organised attacks against the aviation, energy and education sectors before they could disrupt vital systems.

Dr Al Kuwaiti has also framed the country’s ambitions in terms of long-term capability building. During an interview with The National in Washington last year, he said the UAE had long focused on cybersecurity and was committed to becoming a “net exporter of cyber security talent”. “Our main focus is cyber crime, cyber terrorism and cyber warfare,” he added.

With the country’s ranking among the top targets unlikely to shift soon, the gap between threat and response is being managed through a combination of deployed tooling, inter-agency coordination and a stated commitment to building defensive capacity into systems from the start. Whether MDASH and similar deployments can close that gap at the pace the threat environment demands remains the open question for the year ahead.

Q&A

What is MDASH and who is deploying it?

MDASH is Microsoft's AI-powered cybersecurity capability. Microsoft, the UAE Cyber Security Council and Core42 have announced plans to deploy it across UAE government entities to prioritise risk and respond to emerging threats with greater speed and scale.

How highly was the UAE ranked as a target of cyber attacks?

Microsoft's Digital Defence Report ranked the UAE sixth internationally, drawing on cyber crime activity affecting Microsoft's customers between January and June. The US topped the list, followed by Israel, Ukraine, Taiwan, the UK and the UAE.

What role does Iran play in attacks on the UAE?

The UAE was the third-most targeted country by hackers connected to Iran, behind the US and Israel. Iran's internet blackout until May caused a slight dip in Tehran-sponsored attacks, but Microsoft warned those attempts had resumed, with Iranian actors succeeding mainly through known vulnerabilities, weak authentication and exposed internet-facing systems.

What evidence exists that UAE cyber defences work in practice?

In August, the UAE Cyber Security Council said national teams had detected and contained advanced, organised attacks against the aviation, energy and education sectors before they could disrupt vital systems. Dr Mohamed Al Kuwaiti also said the UAE has harnessed cutting-edge technology to detect, defend and disrupt hacking attempts.