19 Nov How hackers think…
…and what UAE businesses must do to protect themselves, according to Danny Jenkins, CEO and co-founder of ThreatLocker®.
As a nation rapidly embracing AI, cloud computing and digitalisation, the UAE is undergoing a significant transformation. But as innovation accelerates, so too do cyber threats, many of which now use artificial intelligence (AI), particularly generative AI. The result? A rise in sophisticated attacks leveraging AI.
According to a Cisco study, 93% of organisations in the UAE faced AI-related incidents in 2024. Similarly, the UAE Cyber Security Council oversaw a growing trend in AI-driven threats at the beginning of 2025.
What was once the domain of highly skilled individuals with deep technical knowledge is no longer the case. Today, with the rise of generative AI tools – such as large language models, AI-powered code generators and synthetic voice systems – almost anyone can launch a sophisticated cyberattack. AI can generate polymorphic code on demand, including scripts capable of evading traditional antivirus detection by not matching known malware signatures.
This dramatically lowers the barrier to entry, expanding the pool of potential attackers – including those with limited technical skills but malicious intent or financial incentive. This shift introduces unprecedented risk, demanding a fundamental change in how UAE organisations defend their systems.
Tapping into hackers’ mindsets
Hackers are not bound by rules; they think opportunistically, scanning for any weak point that offers an easy way in. Attackers take advantage of decentralised IT environments, shadow IT and the assumption of internal trust that still underpins many corporate networks.
For UAE businesses, this means even a single misconfigured setting, untrusted application, or outdated system can become the entry point for a costly breach.
Cybercriminals often aim to exploit the fast-paced adoption of cloud and digital services in the region, seeking gaps in visibility and trust. To remain ahead, UAE businesses must proactively secure their environments. By blocking unknown or unauthorised software and simulating real-world attacks such as penetration testing and red teaming, companies can uncover blind spots before attackers do.
What UAE businesses must do
In this evolving threat environment, traditional detection-based tools – such as antivirus software and behavioural monitoring – are increasingly ineffective. Threats can now be customised in real-time and delivered using legitimate, signed applications or obfuscated payloads.
UAE businesses must adopt a Zero Trust security model. Embracing a Zero Trust framework aligns with the UAE’s National Cybersecurity Strategy and supports compliance with local standards such as the Information Assurance Standards (IAS) and DIFC data regulations. This approach rejects the outdated assumption that anything inside the perimeter is trustworthy. Instead, it is built on the principle of “never trust, always verify”, and mandates that nothing runs or communicates unless it has been explicitly authorised.
Key pillars of a Zero Trust strategy
- Controlling application execution
UAE organisations must restrict which software is allowed to run – not just traditional executables, but also scripts, libraries and portable tools. Only explicitly authorised applications should be permitted, preventing unknown or newly compiled code from executing. Companies should audit or restrict browser extensions due to their elevated permissions.
- Limiting application behaviour
Even trusted applications can be exploited. Their behaviour should be tightly controlled, preventing unnecessary internet access, file access, registry access, or inter-process communication. For example, a PDF reader should not initiate outbound connections or modify system settings.
- Managing administrative privileges
Excessive privileges make lateral movement and persistence easier for attackers. Accounts with administrative rights should be limited, monitored and regularly audited. Dormant accounts must be removed from privileged groups to reduce attack surfaces.
- Network security
Host-level network control is critical. By default, all inbound ports should remain closed for workstations, only opening dynamically for explicitly authorised traffic. Outbound traffic from servers should be tightly regulated, as many breaches rely on outbound communication to Command and Control (C&C) servers.
- Data protection
Organisations must isolate and protect sensitive data, particularly backups. It is also critical to block unauthorised access, modification or exfiltration even from otherwise trusted applications or users. Controls on portable storage should enforce encryption and restrict usage.
- Web content control
Filtering internet access prevents exposure to malicious content and limits shadow IT risks. Blocking categories like advertising networks, unapproved cloud services and unauthorised AI tools reduces exposure to emerging threats.
- Consistent patching
No security model is complete without timely updates. Operating systems, applications and even portable tools like SSH clients must be patched regularly to eliminate known vulnerabilities that could be exploited in an attack.
Beyond prevention: Detection and response
Even the best-prepared environments must assume compromise is possible. That’s why 24/7 monitoring, alert triage and rapid incident response remain critical components of a modern cybersecurity strategy. Whether handled in-house or through a managed detection and response (MDR) provider, UAE companies must act on alerts immediately.
Automated actions – such as disabling administrator tools, isolating systems from the network or revoking access to sensitive data – can contain threats while human analysts investigate. This combination of prevention and real-time response dramatically reduces dwell time and limits the scope of breaches.
The takeaway
The rise of generative AI has permanently changed the threat landscape globally. For a country like the UAE that is committed to digital transformation and innovation, it becomes even more critical to protect themselves from AI-powered attacks. The tools available to attackers are more powerful, accessible and scalable than ever before. Businesses must stop assuming that good intentions or basic antivirus protection will keep them safe.
A Zero Trust strategy, built on strict enforcement of least privilege and application control, offers a proactive defence suited for today’s AI-powered threats. It accepts that human error and software vulnerabilities are inevitable, and builds a layered defence to minimise their impact.
By controlling what runs, what it does, and who can access what, UAE companies can reduce their exposure and shrink the attacker’s opportunity window. In the age of generative AI, that may be the most powerful security tool we have.
Sorry, the comment form is closed at this time.