SECURITY

Cybersecurity built for UAE SMBs

One breached email account is enough to put a firm's payments, contracts and client data in somebody else's hands. We design, deploy, and run the protection layer most SMBs assume they have but don't — endpoint defence, identity hardening, awareness, and response readiness. Below: what attacks on Dubai SMBs actually look like, the baseline that stops most of them, what UAE regulators and customers will ask you for, and what to do in the first hour when something goes wrong.

What we deliver

EDR & threat hunting

Microsoft Defender or third-party EDR rolled out, tuned, and watched. Real alerts triaged, not a dashboard nobody opens.

MFA enforcement

No exception accounts. Conditional Access at the identity layer, not just "MFA enabled" on individual users.

Phishing simulation

Quarterly campaigns calibrated to your industry. Click-rate trended over time, with targeted training for repeat offenders.

Security awareness training

Short, practical, role-specific. Finance team gets BEC scenarios; engineers get supply-chain content.

Incident response runbooks

Documented before you need them. Who to call, what to isolate, what to preserve, what to disclose.

What attacks on Dubai SMBs actually look like

The cybersecurity marketing a small business sees is written about nation-state actors and zero-day exploits. The incidents we are actually called about are far more mundane, and that is the useful news: mundane attacks are stopped by unglamorous controls that a 30-person company can genuinely afford.

In practice, three patterns account for most of the damage. Someone's password is captured on a convincing sign-in page and the mailbox is quietly taken over — often with a forwarding rule added so the real owner never sees the replies. An invoice in an ongoing email thread is intercepted or imitated, the bank details are changed, and the payment goes to the attacker; by the time the supplier chases it, the money has moved. Or a device gets ransomware, and the question stops being about security and becomes entirely about whether the backups restore.

Note what none of those require: a sophisticated attacker, or any interest in your company specifically. Credential harvesting is automated and indiscriminate, and being small is not cover — it usually just means nobody was watching. Invoice fraud in particular is a routine hazard for trading, contracting and logistics businesses across the region, precisely because they move large payments over email as a matter of course.

The baseline that stops most of it

There is a short list of controls that, taken together, prevent the overwhelming majority of incidents that hit SMBs. It is not a secret list, it is not expensive, and it is roughly what a cyber-insurance questionnaire or a corporate customer's vendor assessment will ask you about. It is easy to believe you have all seven; it is common to have four or five.

  • MFA on every account, with no exceptions — especially directors and finance. Enforced through Conditional Access at the identity layer, not switched on per user and quietly disabled for whoever complained.
  • Legacy authentication blocked — old protocols bypass MFA entirely. Leaving them open makes the MFA rollout partly decorative.
  • EDR on every endpoint — Microsoft Defender for Business or an equivalent — deployed everywhere, tuned, and with the alerts going somewhere a human reads them. An EDR console nobody opens is an expense, not a control.
  • Patching on a schedule — operating systems, browsers, third-party applications and firewall firmware. Unpatched perimeter devices are a favourite way in and are frequently years behind.
  • Least privilege — nobody works day to day as a local or global administrator, and leavers are disabled the day they leave, not the month they leave.
  • Email authentication and impersonation protection — SPF, DKIM and DMARC configured properly so your domain is harder to spoof, plus anti-phishing rules that specifically protect your named executives and finance staff.
  • Backups that have been restored — immutable where possible, including the Microsoft 365 tenant, and tested by actually performing a restore rather than by reading a report.

None of this is exotic. The difficulty is not knowing the list — it is that maintaining it is continuous work competing with everything else a small business has to do. That is the actual service we sell.

Identity is the perimeter now

When your email, files and applications live in the cloud, the firewall at your office protects the office — not the business. What protects the business is control over who can sign in, from what, and under what conditions. This is where we spend most of our security effort for Microsoft 365 clients, because it is where most successful attacks now land.

Practically, that means Conditional Access policies rather than per-user settings: block sign-ins from countries you do not operate in, require a compliant and encrypted device for sensitive data, require MFA every time for administrative roles, and challenge sign-ins the platform scores as risky. It also means treating privileged access as a separate category — a few dedicated admin accounts, not used for daily work, with documented break-glass accounts stored securely and deliberately excluded from the policies that could otherwise lock everyone out at once.

One detail routinely missed: when an account is compromised, resetting the password is not enough, because the attacker's active session token can survive it. Sessions must be revoked, MFA methods reviewed for anything the attacker registered, and the mailbox checked for the forwarding rule that is almost always there.

Invoice fraud is a process problem as much as a technical one

Business email compromise deserves its own section because it is the attack most likely to cost a UAE SMB real money, and because technology alone does not close it. The pattern is consistent: an attacker with access to a mailbox — yours or your supplier's — waits for a genuine invoice conversation, then sends a plausible message announcing new bank details, often citing an audit or a change of banking partner. Everything about the thread looks legitimate, because most of it is.

The technical controls help: DMARC makes your domain harder to spoof, external-sender tagging makes lookalike domains more visible, impersonation protection flags messages that mimic your CEO, and monitoring catches suspicious mailbox rules being created. But the control that actually stops the loss is procedural, and it costs nothing.

  • Any change to a supplier's bank details is verified by voice, on a phone number already on file — never on a number supplied in the email requesting the change.
  • Payments above an agreed threshold need two people, one of whom did not originate the request.
  • Urgency and secrecy in a payment request are treated as warning signs rather than as reasons to move faster.
  • Finance staff are trained on this specific scenario, not on phishing in the abstract.

We write these rules into a one-page procedure during onboarding. It is the cheapest security control in the entire engagement and, measured against how these losses actually happen, one of the most valuable.

Compliance: what customers and regulators will ask for

Cybersecurity work at UAE SMBs increasingly gets triggered by someone else's requirement — a corporate customer's vendor questionnaire, an insurer's renewal form, a bank's onboarding pack, or a genuine regulatory obligation. It is worth being ready before the request arrives, because these deadlines are rarely generous.

The federal personal data protection law applies broadly to UAE businesses handling personal data, while entities registered in DIFC or ADGM operate under those free zones' own regimes, and organisations in designated critical sectors carry additional national information-assurance obligations. Beyond regulation, ISO 27001 is the certification most commonly demanded commercially — not because the customer has read the standard, but because it is a convenient proxy for "this supplier is organised".

We are engineers rather than legal advisers, and we are careful about that boundary. What we do is build the controls and produce the evidence: documented policies, access reviews, audit logging that is actually retained, an asset and data inventory, and the configuration backing the claims. When a questionnaire asks whether MFA is enforced on all privileged accounts, the useful answer is a screenshot of the policy, not a yes.

When something does happen

Preparation is judged by the first hour. Most organisations lose time in that hour deciding who is allowed to make decisions, which is a question that should have been answered in advance and written down.

Our incident runbooks are drafted before they are needed and cover the unglamorous specifics: who declares an incident, who can authorise disconnecting a system, what must never be wiped before evidence is preserved, who talks to staff and customers, which insurer and authorities need notifying and within what window, and how the business operates while systems are down. For a compromised account the immediate sequence is: revoke sessions, reset credentials, audit MFA methods and mailbox rules, establish what was accessed, then decide about notification — in that order, because the first three stop the bleeding and the rest can be done properly rather than fast.

If you would rather know where you stand before an incident forces the question, our Cyber Posture Assessment is a fixed-scope starting point: AED 7,500, two weeks, and a written report of your exposure with a prioritised remediation plan. It is sold as standalone work, so you can act on it with us or with anyone else.

Typical engagements

Frequently asked questions

We are a small company — are we really a target?

You are not usually targeted; you are scanned. Credential-harvesting pages, password spraying and malicious attachments are sent indiscriminately by automation that has no idea how large you are. The practical difference between a small business and a large one is not attacker interest, it is that larger organisations have someone whose job is to notice. Small size makes you a softer landing, not an uninteresting one.

Isn't Microsoft 365 secure by default?

It is capable of being very secure, which is not the same thing. The defaults are chosen so that setup succeeds for the widest possible range of customers, which means permissive sharing, per-user MFA rather than enforced policy, legacy protocols often still reachable, and anti-phishing rules not tuned to your named executives. Business Premium includes most of the tooling you need — the gap is almost always configuration and maintenance rather than licensing.

Where should a Dubai SMB start with cybersecurity?

With an honest picture of what you have, then with the baseline: universal MFA, EDR on every endpoint, patching on a schedule, and a backup somebody has actually restored. Those four close most of the realistic risk. Our Cyber Posture Assessment exists for the first step — AED 7,500, two weeks, and a written report with a prioritised plan — and it is deliberately a standalone engagement rather than a sales call with a document attached.

Do we need ISO 27001?

Only if something requires it — most commonly a corporate customer, a tender, or an investor. It is a management system certification, not a security product, and it demonstrates that you run security as a repeatable process. Plenty of well-secured SMBs never certify, and some certified organisations are still poorly defended. If a contract depends on it, the readiness work is well understood and we support it; if nothing does, spend the money on controls first.

What should we do in the first hour of a suspected account compromise?

Revoke the account's active sessions — not just reset the password, because a stolen session token can survive a password change. Then review the MFA methods registered on the account and remove anything the attacker added, check the mailbox for forwarding and hiding rules, and preserve logs before anyone wipes or rebuilds a device. Only then work out what was accessed. If any payment instruction passed through that mailbox, contact your bank and the counterparty by phone immediately.

Does security awareness training actually work?

It works when it is specific, short and repeated, and it fails when it is an annual compliance exercise. What moves the numbers is realistic phishing simulation with immediate, non-punitive feedback and role-relevant content — finance staff drilled on invoice and bank-detail fraud, operations staff on credential-harvesting pages. Trend the click rate rather than chasing a single figure; the direction over a year is the meaningful measure, and repeat clickers need targeted follow-up rather than another company-wide email.

Microsoft Defender for Business · Senior incident response on call
Free IT Health Check →