What attacks on Dubai SMBs actually look like
The cybersecurity marketing a small business sees is written about nation-state actors and zero-day exploits. The incidents we are actually called about are far more mundane, and that is the useful news: mundane attacks are stopped by unglamorous controls that a 30-person company can genuinely afford.
In practice, three patterns account for most of the damage. Someone's password is captured on a convincing sign-in page and the mailbox is quietly taken over — often with a forwarding rule added so the real owner never sees the replies. An invoice in an ongoing email thread is intercepted or imitated, the bank details are changed, and the payment goes to the attacker; by the time the supplier chases it, the money has moved. Or a device gets ransomware, and the question stops being about security and becomes entirely about whether the backups restore.
Note what none of those require: a sophisticated attacker, or any interest in your company specifically. Credential harvesting is automated and indiscriminate, and being small is not cover — it usually just means nobody was watching. Invoice fraud in particular is a routine hazard for trading, contracting and logistics businesses across the region, precisely because they move large payments over email as a matter of course.
The baseline that stops most of it
There is a short list of controls that, taken together, prevent the overwhelming majority of incidents that hit SMBs. It is not a secret list, it is not expensive, and it is roughly what a cyber-insurance questionnaire or a corporate customer's vendor assessment will ask you about. It is easy to believe you have all seven; it is common to have four or five.
- MFA on every account, with no exceptions — especially directors and finance. Enforced through Conditional Access at the identity layer, not switched on per user and quietly disabled for whoever complained.
- Legacy authentication blocked — old protocols bypass MFA entirely. Leaving them open makes the MFA rollout partly decorative.
- EDR on every endpoint — Microsoft Defender for Business or an equivalent — deployed everywhere, tuned, and with the alerts going somewhere a human reads them. An EDR console nobody opens is an expense, not a control.
- Patching on a schedule — operating systems, browsers, third-party applications and firewall firmware. Unpatched perimeter devices are a favourite way in and are frequently years behind.
- Least privilege — nobody works day to day as a local or global administrator, and leavers are disabled the day they leave, not the month they leave.
- Email authentication and impersonation protection — SPF, DKIM and DMARC configured properly so your domain is harder to spoof, plus anti-phishing rules that specifically protect your named executives and finance staff.
- Backups that have been restored — immutable where possible, including the Microsoft 365 tenant, and tested by actually performing a restore rather than by reading a report.
None of this is exotic. The difficulty is not knowing the list — it is that maintaining it is continuous work competing with everything else a small business has to do. That is the actual service we sell.
Identity is the perimeter now
When your email, files and applications live in the cloud, the firewall at your office protects the office — not the business. What protects the business is control over who can sign in, from what, and under what conditions. This is where we spend most of our security effort for Microsoft 365 clients, because it is where most successful attacks now land.
Practically, that means Conditional Access policies rather than per-user settings: block sign-ins from countries you do not operate in, require a compliant and encrypted device for sensitive data, require MFA every time for administrative roles, and challenge sign-ins the platform scores as risky. It also means treating privileged access as a separate category — a few dedicated admin accounts, not used for daily work, with documented break-glass accounts stored securely and deliberately excluded from the policies that could otherwise lock everyone out at once.
One detail routinely missed: when an account is compromised, resetting the password is not enough, because the attacker's active session token can survive it. Sessions must be revoked, MFA methods reviewed for anything the attacker registered, and the mailbox checked for the forwarding rule that is almost always there.
Invoice fraud is a process problem as much as a technical one
Business email compromise deserves its own section because it is the attack most likely to cost a UAE SMB real money, and because technology alone does not close it. The pattern is consistent: an attacker with access to a mailbox — yours or your supplier's — waits for a genuine invoice conversation, then sends a plausible message announcing new bank details, often citing an audit or a change of banking partner. Everything about the thread looks legitimate, because most of it is.
The technical controls help: DMARC makes your domain harder to spoof, external-sender tagging makes lookalike domains more visible, impersonation protection flags messages that mimic your CEO, and monitoring catches suspicious mailbox rules being created. But the control that actually stops the loss is procedural, and it costs nothing.
- Any change to a supplier's bank details is verified by voice, on a phone number already on file — never on a number supplied in the email requesting the change.
- Payments above an agreed threshold need two people, one of whom did not originate the request.
- Urgency and secrecy in a payment request are treated as warning signs rather than as reasons to move faster.
- Finance staff are trained on this specific scenario, not on phishing in the abstract.
We write these rules into a one-page procedure during onboarding. It is the cheapest security control in the entire engagement and, measured against how these losses actually happen, one of the most valuable.
Compliance: what customers and regulators will ask for
Cybersecurity work at UAE SMBs increasingly gets triggered by someone else's requirement — a corporate customer's vendor questionnaire, an insurer's renewal form, a bank's onboarding pack, or a genuine regulatory obligation. It is worth being ready before the request arrives, because these deadlines are rarely generous.
The federal personal data protection law applies broadly to UAE businesses handling personal data, while entities registered in DIFC or ADGM operate under those free zones' own regimes, and organisations in designated critical sectors carry additional national information-assurance obligations. Beyond regulation, ISO 27001 is the certification most commonly demanded commercially — not because the customer has read the standard, but because it is a convenient proxy for "this supplier is organised".
We are engineers rather than legal advisers, and we are careful about that boundary. What we do is build the controls and produce the evidence: documented policies, access reviews, audit logging that is actually retained, an asset and data inventory, and the configuration backing the claims. When a questionnaire asks whether MFA is enforced on all privileged accounts, the useful answer is a screenshot of the policy, not a yes.
ISO 27001 readiness and vCIO support →
When something does happen
Preparation is judged by the first hour. Most organisations lose time in that hour deciding who is allowed to make decisions, which is a question that should have been answered in advance and written down.
Our incident runbooks are drafted before they are needed and cover the unglamorous specifics: who declares an incident, who can authorise disconnecting a system, what must never be wiped before evidence is preserved, who talks to staff and customers, which insurer and authorities need notifying and within what window, and how the business operates while systems are down. For a compromised account the immediate sequence is: revoke sessions, reset credentials, audit MFA methods and mailbox rules, establish what was accessed, then decide about notification — in that order, because the first three stop the bleeding and the rest can be done properly rather than fast.
If you would rather know where you stand before an incident forces the question, our Cyber Posture Assessment is a fixed-scope starting point: AED 7,500, two weeks, and a written report of your exposure with a prioritised remediation plan. It is sold as standalone work, so you can act on it with us or with anyone else.
Cyber Posture Assessment — AED 7,500 →