Cybersecurity · 8 min readBy Youssef Samy

Protecting a UAE Business from Cyber Attacks: Start Where the Money Leaves

UAE businesses arrive at this subject by one of two routes: a supplier invoice paid into an account that was never the supplier's, or a morning when the files will not open on any machine in the office. The two need completely different fixes, and they have one thing in common, which is that nobody in the company knew the door was open. What follows is the order we usually set out in a first meeting: which cyber attacks actually reach a company of this size, which of them takes money straight out of the account, and where to start when the whole list will not fit in one quarter.

A backlit laptop keyboard glowing blue in a dark room, with the open screen out of focus above it.
Philipp Katzenberger / Unsplash
01

The attack that takes the money is not a virus

A fake invoice arrives from an address that looks like your supplier's. It refers to a real order, quotes a real amount, and carries one change: new bank details, with a line explaining that the old account is being audited. The accounts team pays it. Nothing was infected, no alarm went off anywhere, and the money is gone before the real supplier calls to ask about the payment. This is business email compromise, and it is the attack that empties an account rather than the one that locks a laptop.

It defeats antivirus because there is nothing for antivirus to find. No attachment, no link, no malware: a person was persuaded by a convincing document. Often the criminal has read months of the supplier's real correspondence first, because it was the supplier's mailbox that was broken into, not yours. That is why the email matches the order, the tone and the timing so precisely.

What stops it is not another scanner. It is a written rule that a change of bank details is never accepted by email, and is confirmed by calling a number you already had on file rather than one printed on the new invoice. The rule costs nothing and outlives every tool you replace. And if a supplier sends new bank details and presses for speed, that is the moment to pick up the phone, not the moment to pay.

  1. 01A mailbox is broken intoUsually the supplier's, not yours. The criminal reads real orders and learns the tone.
  2. 02An invoice arrives on timeReal order, real amount, the right names, sent in the week one was expected.
  3. 03Only the bank details changedWith a reason attached: an audit, a new branch, a frozen account.
  4. 04Accounts pays itNothing looked wrong, because nothing was wrong except one field.
  5. 05The real supplier callsWeeks later, asking about an invoice you already paid to somebody else.
How a fake invoice becomes a real payment.
02

Ransomware does not decide the outcome, your restore does

Ransomware encrypts your files and asks to be paid to unlock them. Everything written about preventing it is worth doing, and none of it changes the one fact that decides how the week ends: whether you can restore. A company that restores has a bad two days. A company that cannot restore is negotiating with criminals for its own files.

The trap is that nearly every business already has backups, and having backups is not the same as being able to restore from them. The backup report lands every morning in a mailbox nobody opens, so a job that has been failing for months still sits in the list looking like it ran. A backup drive left permanently connected to the server is encrypted along with the server. A backup nobody has ever restored from is a hope rather than a plan. The old habit of keeping three copies, on two kinds of storage, with one of them off the site, exists because each of those three failures happens on its own.

So the question is not whether you have backups. It is when somebody last restored a real file from them, and how long it took. If nobody can answer that with a date, the honest answer is that you do not know what you have.

03

A firewall guards a door these attacks do not use

A firewall sits at the edge of your network and decides what crosses it, and it earns its place in every office. It does not open the invoice in an employee's inbox to see whether the supplier really sent it. It does not know that whoever signed in with the correct password is not the person the password belongs to. Both attacks above walk through the front door holding a valid ticket.

This is why asking which firewall is best for a small business is the wrong first question, even though it is the one most often asked. The right first question is who can sign in to your company email, and with what. An attacker holding a stolen password and meeting nothing in the way needs no exploit and no malware; they simply log in. Multi-factor authentication closes that path. It is already sitting in Microsoft 365 and Google Workspace waiting to be switched on, it takes hours rather than a project, and it only works if you apply it to every account rather than the owner's alone.

The firewall's real job starts after that: separating the network so a compromised laptop cannot reach the server, the cameras and the accounting PC as though they were all one room. That is a networking decision as much as a security one, and it is far cheaper to make while the office is being cabled than afterwards.

04

The order to close them, cheapest and most effective first

Nobody does the whole list at once. Taken in this order, each step removes more risk, and costs less effort, than the one that follows it, which is the only sequence a busy company ever finishes.

Notice what is not at the top: no purchase. The first three steps are a setting, a rule and a test. Buying tools first is how a company ends up paying every month for a product that guards a door nobody was using.

  1. 01Turn on multi-factor authenticationEvery account, not the owner's alone. A stolen password stops being enough by itself.
  2. 02Write the bank-details ruleNever accepted by email. Confirmed by phone, on a number already on file.
  3. 03Restore something todayPick a real file, restore it, time it. Now you know what you actually have.
  4. 04Protect the machinesEndpoint protection on every laptop and server, monitored rather than installed and forgotten.
  5. 05Filter the mail, then teach the teamThe filter removes most of it. People catch what no filter can judge.
  6. 06Separate the networkA compromised laptop should not be able to reach the server and the cameras.
The order that actually gets finished.
05

What the UAE data protection law expects of you

Every business holds personal data: staff files, customer contacts, copies of passports and visas. The UAE's federal personal data protection law, Federal Decree-Law No. 45 of 2021, governs how that data is handled, requires it to be protected with appropriate measures, and requires a breach to be reported to the regulator. What applies to you in detail depends on your activity, and the place to read it is the current official text rather than an article that will outlive the detail.

The practical point is that this does not add a separate project. The steps above are the same ones a regulator expects to see: access limited to the people who need it, a record of what you hold, backups you can restore from, and the ability to say what happened if something goes wrong. A company that can restore a file and name everyone holding administrator access is most of the way there. A company that can do neither has a compliance problem it will discover at the worst possible moment.

06

Where to start this week

Three checks, none of which needs a purchase or a consultant. First, write down everyone who can sign in to company email and confirm multi-factor authentication is on for each of them, including the accounts that belong to nobody in particular: the enquiries mailbox, the accounts mailbox, the shared inbox no single person owns. Second, ask whoever handles payments what they would do if a supplier emailed new bank details today, and write the answer down as a rule if there is not one already. Third, pick a file that matters, restore it from your backup, and note how long it took.

What those three turn up is your real security position, and it is usually not the one described on the invoice from your IT provider. If you would rather somebody went through it with you, that is what a cyber security assessment is: what is protecting you today, what is not, and the order to fix it in, written down so you can hand it to whoever does the work.

Frequently asked

Phishing casts wide: a generic email tries to get a password or a click out of anybody who falls for it. Business email compromise is aimed at your company specifically, usually after somebody has read the real correspondence between you and a supplier. There is often no link and no attachment for a filter to catch, only a correct-looking invoice with one changed field, which is why it passes filters that stop ordinary phishing.
No, and not because it is a weak firewall. Buy one, but do not start with it. Its job is to decide what crosses the edge of your network, and that is exactly why a stolen password and a convincing invoice sail past it: neither of them looks like unusual traffic. Put the money into the settings and the rules first, and buy the better box the day the network is big enough to need dividing.
Restore from it, and make the test harder than it looks in two ways. Restore onto a different machine instead of over the original, because a restore that only works back onto the server it came from will fail on the day that server is the problem. And restore something a month old rather than yesterday's file, because the common surprise is not a broken backup but a retention window far shorter than anyone in the office assumed.
It is worth pricing, and worth knowing that insurers ask what protections you already have before they quote, and may ask again when you claim. The questions usually cover multi-factor authentication, tested backups and managed endpoint protection. That is the practical order: the three answers have to be true before the policy is worth buying, so do them first and price the cover second.
Turn on multi-factor authentication for every mailbox, and expect three awkward cases rather than a clean sweep: the shared mailbox nobody owns, the account still tied to an old app that cannot prompt for a second step, and the colleague who finds the whole thing irritating. Give the shared mailbox an owner, replace or update the old app, and do the irritated colleague's account first rather than last. A rollout that leaves those three for later leaves the door open at exactly the accounts an attacker goes looking for.
It is worked out from your setup rather than read off a list, and four things move the number more than anything else: how many people and devices are covered, how many sites you run, how much data has to be backed up and how far back you need to be able to go, and whether the equipment you already own is worth keeping. An assessment is what settles those four, because a quote given before anyone has looked at your network is a guess. Worth knowing before you ask: the first two steps in the order above cost nothing at all, so what you are really pricing is the part that has to be watched rather than switched on once.
If money has left, call the bank before anything else, because a transfer is easiest to stop before it is drawn down, and then tell the supplier whose invoice was used. Change the password on the mailbox involved, sign every session out of it, and check its rules for a forward nobody in your office set up, which is how the criminal keeps reading after you lock the door. If files are encrypting instead, unplug that machine from the network but leave it switched on, because powering it off destroys what an investigator can still read, and stop any backup that is about to overwrite a good copy with an encrypted one. Then report it: in the UAE this is a crime under the cybercrime law, and a police report is also the first thing an insurer asks for.

All blogs