Awareness and cooperation key to warding off cyberattacks

Awareness and cooperation key to warding off cyberattacks during the upcoming shopping season, by Duane Nicol, Senior Product……
mime

Share this article:

Awareness and cooperation key to warding off cyberattacks during the upcoming shopping season, by Duane Nicol, Senior Product Manager for Awareness Training at Mimecast

Following years of pandemic-induced economic pressure, economies across the Middle East are eyeing a welcome return to normal. With White Friday and the end-of-year Dubai Shopping Festival on the horizon, as well as a hotly anticipated FIFA World Cup in Qatar having kicked off, the region is set to be a hub of activity and tourism over the coming months.

The region’s retail sector is also powering ahead: the UAE’s e-commerce market alone is expected to reach $8-billion by 2025, with the retail mobile-commerce market projected to grow at 19% CAGR. McKinsey data found that the number of people in the UAE and Saudi Arabia shopping online on a weekly basis has doubled in two years.

This has not escaped the notice of cybercriminals, who are almost certain to attempt to spoil the party for Middle East consumers. In fact, attacks are projected to become more prolific in the weeks and months ahead as cybercriminals prey on shoppers with a range of attack methods.

In Mimecast’s latest State of Ransomware Readiness 2 report, 59% of cybersecurity leaders in the UAE reported that the volume of cyberattacks have held firm or even increased over the past year. The State of Email Security 2022 report also found that 90% of organisations in Saudi Arabia have been the target of an email-related phishing attempt in the past year.

Cybercriminals refine, enhance attack methods

The increase in cyber threats is in part being driven by greater digitisation of various aspects of our personal and professional lives, creating valuable sources of information for threat actors as well as potential areas of weakness to exploit.

When the first lockdowns were implemented in early-2020, many office workers were forced to work remotely, a situation that has continued despite lockdown restrictions lifting. While this has undeniable benefits to workers, it has created a security nightmare for many organisations.

With employees working outside the confines of corporate security structures and often under immense pressure, cybercriminals have capitalised by aggressively exploiting the vulnerabilities that come with remote work.

Cybercriminals are also becoming increasingly adept at social engineering at scale. To illustrate, instead of targeting a person with a phishing attack, they seek to understand what their target’s persona represents – for example, a young male that enjoys outdoor sports and activities – and then purchase a mailing list with those interests. This allows them to craft more attractive phishing mails that have a far higher chance at success.

The amount of publicly-available personal information on social media is also giving threat actors valuable data to use in the crafting of their attacks. An attacker could type the name of a potential target on Google, which may bring up their Facebook profile and, in the case of outdoor enthusiasts, their Strava profile. From this they can see the types of activities they engage in, where they train, how often, and more.

From here it’s a simple matter of constructing a mailer with the right offer. For example, if the target is an avid cyclist, the attacker could develop a mailer that offers a substantial discount on a bike of the same brand that the person has put on their Facebook profile. This can increase the hit rate of their attacks from around 2% (for untargeted attacks) to as much as 20%.

In another example, a cybercriminal could infiltrate the mail server of a private school and send parents personalised emails asking for a meeting regarding their child. In a cruel twist, the cybercriminal may attach a malicious file and tell parents that it relates to the discussion they’d like to have about their child’s performance at the school.

Such an attack would likely seem so legitimate and convincing that most parents would open the attachment without a second’s hesitation. This may leave them exposed to further infiltration and potential financial losses as the cybercriminal uses their new-found access to infiltrate the victim’s banking profiles.

Knowledge, awareness the greatest weapon against cyberattacks

In light of such high levels of danger, what can be done to safeguard Middle Eastern organisations and citizens from cybercrime?

The first step is to build greater cyber resilience at a national, provincial and local level by investing in appropriate cybersecurity and continuity solutions. A multi-layered cyber resilience strategy that protects people from cyber threats is vital in the fight against cybercrime.

The Dubai Cyber Security Strategy, introduced in 2017, plays a vital role in strengthening cyber resilience in the UAE. The recently-launched CyberIC program in Saudi Arabia will develop the domestic cybersecurity sector with the aim of developing more than 10 000 skilled cybersecurity professionals over the next few years, boosting regional cyber defences.

Secondly, it is critical that information about likely attack methods and cyber risks reach every citizen. Everyone needs to join forces, from big business to government departments and even celebrities, to help raise the general level of cyber awareness among the broader population.

Businesses could contribute by sponsoring programmes and internships for cybercrime skills development, which has the dual benefit of improving the region’s defences against cyberattacks as well as improving the region’s global competitiveness at a time when the global cyber skills shortage is intensifying.

Universities can host regular guest lectures and information sessions by cybersecurity specialists to teach students about cyber safety and prepare them for the risks they’ll face.

Organisations in the private and public sectors should continuously train employees to become more cyber aware. Government departments can apply some of the learnings from the pandemic and roll out ongoing national cyber awareness campaigns that teach citizens about basic cyber safety.

Finally, a culture of community defence should be established that encourages victims of cybercrime to report cyberattacks. This can drive greater awareness of emerging cyber risks while also giving authorities valuable information about new attack methods that may aid their quest to bring perpetrators of cybercrime to justice.

To read other news stories and exclusives, see our latest issue here.

Never miss a story… Follow us on:
LinkedIn Security Buyer
Twitter logo @SecurityBuyer
Facebook @Secbuyer

Media Contact
Rebecca Morpeth Spayne,
Editor, Security Portfolio
Tel: +44 (0) 1622 823 922
Email: [email protected]

About Security Buyer

Security Buyer is the leading authority in global security content, delivering expert news, in-depth articles, exclusive interviews, and industry insights across print, digital, and event platforms. Published 10 times a year, the magazine is a trusted resource for professionals seeking updates and analysis on the latest developments in the security sector.

To submit an article, or for sponsorship opportunities, please contact our team below.

Rebecca Spayne Picture

Rebecca Spayne

Group Managing Editor

Georgina Turner Picture

Georgina Turner

Sales Manager

Afua Akoto Picture

Afua Akoto

Marketing Manager

Related News

PaxLock Pro2 - securitybuyer.com

Paxton officially launches PaxLock Pro2

Paxton the security technology manufacturer has launched a brand-new re-engineered PaxLock which is built to protect straight
KentixONE data centre - securitybuyer.com

Data centre security with KentixONE

Prior1 develops container data centers to meet the highest security and energy efficiency standards. Their containers require
Chubbsafes - securitybuyer.com

Chubbsafes explores certified storage for jewellery and precious metals

Chubbsafes, part of Gunnebo Safe Storage, has launched a new technical discussion guide examining when certified
Mercury trends report - securitybuyer.com

New Mercury Research Finds Growing Cybersecurity Gap

2026 Trends in Access Controllers Report finds interoperability, cloud connectivity and AI are reshaping long-term controller strategies.
Chris Carroll - securitybuyer.com

Comelit-PAC Promotes Chris Carroll as Sales Director

Comelit-PAC has appointed Chris Carroll as Sales Director, following an 18 year career with the company, seeing him progress
Jason Bezuidenhout - securitybuyer.com

Zygal Appoints Jason Bezuidenhout

Zygal has appointed Jason Bezuidenhout as Chief Revenue Officer (CRO), strengthening its leadership team as the company continues
Eun-Kyung-Hong_- securitybuyer.com

How AI Manages Mixed Surveillance Workloads

Eun-Kyung Hong, HDD Product Manager at Toshiba Electronics Europe GmbH discusses AI optimisation in mixed surveillance workloads
ASSA ABLOY - securitybuyer.com

ASSA ABLOY Door Group highlights importance of BS 8214:2026

ASSA ABLOY Door Group is supporting Fire Door Safety Week 2026 by raising awareness of the latest update to BS 8214:2026
OPTEX at Essen - securitybuyer.com

OPTEX to showcase perimeter solutions at Security Essen

OPTEX will present its latest perimeter and asset protection solutions at Security Essen 2026, one of Europe’s leading security trade fairs.
Dallmeier

Building Trust in Modern Video Security

Rebecca Spayne, Managing Editor of Security Buyer, speaks with Josua Braun, Chief Revenue Officer at Dallmeier electronic, about cyber resilience, trusted supply chains, the practical value of artificial intelligence and what security professionals should consider when investing in modern video technology. 
Scroll to Top