← Back to Blog

GISEC Global, the region's largest cybersecurity event, opened yesterday at Dubai Exhibition Centre in Expo City and runs until tomorrow. It is hosted by the UAE Cyber Security Council, with more than 750 cyber brands and visitors from over 180 countries, according to the organisers. On day one, Dubai Electronic Security Center launched SARAAB, an open-source AI model that detects deepfake videos, built by an Emirati team and described as the first of its kind developed by a government entity in the Arab region. A DESC official told Khaleej Times it is expected on Hugging Face by the end of 2026, with 91 percent detection accuracy.

Deepfakes get the headlines, and they deserve them. A convincing video of a CEO asking finance to move money was expensive two years ago. Now it is not. But for most UAE businesses, the attack that actually lands is older and duller: a stolen password, an outdated plugin, a fake website that looks exactly like yours. This is the checklist we use when we take over a client's website, with the UAE numbers and rules behind each item.

What the UAE's own numbers say

Read together, those figures describe the real threat to a business website: attackers do not need to break anything clever. They need one reused password, one setting left open, or one convincing copy of your brand.

1. Lock the accounts, not just the website

The website is rarely the first thing attacked. The accounts around it are. A hacker with your domain registrar login can point your domain anywhere. One with your hosting or email login does not need to touch the site at all.

2. Treat plugins and packages as the attack surface they are

The OWASP Top 10, the most widely used list of web application risks, added a new category in its 2025 edition: Software Supply Chain Failures, now ranked third. Security Misconfiguration moved to second, behind Broken Access Control. For a typical business website, that is a precise description of the risk: third-party plugins, themes and scripts that nobody updates, and settings nobody checked.

This is also the honest trade-off between platforms. A WordPress site with forty plugins needs maintenance as a service. A custom-coded site has fewer moving parts but needs a developer for changes. We compared both in WordPress or custom-coded.

3. Close the settings attackers look for first

4. Make impersonation harder, and easier to disprove

Deepfakes and fake websites work because customers cannot easily tell what is real. Your website should be the place that settles it.

5. Know within hours if something goes wrong

Google tells site owners when it detects a problem. Search Console's Security issues report flags hacked content, malware and social engineering, and Google says affected pages can show a warning label in search results or a full warning page in the browser. After you fix it, the review can take several days or weeks. For a business that depends on search, that is weeks of customers being told your site is dangerous.

6. Have the breach plan written before you need it

If customer data is exposed, the law sets the first step. Article 9 of the UAE's Personal Data Protection Law requires a business to report a personal data breach to the regulator as soon as it becomes aware of it, with the detailed deadlines left to executive regulations. Businesses in DIFC and ADGM follow their own data protection laws instead. Either way, the plan should name who decides, who contacts the host and developer, who talks to customers, and where the backups are.

If you supply Dubai government, the bar is higher. DESC's Information Security Regulation applies to all Dubai Government entities, explicitly including their contractors, and DESC used GISEC to launch an auditor certification programme for it. Expect the security of a supplier's website and systems to be part of the conversation. We covered the related AI procurement rules in our piece on Dubai's agentic AI training, and the wider legal picture in what actually applies to your business.

What we would do this week

None of this needs a security operations centre. It needs someone to own it. Keeping client websites updated, monitored and backed up is part of our WordPress care and custom website work. If you are not sure who holds the keys to your domain, hosting and site today, send us the website and we will tell you what to lock first.