Skip to main content
BilgeQor
Back to industries

CTO, VP Engineering

Logistics, Travel & Hospitality

Digital surfaces

Booking Engines
Fleet Dashboards
Customer Apps

Threat themes

  • API Scraping
  • Payment Fraud
  • Service Disruption

Verified cybersecurity exposure and threat context · United Arab Emirates / UAE Cyber Security Council

UAE cybersecurity exposure, incident categories and DDoS trend — State of the UAE Cybersecurity Report 2025

Market context — not industry-specific evidence

The State of the UAE Cybersecurity Report 2025, released by UAE Cyber Security Council and CPX, states that over 223,800 assets hosted within the UAE are potentially exposed to cyber-attacks, and that half of the critical vulnerabilities in the report context remain unaddressed for over five years. Within the incident category context in the report, misconfiguration accounts for 32% and improper usage and unlawful activity for 19%. Ransomware groups operating in the UAE witnessed 58% growth in the report context. DDoS attacks in the report context decreased from 58,538 in H1 2023 to 2,301 in H1 2024. These figures are UAE Cyber Security Council / CPX 2025 report-defined context; they are not total UAE business incident prevalence, not a national incident registry, and not industry-specific evidence.

UAE · UAE Cyber Security Council / CPX 2025 report-defined exposure, vulnerability-age, incident-category, ransomware-group activity and DDoS trend contextCalendar year 2024 · H1 2023–H1 2024 comparative · Report published February 2025

Assets hosted within the UAE potentially exposed to cyber-attacks

Assets potentially exposed (report states "over 223,800")
223,800
Unit
assets hosted within the UAE assessed as potentially exposed to cyber-attacks (report states "over 223,800")
Period
UAE Cyber Security Council / CPX 2025 report-defined exposure, vulnerability-age, incident-category, ransomware-group activity and DDoS trend context for calendar year 2024 and H1 2023–H1 2024 comparative period.
Scope
UAE Cyber Security Council / CPX 2025 report-defined exposure and threat context

The State of the UAE Cybersecurity Report 2025 states that over 223,800 assets hosted within the UAE are potentially exposed to cyber-attacks.

UAE Cyber Security Council / CPX 2025 report-defined exposure context. "Over 223,800 assets" refers to assets hosted within the UAE assessed as potentially exposed — not confirmed compromised assets, breached organisations, or active incidents. Not total UAE business incident prevalence and not industry-specific evidence.

Critical vulnerabilities unaddressed for over five years

Share of critical vulnerabilities in report context unaddressed for over five years
50%
Unit
percent of critical vulnerabilities in the report context unaddressed for over five years
Period
UAE Cyber Security Council / CPX 2025 report-defined exposure, vulnerability-age, incident-category, ransomware-group activity and DDoS trend context for calendar year 2024 and H1 2023–H1 2024 comparative period.
Scope
UAE Cyber Security Council / CPX 2025 report-defined exposure and threat context

The State of the UAE Cybersecurity Report 2025 states that half of the critical vulnerabilities in the report context remain unaddressed for over five years.

This refers to critical vulnerabilities described within the report context only, not all vulnerabilities in all UAE systems. Not total UAE business incident prevalence and not industry-specific evidence.

Selected incident categories — UAE Cyber Security Council / CPX 2025 report context

Misconfiguration — 32%
32%
Unit
percent of cyber incidents in the report context categorised as misconfiguration
Period
UAE Cyber Security Council / CPX 2025 report-defined exposure, vulnerability-age, incident-category, ransomware-group activity and DDoS trend context for calendar year 2024 and H1 2023–H1 2024 comparative period.
Scope
UAE Cyber Security Council / CPX 2025 report-defined exposure and threat context
Improper usage and unlawful activity — 19%
19%
Unit
percent of cyber incidents in the report context categorised as improper usage and unlawful activity
Period
UAE Cyber Security Council / CPX 2025 report-defined exposure, vulnerability-age, incident-category, ransomware-group activity and DDoS trend context for calendar year 2024 and H1 2023–H1 2024 comparative period.
Scope
UAE Cyber Security Council / CPX 2025 report-defined exposure and threat context

Report-defined incident category shares within the UAE Cyber Security Council / CPX 2025 report context. These are not all-UAE incident prevalence rates, all-business incident prevalence rates, or industry-specific evidence for the sector shown on this page.

Ransomware group activity growth — UAE 2025 report context

Growth in ransomware groups operating in the UAE (report context)
58%
Unit
percent growth in ransomware groups operating in the UAE witnessed in the report context
Period
UAE Cyber Security Council / CPX 2025 report-defined exposure, vulnerability-age, incident-category, ransomware-group activity and DDoS trend context for calendar year 2024 and H1 2023–H1 2024 comparative period.
Scope
UAE Cyber Security Council / CPX 2025 report-defined exposure and threat context

The State of the UAE Cybersecurity Report 2025 states that ransomware groups operating in the UAE witnessed 58% growth in the report context.

58% growth in ransomware groups operating in the UAE as stated in the report context. Not a UAE-business breach rate, not an incident prevalence rate, and not industry-specific evidence.

DDoS attacks — H1 2023 versus H1 2024 (UAE report context)

H1 2023
58,538
Unit
DDoS attacks recorded in H1 2023 in the report context
Period
UAE Cyber Security Council / CPX 2025 report-defined exposure, vulnerability-age, incident-category, ransomware-group activity and DDoS trend context for calendar year 2024 and H1 2023–H1 2024 comparative period.
Scope
UAE Cyber Security Council / CPX 2025 report-defined exposure and threat context
H1 2024
2,301
Unit
DDoS attacks recorded in H1 2024 in the report context
Period
UAE Cyber Security Council / CPX 2025 report-defined exposure, vulnerability-age, incident-category, ransomware-group activity and DDoS trend context for calendar year 2024 and H1 2023–H1 2024 comparative period.
Scope
UAE Cyber Security Council / CPX 2025 report-defined exposure and threat context

DDoS attack figures compare H1 2023 (58,538) with H1 2024 (2,301) in the report context. This decrease must not be presented as proof that UAE-wide cyber risk decreased overall. Not total UAE business incident prevalence and not industry-specific evidence.

Source: UAE Cyber Security Council / CPX, State of the UAE Cybersecurity Report 2025, 25 February 2025

Scope: UAE Cyber Security Council / CPX, State of the UAE Cybersecurity Report 2025, announced by Emirates News Agency / WAM, 25 February 2025. The "over 223,800 assets" figure describes assets hosted within the UAE assessed as potentially exposed — not confirmed compromised assets, breached organisations, or active incidents. The 50% critical-vulnerability figure refers to critical vulnerabilities in the report context only, not all vulnerabilities in all UAE systems. The 32% misconfiguration and 19% improper usage and unlawful activity figures are report-defined incident category shares and do not measure all-UAE incident prevalence or all-business incident prevalence. The 58% ransomware group growth describes the growth in groups operating in the UAE as stated in the report and is not a UAE-business breach rate. The DDoS comparison (H1 2023: 58,538; H1 2024: 2,301) is drawn from the report context; the decrease must not be presented as proof that UAE-wide cyber risk decreased overall. These figures do not measure total UAE business incident prevalence, hidden incident prevalence, population-wide victimisation rates, industry-specific evidence, compliance achievement, certification or security outcomes. Treat as UAE official/authoritative cybersecurity report context; not an independent government incident registry or complete national incident census.

Methodology: Official UAE Cyber Security Council and CPX joint report context announced by Emirates News Agency / WAM on 25 February 2025. The admitted indicators describe UAE report-defined exposure, vulnerability age, incident categories, ransomware-group activity and DDoS trend context. The "over 223,800 assets" figure refers to assets hosted within the UAE assessed as potentially exposed — not confirmed compromised assets, breached organisations, or active incidents. The 50% critical-vulnerability figure applies to critical vulnerabilities described in the report context only, not all vulnerabilities in all UAE systems. The 32% misconfiguration and 19% improper usage and unlawful activity figures are report-defined incident category shares and must not be presented as all-UAE incident prevalence or all-business incident prevalence. The 58% ransomware group growth is a report-stated growth figure for groups operating in the UAE and must not be presented as a UAE-business breach rate or incident prevalence rate. The DDoS figures compare H1 2023 (58,538) with H1 2024 (2,301) in the report context; the decrease must not be presented as proof that UAE-wide cyber risk decreased overall. Treat as UAE official/authoritative cybersecurity report context; do not present as an independent government incident registry or a complete national incident census.

Accessible data table
Verified UAE Cyber Security Council / CPX 2025 cybersecurity exposure and threat context data from UAE Cyber Security Council / CPX, State of the UAE Cybersecurity Report 2025, 25 February 2025, reporting period UAE Cyber Security Council / CPX 2025 report-defined exposure, vulnerability-age, incident-category, ransomware-group activity and DDoS trend context for calendar year 2024 and H1 2023–H1 2024 comparative period..
MetricValueSourceScopeReporting period
Assets potentially exposed (report states "over 223,800")223,800 assets hosted within the UAE assessed as potentially exposed to cyber-attacks (report states "over 223,800")UAE Cyber Security Council / CPX, State of the UAE Cybersecurity Report 2025, 25 February 2025UAE Cyber Security Council / CPX 2025 report-defined exposure and threat contextUAE Cyber Security Council / CPX 2025 report-defined exposure, vulnerability-age, incident-category, ransomware-group activity and DDoS trend context for calendar year 2024 and H1 2023–H1 2024 comparative period.
Share of critical vulnerabilities in report context unaddressed for over five years50% percent of critical vulnerabilities in the report context unaddressed for over five yearsUAE Cyber Security Council / CPX, State of the UAE Cybersecurity Report 2025, 25 February 2025UAE Cyber Security Council / CPX 2025 report-defined exposure and threat contextUAE Cyber Security Council / CPX 2025 report-defined exposure, vulnerability-age, incident-category, ransomware-group activity and DDoS trend context for calendar year 2024 and H1 2023–H1 2024 comparative period.
Misconfiguration — 32%32% percent of cyber incidents in the report context categorised as misconfigurationUAE Cyber Security Council / CPX, State of the UAE Cybersecurity Report 2025, 25 February 2025UAE Cyber Security Council / CPX 2025 report-defined exposure and threat contextUAE Cyber Security Council / CPX 2025 report-defined exposure, vulnerability-age, incident-category, ransomware-group activity and DDoS trend context for calendar year 2024 and H1 2023–H1 2024 comparative period.
Improper usage and unlawful activity — 19%19% percent of cyber incidents in the report context categorised as improper usage and unlawful activityUAE Cyber Security Council / CPX, State of the UAE Cybersecurity Report 2025, 25 February 2025UAE Cyber Security Council / CPX 2025 report-defined exposure and threat contextUAE Cyber Security Council / CPX 2025 report-defined exposure, vulnerability-age, incident-category, ransomware-group activity and DDoS trend context for calendar year 2024 and H1 2023–H1 2024 comparative period.
Growth in ransomware groups operating in the UAE (report context)58% percent growth in ransomware groups operating in the UAE witnessed in the report contextUAE Cyber Security Council / CPX, State of the UAE Cybersecurity Report 2025, 25 February 2025UAE Cyber Security Council / CPX 2025 report-defined exposure and threat contextUAE Cyber Security Council / CPX 2025 report-defined exposure, vulnerability-age, incident-category, ransomware-group activity and DDoS trend context for calendar year 2024 and H1 2023–H1 2024 comparative period.
H1 202358,538 DDoS attacks recorded in H1 2023 in the report contextUAE Cyber Security Council / CPX, State of the UAE Cybersecurity Report 2025, 25 February 2025UAE Cyber Security Council / CPX 2025 report-defined exposure and threat contextUAE Cyber Security Council / CPX 2025 report-defined exposure, vulnerability-age, incident-category, ransomware-group activity and DDoS trend context for calendar year 2024 and H1 2023–H1 2024 comparative period.
H1 20242,301 DDoS attacks recorded in H1 2024 in the report contextUAE Cyber Security Council / CPX, State of the UAE Cybersecurity Report 2025, 25 February 2025UAE Cyber Security Council / CPX 2025 report-defined exposure and threat contextUAE Cyber Security Council / CPX 2025 report-defined exposure, vulnerability-age, incident-category, ransomware-group activity and DDoS trend context for calendar year 2024 and H1 2023–H1 2024 comparative period.

Verified observed cyber incident context · United Arab Emirates / CPX

Cyber incident categories observed by CPX threat hunting in the UAE

Market context — not industry-specific evidence

The State of the UAE Cybersecurity Report 2025 reports CPX Threat Hunting observations of attacks in 2024 targeting companies located in the UAE. Within the selected source-reported cyber threat categories shown here, e-mail fraud, phishing and spoofing accounted for 61%. These figures are CPX-observed context; they are not a national UAE incident register, not the percentage of UAE businesses identifying or experiencing attacks, and not industry-specific findings for the sector shown on this page.

UAE company-targeting context · CPX Threat Hunting observations · 2024Calendar year 2024 · Report published February 2025

Email fraud, phishing and spoofing

Observed incident category share
61%
Unit
percent
Period
CPX observed incident and threat-hunting context for calendar year 2024.
Scope
Selected CPX threat-hunting incident categories targeting companies located in the UAE during 2024

Source-published share among incidents observed during CPX threat-hunting operations targeting companies located in the UAE in 2024.

CPX-observed incident context only; this is not a national UAE incident register, not the percentage of UAE businesses affected and not industry-specific evidence.

Selected observed cyber threat categories

E-mail fraud / phishing / spoofing
61%
Unit
percent
Period
CPX observed incident and threat-hunting context for calendar year 2024.
Scope
Selected CPX threat-hunting incident categories targeting companies located in the UAE during 2024
Scans / probes / attempted access
8%
Unit
percent
Period
CPX observed incident and threat-hunting context for calendar year 2024.
Scope
Selected CPX threat-hunting incident categories targeting companies located in the UAE during 2024
Vulnerabilities / web application attacks
4%
Unit
percent
Period
CPX observed incident and threat-hunting context for calendar year 2024.
Scope
Selected CPX threat-hunting incident categories targeting companies located in the UAE during 2024
Malicious code
1%
Unit
percent
Period
CPX observed incident and threat-hunting context for calendar year 2024.
Scope
Selected CPX threat-hunting incident categories targeting companies located in the UAE during 2024
Compromised information
1%
Unit
percent
Period
CPX observed incident and threat-hunting context for calendar year 2024.
Scope
Selected CPX threat-hunting incident categories targeting companies located in the UAE during 2024

Selected CPX Threat Hunting categories only. Improper Usage & Unlawful Activity and Investigation are omitted from this peer-category chart because they are not direct attack or compromise categories. These values are not UAE-business incident rates or industry-specific findings.

Source: CPX, State of the UAE Cybersecurity Report 2025

Scope: CPX Threat Hunting observations of attacks targeting companies located in the UAE during 2024, as published in the State of the UAE Cybersecurity Report 2025. The selected chart renders direct cyber threat or compromise categories only. The source also publishes Improper Usage & Unlawful Activity at 24% and Investigation at 1%; they are intentionally not rendered as peer cyber threat categories in this public chart because they are not direct attack or compromise categories. These figures do not measure UAE-business breach rates, industry-specific performance, compliance achievement, certification or security outcomes.

Methodology: Verified CPX-published observation context from the State of the UAE Cybersecurity Report 2025. The admitted indicators are drawn only from the report’s CPX Threat Hunting observations of attacks in 2024 targeting companies located in the UAE. The admitted market-context values are E-mail Fraud / Phishing / Spoofing 61%, Scans / Probes / Attempted Access 8%, Vulnerabilities / Web Application Attacks 4%, Malicious Code 1% and Compromised Information 1%. These are CPX-observed cyber incident context values, not a national incident register, not a percentage of UAE businesses identifying or experiencing attacks, not industry-specific evidence, and not proof of compliance, certification or security outcomes. No UAE local-industry evidence is admitted in this phase because the available CPX sector figures are not cleanly admissible as exact UAE industry-page evidence under the approved public evidence standard.

Accessible data table
Verified UAE CPX-observed cyber incident context data from CPX, State of the UAE Cybersecurity Report 2025, reporting period CPX observed incident and threat-hunting context for calendar year 2024..
MetricValueSourceScopeReporting period
Observed incident category share61% percentCPX, State of the UAE Cybersecurity Report 2025Selected CPX threat-hunting incident categories targeting companies located in the UAE during 2024CPX observed incident and threat-hunting context for calendar year 2024.
Scans / probes / attempted access8% percentCPX, State of the UAE Cybersecurity Report 2025Selected CPX threat-hunting incident categories targeting companies located in the UAE during 2024CPX observed incident and threat-hunting context for calendar year 2024.
Vulnerabilities / web application attacks4% percentCPX, State of the UAE Cybersecurity Report 2025Selected CPX threat-hunting incident categories targeting companies located in the UAE during 2024CPX observed incident and threat-hunting context for calendar year 2024.
Malicious code1% percentCPX, State of the UAE Cybersecurity Report 2025Selected CPX threat-hunting incident categories targeting companies located in the UAE during 2024CPX observed incident and threat-hunting context for calendar year 2024.
Compromised information1% percentCPX, State of the UAE Cybersecurity Report 2025Selected CPX threat-hunting incident categories targeting companies located in the UAE during 2024CPX observed incident and threat-hunting context for calendar year 2024.

Relevant loss and exposure areas

These existing industry scoping prompts help frame a proposal. They do not assert an incident, loss, or market-specific condition.

Industry themes

  • API Scraping
  • Payment Fraud
  • Service Disruption

Digital surfaces in scope

Booking EnginesFleet DashboardsCustomer Apps

What structured security support changes

The Security File turns risk signals into decisions.

Official market data shows where risk exists. The BilgeQor Security File connects that context to your real websites, apps, accounts, payment flows and team responsibilities, so leaders can decide what to fix first.

Why this matters

The file gives your team one place to understand what was reviewed, what matters, what changed, and what still needs a decision.

BilgeQor Method

What the Security File contains

A Security File is not a generic report. It is a structured decision record for the assets, workflows and risks covered by the agreed scope.

01

Market and sector context

We connect official market signals and industry exposure to the business surfaces in scope.

02

Exposure map

We map websites, apps, accounts, payment journeys, admin roles, vendors and customer-facing workflows.

03

Priority register

We separate urgent risks, important improvements and lower-priority findings so the next action is clear.

04

Executive summary

We provide a concise summary that leadership, operations, vendors or insurers can read without needing raw technical detail.

05

Remediation roadmap

We turn findings into a 14 / 30 / 90-day action path with ownership, evidence notes and follow-through guidance.

What it is not

  • Not a guarantee of perfect security.
  • Not a certification or compliance verdict.
  • Not a per-company loss estimate or fear-based claim.