Financial
AI-Driven Cybersecurity in MENA Banking: Why It’s Time to Rethink Our Defenses
By Omar Mansur, Managing Director – APAC, Codebase Technologies
In an age where digital transformation is moving faster than ever, banks around the Middle East and North Africa (MENA) are forced to confront a growing and increasingly evolving threat: cybercrime and fraud. It’s not just about an increase in the number of incidents; it’s about smarter threats. Nefarious agents are utilizing more complex methods such as leveraging artificial intelligence (AI) to outsmart traditional IT security systems, using everything from deepfake-powered scams to AI-generated phishing campaigns along with social engineering strategies.
In the UAE alone, about 21% of cybersecurity incidents in recent years targeted banks and financial institutions, second only to government entities (Lemos, 2025). With costly breaches on the rise cybersecurity has become a top board-level concern. However globally, 71% of leaders report that small organizations can no longer adequately secure themselves against the growing complexity of cyber risks (WEF, 2025). It’s a high-stakes game and I have personally seen how AI and cybersecurity has taken the spotlight in board meetings and discussion with clients from across the GCC and Levant regions.
This urgency has forced MENA banks to explore AI-driven security solutions that can match the speed and complexity of modern threats, protecting both their customers and their bottom line. The conversation is no longer “if” we need AI-driven defenses—it’s how quickly we can deploy them, and how can we optimize them to adapt to the ever-changing tactics of nefarious agents
Where We Stand
It wasn’t that long ago that Gen AI in banking was mostly used to train and create chatbots for customer support, but this is changing quickly. In the UAE, over 70% of banks have rolled out or upgraded their AI capabilities, and not just to streamline operations, but to actively combat cybercrime (PwC, 2023). Across multiple projects I have seen an overarching focus on AI being incorporated into all manner of digital solutions, particularly in the MENA region where cyber fraud has become a prevalent issue affecting credibility and customer confidence.
The push is being led by both necessity and ambition. Saudi Arabia and the GCC states are investing heavily in national digital strategies, and banks are stepping up with AI systems to detect fraud, verify identities, and stay ahead of financial crime. As many countries in the Middle East position themselves as financial and fintech hubs, ensuring security for customers and institutions is a prime concern in garnering not only customer confidence but regional credibility. That’s pushed regional cybersecurity budgets to grow by double digits, with MENA’s total spend expected to exceed $3.3 billion in 2025, driven by Gen-AI, cloud adoption, talent gaps, and evolving threats (Gartner, 2024).
A True Strategic Advantage or Just a Security Upgrade?
Artificial intelligence isn’t just helping plug holes in defenses, it’s defining the rules for how security is built into every layer of operations. Integrating AI into banking operations gives banks a real edge in regions where speed really matters. Having worked with several banks across the region, I’ve seen firsthand how traditional security models are starting to break under the weight of elaborate AI based threats.
For banks in the MENA region, where rapid digitalization coincides with heightened cyber threats, adopting AI-driven systems enhances operational resilience, reduces financial losses due to fraud, and boosts customer trust. AI not only fortifies security frameworks, it also fosters innovation, empowering banks to confidently pursue new digital business models and expansion opportunities.
AI defenses monitor account activity 24/7 and can react in seconds to anomalies, reducing the window of time attackers can exploit. AI-based user behavior analytics can spot an account takeover attempt at the moment it diverges from normal patterns and automatically disable the account, preventing fraud before it escalates. Early-adopting banks in the UAE report that AI systems have sharply reduced successful fraud incidents and enabled rapid intervention in potential cyber attacks.
AI isn’t just a nice to have security upgrade, it’s a question of survival.
How are Banks Using AI for Cyber Security
A simple example of successful AI usage in a cybersecurity context is during a next-gen digital onboarding process. With many regulators now strong encouraging or mandating digital onboarding, banks have been able to benefit from using AI-powered systems to prevent fraud before it has a chance to run rampant. Next gen AI-powered onboarding and eKYC minimizes friction for customers looking to open accounts, while providing a secure backend environment to recude the risks for attacks. Such solutions utilize a variety of AI enabled features such as next-gen biometrics, deep ID document validation, Arabic language detection, glare reduction in ID photos, all ensuring a secure authentication and verification of a new customer. An example of this application can be the digital onboarding process implemented by UAE-based Ajman Bank, which has registered a significant reduction in fraud attempts after implementing an AI-based digital onboarding system as part of its digital transformation.
Another strategy for catching instances of fraud is by using AI for anomaly detection. A machine learning model can study what “normal” looks like, in terms of user behavior, transaction patterns, system activity; and flag anything that stands out. This allows banks to see unusual patterns – e.g. a late-night login or peculiar fund transfers, which would evade static rule-based systems. Unsupervised algorithms (like isolation forests or one-class SVMs) and neural network autoencoders sift through vast streams of events to pinpoint such outliers. Such strategies, can be deployed to facilitate analysis over large numbers of accounts, which can then be flagged to a human for additional intervention and review.
This tactic can work hand in hand with automating routine security tasks with AI, making cybersecurity operations more efficient. This not only addresses the talent shortage by doing more with less, but also lowers costs associated with manual monitoring and investigation. AI-based security solutions have been shown to improve incident response times and cut costs by reducing trivial alerts and speeding up analysis. Banks in MENA benefit by reallocating human experts to higher-value activities like threat hunting and fortifying security architecture, while letting AI handle the heavy lifting of round-the-clock surveillance.
Neural networks can analyze huge volumes of transactional data, cross-referencing dozens of variables to catch fraud in ways that traditional systems simply can’t. Banks train neural networks on historical transactions to recognize subtle indicators of fraud that humans might miss. An ensemble of decision trees (random forests) or a deep neural network can analyze dozens of features (transaction size, timing, location, device, user profile) to instantly assess whether a transaction is suspicious. These models adapt as fraud tactics evolve, improving over time. Similarly, neural networks in intrusion detection systems learn to spot network traffic behaviors that resemble known cyberattacks. This leads to faster, more accurate threat detection and frees up human analysts for higher-level decision-making.
Phishing remains a prime concern for many banks as targeting customers can be a much simpler way to compromise a system than to go after the bank itself. In fact, in 2024 there was a sharp increase in phishing and social engineering attacks, with 42% of organizations reporting incidents (WEF, 2025). To mitigate such threats, many cyber security experts are turning to Natural Language Processing or NLP, which has become a dynamic way in recent years that helps banks detect malicious intent in emails, texts, and even chat messages. NLP enables AI to “read” and analyze text for signs of fraud or attack. An NLP-driven system can scan incoming emails to employees and flag phishing attempts based on language patterns and malicious links. Banks use NLP to monitor chat messages and transaction memos for red flags, like someone soliciting account details. By understanding context in language, AI adds an extra layer of defense to catch social engineering and scam attempts that purely numeric data monitoring might overlook.
By deploying these AI-powered strategies in tandem, banks can create a multi-pronged defense system, akin to a digital immune system, ready to tackle a multitude of afflictions. An anomaly detection system might catch unusual account behavior, while an NLP filter flags a related phishing email – together giving a fuller picture of an attack in progress. This intelligent automation amplifies human analysts’ effectiveness, allowing them to focus on verified threats and complex investigations rather than sifting through noise.
Looking Towards a Future of Cyber Resilience
We’re entering a new era in banking security. One where artificial intelligence and generative-AI doesn’t just assist, but actively drives how banks detect, prevent, and respond to threats. The emerging champions won’t be those with the biggest budgets, but those with the clearest strategy, and those who understand that AI is both a weapon and a shield in the modern cybersecurity landscape. One that must be deployed correctly to protect institutions and customers.
When implemented wisely, AI can dramatically boost a bank’s ability to prevent breaches, detect fraud in real time, and operate securely at scale – all essential for maintaining customer trust. At the same time, banks must remain vigilant: as attackers innovate with AI, defensive strategies must keep adapting, and governance must ensure ethical, compliant use of artificial intelligence.
So, here’s a question worth asking at the next board meeting is, are we using AI to its full potential, not just to defend our systems, but to build customer trust, support innovation, and lead the market in resilience?
Financial
Beyond Borders: Why International Expansion Is a Growth Strategy, Not Just a Milestone
By Máire (Mo) Morris, Founder & CEO of Morris Global Consulting
International expansion has long been seen as a milestone that signals a brand has ‘made it’. I believe that view is outdated, as behind the scenes often tells a different story. Today, expanding into new markets is not simply about increasing a company’s footprint. It needs to be done well, which in turn leads to an effective way to diversify revenue, build resilience and increase long-term enterprise value.
Across the GCC, we are seeing a new generation of founders creating businesses with global potential. The region has evolved into one of the world’s most dynamic business environments, producing brands with stronger operational foundations, more sophisticated leadership teams and products that are increasingly attracting international attention. As a result, the conversation has shifted. It is no longer about whether businesses should expand internationally, but when they should do it and how they can maximise their chances of success.
Several structural changes are driving this trend. Digital commerce has lowered many of the traditional barriers to international growth. Brands can now test demand, build communities and generate sales in overseas markets before committing to physical retail or local operations. Investor expectations have also evolved. Sustainable, well-planned growth is now valued far more highly than expansion for expansion’s sake. Investors want evidence that a business can replicate its success across multiple markets through strong financial discipline, scalable operations and a clear commercial strategy.
At the same time, recent supply chain disruptions have encouraged businesses to diversify production and reduce dependence on a single sourcing region. Many founders are therefore designing their businesses with international growth in mind from the outset, creating brands that can adapt to different markets over time.
However, opportunity should never be confused with readiness. One of the biggest mistakes I see is founders allowing ambition, and sometimes quite frankly ego, to outweigh evidence. Success in one market does not automatically translate into another. Every country has its own consumer behaviours, pricing expectations, regulations and routes to market. Assuming customers will respond in exactly the same way can become an expensive lesson.
Strong domestic performance is only one part of the equation. True readiness means having a scalable business model, healthy cash flow, resilient operations and a product that genuinely meets the needs of the target market. It also requires robust financial planning, legal and intellectual property protection, and a clear strategy for market entry.
Just as importantly, businesses need the right people around them. Local partners, distributors and experienced advisors bring invaluable market knowledge, established networks and cultural understanding. They help brands navigate complexity, avoid costly mistakes and accelerate growth. Even the strongest business can struggle if it enters a market without the right expertise on the ground.
Choosing where to expand is equally important. Too often, founders are drawn to markets that appear exciting or fashionable rather than those offering the strongest commercial opportunity. The first international market should always be selected using data, not instinct. Customer demand, competitive positioning, operational feasibility, acquisition costs and available resources should all inform the decision.
The largest market is not necessarily the best one. If competition is saturated or customer acquisition costs are too high, a smaller market with stronger commercial fundamentals may deliver far better returns. In most cases, I encourage businesses to take a phased approach, establishing success in one market before expanding further. International growth is a long-term strategy, not a race.
For design-led brands, another challenge is maintaining a consistent identity while remaining relevant to local audiences. The strongest brands never lose sight of who they are. Their purpose, quality and positioning remain consistent, while elements such as marketing, product assortment, pricing and customer experience are adapted to reflect local consumer preferences. When approached strategically, localisation strengthens relevance without compromising the essence of the brand. Authenticity, quality and consistency resonate across cultures. Those are the qualities that build trust, regardless of geography.
Digital-first expansion is also changing the way emerging brands enter new markets. For many businesses, e-commerce provides an opportunity to validate demand, build awareness and gather customer insights before making significant investments in physical retail. This reduces risk and allows founders to make decisions based on real customer behaviour rather than assumptions.
Of course, international expansion requires investment before it delivers meaningful returns. Market research, regulatory compliance, intellectual property protection, distribution, marketing, local partnerships and working capital all require careful financial planning. It is common for profitability to soften in the short term while these investments are made.
The businesses that generate the strongest long-term returns are those that enter new markets with realistic expectations, sufficient capital and a clear path to sustainable revenue. This is also where international expansion begins to influence enterprise value. Investors place significant importance on geographic diversification because it reduces risk. Businesses that rely on a single market are naturally more exposed to economic cycles, regulatory changes, geopolitical uncertainty and shifts in consumer demand. Companies that have demonstrated they can replicate success across multiple markets are viewed as more resilient and more scalable.
This is not simply about operating in several countries. Investors want evidence that growth can be repeated through disciplined execution, sound financial performance and a scalable operating model. Successfully establishing one or two international markets often provides that confidence and can materially strengthen investor interest.
It is important to also note that international expansion is not the right strategy for every business. A highly profitable company with a loyal customer base and a dominant regional position can still create exceptional enterprise value. This is particularly true for brands built around local craftsmanship, heritage or provenance, where regional focus strengthens the overall proposition. Expansion should only be pursued when it supports the long-term vision of the business and creates sustainable value.
As we look ahead, international expansion needs to become increasingly strategic and data-driven. Artificial intelligence, digital commerce and more sophisticated market intelligence will help businesses identify opportunities and validate demand before committing significant investment. At the same time, geopolitical uncertainty and supply chain resilience will remain key considerations, making thoughtful planning more important than ever.
Through my work at Morris Global Consulting, supporting hundreds of businesses entering new markets across multiple regions, one lesson remains constant. The companies that succeed internationally are rarely the ones that move the fastest. They are the ones that prepare thoroughly, make decisions based on evidence rather than assumptions, and invest in the right partnerships before taking the next step.
International expansion is not about being present in as many countries as possible. It is about building a stronger, more resilient business that is equipped for sustainable growth over the long term. When approached strategically, crossing borders does far more than open new markets. It creates lasting value.
Financial
TRUST AS A COMPETITIVE ADVANTAGE IN GLOBAL FINANCE
Armin Moradi, the CEO and Founder of Qashio
For centuries, financial institutions relied on one advantage. Whether it was the range of their products, their pricing, or how far their services could reach. Today, those advantages are easy to replicate. Digital infrastructure is widely available, capital moves quickly across borders, and acquiring customers is increasingly automated. What now sets institutions apart is not the breadth of their offerings or the cost of their services. It is the confidence they inspire.
In a world that is increasingly more fragmented, turbulent, and cautious, trust has become one of the few advantages that cannot be replicated. Global investment patterns illustrate this shift. According to the UNCTAD World Investment Report 2025, foreign direct investment (FDI) remains far below its early 2010s peak, reflecting a world that is more risk-aware and geopolitically sensitive. The World Bank’s Global Economic Prospects also highlights uneven growth and rising uncertainty across regions. This means capital is no longer chasing the highest return; instead it is seeking predictability. And institutions that inspire trust are the ones most likely to attract it.
Capital Moves Toward Certainty
The UAE offers a compelling example. The EMIR report, supported by Qashio, Flows of Capital: Mapping the UAE’s Role as a Global Financial Gateway, shows that FDI into the country reached $40 billion, doubling from 2019 levels, and accounting for 40% of gross capital formation compared to a developed economy average of 4.3%. That differential cannot be explained by tax efficiency alone. It reflects regulatory clarity, institutional stability, and operational reliability, all of which underpin trust
The same principle is playing out at the company level.
UAE banks are increasingly pushing for founders and business owners to separate personal and corporate spending. On paper, that is a compliance issue. In reality, it signals a structural shift. Poor accounting discipline creates risk. Blurred financial lines complicate audits, funding discussions, and cross-border expansion. When investors and regulators examine financial behaviour, governance becomes visible immediately, highlighting that trust begins with discipline.
Designing Trust: Transparency, Control, Reliability
As finance becomes more digital, trust is becoming more measurable. It rests on three interlocking foundations: transparency, control, and reliability.
Transparency is now a baseline expectation. Customers want to know what they are paying, when transactions settle, and how fees are calculated. The scale of global financial flows reinforces this demand. The World Bank estimates that remittance flows to low- and middle-income countries reached $685 billion in 2024. That figure exceeds FDI and official development assistance combined for those economies. When volumes are that significant, even marginal opacity in pricing or settlement becomes economically material, making clarity a matter of cost efficiency at the system level rather than a branding exercise.
Control is equally critical. Modern finance teams operate across distributed workforces, multi-entity structures, and global vendor networks. Organisations lose an estimated 5% of revenue annually to fraud. While fraud has multiple sources, weak internal controls and policy bypass increase exposure. Giving customers direct control of their funds, through stronger controls and policies, helps reinforce trust in financial institutions.
The most resilient organisations design policy directly into their payment infrastructure. Approval hierarchies, spend limits, and permission layers are embedded into the system itself. This allows companies to move quickly without sacrificing oversight. The distinction between proactive and reactive governance is not philosophical. It determines speed, cost of capital, and investor confidence.
Reliability completes the triad. Finance is ultimately about certainty. Platforms must perform consistently. Settlements must arrive when expected. Liquidity windows must be predictable. Inconsistent infrastructure creates friction not just for finance teams, but for suppliers and partners across the value chain.
The Economics of “Free”
Digital finance has conditioned customers to expect “free” services: zero-fee accounts, no-cost cards, complimentary transfers. Yet compliance, fraud monitoring, capital provisioning, cybersecurity, and regulatory reporting all carry measurable costs. If a core financial service is offered at no charge, the obvious question becomes: how is it funded?
Revenue may come from interchange, cross-selling, float income, or data monetisation. None of these are inherently problematic. But misalignment between a provider’s revenue model and a customer’s long-term interests can erode confidence over time.
The question “How good can it be if it’s free?” is not rhetorical. It is structural. Sustainable economics enables sustained investment in compliance, uptime, and risk management. Underinvestment may not be visible immediately, but in financial services, weaknesses surface under stress.
From Compliance to Competitive Moat
Trust can no longer be viewed as a soft metric. It is measurable in capital inflows, in regulatory endorsements, in uptime statistics, and in audit outcomes. It influences valuation multiples and partnership decisions.
Institutions that deliberately design for transparency, embed control within infrastructure, and invest consistently in reliability will compound confidence over time. Those that rely primarily on aggressive pricing or superficial features may gain short-term adoption, but long-term retention is built on predictability.
In a more volatile global environment, the question facing financial leaders is shifting. It is no longer simply about how fast a product can scale or how cheaply it can be distributed. It now depends on the system’s ability to remain reliable under pressure.
Financial
UAE energy firms risk forfeiting millions in R&D credits unless spend is qualified and pre-approved
From enhanced carbon capture at gas processing plants to grid modernisation and renewable energy storage, the technology reshaping the UAE’s oil and gas industry, has acquired a new dimension. As of the 2026, a significant portion of the research and development (R&D) behind it can be converted into a corporate tax credit of up to 50 percent under the country’s first dedicated R&D Tax Credit regime. According to Dhruva, a Ryan Affiliate, the opportunity for the energy sector is substantial, but the design of the regime rewards companies that act early and penalises those that treat it as a year-end exercise.
The regime was established by Cabinet Decision No. 215 of 2025 and made operational by Ministerial Decision No. 24 of 2026, issued on 18 March 2026. It applies to tax periods and fiscal years beginning on or after 1 January 2026, with the first claims expected in 2027. Credits are calculated on a tiered basis, rising from 15 percent to a headline 50 percent. Qualifying expenditure is capped at AED 5 million per qualifying entity or tax group per year, which produces a maximum credit of AED 2 million.
“The UAE’s energy transition has been told as a sustainability story and an investment story. From this year it is also a tax story. The work being undertaken to decarbonise hydrocarbon production, including enhanced oil recovery, carbon capture and storage, methane abatement, and the development of digital twins for processing plants, exemplifies the systematic, uncertainty-driven R&D that this regime is designed to reward. The catch is that the value sits in the documentation, and the documentation has to be built in real time. You cannot retrospectively reconstruct a year’s worth of R&D evidence in 2027,” said Nimish Goel, Leader, Middle East, Dhruva, Ryan LLC Affiliate.
For an industry as engineering-intensive as oil and gas, the central question is not whether qualifying activity exists. It is whether companies can tell the difference between routine engineering and genuine R&D, and prove it. Applying an established recovery method to a new reservoir does not, in itself, qualify. By contrast, systematically resolving technical uncertainty, whether relating to reservoir behaviour, materials performance under high-pressure conditions, the capture of CO₂ from sulphur recovery flue gas, or the integration of new digital control systems, may qualify, provided the systematic experimentation and its outcomes are documented as the work is carried out.
“Two features will catch international energy companies off guard. Only R&D performed inside the UAE qualifies, and subcontracted R&D counts only when it is carried out by UAE-based third parties. Much of the sector’s historical R&D has run through global technology centres and group affiliates abroad. Companies will need to look hard at where their R&D actually physically takes place, before they assume they qualify,” said Fran Wilhelm, Associate Partner, Dhruva, Ryan LLC Affiliate.
The regime’s defining feature is a dual threshold that links the credit rate to both qualifying spend and headcount. The first AED 1 million of qualifying spend earns 15 percent and requires at least two R&D staff on average; spend between AED 1 million and AED 2 million earns 35 percent and requires at least six; and spend between AED 2 million and AED 5 million earns the top 50 percent rate and requires at least fourteen. Both conditions must be met for each band. Where the headcount falls short, the claim drops back to the highest band where both the spend and the staffing tests are satisfied. A minimum of AED 500,000 of qualifying expenditure applies to each R&D project.
This is where oil and gas companies face a structural choice that other sectors may not. R&D in the industry is often capital-intensive rather than people-intensive: a single carbon capture or enhanced oil recovery pilot can absorb millions in equipment and consumables while employing only a handful of dedicated researchers. Under the dual threshold, that profile caps the credit at the lowest band regardless of how much is spent. Reaching the higher rates means building R&D headcount physically in the UAE.
Pre-approval from the Emirates Research and Development Council is mandatory before any credit can be claimed, with no exceptions. No pre-approval means no credit, however strong the underlying scientific or technological uncertainty. Businesses must keep detailed technical records of objectives, methods, experiments and outcomes for at least seven years. The credit is also currently non-refundable, so it benefits companies that have a corporate tax or top-up tax liability to offset, which describes most established producers and service contractors in the sector. That said, it has been suggested that Phase 2 may include a refundable credit and an increase in both application and generosity, meaning all businesses should start planning ahead, irrespective of their tax position.
“Companies that map their qualifying projects now, secure pre-approval and build the evidence trail through the 2026 financial year will capture real value when claims open in 2027. Those that wait will find that the spend was eligible but the proof was never created. In this regime, the documentation is the asset,” concluded Nimish Goel.
-
News11 years ago
SENDQUICK (TALARIAX) INTRODUCES SQOOPE – THE BREAKTHROUGH IN MOBILE MESSAGING
-
Trending9 months agoOPPO A6 Pro 5G Review: Reliable Daily Driver
-
Tech News2 years agoDenodo Bolsters Executive Team by Hiring Christophe Culine as its Chief Revenue Officer
-
VAR1 year agoMicrosoft Launches New Surface Copilot+ PCs for Business
-
Automotive2 years agoAGMC Launches the RIDDARA RD6 High Performance Fully Electric 4×4 Pickup
-
Tech Interviews2 years ago
Navigating the Cybersecurity Landscape in Hybrid Work Environments
-
Tech News1 year agoNothing Launches flagship Nothing Phone (3) and Headphone (1) in theme with the Iconic Museum of the Future in Dubai
-
VAR2 years agoSamsung Galaxy Z Fold6 vs Google Pixel 9 Pro Fold: Clash Of The Folding Phenoms


