Connect with us

Financial

LATEST CYBERSECURITY CHALLENGES IN THE WORLD OF BFSI

Published

on

Exclusive interview with Premchand Kurup, CEO, Paramount

Which emerging cyber risks are most likely to influence or reshape GCC banking regulations in the coming years?

We live in an era where nearly every banking service depends on advanced digital infrastructure, and cybercriminals are aware of it. With the emergence of AI, the risks have evolved even further, enabling attacks that can adapt and operate at an unprecedented scale. Over the period of 2024–2026, GCC banking regulations in the region are being influenced by the convergence of advanced ransomware, API-driven open banking risks and AI-enabled cyber threats.

Firstly, targeted ransomware and data extortion attacks against banks and fintechs in the Gulf region have evolved from isolated incidents into a persistent and systemic risk. Financial institutions in the UAE and across the GCC region have experienced a noticeable rise in incidents and malware activity through 2024 and into 2025 by nearly 100%, and this is specific to Paramount. . In response, regulators are tightening requirements for incident reporting timelines, operational resilience testing and recovery capabilities within central banks and national cybersecurity frameworks, with these requirements expected to become more stringent in 2026.

Secondly, the rapid expansion of open banking and digital transformation initiatives has made API security and cloud exposure critical regulatory concerns. Misconfigured cloud environments, weak API authentication, and complex third-party integrations are creating new attack surfaces that traditional perimeter-based security models cannot adequately protect. As a result, regulators in the UAE, Saudi Arabia, and other GCC countries are strengthening supervisory expectations around identity management, data protection and third-party risk management within banking regulations.

Additionally, the rise of AI-driven fraud and AI-assisted cyberattacks is reshaping how supervisors view the intersection of model risks and cyber risks. AI is being increasingly used to support credit assessment, KYC and fraud detection, while also being leveraged by attackers to scale phishing, social engineering and evasion techniques. This dual-use nature of AI is prompting regulators to develop guidance on AI governance, explainability and enhanced monitoring of AI-enabled processes in the financial sector.

What is one underrated cybersecurity innovation today that you believe will become critical for the Middle East’s BFSI sector over the next few years?

One of the most underrated cybersecurity innovations today, and yet one that is likely to become critical for the Middle East’s banking, financial services and insurance (BFSI) sector over the next few years, is behaviour-based analytics, which has become deeply integrated into security operations centre (SOC) functions and fraud detection systems. Numerous financial institutions still rely heavily on static, rule-based systems that trigger alerts based on fixed thresholds or known attack signatures. While effective against traditional threats, these approaches struggle to detect modern attacks that rely on lateral movement, living off the land (LOTL) techniques and sophisticated social engineering.

In contrast, behaviour-driven analytics establishs dynamic baselines for users, devices, applications and APIs. It continuously monitors the way accounts are accessed, transactions are executed and systems communicate, enabling early detection of anomalies that signal potential fraud or intrusion. These capabilities closely mirror the patterns observed in recent high-impact attacks on banks and fintechs across the region. For GCC banks navigating rapid cloud adoption, open banking frameworks and increasing use of AI in core operations, behavioural analytics is becoming essential. It allows institutions to distinguish legitimate high-volume digital activity from subtle intrusions, as highlighted in the report titled ‘2025 Global Digital Trust Insights – Middle East findings’.

Reflecting this shift, Paramount’s advisory and SOC services in the region are increasingly promoting a transition from purely rule-driven monitoring to a blended model that combines behavioural analytics, traditional rules, and threat intelligence. This integrated approach significantly improves detection speed and reduces false positives in complex Middle Eastern financial environments.

From the Paramount SOC’s perspective, approximately how many security incidents or threats have been monitored and mitigated this year


Over the last year we have issued over 592 critical advisories and mitigated them. Critical advisories are those that have the potential to halt business operations significantly.
The year 2026 has just begun, and we have issued nearly 100 advisories already.

Apart from critical advisories we have issued regular 318 advisories this year while the number stood at 2208 last year . We have just begun the year, but the number of alerts shows an increasing trend.

What types of cyber threats are most frequently detected and addressed by the SOC?

During the fiscal year 2024–2025, the most frequently detected threats identified by Paramount’s SOC include phishing and credential theft leading to account takeover, often using highly localised and AI-generated lures. SOC teams also regularly respond to ransomware and data extortion campaigns, alongside API, web application, and DDoS attacks targeting digital banking platforms. Moreover, cloud misconfigurations and excessive access permissions remain a persistent risk, frequently identified through continuous monitoring and threat hunting.

How can C-suite leaders better prepare their organisations, and what proactive steps should banks take to stay ahead of fraud and cyber threats?

For banks across the GCC region, C-suite leaders need to treat cyber resilience as a core board-level business capability, and not simply as a technical or IT function. With cyber threats having direct implications for financial stability, reputation, and regulatory compliance, leadership should embed cyber risk into enterprise risk management frameworks and board reporting. Major threat scenarios such as prolonged digital channel outages, data extortion incidents, or systemic third-party failures should be quantified and reviewed alongside credit and liquidity risks, in line with evolving GCC regulatory expectations. Leaders should further align their cyber strategies with national cybersecurity frameworks and central bank guidance, using independent maturity assessments to identify gaps and prioritise investments through 2026.

From an operational and technology perspective, adopting a zero-trust approach across identities, devices, networks and applications is becoming essential, particularly in API-enabled and cloud-based banking environments. This should be supported by strong SOC and incident response capabilities, whether in-house or through specialised providers such as Paramount, to ensure 24/7 monitoring, rapid containment and documented playbooks for both regulators and customers. Banks also need to invest in advanced fraud analytics and behaviour-based monitoring to detect account takeover and payment fraud, particularly as AI tools make phishing and social engineering more convincing, as witnessed in recent UAE ransomware trends.

Equally important is rigorous third-party and supply chain risk management. This includes structured security due diligence and continuous monitoring of fintech partners, cloud providers and critical vendors, given the growing risk of indirect compromised paths into Gulf financial institutions. Finally, C-suite leaders should actively promote a strong cyber resilience culture. This involves running realistic simulations of ransomware, data leaks, and payment fraud scenarios to sharpen organisational readiness and showcase proactive resilience to regulators, customers and shareholders.

Given the distinct regulatory, cultural, and operational landscape of the GCC, what makes cybersecurity in the region’s BFSI sector uniquely challenging compared to the US or Europe?

Cybersecurity in the GCC region’s BFSI sector is uniquely challenging because financial institutions operate at the intersection of rapid digital transformation, high geopolitical relevance and complex, multi-layered regulation. From a regulatory standpoint, institutions in the region must comply simultaneously with national cybersecurity authorities, central banks, and in some cases, free zone regulators. These entities impose detailed requirements on controls, data protection and incident reporting, creating a more fragmented and demanding compliance landscape than in many single-jurisdiction markets. The situation is further complicated by strict data residency and data sovereignty rules, which significantly influence how banks can design and deploy cloud, analytics, and cross-border platforms.

Operationally, GCC banks are advancing quickly into digital, mobile and open banking services, often faster than ecosystem-wide security maturity. While this supports financial inclusion, it also expands the attack surface through APIs, cloud services, and fintech partnerships. At the same time, the Gulf region has become one of the most actively targeted regions for financially motivated cybercrime and disruptive attacks, with banks and fintechs featuring prominently in 2024–2025 reports on ransomware, DDoS campaigns and sophisticated fraud schemes. The combination of rapid innovation, partner security, high attacker interest and evolving regulatory expectations creates a risk profile that is distinct from more established markets in North America and Europe.

In response, Paramount’s work with GCC BFSI clients focuses on developing region-specific security architectures and systems rather than simply importing models from other geographies. This includes designing frameworks aligned with local regulatory obligations, regional threat intelligence and the operational realities of Middle Eastern institutions as they evolve through 2026.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Financial

Beyond Borders: Why International Expansion Is a Growth Strategy, Not Just a Milestone

Published

on

By Máire (Mo) Morris, Founder & CEO of Morris Global Consulting

International expansion has long been seen as a milestone that signals a brand has ‘made it’. I believe that view is outdated, as behind the scenes often tells a different story. Today, expanding into new markets is not simply about increasing a company’s footprint. It needs to be done well, which in turn leads to an effective way to diversify revenue, build resilience and increase long-term enterprise value.

Across the GCC, we are seeing a new generation of founders creating businesses with global potential. The region has evolved into one of the world’s most dynamic business environments, producing brands with stronger operational foundations, more sophisticated leadership teams and products that are increasingly attracting international attention. As a result, the conversation has shifted. It is no longer about whether businesses should expand internationally, but when they should do it and how they can maximise their chances of success.

Several structural changes are driving this trend. Digital commerce has lowered many of the traditional barriers to international growth. Brands can now test demand, build communities and generate sales in overseas markets before committing to physical retail or local operations. Investor expectations have also evolved. Sustainable, well-planned growth is now valued far more highly than expansion for expansion’s sake. Investors want evidence that a business can replicate its success across multiple markets through strong financial discipline, scalable operations and a clear commercial strategy.

At the same time, recent supply chain disruptions have encouraged businesses to diversify production and reduce dependence on a single sourcing region. Many founders are therefore designing their businesses with international growth in mind from the outset, creating brands that can adapt to different markets over time.

However, opportunity should never be confused with readiness. One of the biggest mistakes I see is founders allowing ambition, and sometimes quite frankly ego, to outweigh evidence. Success in one market does not automatically translate into another. Every country has its own consumer behaviours, pricing expectations, regulations and routes to market. Assuming customers will respond in exactly the same way can become an expensive lesson.

Strong domestic performance is only one part of the equation. True readiness means having a scalable business model, healthy cash flow, resilient operations and a product that genuinely meets the needs of the target market. It also requires robust financial planning, legal and intellectual property protection, and a clear strategy for market entry.

Just as importantly, businesses need the right people around them. Local partners, distributors and experienced advisors bring invaluable market knowledge, established networks and cultural understanding. They help brands navigate complexity, avoid costly mistakes and accelerate growth. Even the strongest business can struggle if it enters a market without the right expertise on the ground.

Choosing where to expand is equally important. Too often, founders are drawn to markets that appear exciting or fashionable rather than those offering the strongest commercial opportunity. The first international market should always be selected using data, not instinct. Customer demand, competitive positioning, operational feasibility, acquisition costs and available resources should all inform the decision.

The largest market is not necessarily the best one. If competition is saturated or customer acquisition costs are too high, a smaller market with stronger commercial fundamentals may deliver far better returns. In most cases, I encourage businesses to take a phased approach, establishing success in one market before expanding further. International growth is a long-term strategy, not a race.

For design-led brands, another challenge is maintaining a consistent identity while remaining relevant to local audiences. The strongest brands never lose sight of who they are. Their purpose, quality and positioning remain consistent, while elements such as marketing, product assortment, pricing and customer experience are adapted to reflect local consumer preferences. When approached strategically, localisation strengthens relevance without compromising the essence of the brand. Authenticity, quality and consistency resonate across cultures. Those are the qualities that build trust, regardless of geography.

Digital-first expansion is also changing the way emerging brands enter new markets. For many businesses, e-commerce provides an opportunity to validate demand, build awareness and gather customer insights before making significant investments in physical retail. This reduces risk and allows founders to make decisions based on real customer behaviour rather than assumptions.

Of course, international expansion requires investment before it delivers meaningful returns. Market research, regulatory compliance, intellectual property protection, distribution, marketing, local partnerships and working capital all require careful financial planning. It is common for profitability to soften in the short term while these investments are made.

The businesses that generate the strongest long-term returns are those that enter new markets with realistic expectations, sufficient capital and a clear path to sustainable revenue. This is also where international expansion begins to influence enterprise value. Investors place significant importance on geographic diversification because it reduces risk. Businesses that rely on a single market are naturally more exposed to economic cycles, regulatory changes, geopolitical uncertainty and shifts in consumer demand. Companies that have demonstrated they can replicate success across multiple markets are viewed as more resilient and more scalable.

This is not simply about operating in several countries. Investors want evidence that growth can be repeated through disciplined execution, sound financial performance and a scalable operating model. Successfully establishing one or two international markets often provides that confidence and can materially strengthen investor interest.

It is important to also note that international expansion is not the right strategy for every business. A highly profitable company with a loyal customer base and a dominant regional position can still create exceptional enterprise value. This is particularly true for brands built around local craftsmanship, heritage or provenance, where regional focus strengthens the overall proposition. Expansion should only be pursued when it supports the long-term vision of the business and creates sustainable value.

As we look ahead, international expansion needs to become increasingly strategic and data-driven. Artificial intelligence, digital commerce and more sophisticated market intelligence will help businesses identify opportunities and validate demand before committing significant investment. At the same time, geopolitical uncertainty and supply chain resilience will remain key considerations, making thoughtful planning more important than ever.

Through my work at Morris Global Consulting, supporting hundreds of businesses entering new markets across multiple regions, one lesson remains constant. The companies that succeed internationally are rarely the ones that move the fastest. They are the ones that prepare thoroughly, make decisions based on evidence rather than assumptions, and invest in the right partnerships before taking the next step.

International expansion is not about being present in as many countries as possible. It is about building a stronger, more resilient business that is equipped for sustainable growth over the long term. When approached strategically, crossing borders does far more than open new markets. It creates lasting value.

Continue Reading

Financial

TRUST AS A COMPETITIVE ADVANTAGE IN GLOBAL FINANCE

Published

on

Armin Moradi, the CEO and Founder of Qashio

For centuries, financial institutions relied on one advantage. Whether it was the range of their products, their pricing, or how far their services could reach. Today, those advantages are easy to replicate. Digital infrastructure is widely available, capital moves quickly across borders, and acquiring customers is increasingly automated. What now sets institutions apart is not the breadth of their offerings or the cost of their services. It is the confidence they inspire.

In a world that is increasingly more fragmented, turbulent, and cautious, trust has become one of the few advantages that cannot be replicated. Global investment patterns illustrate this shift. According to the UNCTAD World Investment Report 2025, foreign direct investment (FDI) remains far below its early 2010s peak, reflecting a world that is more risk-aware and geopolitically sensitive. The World Bank’s Global Economic Prospects also highlights uneven growth and rising uncertainty across regions. This means capital is no longer chasing the highest return; instead it is seeking predictability. And institutions that inspire trust are the ones most likely to attract it.

Capital Moves Toward Certainty

The UAE offers a compelling example. The EMIR report, supported by Qashio, Flows of Capital: Mapping the UAE’s Role as a Global Financial Gateway, shows that FDI into the country reached $40 billion, doubling from 2019 levels, and accounting for 40% of gross capital formation compared to a developed economy average of 4.3%. That differential cannot be explained by tax efficiency alone. It reflects regulatory clarity, institutional stability, and operational reliability, all of which underpin trust

The same principle is playing out at the company level.

UAE banks are increasingly pushing for founders and business owners to separate personal and corporate spending. On paper, that is a compliance issue. In reality, it signals a structural shift. Poor accounting discipline creates risk. Blurred financial lines complicate audits, funding discussions, and cross-border expansion. When investors and regulators examine financial behaviour, governance becomes visible immediately, highlighting that trust begins with discipline.

Designing Trust: Transparency, Control, Reliability

As finance becomes more digital, trust is becoming more measurable. It rests on three interlocking foundations: transparency, control, and reliability.

Transparency is now a baseline expectation. Customers want to know what they are paying, when transactions settle, and how fees are calculated. The scale of global financial flows reinforces this demand. The World Bank estimates that remittance flows to low- and middle-income countries reached $685 billion in 2024. That figure exceeds FDI and official development assistance combined for those economies. When volumes are that significant, even marginal opacity in pricing or settlement becomes economically material, making clarity a matter of cost efficiency at the system level rather than a branding exercise.

Control is equally critical. Modern finance teams operate across distributed workforces, multi-entity structures, and global vendor networks. Organisations lose an estimated 5% of revenue annually to fraud. While fraud has multiple sources, weak internal controls and policy bypass increase exposure. Giving customers direct control of their funds, through stronger controls and policies, helps reinforce trust in financial institutions.

The most resilient organisations design policy directly into their payment infrastructure. Approval hierarchies, spend limits, and permission layers are embedded into the system itself. This allows companies to move quickly without sacrificing oversight. The distinction between proactive and reactive governance is not philosophical. It determines speed, cost of capital, and investor confidence.

Reliability completes the triad. Finance is ultimately about certainty. Platforms must perform consistently. Settlements must arrive when expected. Liquidity windows must be predictable. Inconsistent infrastructure creates friction not just for finance teams, but for suppliers and partners across the value chain.

The Economics of “Free”

Digital finance has conditioned customers to expect “free” services: zero-fee accounts, no-cost cards, complimentary transfers. Yet compliance, fraud monitoring, capital provisioning, cybersecurity, and regulatory reporting all carry measurable costs. If a core financial service is offered at no charge, the obvious question becomes: how is it funded?

Revenue may come from interchange, cross-selling, float income, or data monetisation. None of these are inherently problematic. But misalignment between a provider’s revenue model and a customer’s long-term interests can erode confidence over time.

The question “How good can it be if it’s free?” is not rhetorical. It is structural. Sustainable economics enables sustained investment in compliance, uptime, and risk management. Underinvestment may not be visible immediately, but in financial services, weaknesses surface under stress.

From Compliance to Competitive Moat

Trust can no longer be viewed as a soft metric. It is measurable in capital inflows, in regulatory endorsements, in uptime statistics, and in audit outcomes. It influences valuation multiples and partnership decisions.

Institutions that deliberately design for transparency, embed control within infrastructure, and invest consistently in reliability will compound confidence over time. Those that rely primarily on aggressive pricing or superficial features may gain short-term adoption, but long-term retention is built on predictability.

In a more volatile global environment, the question facing financial leaders is shifting. It is no longer simply about how fast a product can scale or how cheaply it can be distributed. It now depends on the system’s ability to remain reliable under pressure.

Continue Reading

Financial

UAE energy firms risk forfeiting millions in R&D credits unless spend is qualified and pre-approved

Published

on

From enhanced carbon capture at gas processing plants to grid modernisation and renewable energy storage, the technology reshaping the UAE’s oil and gas industry, has acquired a new dimension. As of the 2026, a significant portion of the research and development (R&D) behind it can be converted into a corporate tax credit of up to 50 percent under the country’s first dedicated R&D Tax Credit regime. According to Dhruva, a Ryan Affiliate, the opportunity for the energy sector is substantial, but the design of the regime rewards companies that act early and penalises those that treat it as a year-end exercise.

The regime was established by Cabinet Decision No. 215 of 2025 and made operational by Ministerial Decision No. 24 of 2026, issued on 18 March 2026. It applies to tax periods and fiscal years beginning on or after 1 January 2026, with the first claims expected in 2027. Credits are calculated on a tiered basis, rising from 15 percent to a headline 50 percent. Qualifying expenditure is capped at AED 5 million per qualifying entity or tax group per year, which produces a maximum credit of AED 2 million.

“The UAE’s energy transition has been told as a sustainability story and an investment story. From this year it is also a tax story. The work being undertaken to decarbonise hydrocarbon production, including enhanced oil recovery, carbon capture and storage, methane abatement, and the development of digital twins for processing plants, exemplifies the systematic, uncertainty-driven R&D that this regime is designed to reward. The catch is that the value sits in the documentation, and the documentation has to be built in real time. You cannot retrospectively reconstruct a year’s worth of R&D evidence in 2027,” said Nimish Goel, Leader, Middle East, Dhruva, Ryan LLC Affiliate.

For an industry as engineering-intensive as oil and gas, the central question is not whether qualifying activity exists. It is whether companies can tell the difference between routine engineering and genuine R&D, and prove it. Applying an established recovery method to a new reservoir does not, in itself, qualify. By contrast, systematically resolving technical uncertainty, whether relating to reservoir behaviour, materials performance under high-pressure conditions, the capture of CO₂ from sulphur recovery flue gas, or the integration of new digital control systems,  may qualify, provided the systematic experimentation and its outcomes are documented as the work is carried out.

“Two features will catch international energy companies off guard. Only R&D performed inside the UAE qualifies, and subcontracted R&D counts only when it is carried out by UAE-based third parties. Much of the sector’s historical R&D has run through global technology centres and group affiliates abroad. Companies will need to look hard at where their R&D actually physically takes place, before they assume they qualify,” said Fran Wilhelm, Associate Partner, Dhruva, Ryan LLC Affiliate.

The regime’s defining feature is a dual threshold that links the credit rate to both qualifying spend and headcount. The first AED 1 million of qualifying spend earns 15 percent and requires at least two R&D staff on average; spend between AED 1 million and AED 2 million earns 35 percent and requires at least six; and spend between AED 2 million and AED 5 million earns the top 50 percent rate and requires at least fourteen. Both conditions must be met for each band. Where the headcount falls short, the claim drops back to the highest band where both the spend and the staffing tests are satisfied. A minimum of AED 500,000 of qualifying expenditure applies to each R&D project.

This is where oil and gas companies face a structural choice that other sectors may not. R&D in the industry is often capital-intensive rather than people-intensive: a single carbon capture or enhanced oil recovery pilot can absorb millions in equipment and consumables while employing only a handful of dedicated researchers. Under the dual threshold, that profile caps the credit at the lowest band regardless of how much is spent. Reaching the higher rates means building R&D headcount physically in the UAE.

Pre-approval from the Emirates Research and Development Council is mandatory before any credit can be claimed, with no exceptions. No pre-approval means no credit, however strong the underlying scientific or technological uncertainty. Businesses must keep detailed technical records of objectives, methods, experiments and outcomes for at least seven years. The credit is also currently non-refundable, so it benefits companies that have a corporate tax or top-up tax liability to offset, which describes most established producers and service contractors in the sector. That said, it has been suggested that Phase 2 may include a refundable credit and an increase in both application and generosity, meaning all businesses should start planning ahead, irrespective of their tax position.

“Companies that map their qualifying projects now, secure pre-approval and build the evidence trail through the 2026 financial year will capture real value when claims open in 2027. Those that wait will find that the spend was eligible but the proof was never created. In this regime, the documentation is the asset,” concluded Nimish Goel.

Continue Reading

Trending

Copyright © 2023 | The Integrator