Financial
LATEST CYBERSECURITY CHALLENGES IN THE WORLD OF BFSI
Exclusive interview with Premchand Kurup, CEO, Paramount
Which emerging cyber risks are most likely to influence or reshape GCC banking regulations in the coming years?
We live in an era where nearly every banking service depends on advanced digital infrastructure, and cybercriminals are aware of it. With the emergence of AI, the risks have evolved even further, enabling attacks that can adapt and operate at an unprecedented scale. Over the period of 2024–2026, GCC banking regulations in the region are being influenced by the convergence of advanced ransomware, API-driven open banking risks and AI-enabled cyber threats.
Firstly, targeted ransomware and data extortion attacks against banks and fintechs in the Gulf region have evolved from isolated incidents into a persistent and systemic risk. Financial institutions in the UAE and across the GCC region have experienced a noticeable rise in incidents and malware activity through 2024 and into 2025 by nearly 100%, and this is specific to Paramount. . In response, regulators are tightening requirements for incident reporting timelines, operational resilience testing and recovery capabilities within central banks and national cybersecurity frameworks, with these requirements expected to become more stringent in 2026.
Secondly, the rapid expansion of open banking and digital transformation initiatives has made API security and cloud exposure critical regulatory concerns. Misconfigured cloud environments, weak API authentication, and complex third-party integrations are creating new attack surfaces that traditional perimeter-based security models cannot adequately protect. As a result, regulators in the UAE, Saudi Arabia, and other GCC countries are strengthening supervisory expectations around identity management, data protection and third-party risk management within banking regulations.
Additionally, the rise of AI-driven fraud and AI-assisted cyberattacks is reshaping how supervisors view the intersection of model risks and cyber risks. AI is being increasingly used to support credit assessment, KYC and fraud detection, while also being leveraged by attackers to scale phishing, social engineering and evasion techniques. This dual-use nature of AI is prompting regulators to develop guidance on AI governance, explainability and enhanced monitoring of AI-enabled processes in the financial sector.
What is one underrated cybersecurity innovation today that you believe will become critical for the Middle East’s BFSI sector over the next few years?
One of the most underrated cybersecurity innovations today, and yet one that is likely to become critical for the Middle East’s banking, financial services and insurance (BFSI) sector over the next few years, is behaviour-based analytics, which has become deeply integrated into security operations centre (SOC) functions and fraud detection systems. Numerous financial institutions still rely heavily on static, rule-based systems that trigger alerts based on fixed thresholds or known attack signatures. While effective against traditional threats, these approaches struggle to detect modern attacks that rely on lateral movement, living off the land (LOTL) techniques and sophisticated social engineering.
In contrast, behaviour-driven analytics establishs dynamic baselines for users, devices, applications and APIs. It continuously monitors the way accounts are accessed, transactions are executed and systems communicate, enabling early detection of anomalies that signal potential fraud or intrusion. These capabilities closely mirror the patterns observed in recent high-impact attacks on banks and fintechs across the region. For GCC banks navigating rapid cloud adoption, open banking frameworks and increasing use of AI in core operations, behavioural analytics is becoming essential. It allows institutions to distinguish legitimate high-volume digital activity from subtle intrusions, as highlighted in the report titled ‘2025 Global Digital Trust Insights – Middle East findings’.
Reflecting this shift, Paramount’s advisory and SOC services in the region are increasingly promoting a transition from purely rule-driven monitoring to a blended model that combines behavioural analytics, traditional rules, and threat intelligence. This integrated approach significantly improves detection speed and reduces false positives in complex Middle Eastern financial environments.
From the Paramount SOC’s perspective, approximately how many security incidents or threats have been monitored and mitigated this year
Over the last year we have issued over 592 critical advisories and mitigated them. Critical advisories are those that have the potential to halt business operations significantly.
The year 2026 has just begun, and we have issued nearly 100 advisories already.
Apart from critical advisories we have issued regular 318 advisories this year while the number stood at 2208 last year . We have just begun the year, but the number of alerts shows an increasing trend.
What types of cyber threats are most frequently detected and addressed by the SOC?
During the fiscal year 2024–2025, the most frequently detected threats identified by Paramount’s SOC include phishing and credential theft leading to account takeover, often using highly localised and AI-generated lures. SOC teams also regularly respond to ransomware and data extortion campaigns, alongside API, web application, and DDoS attacks targeting digital banking platforms. Moreover, cloud misconfigurations and excessive access permissions remain a persistent risk, frequently identified through continuous monitoring and threat hunting.
How can C-suite leaders better prepare their organisations, and what proactive steps should banks take to stay ahead of fraud and cyber threats?
For banks across the GCC region, C-suite leaders need to treat cyber resilience as a core board-level business capability, and not simply as a technical or IT function. With cyber threats having direct implications for financial stability, reputation, and regulatory compliance, leadership should embed cyber risk into enterprise risk management frameworks and board reporting. Major threat scenarios such as prolonged digital channel outages, data extortion incidents, or systemic third-party failures should be quantified and reviewed alongside credit and liquidity risks, in line with evolving GCC regulatory expectations. Leaders should further align their cyber strategies with national cybersecurity frameworks and central bank guidance, using independent maturity assessments to identify gaps and prioritise investments through 2026.
From an operational and technology perspective, adopting a zero-trust approach across identities, devices, networks and applications is becoming essential, particularly in API-enabled and cloud-based banking environments. This should be supported by strong SOC and incident response capabilities, whether in-house or through specialised providers such as Paramount, to ensure 24/7 monitoring, rapid containment and documented playbooks for both regulators and customers. Banks also need to invest in advanced fraud analytics and behaviour-based monitoring to detect account takeover and payment fraud, particularly as AI tools make phishing and social engineering more convincing, as witnessed in recent UAE ransomware trends.
Equally important is rigorous third-party and supply chain risk management. This includes structured security due diligence and continuous monitoring of fintech partners, cloud providers and critical vendors, given the growing risk of indirect compromised paths into Gulf financial institutions. Finally, C-suite leaders should actively promote a strong cyber resilience culture. This involves running realistic simulations of ransomware, data leaks, and payment fraud scenarios to sharpen organisational readiness and showcase proactive resilience to regulators, customers and shareholders.
Given the distinct regulatory, cultural, and operational landscape of the GCC, what makes cybersecurity in the region’s BFSI sector uniquely challenging compared to the US or Europe?
Cybersecurity in the GCC region’s BFSI sector is uniquely challenging because financial institutions operate at the intersection of rapid digital transformation, high geopolitical relevance and complex, multi-layered regulation. From a regulatory standpoint, institutions in the region must comply simultaneously with national cybersecurity authorities, central banks, and in some cases, free zone regulators. These entities impose detailed requirements on controls, data protection and incident reporting, creating a more fragmented and demanding compliance landscape than in many single-jurisdiction markets. The situation is further complicated by strict data residency and data sovereignty rules, which significantly influence how banks can design and deploy cloud, analytics, and cross-border platforms.
Operationally, GCC banks are advancing quickly into digital, mobile and open banking services, often faster than ecosystem-wide security maturity. While this supports financial inclusion, it also expands the attack surface through APIs, cloud services, and fintech partnerships. At the same time, the Gulf region has become one of the most actively targeted regions for financially motivated cybercrime and disruptive attacks, with banks and fintechs featuring prominently in 2024–2025 reports on ransomware, DDoS campaigns and sophisticated fraud schemes. The combination of rapid innovation, partner security, high attacker interest and evolving regulatory expectations creates a risk profile that is distinct from more established markets in North America and Europe.
In response, Paramount’s work with GCC BFSI clients focuses on developing region-specific security architectures and systems rather than simply importing models from other geographies. This includes designing frameworks aligned with local regulatory obligations, regional threat intelligence and the operational realities of Middle Eastern institutions as they evolve through 2026.
Financial
PATRIZIA appoints Hassan Awada as Senior Executive Officer to lead and accelerate Middle East expansion
PATRIZIA, a global investment manager in real assets, has announced the appointment Hassan Awada as Senior Executive Officer (SEO), MENA. Based in ADGM, the international financial centre of the UAE’s capital, Abu Dhabi, Awada will lead the continued growth of PATRIZIA’s business across the MENA region, with a focus on deepening relationships with institutional investors and strategic partners and providing access to PATRIZIA’s international real assets investment platform.
Awada brings over 20 years of experience advising institutional investors across the full investment lifecycle, including origination, structuring, execution and asset management. Prior to joining PATRIZIA, he held senior roles at Kroll, Cornerstone Capital, Gleacher Shacklock, PwC and EY.
Konrad Finkenzeller, Head of Client Division at PATRIZIA, commented: “The Middle East is a key strategic region for PATRIZIA, and we continue to see strong demand from investors for direct exposure to high-quality real estate and infrastructure opportunities globally. Hassan’s appointment strengthens our presence on the ground and enhances our ability to deepen relationships with regional investors and connect them with PATRIZIA’s global investment platform.”
Hassan Awada, SEO MENA at PATRIZIA, added: “Real assets have long underpinned Middle Eastern economies and will continue to play a central role in the region’s growth. Meeting increasingly sophisticated investor needs requires tailored, strategic solutions. With its global platform and 42-year track record, PATRIZIA is well positioned to deliver. Our focus will be on building long-term partnerships with investors across the region and supporting their access to PATRIZIA’s global investment capabilities, aligned with their strategic priorities and long-term objectives.”
Arvind Ramamurthy, Chief Market Development Officer, ADGM, said: “This appointment reflects the firm’s strong growth trajectory in the Middle East and its commitment to expanding from Abu Dhabi. It also underscores ADGM’s role as a leading international financial centre, enabling firms to establish and scale their regional presence from the capital.”
With EUR 17.5 billion in Living assets under management, PATRIZIA is one of Europe’s largest residential investment managers and continues to grow its platform across major urban markets. The firm is currently delivering new housing across a number of European markets, including Germany, UK & Ireland, Spain and Belgium, reflecting the scale of its European platform. Alongside Living, PATRIZIA is expanding its infrastructure platform across energy, digital and smart city assets, supporting the transition to low-carbon and connected economies while delivering long-term, resilient returns for investors.
Financial
Fimple adds five GCC financial institutions in first year, targets doubling regional customer base
Fimple, an AI-native, API-first, composable financial platform, has signed five financial institutions across the GCC within its first year in the region and plans to double its regional customer base.
Fimple established its Dubai presence in October 2025 and has grown from zero to five GCC customers in 12 months. The region now accounts for close to a fifth of its global customer base of more than 35 financial institutions across 10 countries, making it the company’s fastest-growing region.
The company has also opened an office in Riyadh and plans to expand its customer and delivery presence across the GCC, serving institutions with teams based within the region.
Fimple’s regional growth comes as the UAE continues to advance its ambitions across Islamic finance and financial technology. Under the UAE Strategy for Islamic Finance and Halal Industry, the country aims to increase local Islamic bank assets from AED 986 billion to AED 2.56 trillion by 2031. (Source: UAECabinet.ae)
Dubai is also advancing its ambitions in AI-enabled financial services, with the Dubai International Financial Centre (DIFC) announcing plans in 2026 to become the world’s first AI-native financial centre. (Source: Dubai Media Office/DIFC)
“The UAE is an important market for Fimple because financial institutions here are moving quickly on both Islamic finance and new technology,” said Amr Kandel, GCC Country Manager and Product Director at Fimple. “Banks want to launch products faster, respond to local market needs and modernise without having to change everything at once. The growth we’ve seen in our first year shows there is real appetite for that.”
Islamic finance is a key driver of Fimple’s growth in the GCC. The platform enables financial institutions to run conventional and Islamic finance within the same system, with a range of Sharia-compliant financing and investment structures built into its product engine.
Fimple’s regional customers include Mawarid Finance, a UAE Islamic finance provider that entered into a strategic agreement with Fimple in June 2026.
As banks look to move AI from pilot projects into wider use, Fimple says the underlying core banking infrastructure is becoming increasingly important.
“Banks are already experimenting with AI, but the systems underneath need to be ready for it,” Kandel said. “If the core can’t provide the right data or connect easily with new technology, AI can get stuck at the pilot stage. That’s why the core matters.”
Fimple has built three banking AI agents covering independent audit report processing, customer intelligence from official notices and risk screening across official sources. The agents operate on the Fimple platform with human approval required for each action and full traceability. Further agents are planned as part of the company’s 2026–2027 roadmap.
According to Fimple, it implements a full working core in three to six months on average. Its composable architecture also enables financial institutions to connect selected modules to existing systems rather than replacing their entire core infrastructure at once.
“The GCC has become our fastest-growing region in just one year, and we expect to double our customer base here,” said Mücahit Gündebahar, CEO and Co-founder of Fimple. “We are growing our team and presence in the region so we can support customers locally as we expand across the GCC.”
Fimple will participate as a Gold Sponsor of Seamless Middle East 2026, taking place from Sept. 22–24 at Dubai World Trade Centre. The company will exhibit at stand G64, with Kandel delivering the session “Beyond the AI Hype: Why the Future of Banking Depends on an AI-Ready Core” on Sept. 23 at Stage 1, Fintech Forum.
Financial
Al Masraf and Moody’s Sign Strategic Agreement to Strengthen Risk Intelligence and Credit Capabilities
Al Masraf has signed a strategic agreement with Moody’s, a global provider of financial intelligence and risk assessment, marking an important step in strengthening the Bank’s risk management and credit capabilities through enhanced data, insights and technology.
The agreement was formalized during a signing ceremony held in Abu Dhabi, bringing together senior leadership from Al Masraf and Moody’s. The collaboration reflects both organizations’ commitment to leveraging advanced intelligence and risk expertise to support informed, data-driven decision-making in an increasingly complex financial environment.
As risks become increasingly interconnected and the financial landscape continues to evolve, access to timely, reliable and actionable intelligence is becoming essential for financial institutions. Through its combination of data, intelligence, risk expertise and technology, Moody’s helps organizations better understand interconnected risks.
The partnership will further support Al Masraf’s continued focus on strengthening its risk management framework, enhancing credit decision-making and building resilient, forward-looking capabilities that support sustainable growth.
Commenting on the occasion, Fuad Mohamed, CEO of Al Masraf, said: “At Al Masraf, we believe that sustainable growth is built on the strength of our ability to understand risk, anticipate change and make informed decisions. Our collaboration with Moody’s represents an important step in advancing our risk and credit capabilities through deeper intelligence, data and technology.”
He continued: “As the financial landscape continues to evolve, partnerships of this nature enable us to strengthen our resilience, enhance decision-making and create greater value for our customers and stakeholders. We look forward to building on this collaboration as we continue to shape a more agile, intelligent and future-ready Al Masraf.”
“We are delighted to partner with Al Masraf on an important step in modernizing its corporate lending operations. By bringing greater automation, efficiency, and insight to the credit journey, Moody’s is helping the bank build a future-ready operating model that enables faster, better-informed lending decisions, strengthens governance, and enhances risk management.” said Wael Jadallah, Managing Director, Head of Asia Pacific and Middle East at Moody’s.
Senior representatives from both organizations attended the signing ceremony.
Representing Al Masraf were Fuad Mohamed, Chief Executive Officer; Moataz Khalil, Chief Wholesale Banking Officer; Safeya Almarzooqi, Chief Credit Officer; Mirel Baila, Acting Chief Operating Officer; Rohit Kumar, Chief Risk Officer; and senior representatives from the Bank’s Wholesale Banking, Credit, Risk, Information Technology, Islamic Banking, Corporate Banking, Project Management and Business Management functions.
Representing Moody’s were Wael Jadallah, Managing Director, Head of Asia Pacific and Middle East; Brendan Gavaghan, Senior Director, Middle East; Raghavendra Katagade, Director, UAE; Blaine Connan, Director, UAE; Ali Abdullah, Director, UAE; and Anand Thirunellai Radhakrishnan, Senior Director, Middle East & Europe.
The agreement underscores Al Masraf’s commitment to continuous innovation and adopting advanced capabilities that strengthen its ability to navigate an evolving risk environment, while supporting the Bank’s broader ambition to deliver sustainable growth and enhanced value to its customers and stakeholders.
-
News11 years ago
SENDQUICK (TALARIAX) INTRODUCES SQOOPE – THE BREAKTHROUGH IN MOBILE MESSAGING
-
Trending11 months agoOPPO A6 Pro 5G Review: Reliable Daily Driver
-
Tech News2 years agoDenodo Bolsters Executive Team by Hiring Christophe Culine as its Chief Revenue Officer
-
VAR1 year agoMicrosoft Launches New Surface Copilot+ PCs for Business
-
Automotive2 years agoAGMC Launches the RIDDARA RD6 High Performance Fully Electric 4×4 Pickup
-
Tech Interviews3 years ago
Navigating the Cybersecurity Landscape in Hybrid Work Environments
-
Tech News2 years agoToshiba Announces MG10-D Series of Enterprise HDDs with Capacities up to 10TB
-
Tech News1 year agoNothing Launches flagship Nothing Phone (3) and Headphone (1) in theme with the Iconic Museum of the Future in Dubai


