Dr. Emad Fahmy, Systems Engineering Manager for NETSCOUT in the Middle
The Middle East is increasingly becoming a testbed for some of the most intricate and ongoing cyber operations globally. Due to its significant position in international trade, energy production, and rapid advancements in digital technology, the region is facing a surge in sophisticated DDoS attacks driven by AI, aimed at destabilizing key national strategies in telecommunications, energy, finance, and education. In this interview, Dr. Emad Fahmy discusses the motivations behind these attacks on Saudi Arabia and the UAE, the evolution of new attack strategies, and the measures that both governments and businesses should adopt to enhance their resilience ahead of future threats.
Reasons for the Region’s Status as a Cyber Battleground
Positioned at the crossroads of crucial global trade and digital expansion, the Middle East is particularly appealing to cyber adversaries looking to experiment with innovative DDoS tactics, including those driven by AI. During the first half of 2025, the EMEA region recorded over 3.2 million DDoS incidents, surpassing all other monitored areas worldwide.
Impact of Cyber Attacks on National Strategies in Key Sectors
Industries such as telecommunications, energy, and finance are vital for national stability. Disruptions from DDoS assaults present both operational hazards and strategic weaknesses. It is essential for national strategies to prioritize DDoS mitigation as a fundamental aspect of digital security, incorporating early detection systems, automated responses, and greater collaboration between government entities and critical infrastructure providers.
Strategies for Increasing Resilience Before Future Attacks
Fortifying resilience begins with enhancing visibility. Organizations should adopt hybrid mitigation approaches—both on-premise and cloud-based—anchored by real-time threat intelligence and automated management. Governments can boost preparedness by mandating coordinated measures across sectors, ensuring that service providers are equipped with the necessary telemetry and tools to minimize the time required for large-scale mitigation.
Discussion on Saudi Arabia:
Insights on the Scale and Consequences of Record DDoS Attacks
In the first half of 2025, Saudi Arabia experienced more than 270,000 DDoS attacks, marking the highest frequency in the region. One attack peaked at an astonishing 1 Tbps, utilizing 24 distinct vectors in a single assault. These attacks not only tested perimeter defenses but also sought vulnerabilities across satellite communications, energy distribution, and cloud services, posing significant implications for the country’s digital transformation efforts.
Influence of AI-Powered Botnets and DDoS-for-Hire Services on Regional Cybersecurity
The emergence of DDoS-for-hire services, coupled with AI-enhanced automation, has lowered the entry barrier for orchestrating complex attacks. Botnets are now capable of adjusting during attacks, altering their vectors, and exerting pressure for longer periods than ever. This evolution implies that traditional manual responses are no longer adequate, as the pace of threats continues to escalate, with attackers rapidly innovating.
Saudi Arabia’s Target Status in 2025
Saudi Arabia is at the forefront of regional digital advancements, particularly in smart cities, e-government, and telecommunications, making it an attractive target for adversaries aiming to impede economic growth. The combination of high-value infrastructure and visibility on the global stage makes the Kingdom appealing to both politically and financially motivated attackers.
Discussion on the UAE:
Evolving Tactics in Regional Cyber Conflicts
Threat actors are transitioning from short, intense attacks to prolonged, adaptable campaigns. In the UAE, the average duration of an attack was recorded at 27.34 minutes, with some lasting over three hours. This shift indicates a growing tendency for attackers to leverage time and complexity rather than solely brute force to undermine services and circumvent defenses.
Why AI-Enabled Botnets Target the UAE
The UAE’s rapid embrace of digital technologies across sectors such as fintech and cloud computing makes it a high-priority target. AI-driven botnets allow adversaries to dynamically identify and exploit vulnerabilities. Operating at machine speed, these systems can mix various attack types instantaneously, leading to a higher incidence of intricate, targeted assaults on the UAE.
Effects of Extended Attacks on the Country’s Financial Systems and Innovation
Prolonged DDoS incidents pose severe risks to service availability, customer trust, and the integrity of transactions. With the UAE’s financial sector relying heavily on continuous digital operations, these attacks, which can last from seconds to several hours, increase their vulnerability. Innovation hubs must design their systems to endure, mitigate, and adapt to these extended, multi-vector attacks in real time.
The Regional Consequences of Adopting a Patient Approach by Attackers
The trend towards sustained disruption signifies an evolution in attack strategies. Adversaries are employing “slow burn” tactics that wear down mitigation measures, prolong detection, and exert continuous pressure on service providers. For the region, this highlights the necessity for proactive defense strategies that account for longer dwell times as opposed to merely preparing for bandwidth surges.