Writing · Gulf Market
The Gulf has mandated cybersecurity awareness training. Nobody told the training to speak Arabic.
By Mahmoud Lotfy · Mar 2026 · 8 min read
Banks, government entities, telecoms, and financial institutions. The organisations that power the Gulf economy. All legally required to train their people on cybersecurity. This is not a future ambition. It is the law today, across all six member states, enforced with penalties, audits, and in serious cases, the suspension of operating licences.
Saudi Arabia's National Cybersecurity Authority Essential Cybersecurity Controls, updated to ECC-2:2024 in October 2024, explicitly mandate that a cybersecurity awareness programme must be developed, approved, and implemented periodically through multiple channels. Non-compliance can now result in substantial fines and the revocation of licences, following December 2024 regulations that gave the NCA formal enforcement authority for the first time.
"The attack is designed around Gulf professional culture. The training is designed around a generic employee who does not exist."
The UAE's Information Assurance Standard requires organisations to develop an awareness and training programme for all employees, a named control, not a recommendation. As of 2026, compliance is no longer voluntary. Companies must execute security-by-design, with failure to adhere resulting in penalties ranging from AED 100,000 to over AED 5 million.
Qatar launched its National Cyber Security Strategy 2024 to 2030 with awareness as a named pillar. Bahrain, operating in the highest tier of the Global Cybersecurity Index, has established training requirements tied to its national cybersecurity framework. Oman's Basic Controls Standards mandate awareness programmes across government entities. Kuwait's newly established National Cyber Security Center issued binding data classification and governance regulations in October 2025.
By the end of 2025, all six GCC member states had either introduced or updated their national cybersecurity frameworks. The direction is clear and consistent: awareness training is not optional, and enforcement is tightening.
And yet.
Walk into almost any enterprise across the Gulf and ask what their security awareness programme looks like. The answer is almost always the same. A global platform was purchased. Modules were assigned. Completion certificates were collected. The compliance box was ticked.
Nobody learned anything that changed how they behave.
This is not a criticism of the security teams running these programmes. It is a structural problem that the entire industry has accepted without question. The platforms dominating this market were built for Western enterprise contexts and localised as an afterthought. Their content is generic by design. A CFO at a Riyadh bank and a junior analyst at a Dubai logistics company sit through the same module, in the same language, with the same examples, facing threats that are described as if they are happening somewhere else entirely.
They are not happening somewhere else. In the GCC, social engineering attacks are frequently written in perfect Arabic, referencing local events, religious holidays, and regional regulatory updates. The attack is designed around Gulf professional culture. The training is designed around a generic employee who does not exist.
The Middle East cybersecurity market is valued at $16.75 billion in 2025 and projected to reach $26.04 billion by 2030. Billions are flowing into tools, infrastructure, and compliance programmes. And one CISO in the region put it plainly: "We spent $3 million on tools, we're still not compliant, we still got breached, and my team is exhausted."
The frameworks are asking the right question
They are simply accepting the wrong answer.
What Gulf enterprises actually need is training that knows who the person is. Their role, their organisation, their language, their actual threat exposure. Not a module retrieved from a library built in San Francisco. A session generated for this person, at this organisation, aligned to the frameworks they are actually being audited against.
The regulatory foundation across the GCC is solid. The mandate is clear, the penalties are real, and the enforcement is arriving. What has been missing is a product built natively for this market, not retrofitted for it.
That gap will not stay empty for long. It shouldn't.