The UAE ranked sixth globally for cyber activity affecting Microsoft customers during the first half of 2026. The country also ranked second across the Middle East and Africa, according to Microsoft’s 2026 Digital Defence Report.
Microsoft based the findings on its visibility across the global digital ecosystem. The company analyses more than 165 trillion security signals each day.
The report arrives as the UAE expands artificial intelligence across government, business and critical infrastructure. At the same time, Microsoft warns that AI is changing both cyberattacks and cybersecurity defences.
AI Accelerates Cyber Threats
Microsoft said attackers are using AI to operate faster and at greater scale. Meanwhile, defenders are using similar capabilities to detect, investigate and disrupt threats more quickly.
The report also identifies identity as a major route into organisations. Attackers continue to target accounts, credentials and users to gain access. Therefore, Microsoft recommends stronger authentication and tighter protection for high-value identities.
AI is also creating new security exposure. As organisations deploy more AI systems and agents, they introduce additional data, identities and access points. Consequently, companies must secure these elements throughout the AI lifecycle.
Microsoft highlighted the growing agentic attack surface as another concern. The report identifies risks involving AI models, identities, data, tools and connected systems. Moreover, Microsoft said AI can compress parts of the attack chain from days to seconds.
The report also points to a rise in reported software vulnerabilities. Nearly 40,000 CVEs were disclosed in the first half of 2026, according to Microsoft. The company said the annual total could roughly double compared with previous years.
UAE Expands AI-Powered Cyber Defence
The UAE is responding through closer cooperation between government and technology organisations. Microsoft, the UAE Cyber Security Council and Core42 recently announced plans to deploy Microsoft’s MDASH cybersecurity capability across UAE government entities.
MDASH uses AI models and automated analysis to identify vulnerabilities and prioritise risks. It also aims to help security teams respond to emerging threats more quickly.
Under the proposed rollout, the Cyber Security Council will support the adoption of responsible AI through the UAE’s National AI Test and Validation Lab. Meanwhile, Core42 will provide implementation and capacity-building support through its Sovereign Public Cloud offering.
The initiative also emphasises security, privacy, and operational resilience. Therefore, the partnership links AI adoption with measures designed to protect government systems and critical services.
Yazan Khasawneh, Director of Cyber Security at Microsoft UAE, said cybersecurity needs to become part of AI adoption from the beginning. He highlighted the need to secure identities, protect data and maintain continuity as organisations deploy AI.
Identity and Resilience Remain Priorities
Microsoft’s findings show that cyber risk increasingly extends beyond individual organisations. A compromised identity, supplier, platform or service provider can create consequences across connected organisations and sectors.
Consequently, Microsoft recommends stronger authentication, reduced dependence on passwords and faster incident response. It also recommends regular response exercises and systems designed to maintain critical operations during disruption.
The UAE’s position in Microsoft’s data comes as the country continues to expand digital government services and AI infrastructure. As a result, securing these systems has become increasingly connected to the country’s wider digital transformation.
At the same time, Microsoft’s report emphasises that AI presents opportunities for both attackers and defenders. Organisations can use AI to strengthen detection and response, while attackers can use the same technology to increase speed and scale.
For the UAE, the latest government and industry initiatives reflect that dual challenge. The focus is now shifting toward stronger identity protection, AI-aware security controls and resilience across increasingly connected digital systems.








