ObsidioMESA

DDoS Resilience Is a Critical Infrastructure Problem, Not Just a Banking One

Nader Salem· Obsidio MESA ·July 30, 2026
DDoS Resilience Is a Critical Infrastructure Problem, Not Just a Banking One

Most of the conversations I've had over the past few months around DDoS resilience have been with financial services institutions. Banks, insurers, payment infrastructure providers. That makes sense. Financial services was the first sector where regulators started asking specific questions about operational resilience, and it remains the sector where the consequences of downtime are most immediately visible.

But the assumption that DDoS risk belongs primarily to the financial sector is one the threat data no longer supports.

What the Numbers Actually Show

Between Q2 2025 and Q1 2026, DDoS attacks accounted for 42% of successful cyberattacks across the Middle East. By Q1 2026 that figure had risen to 83% of attacks in the quarter, driven by a sharp escalation in regional tensions and the emergence of coordinated hacktivist campaigns targeting public infrastructure at scale.

Government institutions accounted for 45% of targeted national-level organisations during that period. Telecommunications followed. Energy, aviation, and healthcare were all in the mix.

In the UAE, wired telecommunications carriers were the most heavily targeted sector in the second half of 2025, recording more than 6,300 DDoS attacks with average durations exceeding 1,000 minutes. Saudi Aramco and a major cloud data centre in the UAE were among the named targets of state-linked cyber operations during the regional escalation at the beginning of the year.

These are not isolated incidents affecting one sector. They represent a broad and sustained campaign against the infrastructure that Gulf societies depend on to function.

Why Critical Infrastructure Is Different

The financial services case for DDoS resilience is built on a combination of regulatory pressure and commercial consequence. A bank that goes offline loses transactions, triggers reporting obligations, and faces reputational damage that takes months to repair. Those are serious stakes, but they are largely contained within the institution and its customers.

Critical national infrastructure operates on different terms entirely.

When a telecommunications operator goes offline, it doesn't just affect the telco. It affects every business, hospital, government service, and individual behind it. When energy infrastructure is disrupted, the consequences can extend to physical safety and national security. When aviation systems come under attack, the ripple effects reach supply chains, travel, and logistics across borders.

At the SAMENA Council Leaders' Summit 2026, Dr. Mohamed Al Kuwaiti, Head of Cybersecurity for the UAE Government, framed the current environment in terms that go well beyond commercial risk management. What the UAE and the GCC are facing, he said, is a hybrid war encompassing conventional threats, cyber threats, and disinformation designed to undermine public trust.

That framing matters. DDoS attacks against critical infrastructure are not an operational inconvenience. They are a tool of strategic disruption, designed to create uncertainty and erode confidence in the institutions that people depend on.

The Resilience Gap in Critical Infrastructure

The financial sector has spent several years being pushed by regulators toward a clearer standard of evidence around resilience. Frameworks like SAMA's Cybersecurity Framework, the CBUAE's operational resilience requirements, and BNM's RMiT have all moved in the direction of requiring institutions to demonstrate that their controls actually work under realistic conditions, not just that the controls exist.

Critical infrastructure operators are at an earlier stage of that journey, but the direction of travel is the same.

Computer Weekly's May 2026 analysis quoted Gaurav Mohan of Netscout describing the pressure on Gulf telecommunications infrastructure in terms that apply well beyond that sector: "This is not sporadic disruption. It is continuous operational strain."

The traditional model of resilience testing was built for a world of occasional, identifiable incidents. You test periodically, review the results, update your controls. The threat environment that Gulf critical infrastructure operators are actually facing is not occasional. It is persistent, distributed, and running on attack durations measured in days and weeks rather than hours.

What Demonstrable Resilience Looks Like for Critical Infrastructure

Financial services has spent several years moving from assumed resilience to demonstrable resilience. Every operator of critical national infrastructure needs to make the same journey.

That means testing with distributed traffic from residential IP ranges across dozens of countries, traffic that looks like legitimate users until it doesn't. It means multi-vector simulations that run long enough to test whether organisations can maintain critical services under sustained pressure, not just whether mitigation tools activate. And it means producing evidence that can withstand scrutiny: a tamper-proof, cryptographically attested report that documents what was tested, under what conditions, and what the results showed.

For operators of critical national infrastructure, the question of whether their resilience can be demonstrated rather than assumed is becoming as urgent as it has been for regulated financial institutions. The threat data and the people responsible for national cybersecurity are saying the same thing: this is not a future concern.

If you are responsible for the resilience of critical infrastructure and you haven't had this conversation yet, it is worth having.

Nader Salem is the regional partner for Obsidio in the Middle East and Southeast Asia.

← Back to Insights

Ready to see what your defences look like under real pressure?

A demonstration takes less than an hour. You will see exactly how Obsidio runs a realistic DDoS simulation against your infrastructure, what the output looks like, and how it maps to your regulatory obligations.