Over the past year, I've had a number of conversations with security leaders across the GCC and Southeast Asia. CISOs, heads of infrastructure, risk and compliance teams at banks, telcos, and government entities. And there's a question I've started asking in almost every one of those conversations.
"When did you last test your DDoS resilience under conditions that actually resemble a real attack?"
The answers are telling. Most organisations have protection in place. Firewalls, scrubbing centres, mitigation tools. The stack exists. But when it comes to whether that stack has ever been genuinely put under pressure, the honest answer is usually some version of:
"We think we're covered."
That used to be an acceptable answer. I'm not sure it still is.
The Gap Nobody Talks About
Here's the thing about assumed resilience. It's not the result of negligence. Security teams are doing exactly what they're supposed to do. They're deploying the right tools, following the right frameworks, briefing their boards, and ticking the right boxes.
But there's a difference between having protection and knowing it works. That difference usually reveals itself at the worst possible time, during an actual incident, with customers and regulators watching.
Meaningful resilience testing has historically been difficult to do well. Testing against live infrastructure carries operational risk. Synthetic lab environments don't replicate real-world attack conditions closely enough to give you genuine confidence. And even when testing does happen, the output is often an internal document that lives somewhere in a shared drive rather than something you could put in front of a regulator and feel good about.
So the gap persists. Not because anyone wants it to, but because closing it has never been straightforward.
What Regulators Are Starting to Ask
This is where I think the conversation is shifting, and faster than many organisations realise.
Across the GCC and Southeast Asia, regulators are increasingly moving in the same direction. CBUAE, SAMA, NESA, NCA, OCA, and Malaysia's RMiT are all placing operational resilience higher on the agenda, and the expectations are getting more specific.
It's no longer enough to have controls in place. The question regulators are increasingly asking is whether those controls have been validated, under what conditions, and whether the evidence is documented in a way that stands up to scrutiny.
That's a meaningfully different question. And it requires a meaningfully different answer.
For DDoS resilience specifically, validation needs to reflect how attacks actually happen. Not controlled simulations using synthetic traffic, but testing that uses distributed, residential IP-based traffic patterns that resemble what real threat actors deploy. The kind of traffic that initially looks like legitimate user activity and exposes gaps in mitigation tools that were calibrated for more obvious attack signatures.
And the output of that testing matters as much as the testing itself. A cryptographically attested report tied to a recognised framework is something you can present to an auditor or regulator with confidence. An internal summary from a limited test environment is not.
Compliance Versus Evidence
I think about this as the difference between compliance and evidence.
Compliance tells you whether you've done the required things. Evidence tells you whether those things work.
The two are related, but they're not the same. And in a threat environment that keeps getting more sophisticated, the gap between them becomes harder to ignore.
Organisations I've spoken to that have already started making this shift describe a few things consistently. They have a clearer picture of their actual exposure rather than their assumed exposure. They have documentation that survives regulatory scrutiny. And they have a baseline they can measure against over time, so when they make changes to their infrastructure or mitigation stack, they can verify the effect rather than assume it.
There's also a commercial dimension to this that doesn't get discussed as openly as it should. In markets where regulatory expectations are rising, the ability to demonstrate resilience clearly and credibly is becoming a differentiator. It changes conversations with enterprise customers, insurers, and counterparties who are doing their own due diligence.
Where I Think This Is Heading
I believe operational resilience validation is going to become a much bigger conversation across this region over the next few years, for the same reason it already has in parts of Europe.
The digital transformation happening across the GCC is real and it's accelerating. Cloud infrastructure, digital banking, AI-driven services, smart city platforms. All of it increases dependency on resilient systems. And as governments and enterprises position themselves as serious technology operators, resilience stops being purely a cybersecurity question and becomes part of national and institutional credibility.
The organisations that are ahead of this will be the ones that treated resilience testing as an ongoing capability rather than a one-time exercise. The ones integrating it into assurance cycles, vendor assessments, and board-level reporting. The ones that, when a regulator asks for evidence, can produce something credible rather than scrambling to find it.
Assumed resilience served its purpose. What's being asked for now is proof.
Nader Salem is the regional partner for Obsidio in the Middle East and Southeast Asia.
← Back to Insights