Something has shifted in the conversations I've been having with security and compliance teams across the GCC and Southeast Asia over the past year.
The questions coming from regulators have changed. Not dramatically, and not all at once. But the direction is consistent enough that it's worth paying attention to.
For a long time, the regulatory conversation around DDoS resilience was essentially a controls conversation. Do you have mitigation in place? What tools are you running? Who is your provider? The answers to those questions were enough to satisfy most audit processes.
That's no longer the case. The questions are getting more specific, and they're harder to answer with a policy document and a vendor contract.
Here are the three I keep hearing about.
Have You Actually Tested It?
The first question is deceptively simple. It isn't asking whether protection exists. It's asking whether that protection has ever been subjected to conditions that resemble a real attack.
Deploying a mitigation tool and knowing how it performs under sustained, distributed pressure are two different things. Most organisations can answer the first question confidently. Fewer can answer the second.
Regulators across the region are starting to draw that distinction explicitly. Bank Negara Malaysia's updated Risk Management in Technology policy, issued in November 2025, requires financial institutions to conduct realistic attack simulations against their infrastructure at least once every three years. The language is specific: realistic simulations, not synthetic tests from controlled environments.
The CBUAE and SAMA frameworks are moving in the same direction. The expectation is shifting from documentation of intent to evidence of performance.
Can You Prove It to Someone Who Wasn't in the Room?
The second question follows from the first. Even if testing has taken place, the output needs to be something a regulator, auditor, or board member can actually evaluate.
An internal summary document from an internal test is not that. It tells you what the team observed. It doesn't provide independent verification that the test reflected realistic conditions, that the methodology was sound, or that the results are accurate.
What regulators are looking for is evidence that can stand on its own. A tamper-proof, cryptographically attested report that documents what was tested, under what conditions, and what the results showed. Something that doesn't require the reader to take the security team's word for it.
This matters more than most organisations realise. The gap between "we tested our resilience" and "here is independently verifiable evidence that we tested our resilience under realistic conditions" is significant. One satisfies an internal review. The other satisfies an auditor.
Does Your Testing Reflect How Attacks Actually Happen?
The third question is the most technically specific, and the most important.
Modern DDoS attacks don't originate from a handful of recognisable data centre IP ranges. They come from distributed networks of compromised residential devices, smartphones, home routers, consumer IoT equipment, spread across dozens of countries. The traffic they generate carries the characteristics of legitimate users. It looks like normal activity until it doesn't, and by the time the picture becomes clear, the damage is already happening.
Most DDoS testing doesn't reflect this. Synthetic tests run from controlled environments generate traffic your mitigation tools can identify. They validate that your protection responds to conditions it was designed to recognise. They don't validate how your infrastructure performs when the traffic is indistinguishable from legitimate demand.
Akamai's latest research identified a 147% surge in advanced bot activity in late 2025, with sophisticated botnets capable of mimicking legitimate browser behaviour. The attack surface is evolving. Testing methodologies need to evolve with it.
When regulators ask whether resilience has been validated under realistic conditions, this is what they mean. Not whether the test was conducted, but whether the conditions of the test actually resembled the threat.
Where This Leaves Security Teams
None of this means that existing security programmes are inadequate. Most organisations in the region have invested seriously in DDoS protection and the frameworks around it. The point isn't to start over.
The point is that the standard of evidence is rising. Having protection in place is no longer the end of the conversation. The question that follows, the one regulators are asking and boards are starting to raise, is whether that protection has been validated in a way that produces credible, independently verifiable evidence under conditions that reflect how attacks actually happen.
Three of the five largest banks in Switzerland already run regular resilience tests that meet this standard. They operate under FINMA Circular 2023/1, one of the most demanding operational resilience frameworks in the world, and they have concluded that realistic simulation is the only way to generate the kind of evidence that framework requires.
The regulatory direction across the GCC and Southeast Asia is moving the same way. The organisations that get ahead of it won't be the ones with the most protection deployed. They'll be the ones who can answer all three questions with evidence rather than assurances.
Nader Salem is the regional partner for Obsidio in the Middle East and Southeast Asia.
← Back to Insights