ObsidioMESA

The UAE Cyber Factory Is a Necessary Step. The Next Challenge Is Validation.

Nader Salem· Obsidio MESA ·June 3, 2026
The UAE Cyber Factory Is a Necessary Step. The Next Challenge Is Validation.

The numbers are stark.

According to the UAE Cyber Security Council, the UAE is experiencing more than 800,000 cyber attacks every day against public and private sector organisations. Energy, finance, aviation, telecommunications and government services remain among the primary targets.

Against that backdrop, the launch of the UAE Cyber Factory by the UAE Cyber Security Council and CPX is the kind of initiative the region needs.

AI-powered threat detection, sovereign cyber capabilities, real-time response, and enhanced protection for critical infrastructure are all essential components of a modern national cyber defence strategy.

But initiatives like the Cyber Factory also raise another important question.

How do organisations know the infrastructure they're protecting will actually perform when it comes under real attack?

Understanding the Threat

Before getting to that question, it's worth understanding one of the most common threats facing critical infrastructure today: Distributed Denial of Service, or DDoS.

In simple terms, a DDoS attack overwhelms systems with traffic from thousands of devices simultaneously until services slow down or become unavailable.

The objective isn't necessarily to steal information.

It's to disrupt operations.

An attack against an online banking platform can prevent customers from accessing accounts or making payments.

An attack against an airport system can disrupt passenger services.

An attack against a logistics platform or port infrastructure can impact supply chains far beyond the organisation directly involved.

The consequences are operational, financial, and reputational.

Protection Versus Resilience

This is why initiatives like the Cyber Factory matter.

The ability to detect threats, identify malicious activity, and coordinate response efforts is critical.

At the same time, organisations are increasingly recognising that protection and resilience are not the same thing.

Protection focuses on preventing disruption.

Resilience focuses on maintaining critical services when disruption occurs.

That distinction is becoming increasingly important as boards, regulators, and executive teams shift their focus from controls to outcomes.

The question is no longer simply, "What protection do we have in place?"

It's increasingly, "How do we know it works?"

That is where resilience validation enters the conversation.

The Rise of Resilience Validation

For DDoS resilience specifically, organisations are beginning to look beyond traditional assessments and explore ways to validate how infrastructure behaves under realistic attack conditions.

Through my work with Obsidio, a Swiss DDoS resilience testing platform developed by Papers AG in Zug, I've seen growing interest from financial institutions and critical infrastructure operators looking to move beyond assumptions and generate evidence of how their environments perform under pressure.

Rather than relying solely on synthetic traffic generation, Obsidio uses real distributed devices across 175 countries to emulate botnet behaviour and validate how infrastructure responds under realistic conditions. What is, effectively, an ethically sourced, fully compliant botnet attack that can be tailored and controlled.

The Swiss banking sector has been among the early adopters. One of the five largest Swiss banks now runs weekly resilience tests through Obsidio as part of its hardening cycle.

If the methodology meets the standards required by institutions as conservative as that about their infrastructure, it's worth paying attention to.

This isn't about replacing existing cyber investments.

It's about understanding how those investments perform when they matter most.

What Comes Next

The UAE Cyber Factory represents an important investment in the country's cyber future and a significant step toward strengthening national cyber sovereignty.

The next challenge for many organisations will be turning resilience from something that is assumed into something that is demonstrably proven.

That conversation isn't emerging.

In the UAE, it's already here.

Nader Salem is the regional partner for Obsidio in the Middle East and Southeast Asia.

← Back to Insights

Ready to see what your defences look like under real pressure?

A demonstration takes less than an hour. You will see exactly how Obsidio runs a realistic DDoS simulation against your infrastructure, what the output looks like, and how it maps to your regulatory obligations.