Human risk

Phishing protection in Dubai, UAE

Our phishing protection in Dubai combines simulated phishing, awareness training aimed at the roles being targeted, impersonation and domain controls on the email platform, and a reporting workflow in which every reported message is investigated.

Hooded figure at a laptop in front of binary code, representing an attacker sending phishing messages
Why reporting matters

Why phishing protection measures reporting as well as clicks

Click rate is the percentage of staff who follow a link in a simulated phishing message. It is a useful measure, but it cannot be brought to zero, because a convincing message will deceive someone in any organisation.

The reporting rate is the percentage of staff who report the message. When a message is reported promptly, the security team can remove it from every mailbox that received it and block the sender. When it is not reported, the attack is discovered later, from its effects.

The programme is therefore built to make reporting simple: a one-click report button in the mail client, investigation of every report, and a reply to the person who reported it. Reporting rate is tracked from the first campaign alongside click rate.

Attack types

Four types of phishing attack the programme covers

These attacks do not rely on a malicious attachment, so attachment scanning at the gateway does not stop them on its own.

Credential harvesting

A message links to a fake sign-in page for a service staff use every day. It carries no malware, only a link to a page that copies the real one, and the password entered there is captured.

Business email compromise

A message that appears to come from a supplier or a director asks for a payment or a change of bank details. It contains no malware and no link, and depends on the request being accepted as genuine.

Spear phishing

A message written for one named person, using details taken from social media and the organisation's own website. Simulation templates are written for the roles most likely to receive this type of message.

Clone phishing

A copy of a genuine message the recipient has already received, resent with the link or attachment replaced. Because it is familiar, it is less likely to be questioned.

The programme

What phishing protection covers

The programme combines measurement and training for staff, technical controls on the email platform, and a defined response to reported messages.

Baseline simulation

An unannounced simulated phishing campaign is run before any training, so that the starting click rate and reporting rate are measured accurately.

Simulation programme

Campaigns are spread across each month, and the difficulty of the templates is increased as results improve, so the exercise continues to measure recognition of realistic attacks.

Targeted training

Training is assigned by role, in the languages the workforce reads, and is delivered at the point a member of staff clicks a simulated link.

Reporting and follow-up

Results are reported by department and role so that managers see the figures for their own teams. Staff who click repeatedly are supported individually with their manager.

Impersonation protection

Rules are configured around the names of executives, finance staff and the suppliers the organisation pays, so that messages imitating those senders are flagged or held.

Business email compromise defence

Detection rules for payment and bank-detail requests that carry no malware or link, so these messages are flagged for verification.

Domain authentication

SPF, DKIM and DMARC are configured and taken to an enforcement policy, so that messages sent as your domain by unauthorised senders are rejected.

Link and attachment handling

URLs are rewritten and checked at the time they are clicked, so that a link that was clean at delivery is examined again when a user follows it.

Report button deployment

A one-click report button is deployed in the desktop, web and mobile mail clients staff use, so that reporting does not depend on forwarding a message to a mailbox.

Reported mail investigation

Every reported message is investigated, and the person who reported it is told the outcome.

Tenant-wide remediation

A message confirmed as malicious is removed from every mailbox that received it, not only from the mailbox of the person who reported it.

Credential compromise response

When a password has been entered on a phishing page, the password is reset, active sessions are revoked and the account's access is reviewed.

How we work

How a phishing programme runs

Person at a desk with an email inbox on screen and a verified envelope icon, representing a reported message being checked

An unannounced simulation is run before any training, so that improvement is measured from a real starting point.

  • Run without advance notice to staff, so the result reflects normal behaviour
  • Results broken down by department and role
  • Reporting rate recorded alongside click rate from the first campaign

Frequency, difficulty and content are set for the organisation's workforce and the types of attack it receives.

  • Language mix matched to the workforce, not limited to English
  • Roles with payment authority given templates based on business email compromise attempts
  • Difficulty planned to rise over the programme, so staff learn the features of a real attack

Groups, the report button and allow-listing are configured before the first campaign is sent.

  • Groups synchronised from the directory so the target population stays current
  • Report button deployed to desktop, web and mobile mail clients
  • Allow-listing tested so that simulated messages are delivered and not filtered

Impersonation rules and domain authentication are configured alongside the awareness programme.

  • Impersonation protection tuned to named executives and paying suppliers
  • DMARC moved to an enforcement policy in stages, based on the reports received
  • Click-time URL checking enabled so that delivery-time scanning is not the only check

Simulations and training run to the agreed schedule, and the results are reviewed after each campaign.

  • Campaigns spread across the month so that staff are not warned by colleagues
  • Training assigned automatically when a simulated link is clicked
  • Reported messages investigated and the reporter told the outcome

The programme is measured against its own baseline and adjusted as the results change.

  • Progress measured against the original baseline as well as the previous campaign
  • Templates updated as attacker techniques change
  • Repeat clickers supported individually, with their manager involved
Compliance

Phishing awareness evidence UAE frameworks expect

Security awareness is a named control in several UAE frameworks, and each of them asks for records of the activity.

UAE Information Assurance Standards

The IAS expects documented security awareness activity with evidence of delivery and completion. Campaign records, completion rates and the click-rate trend are kept as the programme runs and can be produced for an audit without further preparation.

DESC ISR

Dubai government and semi-government bodies have comparable awareness requirements under DESC ISR. Records for each campaign provide the evidence an assessor asks for.

ADHICS and ISO 27001

Both require awareness training with records of completion. Reporting is broken down by group so an assessor can see coverage across the organisation as well as the aggregate figure.

UAE PDPL

Simulation results identify individuals, so they are personal data under the PDPL. Retention of and access to the results are configured to match your lawful basis, and results are reported by group, not by name.

Why iConnect

Why choose iConnect for phishing protection

Baseline before training

An unannounced baseline simulation is run before any training, so that improvement is measured against a real starting figure.

Reporting rate is the target

The programme tracks the reporting rate as well as the click rate, because early reporting allows a phishing message to be removed before it spreads.

Measurement, not entrapment

Results go to managers by department and role, not as a list of names. Staff who click are given a short piece of training at the time.

Every report is investigated

Reported mail is investigated and the person who reported it is told the outcome, so staff can see that reporting has an effect.

Both layers together

The awareness programme and the technical email controls are configured as one piece of work, so a message that passes the filters can still be recognised and reported.

Local delivery

Campaign design, training content and reporting are produced by our team in Dubai, in the languages your workforce reads.

Client feedback

What our clients say

“Whenever an issue arises, iConnect is there immediately: quick, efficient and proactive in keeping everything running without disruptions. iConnect has become a crucial part of our operations.”

Head of IT Infrastructure and Network SecurityDragon Oil
FAQ

Phishing protection questions

Annual training records show that staff completed a module. They do not show how staff respond to a realistic phishing message during a normal working day. A simulation programme measures that behaviour directly and repeats the measurement through the year, so the organisation has a current click rate and reporting rate.

Email security is the platform layer: the secure email gateway, filtering, encryption, data loss prevention and archiving. Phishing protection is the human layer: baseline measurement, simulated phishing, training for the roles being targeted, and the workflow for reported messages. The two are configured together.

Simulations are run as a measurement exercise, not as a test of individuals. Results are reported by department and role, and no list of names is circulated. A member of staff who clicks a simulated link receives a short piece of training at that moment, and managers see the figures for their own department.

Reported figures for a first unannounced simulation range from about one in five to one in three, depending on the sector and how convincing the test message is. The more useful measures are the trend across later campaigns and the reporting rate, which shows how quickly a suspicious message reaches the security team.

A click rate cannot be reduced to zero, because a well-written message will deceive someone. The reporting rate shows how quickly the security team learns that a phishing message has arrived. A message reported early can be removed from every mailbox that received it before more people open it.

Each reported message is investigated. If it is confirmed as malicious, the same message is removed from every other mailbox that received it, the sender is blocked and the indicators are added to the email security platform. The person who reported it is told the outcome, so they know the report was acted on.

Yes. The UAE Information Assurance Standards expect documented security awareness activity with evidence of delivery and completion, and DESC ISR applies comparable requirements to Dubai government bodies. Campaign records, completion rates and the click-rate trend are kept as the programme runs and can be produced for an assessor.

The baseline simulation runs in the first fortnight of the programme. Progress is measured against that baseline, and the third or fourth campaign, roughly one quarter in, is the first point at which a trend can be read. Difficulty is raised as results improve, so staff learn the features of a real attack and not the pattern of the test.

Contact us

Talk to our team about your requirement

We’re happy to answer any questions you may have and help you determine which of our services best fit your needs.

Our Value Proposition

What happens next?

1

We’ll arrange a call at your convenience.

2

We do a discovery and consulting meeting 

3

We’ll prepare a detailed proposal tailored to your requirements.

Schedule a Free Consultation