Phishing protection in Dubai, UAE
Our phishing protection in Dubai combines simulated phishing, awareness training aimed at the roles being targeted, impersonation and domain controls on the email platform, and a reporting workflow in which every reported message is investigated.

Why phishing protection measures reporting as well as clicks
Click rate is the percentage of staff who follow a link in a simulated phishing message. It is a useful measure, but it cannot be brought to zero, because a convincing message will deceive someone in any organisation.
The reporting rate is the percentage of staff who report the message. When a message is reported promptly, the security team can remove it from every mailbox that received it and block the sender. When it is not reported, the attack is discovered later, from its effects.
The programme is therefore built to make reporting simple: a one-click report button in the mail client, investigation of every report, and a reply to the person who reported it. Reporting rate is tracked from the first campaign alongside click rate.
Four types of phishing attack the programme covers
These attacks do not rely on a malicious attachment, so attachment scanning at the gateway does not stop them on its own.
What phishing protection covers
The programme combines measurement and training for staff, technical controls on the email platform, and a defined response to reported messages.
Baseline simulation
An unannounced simulated phishing campaign is run before any training, so that the starting click rate and reporting rate are measured accurately.
Simulation programme
Campaigns are spread across each month, and the difficulty of the templates is increased as results improve, so the exercise continues to measure recognition of realistic attacks.
Targeted training
Training is assigned by role, in the languages the workforce reads, and is delivered at the point a member of staff clicks a simulated link.
Reporting and follow-up
Results are reported by department and role so that managers see the figures for their own teams. Staff who click repeatedly are supported individually with their manager.
Impersonation protection
Rules are configured around the names of executives, finance staff and the suppliers the organisation pays, so that messages imitating those senders are flagged or held.
Business email compromise defence
Detection rules for payment and bank-detail requests that carry no malware or link, so these messages are flagged for verification.
Domain authentication
SPF, DKIM and DMARC are configured and taken to an enforcement policy, so that messages sent as your domain by unauthorised senders are rejected.
Link and attachment handling
URLs are rewritten and checked at the time they are clicked, so that a link that was clean at delivery is examined again when a user follows it.
Report button deployment
A one-click report button is deployed in the desktop, web and mobile mail clients staff use, so that reporting does not depend on forwarding a message to a mailbox.
Reported mail investigation
Every reported message is investigated, and the person who reported it is told the outcome.
Tenant-wide remediation
A message confirmed as malicious is removed from every mailbox that received it, not only from the mailbox of the person who reported it.
Credential compromise response
When a password has been entered on a phishing page, the password is reset, active sessions are revoked and the account's access is reviewed.
How a phishing programme runs
An unannounced simulation is run before any training, so that improvement is measured from a real starting point.
- Run without advance notice to staff, so the result reflects normal behaviour
- Results broken down by department and role
- Reporting rate recorded alongside click rate from the first campaign
Frequency, difficulty and content are set for the organisation's workforce and the types of attack it receives.
- Language mix matched to the workforce, not limited to English
- Roles with payment authority given templates based on business email compromise attempts
- Difficulty planned to rise over the programme, so staff learn the features of a real attack
Groups, the report button and allow-listing are configured before the first campaign is sent.
- Groups synchronised from the directory so the target population stays current
- Report button deployed to desktop, web and mobile mail clients
- Allow-listing tested so that simulated messages are delivered and not filtered
Impersonation rules and domain authentication are configured alongside the awareness programme.
- Impersonation protection tuned to named executives and paying suppliers
- DMARC moved to an enforcement policy in stages, based on the reports received
- Click-time URL checking enabled so that delivery-time scanning is not the only check
Simulations and training run to the agreed schedule, and the results are reviewed after each campaign.
- Campaigns spread across the month so that staff are not warned by colleagues
- Training assigned automatically when a simulated link is clicked
- Reported messages investigated and the reporter told the outcome
The programme is measured against its own baseline and adjusted as the results change.
- Progress measured against the original baseline as well as the previous campaign
- Templates updated as attacker techniques change
- Repeat clickers supported individually, with their manager involved
Phishing awareness evidence UAE frameworks expect
Security awareness is a named control in several UAE frameworks, and each of them asks for records of the activity.
UAE Information Assurance Standards
The IAS expects documented security awareness activity with evidence of delivery and completion. Campaign records, completion rates and the click-rate trend are kept as the programme runs and can be produced for an audit without further preparation.
DESC ISR
Dubai government and semi-government bodies have comparable awareness requirements under DESC ISR. Records for each campaign provide the evidence an assessor asks for.
ADHICS and ISO 27001
Both require awareness training with records of completion. Reporting is broken down by group so an assessor can see coverage across the organisation as well as the aggregate figure.
UAE PDPL
Simulation results identify individuals, so they are personal data under the PDPL. Retention of and access to the results are configured to match your lawful basis, and results are reported by group, not by name.
Why choose iConnect for phishing protection
Baseline before training
An unannounced baseline simulation is run before any training, so that improvement is measured against a real starting figure.
Reporting rate is the target
The programme tracks the reporting rate as well as the click rate, because early reporting allows a phishing message to be removed before it spreads.
Measurement, not entrapment
Results go to managers by department and role, not as a list of names. Staff who click are given a short piece of training at the time.
Every report is investigated
Reported mail is investigated and the person who reported it is told the outcome, so staff can see that reporting has an effect.
Both layers together
The awareness programme and the technical email controls are configured as one piece of work, so a message that passes the filters can still be recognised and reported.
Local delivery
Campaign design, training content and reporting are produced by our team in Dubai, in the languages your workforce reads.
Sectors the programme is run for
The people targeted and the requests attackers make differ by sector, and the simulation content is written to match.

Government
Impersonation of officials and DESC ISR evidence requirements.

Banking and Finance
Payment redirection attempts and misuse of the bank's brand towards customers.

Healthcare
Shift patterns, shared workstations and high staff turnover in clinical teams.

Manufacturing
Supplier impersonation across long payment chains.

Retail and E-commerce
Seasonal staff and peak trading periods when message volumes are high.

Education
Credential harvesting aimed at students and staff at the start of term.
What our clients say
“Whenever an issue arises, iConnect is there immediately: quick, efficient and proactive in keeping everything running without disruptions. iConnect has become a crucial part of our operations.”
Head of IT Infrastructure and Network SecurityDragon OilPhishing protection questions
Annual training records show that staff completed a module. They do not show how staff respond to a realistic phishing message during a normal working day. A simulation programme measures that behaviour directly and repeats the measurement through the year, so the organisation has a current click rate and reporting rate.
Email security is the platform layer: the secure email gateway, filtering, encryption, data loss prevention and archiving. Phishing protection is the human layer: baseline measurement, simulated phishing, training for the roles being targeted, and the workflow for reported messages. The two are configured together.
Simulations are run as a measurement exercise, not as a test of individuals. Results are reported by department and role, and no list of names is circulated. A member of staff who clicks a simulated link receives a short piece of training at that moment, and managers see the figures for their own department.
Reported figures for a first unannounced simulation range from about one in five to one in three, depending on the sector and how convincing the test message is. The more useful measures are the trend across later campaigns and the reporting rate, which shows how quickly a suspicious message reaches the security team.
A click rate cannot be reduced to zero, because a well-written message will deceive someone. The reporting rate shows how quickly the security team learns that a phishing message has arrived. A message reported early can be removed from every mailbox that received it before more people open it.
Each reported message is investigated. If it is confirmed as malicious, the same message is removed from every other mailbox that received it, the sender is blocked and the indicators are added to the email security platform. The person who reported it is told the outcome, so they know the report was acted on.
Yes. The UAE Information Assurance Standards expect documented security awareness activity with evidence of delivery and completion, and DESC ISR applies comparable requirements to Dubai government bodies. Campaign records, completion rates and the click-rate trend are kept as the programme runs and can be produced for an assessor.
The baseline simulation runs in the first fortnight of the programme. Progress is measured against that baseline, and the third or fourth campaign, roughly one quarter in, is the first point at which a trend can be read. Difficulty is raised as results improve, so staff learn the features of a real attack and not the pattern of the test.


