The UAE Cyber Security Council has signed a Memorandum of Understanding with Cyble, a global AI-native cybersecurity company, to strengthen the country’s national threat intelligence capabilities and protect its digital infrastructure. The agreement, announced in Abu Dhabi on September 17, 2026, establishes a framework for Cyble to deliver advanced threat intelligence, early warning capabilities and actionable insights into emerging cyber risks facing government and critical infrastructure entities across the country.
The MOU formalises a strategic collaboration centred on Cyble’s threat intelligence capabilities. Cyble Vision, the company’s flagship platform powered by Blaze AI, will play a central role in the partnership. The platform provides rapid threat detection, automated analysis and contextual intelligence covering ransomware, phishing, fraud and other evolving cyber risks.
The deal reflects the UAE’s deliberate strategy of building a national cybersecurity ecosystem that combines sovereign capability with partnerships from leading global technology providers.

Cyble Brings AI-Native Threat Intelligence to a National Mission
Cyble operates as an AI-native cybersecurity company specialising in threat intelligence, digital risk protection and dark web monitoring. The company has raised $38.6 million in total funding, including a $24 million Series B round co-led by Blackbird Ventures and King River Capital, with participation from Spider Capital, January Capital and Summit Peak Ventures.
The company’s platform, Cyble Vision, delivers rapid threat detection, automated analysis and contextual insights into ransomware, phishing and fraud. For a national cybersecurity authority, that capability matters because modern cyber campaigns move quickly and involve malicious infrastructure, malware and attack techniques that operate across multiple jurisdictions.
Beenu Arora, CEO and Co-Founder of Cyble, described the MOU as more than a routine partnership announcement. “This is not just a partnership announcement. It is a strategic validation of Cyble’s capabilities at the national cybersecurity level and potentially a gateway to the UAE government and critical-infrastructure ecosystem,” he said. “Working alongside the Cyber Security Council underscores the trust placed in our threat intelligence platform and reflects the growing importance of proactive, intelligence-led defence in protecting nations against increasingly sophisticated cyber threats.”
The UAE Faces a Rising Tide of Cyber Attacks
The partnership arrives at a moment when the UAE faces intense pressure from cyber threats. Organisations in the UAE and Saudi Arabia experienced nearly 2,700 attacks per week in the first half of 2026, compared with about 2,300 attacks per week for a typical organisation globally, according to data from Check Point Software Technologies.
The UAE alone accounted for 35 percent of all cyberattacks recorded across the Gulf in the first half of 2026, making it the region’s most targeted country. Saudi Arabia recorded 15 percent of incidents on its own. Together, the two nations made up 50 percent of all recorded Gulf cyberattacks.
The scale of the threat became even clearer during periods of heightened regional conflict. The UAE recorded 640,000 cyberattacks in a single day amid the Iran conflict, according to authorities. Earlier in the year, the country recorded nearly 800,000 daily attacks.
Government agencies bore the brunt of successful attacks, accounting for 27 percent across the Gulf. Attackers relied most heavily on exploiting software and hardware vulnerabilities, which featured in 38 percent of incidents. Malware deployment ranked second at 31 percent, followed by social engineering at 27 percent.
The Council Has Built a Multi-Partner Defence Strategy
The Cyble MOU does not stand alone. The UAE Cyber Security Council has assembled a network of partnerships with global cybersecurity providers, each bringing different capabilities to the national defence effort.
In September 2026, Group-IB announced a strategic partnership with the Council during GISEC Global 2026. That collaboration focuses on threat intelligence sharing, incident response coordination and cybersecurity skills development, with both organisations exploring a joint Innovation Center of Excellence in the UAE.
The Council also signed agreements with Dell Technologies, Siemens, IBM, ATRC and Dragos at MIITE 2026 in May. Those partnerships aim to strengthen national cyber resilience across critical infrastructure and industry. The Council has also launched the UAE Cyber Factory initiative in collaboration with CPX Holding, a national programme designed to strengthen digital sovereignty and accelerate the development of home-grown cyber defence technologies powered by artificial intelligence.
The UAE has positioned AI at the centre of its national transformation agenda. The country’s National Cybersecurity Strategy focuses on establishing cohesive governance, delivering a safe and resilient digital environment, enabling the rapid adoption of innovation and strengthening national digital capabilities.
This multi-partner approach reflects a broader recognition that no single vendor or technology can address the full spectrum of cyber threats facing a modern state. By combining sovereign capability building with partnerships from leading global providers, the UAE is building depth across intelligence gathering, incident response, capacity building and technology development. The same discipline of building layered capability applies to companies scaling across African markets, where the most resilient operators build systems that work in local conditions rather than importing templates wholesale.
Cyble Simultaneously Signed a Distribution Deal for Wider Regional Reach
The UAE MOU was not Cyble’s only move in the region during September 2026. The company also signed a strategic distribution partnership with QBS Software META & Eurasia at GISEC Global 2026 in Dubai. Under that agreement, QBS Software will distribute Cyble’s full solution suite, including Cyble Vision, to enterprises and government entities across the Middle East, Africa and Eurasia.
The two deals serve different purposes. The UAE MOU establishes a direct relationship with a national cybersecurity authority. The QBS partnership expands Cyble’s commercial reach through an established distribution network that operates across more than 12,000 SaaS products from over 12,500 publishers.
Beenu Arora framed the QBS partnership in terms of access. “This partnership with QBS Software META & Eurasia isn’t just about distribution. It is about giving our joint customers earlier visibility into the threats that matter, and the ability to act on that intelligence before it becomes a breach,” he said.
M Mobasseri, CEO of QBS Software META & Central Asia, described the regional threat environment as “more complex and fast-moving than ever before.” He said partnering with Cyble allows QBS to bring differentiated, AI-native threat intelligence into its regional channel.
The combination of a national-level MOU and a broad distribution deal gives Cyble both credibility and reach. The UAE partnership validates the company’s technology at the highest level of government. The QBS deal gives it a channel to sell that technology across a much wider geography. This dual approach mirrors how successful companies expand across multiple markets, building anchor partnerships while simultaneously developing distribution channels that reach a broader customer base.
What the MOU Means for the UAE’s Cybersecurity Ecosystem
For the UAE, the Cyble agreement adds another layer to a cybersecurity ecosystem that has become one of the most advanced in the Middle East. The Council’s approach combines real-time monitoring, advanced threat intelligence sharing and coordinated incident response across government entities and strategic industries.
Cyber operations centres across sectors are interconnected to enable rapid intelligence sharing and coordinated responses to emerging threats. That integrated model positions the UAE as a leader in sectors such as energy, finance, aviation and telecommunications, where operational continuity is critical.
Dr Mohamed Al Kuwaiti, Head of Cyber Security for the UAE, said the Council is committed to building strategic partnerships with world-class technology providers that strengthen the UAE’s cyber resilience at every level. “This MOU with Cyble reflects our shared commitment to safeguarding the nation’s digital infrastructure through advanced threat intelligence and proactive, intelligence-led defence, ensuring the UAE remains at the forefront of global cybersecurity readiness,” he said.
The emphasis on intelligence-led defence marks a shift away from reactive security models. Instead of waiting for attacks to succeed and then responding, the Council aims to identify threats before they develop into active attacks. That requires intelligence that is timely, accurate and actionable. Cyble’s platform is designed to provide exactly that.
The Regional Cyber Threat Landscape Demands Proactive Defence
The broader Middle East continues to see an increase in cyberattacks, with a surge in financially motivated threats despite the focus on the widening military conflict in the region. The UAE, Iran and Saudi Arabia accounted for about two-thirds of all attacks discovered through open source methods, which scan for attack information on Dark Web forums and on threat actors’ Telegram channels.
The vast majority of cyberattacks likely remain unreported because of concern over reputational harm. That underreporting makes threat intelligence even more valuable. When organisations cannot rely on public reporting to understand the threat environment, they need intelligence that comes from direct monitoring of criminal ecosystems.
Cyble’s platform monitors dark web forums, criminal marketplaces and other sources to identify threats before they reach their targets. For a national cybersecurity authority, that capability extends the visibility that individual organisations cannot achieve on their own. A single bank can monitor its own network. A national authority needs to see across all critical sectors to understand how threats move and evolve.
The Partnership Reflects a New Model for National Cyber Defence
The Cyble MOU represents a model that other governments are watching. Rather than building all cybersecurity capability in-house, the UAE combines sovereign initiatives with partnerships from leading global providers. The Cyber Factory initiative builds local capability and reduces reliance on external technologies. The Cyble, Group-IB, Siemens, and IBM partnerships bring in best-in-class capabilities that would take years to develop internally.
That balance between building and buying gives the UAE flexibility. When a capability is critical for sovereignty, the country builds it locally. When a capability is available from a trusted partner with proven technology, the country partners. The result is a layered defence that combines national control with global reach.
For Cyble, the UAE MOU provides validation that extends beyond the Emirates. Governments across the region and beyond look to the UAE as a leader in cybersecurity adoption. A partnership with the UAE Cyber Security Council signals to other national authorities that Cyble’s technology meets the standards required for national-level deployments. That validation is difficult to purchase. It has to be earned through demonstrated capability.
The UAE has made its choice. It will build a cybersecurity ecosystem that combines sovereign capability, global partnerships and AI-powered intelligence. Cyble is now part of that ecosystem. The MOU is the beginning of the relationship, not the end of it. What happens next depends on how effectively the two organisations work together to protect the UAE’s digital infrastructure.












