Technology
Business Bay rewrites cyber training as 70% of employees still fail attacks
Gamification, real-world simulations and a focus on 'human risk management' are replacing old-school compliance modules in Business Bay's tech scene.
How we reported this

Cybersecurity awareness training in 2026 is undergoing a fundamental shift, moving away from annual compliance modules toward what industry analysts call “human risk management”, an approach that uses behavioral science and data analytics to change how employees actually handle threats. The reason is stark: according to a report from SentinelOne, 70% of employees who have completed traditional security training still behave insecurely online.
In the UAE and Saudi regions near Business Bay, all companies now report having some form of cyber awareness training in place, according to a Gartner report. That widespread adoption reflects heightened alertness in a region that has become a prime target for cybercriminals. Yet the same Gartner data found that 61% of firms in the area acknowledge they need to boost their cybersecurity spending. The training gap is not about availability, it is about effectiveness.
From phishing drills to deepfake defense
The new wave of awareness programs covers threats far beyond the familiar phishing email. Training now includes vishing (voice phishing), smishing (SMS phishing), and deepfake lures that use AI-generated audio or video to impersonate executives, as detailed by Forbes Business Council. These simulations are designed to mirror real-world attacks that employees in Business Bay’s tech and startup scene may encounter daily.
Engagement remains a major hurdle. A report from Auxis found that 41% of employees bypass security guidance at work, often because they find existing training tedious or irrelevant. In response, companies are adopting interactive methods including gamification, points, leaderboards and digital rewards, and real-world simulations that mimic actual breach scenarios. The goal is to move beyond rote memorization and build instinctive security habits.
Shadow AI and the new threat vector
One of the most pressing challenges for awareness programs in 2026 is the explosion of shadow AI use. According to Kaspersky, 67% of corporate devices now have some form of unauthorized generative AI tool installed, often used for tasks like drafting emails, summarizing documents or generating code. These tools can leak sensitive data or introduce vulnerabilities if employees are not trained on proper data handling for approved generative AI applications.
For Business Bay’s startups and scale-ups, where speed often trumps security protocols, the risk is acute. Awareness programs now include modules on identifying approved AI tools, understanding data classification, and recognizing when a prompt to a public AI model could expose proprietary information. The training is less about blocking tools and more about teaching discernment.
What comes next is a move toward continuous, data-driven training rather than once-a-year sessions. Security teams in the region are increasingly using analytics to identify which employees click on simulated phishing links, which teams ignore updates, and which behaviors pose the highest risk. The data then feeds personalized micro-training, short, targeted nudges delivered through Slack, Teams or email, designed to close specific gaps. The shift amounts to a recognition that in 2026, the biggest cybersecurity vulnerability is not the software stack. It is the human at the keyboard.