The Numbers Are Worse Than Most Organisations Know
Healthcare topped global ransomware target lists in 2024. The UAE and Saudi Arabia are not exceptions to this trend - research shows that nearly three quarters of top GCC hospitals have not implemented basic email validation controls.
Why Healthcare Is the Primary Target
Healthcare organisations hold three things ransomware groups find uniquely valuable: patient data that is highly sensitive and immediately monetisable, operational systems where downtime has direct patient safety implications, and historically under-resourced security teams.
The combination creates a predictable target profile.
The Attack Vector Most Organisations Are Ignoring
DMARC - Domain-based Message Authentication - is a basic email validation standard that prevents attackers from spoofing your domain to send phishing emails that appear to come from inside your organisation.
Without DMARC, a phishing email appearing to come from your own medical director lands in every staff member's inbox with no technical indicator that it is fake.
What a Ransomware Attack Costs a UAE Hospital
The average cost of a healthcare data breach reached USD 9.7 million in 2024 - the highest of any industry for the 13th consecutive year. For a UAE hospital, this includes regulatory fines under ADHICS, operational downtime and patient safety incidents.
The ADHICS v2.0 Response
ADHICS v2.0 addresses the ransomware threat directly through mandatory email security controls, Zero Trust implementation and the 4-hour breach containment requirement. Compliance with ADHICS v2.0 is not just a regulatory obligation - it is the minimum viable defence posture for a UAE healthcare organisation.
What Organisations Should Do Now
Implement DMARC, DKIM and SPF email authentication immediately. These are low-cost, high-impact controls that close the most common initial attack vector.
Conduct a phishing simulation to understand your actual staff exposure before an attacker does.
Review your incident response plan against the ADHICS v2.0 4-hour containment requirement.