ThreatLocker CEO Danny Jenkins explains why aviation, energy and education organisations remain attractive targets, and why prevention should take precedence over detection
The UAE’s aviation, energy and education sectors have once again been reminded of the cyber risks that accompany digital transformation after the UAE Cybersecurity Council revealed it had recently disrupted a coordinated cyber campaign aimed at organisations operating in these industries.
According to the council, national cyber defence capabilities identified suspicious activity targeting entities across the three sectors and intervened before it caused significant disruption.
The activity involved attempts to gain unauthorised access to systems and information used in day-to-day operations, highlighting attackers’ continued focus on critical services and infrastructure.
The incident reflects a broader trend seen globally, where cyber criminals and state-linked threat actors are increasingly directing their efforts towards organisations whose operations are considered essential to economic activity and public services.
Danny Jenkins, co-founder and CEO of ThreatLocker, said the sectors identified by the UAE authorities are particularly appealing targets because of the consequences that can result from operational disruption.
“For attackers motivated by nation-state politics, sectors like aviation, energy and education are obvious targets because of the consequences of a successful breach,” he said. “At the same time, organisations in these sectors often have limited tolerance for downtime, which can make them attractive to financially motivated attackers seeking leverage.”
According to Jenkins, the ability to interrupt critical services can significantly increase pressure on victims to restore systems quickly, particularly in ransomware scenarios.
Familiar attack techniques continue to dominate
While cyber threats continue to evolve, Jenkins said the methods used to gain initial access often remain surprisingly consistent.
“What we’ve seen globally is that threat actors still rely on the same points of entry,” he added. “Compromised accounts, often obtained through phishing, and malware.”
Rather than relying on highly sophisticated techniques, attackers frequently exploit weaknesses that organisations have struggled to eliminate for years.
“The important lesson is that there isn’t a new array of attack styles here,” said Jenkins. “It’s still the standard point of entry. Someone downloaded malware, someone got phished, or someone left a port open.”
The tactics identified by the UAE Cybersecurity Council suggest that credential theft and phishing remain among the most effective ways for attackers to establish a foothold inside corporate environments.
Operational systems are increasingly valuable targets
Jenkins believes organisations should pay close attention to attackers’ growing interest in operational data and systems rather than focusing solely on the theft of customer information.
“When people talk about operational data, they mean the information and access that keeps an organisation running, rather than the customer records most people picture when they hear about a data breach,” he said.
In sectors such as aviation, this could include systems used for maintenance planning, crew scheduling or other operational processes. Similar dependencies exist across energy and education environments, where disruption can have immediate consequences.
“It’s more valuable to an attacker because losing customer records is expensive and damaging, but losing your operational systems means you stop operating, and that gives an attacker far more leverage over how fast you pay,” said Jenkins.
Unlike data theft incidents, where the damage may unfold over time, outages affecting operational environments can have an immediate impact on service delivery and revenue generation.
Moving beyond detection
The recent attacks also raise questions about whether organisations are placing too much emphasis on identifying threats after they have entered the environment. “Cyber attack detection is like a home alarm system,” said Jenkins. “It only alerts you when something has already gone wrong.”
While monitoring technologies remain an important component of cyber security programmes, organisations should invest more in preventing unauthorised activity from occurring in the first place.
“In the age of AI, it’s nearly impossible to try and keep up with every new piece of malware,” he said. “The focus should be on locking the door in the first place, rather than constantly investing in new alarm systems.”
Jenkins highlighted zero trust security models as one way of reducing risk by restricting activity to only what has been explicitly authorised. “Zero trust is an approach that defines what is allowed in an environment and stops everything else by default,” he said.
Jenkins added that technologies such as application allowlisting can prevent unknown software, scripts and code from executing, helping organisations reduce their exposure to malware and other threats.
With phishing and account compromise continuing to feature prominently in cyber attacks, Jenkins believes organisations should focus on ensuring that stolen credentials do not automatically grant access to sensitive systems.
“The single most important thing UAE organisations can do to reduce the impact of phishing and credential theft is to add hardware verification into the authorisation for network and SaaS [software as a service] access,” he said.
“The goal should be to ensure that a compromised credential doesn’t automatically translate into access,” said Jenkins. “Organisations should combine strong identity verification with device trust and least-privilege access, so that access depends not simply on whether someone has the right password, but whether the user, device and requested access are all authorised.”
As the UAE continues to expand digital services and modernise critical infrastructure, the latest cyber incident serves as a reminder that while threat actors may target new sectors and technologies, many attacks still begin with familiar weaknesses.
Read more on IT careers and IT skills
Middle East faces new cyber reality: attackers logging in, not breaking in
By: Andrea Benito
DMCC launches cyber security hub as UAE accelerates development of digital resilience ecosystem
By: Andrea Benito
Middle East urged to prioritise prevention as cyber workforce gap hits 300,000
By: Andrea Benito
Gulf enterprises face the resilience gap ransomware is exposing







