The Numbers Are Worse Than Most Organisations Know

Healthcare topped global ransomware target lists in 2024. The UAE and Saudi Arabia are not exceptions to this trend - research shows that nearly three quarters of top GCC hospitals have not implemented basic email validation controls.

72%
of top GCC hospitals lack basic email security (DMARC)

Why Healthcare Is the Primary Target

Healthcare organisations hold three things ransomware groups find uniquely valuable: patient data that is highly sensitive and immediately monetisable, operational systems where downtime has direct patient safety implications, and historically under-resourced security teams.

The combination creates a predictable target profile.

The Attack Vector Most Organisations Are Ignoring

DMARC - Domain-based Message Authentication - is a basic email validation standard that prevents attackers from spoofing your domain to send phishing emails that appear to come from inside your organisation.

Without DMARC, a phishing email appearing to come from your own medical director lands in every staff member's inbox with no technical indicator that it is fake.

What a Ransomware Attack Costs a UAE Hospital

The average cost of a healthcare data breach reached USD 9.7 million in 2024 - the highest of any industry for the 13th consecutive year. For a UAE hospital, this includes regulatory fines under ADHICS, operational downtime and patient safety incidents.

$9.7M
Average healthcare data breach cost - highest of any industry

The ADHICS v2.0 Response

ADHICS v2.0 addresses the ransomware threat directly through mandatory email security controls, Zero Trust implementation and the 4-hour breach containment requirement. Compliance with ADHICS v2.0 is not just a regulatory obligation - it is the minimum viable defence posture for a UAE healthcare organisation.

What Organisations Should Do Now

Implement DMARC, DKIM and SPF email authentication immediately. These are low-cost, high-impact controls that close the most common initial attack vector.

Conduct a phishing simulation to understand your actual staff exposure before an attacker does.

Review your incident response plan against the ADHICS v2.0 4-hour containment requirement.