Posted inEconomyTECHNOLOGY

What Cyber Teams Can Learn from Military Intelligence?

DeForge outlines the military lessons that financial institutions can address in cyber following the uptick in Iranian cyber attacks after Operation Epic Fury.

Burj Khalifa, Downtown Dubai
Burj Khalifa, Downtown Dubai

The Middle East may be among the world’s most dynamic financial zones yet this brings additional risks as digital networks expand and cyber threats rise in a climate of geopolitical risk.

According to Mordor Intelligence, the MENA fintech market size is expected to reach US $11.46B by 2031, growing at 12.52% compound annual growth rate (CAGR) in the period 2026-2031, while a recent reports projects that the UAE’s fintech market alone will reach US $6.43B by 2030, growing at a CAGR of 12.56% over the five years prior. 

Cyber & Military

Recent events have drawn attention to how closely intertwined cyber and military warfare have become and the many parallels that exist between the two areas. 

Cyberattacks targeting businesses in the Middle East region have been ramping up significantly in recent times; even before the start of the current conflict in Iran, the threats were rising. Cloudflare reported that in Q1 2026, cyber threats targeting the UAE rose 51% quarter over quarter (QoQ), while cyber threats targeting Saudi Arabia rose 37% QoQ. 

Yet the war in Iran raised the stakes. Within hours of Operation Epic Fury being launched in February, Palo Alto Networks’ Unit 42 counted more than 60 active pro-Iranian hacktivist groups. In March, the Iran-linked hacktivist group, Handala, claimed a major cyberattack against Stryker Corporation, a prominent U.S. medical technology company.  

How Financial Firms Can Mitigate Risks

Firms across the region face complex challenges in dealing with today’s rapidly escalating cyber threats. Many remain wedded to legacy software, which is difficult to secure and leads to longer detection and recovery times.  

Firms have also been primarily focused on protecting their own perimeter from malware and intrusions. Today, thanks to the drive to open banking and mobile first services, financial organisations are often part of complex supply chains. Because of this, they need to be more proactive in their approach to cybersecurity. With threats becoming more complex and unpredictable, firms must both understand the tactics of threat actors and be agile enough to counter them. 

Attackers as Adversaries

In dealing with these threats, Middle East financial services firms need to start thinking of their attackers as adversaries. They need to place themselves in the mindset of their opponent, whether they are a malicious actor or a larger threat group. Then, they need to predict their next move and pin down their most likely and most dangerous course of action for infiltrating their firm.

The next step is to prepare for all eventualities. ‘If this happens, then we do this,’ or ‘if that takes place, then we’re going to pivot here.’ It is this kind of focused thinking that is routine in the military. Cybersecurity strategy is similar. Teams ingest information from multiple sources, including their endpoint detection and response systems, email security tools and firewalls. They then bring them together into a fusion centre to help identify next steps. Having that intelligence in place allows them to predictively analyse what resources to invest in to build the strongest possible defence. 

With all this done, teams then need to start moving from theory into practice and begin engaging with their adversary through proactive security tactics. But there is a saying in the military that no plan survives first contact with the enemy. The same applies to cybersecurity. Threats are unpredictable, so organisations need more than a single line of defence.

A defence-in-depth approach creates layered protection, helping teams remain resilient when one control fails. As in the military, cyber teams cannot rely on a single strong point to keep themselves secure. They need layered defences and a plan for what happens when the first barrier fails. If a firewall is bypassed, how can the attacker be prevented from causing wider damage? Effective cyber defence depends on the ability to both contain threats and rapidly restore control.  There are also military parallels with red teaming. 

To have a world-class red team, organisations need individuals who are confident in network and application testing as well as employees who are specialists in reconnaissance and understand businesses’ working practices and vulnerabilities in detail.

Yet, they also need leaders who can develop attack strategies, just like on the battlefield. Red teaming ultimately resembles a military assault on an organisation, carried out through technical means.

How Cyber Units Can Adopt Military Levels of Discipline 

Just like the best military unit, a well-run cybersecurity team must have razor-sharp discipline. There is another phrase frequently used in the US military which is ‘trust but verify.’ Because there is an ongoing opportunity for things to not only go well but also wrong, guardrails are needed.  

Cybersecurity programs are like military campaigns, complex, even for small firms. There are multiple elements and nobody can have a deep understanding of all of them. Cyber teams need to ensure that while their subject matter experts have the necessary freedom to build programmes, there are always checks and balances in place to ensure there is a coherent strategy.  

As the programme matures, there needs to be integration and collaboration within the team, because if any one micro unit is doing things in a vacuum, it can throw off the entire ecosystem. As anyone who has spent time in the armed forces would testify, there are many strong parallels between military units and cybersecurity teams – and the operational mindset needed to succeed in either area. 

In both, it is crucial to be able to analyse all available intelligence to predict the likely and most dangerous course of action their adversaries could take and to be prepared for all eventualities. At the same time, teams need the flexibility to adapt to fast-changing circumstances, to be always disciplined, and to collaborate to address emerging threats.  


Stay Up to Date with the Latest Updates at Finance ME

Sarah Al-Shawwaf: Vision 2030 Has Unlocked the Potential of Saudi Women

World Bank Projects 2.4% Growth for Oman in FY26

EDGE’s Rodrigo Torres on Risk, Sovereignty and Defence Finance in a Multipolar World