Security budgets have a long-standing shape problem. The largest line items sit at the network edge — firewalls, gateways, intrusion prevention, segmentation — while the overwhelming majority of successful intrusions begin with a person receiving a message and doing something entirely reasonable with it. The perimeter is defended against a category of attack that has largely stopped being the primary route in. The reason is straightforward economics. Exploiting a vulnerability requires research, tooling and a target that has not patched. Persuading an employee to enter credentials on a convincing page requires a domain name, a template and one person having a busy morning. Attackers optimise for cost like everyone else. The important shift is what phishing is for. It is no longer mainly about malware delivery. It is credential theft, and once an attacker holds valid credentials the firewall is irrelevant, because the traffic arriving is an authenticated user doing legitimate things. Every control designed to distinguish inside from outside fails at that point, not because it is broken but because the distinction it enforces has stopped being meaningful.
Why awareness training is not the answer
The standard response to phishing is user education, and it does not work well enough to be a control. The arithmetic defeats it. A campaign against a thousand employees needs one success. Training that reduces click rates from a fifth of recipients to a twentieth is a real improvement and leaves fifty people who will click. Awareness reduces frequency; it does not change the outcome. Worse, the signals people are taught to look for have stopped being reliable. Poor grammar and obvious formatting errors were never a robust detection method and are now essentially absent. Sender addresses can be spoofed or come from a genuinely compromised partner mailbox. Links can point to legitimate hosting providers and cloud storage. Attachments can be innocuous documents that simply ask the reader to log in somewhere. Teaching people to spot fakes sets them a task they cannot reliably perform, and then blames them when they fail — which also produces the worst possible secondary effect: someone who clicks and is afraid to report it, turning a five-minute containment into a three-week incident. The productive reframing is to treat credential compromise as inevitable and design so that a stolen password is insufficient.
What actually reduces the impact
Phishing-resistant authentication. Not all multi-factor is equal. One-time codes can be relayed in real time by an attacker-in-the-middle page, and push approvals can be defeated by fatigue — sending requests until someone taps accept. Hardware security keys and passkeys bind the credential to the legitimate domain, which breaks the relay attack structurally rather than probabilistically. This is the single highest-value control in the category. Conditional access. Evaluate device state, location and risk signals at authentication. A valid credential presented from an unmanaged device in an unusual location should face additional checks or be refused. Session and token protection. Attackers increasingly steal session tokens rather than passwords, which bypasses authentication entirely. Token binding, shorter lifetimes and reauthentication for sensitive actions matter. Detection of post-authentication anomalies. Impossible travel, new mail forwarding rules, unusual mailbox search patterns, mass file access, new OAuth application consents. Almost every account-compromise incident shows one of these before the damage, and almost nobody alerts on them. Reporting made frictionless and blameless. A one-click report button, acknowledged quickly, with no consequence for false positives. Time-to-report is the variable that determines incident cost. Procedural controls on money and data movement. Callback verification on bank detail changes, dual authorisation on payments, and approval workflows that cannot be satisfied by email alone. These stop the objective even when the credential theft succeeds.
| Layer | Question to test |
|---|---|
| Authentication | Which factors resist relay on supported applications? |
| Session and access | Can stolen sessions or unmanaged devices be contained? |
| Post-login detection | Are forwarding rules, consent and unusual access reviewed? |
| Money movement | Is a known-contact check and independent approval required? |
Qualitative summary of this article's source text, not a measured outcome or performance estimate.
Practical Guidance for Identity Security Assessment
- Deploy phishing-resistant authentication for administrators and finance first. Hardware keys or passkeys where the consequence of compromise is highest, then broaden.
- Treat one-time codes and push approvals as weak factors. They are better than passwords alone and are routinely defeated by current attacks.
- Alert on mail forwarding rule creation. This is the most reliable indicator of a compromised mailbox and one of the least monitored events in most environments.
- Monitor and govern OAuth application consent. A consented application survives a password reset; revocation must be part of your response runbook.
- Make reporting one click and explicitly blameless. Measure time-to-report as a security metric and publish the improvement.
- Put procedural controls on the attacker's objective. Callback verification and dual authorisation stop payment fraud regardless of how the credentials were obtained.
- Rehearse account compromise response. Revoke sessions, reset credentials, remove forwarding rules and consents, review what was accessed. Know the order before the day.
- Assume the perimeter is already inside out. Authorise per request on identity and device state rather than on network position.
The Regional Dimension
Gulf organisations face a phishing environment with several features that raise the base rate. Bilingual operation is the most significant and the least discussed. Staff routinely receive legitimate correspondence in Arabic and English, from counterparties with varying levels of written formality, in multiple transliterations of the same company name. The heuristics people use elsewhere to spot an odd message — unfamiliar phrasing, unusual formatting, a name spelled differently — are unusable when all of those are normal. A message from "Al Futtaim" versus "Al-Futtaim" versus "AlFuttaim" carries no signal because all three appear in genuine correspondence. Government and quasi-government interaction is the second. Businesses here interact constantly with digital identity platforms and government portals for visas, labour files, tax filings, customs and licensing. Messages purporting to come from these services carry high implied authority and genuine urgency, because a missed government deadline has real operational consequences. Phishing that impersonates a licensing renewal or a tax portal notice is disproportionately effective for that reason. Third is channel culture. A large share of business coordination happens over messaging apps, including approvals and instructions that in other markets would sit in email or a workflow system. That channel is outside most email security tooling entirely, and it is where impersonation of a manager or a supplier is hardest to verify and easiest to act on. Fourth is workforce structure. High turnover means unfamiliar names in the directory are normal, so "I don't recognise this person" is not a usable filter. Large frontline and multilingual workforces — logistics, retail, hospitality, construction — mean a significant population accesses systems from personal mobile devices, often in a language other than the one security training was delivered in. And the long chain of external intermediaries handling employee and company documentation means legitimate requests for sensitive documents arrive from outside parties routinely. The positive development: regional regulators and national cybersecurity authorities have pushed identity controls into the mandatory tier for banks, government suppliers and critical sectors, and government digital identity platforms have normalised strong authentication for a wide population. The consumer-side habit is ahead of the corporate-side implementation in many mid-market firms.
The objection worth taking seriously
There is a fair criticism that "phishing beats firewalls" is a slogan that leads to real misallocation. Perimeter and network controls still prevent a large volume of attacks that never reach a person, including exploitation of internet-facing services, which remains a significant intrusion vector in its own right. An organisation that redirects its network security budget into identity tooling and discovers an unpatched edge appliance being exploited has learned the wrong lesson from the right observation. These are complementary controls, and the framing of one replacing the other is rhetorical rather than architectural. There is also a cost and usability reality. Hardware keys for a distributed frontline workforce are expensive to deploy, lose and replace. Conditional access policies built without care lock out legitimate users at the worst moments and generate pressure to weaken them. Passkey support remains uneven across the long tail of business applications, particularly older regional and industry-specific systems, so the strong control frequently cannot be applied where it is most needed. Organisations that mandate phishing-resistant authentication everywhere without checking application support end up with broad exceptions that hollow out the policy. The balanced position: apply the strongest authentication where consequence is highest and application support exists, keep the network controls funded, and put procedural controls around the attacker's actual objective — money movement and data exfiltration — because those work regardless of which technical control failed.
Common Questions
Is multi-factor authentication enough?
It depends entirely on the factor. Codes and push approvals are routinely defeated by relay and fatigue attacks. Hardware keys and passkeys bind to the legitimate domain and resist those attacks structurally. Treat "we have MFA" as an incomplete statement until you know which kind.
What is the first sign of a compromised mailbox?
A new forwarding or inbox rule, usually created within minutes of access and designed to hide the attacker's correspondence. Alerting on rule creation catches a large proportion of account compromises before any financial loss.
Should we run phishing simulations?
Use them to measure reporting rate, not click rate. A simulation programme that punishes clicks produces employees who hide incidents, which is worse than the clicks. The useful metric is how quickly a real message gets reported.
How does AI change the phishing threat?
It removes the last reliable detection signals. Fluent, context-aware messages in Arabic and English, written in a specific colleague's style, referencing a real project pulled from public or breached sources, are now cheap to produce at scale — which retires the grammar-and-formatting heuristic permanently. Voice cloning does the same for the verification call, and that is a direct problem for callback procedures that rely on recognising a voice rather than dialling a number held on file. On the defensive side, models are genuinely good at spotting anomalies in messaging patterns and in post-authentication behaviour. The net effect is a shift away from human judgement toward cryptographic authentication and fixed procedure: controls that do not depend on anyone being able to tell a real message from a fake one.
Identity Security Assessment — assume credentials will be stolen, then check what still holds: phishing-resistant factors, conditional access, and procedure around money movement.
