The UAE’s cybersecurity head on adapting to digital warfare and the promise of AI
Mohamed Al Kuwaiti recognises the dangers that AI poses in the sphere of cybersecurity. But its potential benefits, he argues, outweigh its risks.
The machinery of everyday life attracts little attention until someone tries to disrupt or, indeed, destroy it. According to Mohamed Al Kuwaiti, the head of the UAE Cyber Security Council, Iran has targeted the UAE’s power grid and sought to wipe its digital records. At the Arab Media Summit in Dubai, he tells Monocle Radio how the Islamic Revolutionary Guard Corps has overseen a digital offensive alongside missile and drone attacks. As the conflict continues, he explains how his country’s defences are evolving and why confronting technology’s darker uses hasn’t dented his optimism about AI.

Did anything about Iran’s cyberattacks on the UAE surprise you?
We expected data leaks and spying on information; we expected theft, scams and attempts to steal data. But we didn’t anticipate someone attacking our power grid and trying to disrupt and destroy it, or targeting our database of digitised information and deleting everything. And we didn’t expect such things to happen so soon after the conflict began. We have learnt from this, which is why we are emerging more powerful.
Were these cyberattacks happening alongside the missile and drone strikes?
Whenever you heard about drone or ballistic-missile strikes on critical infrastructure such as energy, aviation or health care, there would also have been cyberwarfare, trying to add to the impact of the physical attack. We have seen this beyond the UAE: with Russia, Ukraine, Estonia, Israel and Palestine. It’s not only psychological operations or misinformation and disinformation on social media.
What lessons has the UAE taken from Russia’s war in Ukraine?
We have been holding cyber drills and national exercises for the past two or three years, with every sector being tested. We cover every scenario that we can think of: AI versus humans, AI versus AI and machines versus critical infrastructure. Last year we ran a cybersecurity drill in Dubai with 133 nations coming together for one cause: to protect against cyberattacks. We will have another one this week.
What has changed when it comes to how you protect the country against these attacks?
There are three layers to this. To protect our critical infrastructure, we have changed many policies and compliance requirements. When there’s an attack, AI detects the pattern and can proactively stop it. The second is partnership. Many of these technologies are owned by third parties in the private sector. This is where we saw solidarity. Private companies came forward and showed us indicators of when something had been compromised, attack patterns and what they had been seeing in their cloud systems. They shared those indicators with us for everyone’s benefit. The most important thing is the community. Here in the UAE, we have changed the curriculum to include more about cybersecurity and AI. This goes from kindergarten all the way to the board room. We have learnt that technology is an integral part of everything that we do and we need to be ready to use it positively. Yes, there is a downside but we will prepare for it.
For those who are worried about the damage that AI could do, what reassurance can you offer?
I’m optimistic. The technology will add great value to us all. AI has saved lives and its use in medicine has changed so much. Yes, there are grey areas and risks if we don’t have the right guardrails, guidance and policies in place. But I don’t think that these will outweigh all of the good things. Ultimately, it is designed by people. Some could be evil but most use it for good. That is the message that we are sending from the UAE: we are using this technology for the best of humanity.
