The AccuSights blog

Stories, threats and plain-English fixes from the Cyber Expert and Dr. Kash

Every post opens with what a breach looks like from the inside, gives you the 2026 numbers behind it, and ends with the handful of moves that decide how it turns out. Written for the owner and the compliance officer, by people who ran security inside the largest institutions.

UAE compliance

ADHICS v2 for an Abu Dhabi Clinic: Triage the Control List, Then Start With Six Things

ADHICS v2 for an Abu Dhabi clinic: how to triage a long control list, the six things a small facility does first, and what evidence the DoH expects.

Dr. Kashmala Khalid6 min read24 September 2026
Reputation and business risk

Agencies and Staffing Firms: The Shared Drive, the SOC 2 Question, and What to Answer Before You Have a Report

Agency and staffing SOC 2 questions arrive with your biggest deal. What client data in shared drives exposes, and the answer that keeps the deal alive.

Sam Khan6 min read24 September 2026
Practical controls

Cybersecurity Awareness Month for a 30-Person Business: Four Controls, in Order

Cybersecurity Awareness Month, done properly by a 30-person business: four controls in the order that removes the most risk per hour of work, not a poster.

Sam Khan6 min read24 September 2026
UAE compliance

DIFC and ADGM Fintechs: The DFSA and FSRA Cyber Rules Side by Side, and the One Control Set That Answers Both

DIFC and ADGM fintech cyber rules compared: what the DFSA and FSRA both expect on governance, vendors and incidents, and the single control set underneath.

Sam Khan6 min read24 September 2026
Practical controls

Renewal Season: Answer the MFA, EDR and Backup Questions Before the Broker Asks Twice

Cyber insurance renewal questions on MFA, EDR and backups: the eight-item evidence pack that shortens the form, sharpens the quote and protects the claim.

Sam Khan6 min read24 September 2026
Practical controls

Restaurants and Hotels: The Point-of-Sale Network, the Guest Wi-Fi and the PCI Question Your Bank Will Eventually Ask

Restaurant and hotel PCI compliance starts with one cable: how the point-of-sale network, guest Wi-Fi and the SAQ your bank asks for actually fit together.

Sam Khan6 min read24 September 2026
UAE compliance

Sharjah Factories and the 68-Question Supplier Form: The Old Server, the Flat Network and the March Renewal

Sharjah factory cybersecurity: the supplier questionnaire, the 2014 ERP server and the flat OT network, and the checks to run before a customer asks.

Sam Khan6 min read24 September 2026
UAE compliance

The 2027 UAE Regulatory Calendar: Four Real Dates, Several Renewals, and the Deadline Nobody Has Published

A UAE regulatory calendar for 2027: which cybersecurity and data dates are published, which are renewals you set yourself, and what NCAP has not announced.

Sam Khan6 min read24 September 2026
UAE compliance

The NABIDH Connection Audit: What a Dubai Clinic Is Asked, in the Order It Is Asked

The NABIDH connection audit for a Dubai clinic, in the order the DHA asks: facility identity, EMR interface, consent, access control, audit trail and evidence.

Dr. Kashmala Khalid6 min read24 September 2026
UAE compliance

NCAP: What National Accreditation Changes for Anyone Selling Cybersecurity to UAE Government and Critical Sectors

NCAP is the Cyber Security Council's accreditation programme for cybersecurity providers. What it is built on, what is not published yet, and how to prepare.

Sam Khan6 min read21 September 2026
UAE compliance

GISEC Global 2026: Five Conversations a UAE Regulated Business Should Have on the Floor

GISEC Global 2026 runs 16 to 18 September in Dubai. The five conversations a UAE regulated business should have on the floor, and what to bring home.

Sam Khan6 min read14 September 2026
Practical controls

How to Read Your Cyber Hygiene Score: What 77 Percent Coverage Means and the Three Fixes That Move It

Your cyber hygiene score is coverage, not a grade. What 77 percent coverage means, why the number moves, and the three fixes that raise it fastest.

Sam Khan6 min read7 September 2026
Practical controls

A Backup Strategy for a Small Business That Survives Ransomware: 3-2-1-1-0 and the Restore Test Nobody Runs

A backup strategy for a small business that survives ransomware: why sync is not backup, what 3-2-1-1-0 means, and the monthly restore test nobody runs.

Sam Khan6 min read2 September 2026
UAE compliance

ADHICS v2 for a Clinic: Three Tiers, a 24-Hour Clock and What the DoH Auditor Asks

ADHICS v2 compliance for an Abu Dhabi clinic: which tier applies, what the 24-hour breach notice means, and what the DoH auditor asks at renewal.

Dr. Kashmala Khalid6 min read2 September 2026
Threats

AI Cyber Attacks: What Actually Changed for a Small Business, and What Did Not

AI cyber attacks made phishing personal, fluent and cheap. What changed for a small business in 2026, what did not, and the controls that still hold.

Sam Khan6 min read2 September 2026
AI and new risks

AI Governance for a Small Business: NIST AI RMF, ISO 42001 and the UAE AI Charter Without the Consultancy Bill

An AI governance framework a 30-person business can run: what NIST AI RMF, ISO 42001 and the UAE's AI rules ask, and the five documents to write first.

Sam Khan7 min read2 September 2026
AI and new risks

AI Inside Your Vendors: Prompt Injection, Agent Permissions and the Questions to Ask Before You Connect Anything

AI agent security for a small business: how prompt injection turns a helpful assistant against you, what permissions to give it, and what to ask the vendor.

Sam Khan6 min read2 September 2026
Practical controls

Audit Logging for a Small Business: What to Keep, for How Long, and How to Stop Your Data Walking Out the Door

Audit logging for a small business: which logs to keep, for how long, and the DLP settings that stop a departing employee taking the whole database with them.

Sam Khan6 min read2 September 2026
Threats

Business Email Compromise: How One Polite Email Moves Your Money to a Stranger's Bank

Business email compromise drove more than half of reported cyber incidents in 2026. How invoice and payroll scams work, and the callback rule that stops them.

Sam Khan6 min read2 September 2026
The data you hold

Card Data: The Safest Way to Store It Is to Never Touch It

PCI scope reduction in plain terms: why a small business should never store card numbers, what tokenization does, and what changed in SAQ A in 2025.

Sam Khan6 min read2 September 2026
UAE compliance

CBUAE Cyber Rules for Fintechs and the Suppliers Who Serve Banks

CBUAE cybersecurity framework explained for a small fintech or bank supplier: which regulations reach you, why the bank's questionnaire exists, and what to fix.

Sam Khan6 min read2 September 2026
The data you hold

Client Financial Data: What a Law Firm, CPA or Wealth Advisor Is Really Holding

Client financial data security for law firms, CPAs and advisors: what you are holding, the 30-day breach clocks that now apply, and the folder to lock first.

Sam Khan6 min read2 September 2026
Reputation and business risk

Cyber Insurance in 2026: The Renewal Form, the Premium and the Claim That Gets Denied

Cyber insurance requirements in 2026: what the renewal form asks, why premiums moved, and how a ticked box about MFA on a shared mailbox gets a claim denied.

Sam Khan6 min read2 September 2026
Threats

Data Extortion Without Encryption: They Did Not Lock Anything. They Just Took It.

A data extortion attack skips encryption and goes straight to the threat: pay or your customer files go public. How it works, and what to do in the first hour.

Sam Khan6 min read2 September 2026
Threats

Deepfake Voice and Video Fraud: When the Managing Director on the Phone Is Not the Managing Director

Deepfake fraud against a business starts with a cloned voice and an urgent payment. What changed in 2026, what did not, and the callback rule that beats both.

Sam Khan6 min read2 September 2026
UAE compliance

DESC ISR v3: What a Dubai Government Supplier Has to Show Before the Contract Is Signed

DESC ISR compliance for a Dubai government supplier: what ISR v3's 13 domains cover, who it applies to, and what to fix before the contract is signed.

Sam Khan6 min read2 September 2026
UAE compliance

DIFC, ADGM or Federal PDPL: Which Data Rules Apply to Your Free-Zone Company

DIFC Data Protection Law, ADGM regulations or federal PDPL: how to tell which one governs your data, what changes at the free-zone boundary, and what to fix.

Sam Khan6 min read2 September 2026
Practical controls

EDR vs Antivirus for a Small Business, and the Question That Matters More: Who Is Watching It at 2 a.m.?

EDR vs antivirus explained for a business owner: what each one catches, why insurers ask for EDR, and why a red alert nobody reads is the same as no alert.

Sam Khan6 min read2 September 2026
Threats

Infostealers and Stolen Session Cookies: How Attackers Walk Past Your MFA Without Touching It

Infostealer malware lifts saved passwords and live session cookies from a browser, so the attacker never sees an MFA prompt. Here is how to close the door.

Sam Khan6 min read2 September 2026
Threats

Insider Risk in 2026: The Disgruntled Admin, the Careless Contractor and the Remote Hire Who Is Not Who You Think

Insider threat now includes the remote developer whose laptop lives in a stranger's house. How to verify hires, cut access on exit day, and watch the logs.

Sam Khan6 min read2 September 2026
UAE compliance

ISO 27001 for UAE Tenders: Why the Certificate Is Now a Bid Document

ISO 27001 UAE tender guide: why a current certificate is now a prequalification document, how long it takes a small firm, and what to do this week.

Sam Khan6 min read2 September 2026
Reputation and business risk

Licence, Accreditation and Reputation: The Breach That Ends a Practice Without a Fine

Healthcare data breach consequences rarely arrive as a fine. They arrive as a conditional licence renewal, a delisted insurer network and referrals that stop.

Dr. Kashmala Khalid6 min read2 September 2026
Threats

Mobile Banking Malware: The Phone That Approves Your Payments Now Works for Someone Else

Mobile banking malware on one phone can overlay the bank app and forward one-time codes. How it gets in and how to keep it off the phones that approve payments.

Sam Khan6 min read2 September 2026
Practical controls

Multi-Factor Authentication for a Small Business: Where It Belongs, Which Kind Works, and Why Outlook Alone Is Not Enough

Multi-factor authentication for a small business: the five doors it must be on, which kind survives a fake login page, and why Outlook alone is not enough.

Sam Khan6 min read2 September 2026
UAE compliance

NABIDH Compliance for a Dubai Clinic: Access, Consent and the Audit Trail You Have to Prove

NABIDH compliance for a Dubai clinic: what the DHA expects on access control, patient consent and audit trails, and why connecting your EMR is only the start.

Dr. Kashmala Khalid6 min read2 September 2026
Practical controls

Patch Management for a Small Business: Why 43 Days Is Too Slow for the Firewall and Fine for the Printer

Patch management for a small business: which devices need updates within days, which can wait, and why the firewall nobody reboots is the one that gets you.

Sam Khan6 min read2 September 2026
Threats

Phishing in 2026: The QR Code, the Text Message and the Login Page That Steals Your Session

Phishing attacks on small business now arrive by QR code, text and phone call, and the fake login page steals your session, not just your password.

Sam Khan6 min read2 September 2026
The data you hold

PII You Did Not Know You Were Holding: Employee Files, Web Forms and the CRM Export

PII hides in employee files, web forms and CRM exports. What counts as personally identifiable information, which laws reach a small business, what to delete.

Sam Khan6 min read2 September 2026
Threats

Ransomware in a Clinic: What Nine Days Without the EHR Really Looks Like

Healthcare ransomware stops refills, referrals and the front desk, not just files. What nine days of EHR downtime looks like, and how a small practice prepares.

Dr. Kashmala Khalid6 min read2 September 2026
Threats

Remote Desktop Security: RDP, VPN and RMM Are the New Front Door, and It Is Usually Unlocked

Remote desktop security in 2026 is about three doors: RDP, the VPN box and the RMM tool. How attackers find them in days, and how to lock each one this week.

Sam Khan6 min read2 September 2026
Practical controls

Security Awareness Training for a Small Business: Why the Report Button Beats the Delete Key

Security awareness training for small business that works: short, monthly, scored per person and team, tied to real threats, judged by who reports.

Sam Khan6 min read2 September 2026
AI and new risks

Shadow AI: Your Staff Are Already Pasting Client Data Into Chatbots. Here Is the Policy.

Shadow AI is already in your business: what the 2026 breach data says about unapproved chatbots, and the one-page AI acceptable use policy that fixes it.

Sam Khan6 min read2 September 2026
The data you hold

Source Code and Secrets: The API Key in the Repo Is the Whole Company

Source code security for a small software team: why the API key in the repo is the whole business, the first hour after a leak, and how to stop the next one.

Sam Khan6 min read2 September 2026
Reputation and business risk

The Enterprise Security Questionnaire: How to Answer 212 Questions Without Lying or Losing the Deal

How to answer a security questionnaire from a big customer without lying or losing the deal: the 212-question workbook, what 'yes' commits you to, a method.

Sam Khan6 min read2 September 2026
Threats

The First 72 Hours of a Ransomware Attack on a Small Business, Hour by Hour

What a ransomware attack on a small business looks like in the first 72 hours, what the 2026 numbers say about paying, and five moves that decide recovery.

Sam Khan6 min read2 September 2026
Practical controls

The One-Page Incident Response Plan a 25-Person Company Can Actually Follow

An incident response plan for a small business on one page: who calls whom in the first hour, the regulator clocks, and what to do when your IT provider is hit.

Sam Khan6 min read2 September 2026
UAE compliance

UAE IA Standard v2 and NCAP: What "Accredited" Means and Who Has to Care

UAE Information Assurance Standard v2 and NCAP accreditation, explained for a supplier to critical infrastructure: what changed in 2026 and what to do now.

Sam Khan6 min read2 September 2026
UAE compliance

UAE PDPL for a 30-Person Company: What the Federal Data Law Asks of You

UAE PDPL compliance for a small company: who the federal data law covers, what the breach notice actually requires, and six practical fixes for this week.

Sam Khan6 min read2 September 2026
Reputation and business risk

What a Breach Really Costs a 30-Person Business (It Is Not the USD 4.99 Million Headline)

The cost of a data breach, small business edition: not the USD 4.99 million headline but eleven days of lost closings, a bank that drops you, and payroll.

Sam Khan6 min read2 September 2026
Reputation and business risk

What a Cybersecurity Risk Assessment Actually Checks (and What a Free Scan Does Not)

What a cybersecurity risk assessment checks, what it costs for a company under 50 people, and why three free scans left a law firm unable to answer a client.

Sam Khan6 min read2 September 2026
The data you hold

Where PHI Hides in a Small Practice: 14 Places Nobody Thinks to Check

What is PHI, and where does it live in a small practice? Fourteen places patient data hides outside the practice-management system, and how to find them.

Dr. Kashmala Khalid6 min read2 September 2026
Threats

Your Vendor Got Hacked: What a Third-Party Data Breach Means for You, and the One-Hour Vendor Review

A third-party data breach lands on your desk even when the hack was not yours. Which vendors matter, what to ask them, and a review that takes one hour.

Sam Khan6 min read2 September 2026
Threats

Cloud security threats, and the five that actually cause the breaches

Misconfiguration, identity abuse, exposed APIs, data loss and persistent intruders. What each one looks like in a cloud estate, and what closes it.

AccuSights Cybersecurity Team5 min read19 January 2026
Threats

Cyber threat management, and the intelligence lifecycle behind it

The five stages of the threat intelligence lifecycle, what each one produces, and why insider risk is the part most programmes underweight.

AccuSights Cybersecurity Team5 min read12 January 2026
Threats

Dormant accounts are a way in, and most organisations have more than they think

Unused accounts keep their passwords and their permissions. How attackers use them to run malware, and the account housekeeping that closes the gap.

AccuSights Cybersecurity Team6 min read23 December 2025
Threats

Reporting cyber crime in the UAE: the channels, and what to have ready

Where a UAE business reports a cyber crime, what the report needs to contain, and what to do in the hour before you file it.

AccuSights Cybersecurity Team5 min read23 December 2025
Practical controls

What are the CIS Controls, and where do they fit in the UAE?

The CIS Controls are a numbered list of things to do, grouped by how much security work you can carry. What they cover, and how UAE organisations use them alongside local requirements.

AccuSights Cybersecurity Team5 min read22 December 2025
UAE compliance

A cybersecurity risk management framework, and what it buys you in the UAE

What a cybersecurity risk management framework does, the five stages every version of it shares, and how it lines up with what UAE regulators ask for.

AccuSights Cybersecurity Team6 min read16 December 2025
Practical controls

How to map NIST CSF and CIS Controls to UAE requirements

If you already run NIST CSF or the CIS Controls, you need a map to the UAE requirements rather than a second programme. Where the two line up, and where the mapping gets thin.

AccuSights Cybersecurity Team5 min read20 October 2025
UAE compliance

UAE cybersecurity compliance for SMEs: which rules reach your business

The Cybercrime Law, the PDPL and the Information Assurance Regulation, what each one asks of a small UAE business, and where to start.

AccuSights Cybersecurity Team4 min read20 October 2025