A suspicious login, fraudulent payment instruction or encrypted laptop can become a much larger business problem when staff improvise. Small companies need a short response plan that works before a specialist arrives: confirm the incident, isolate affected systems, preserve evidence, protect money and data, and report through the correct official channel.
The TDRA’s official Report a Cyber Incident service page describes investigation and incident-response support for eligible government entities. Small businesses should use the relevant police, Ministry of Interior or sector-regulator channel for their case, while 999 is reserved for immediate emergencies.
Define what counts as an incident
An incident may be an account takeover, malware warning, lost device, altered bank details, unauthorised data access, denial of service or a convincing impersonation attempt. Staff should know one internal contact and one method of reaching that person when normal email cannot be trusted.
The Dubai deepfake scam guide helps teams verify suspicious voices and videos. The UAE online-shopping records guide is useful when a consumer transaction or payment dispute is involved.
| First-hour action | Purpose | Avoid |
|---|---|---|
| Record the alert | Create a reliable timeline | Deleting messages or logs |
| Contain | Limit further access or spread | Shutting down everything without advice |
| Protect funds | Stop or recall suspicious payments | Calling a number supplied by the attacker |
| Escalate | Bring in authorised decision-makers | Discussing details in public channels |
| Report | Reach the correct authority | Waiting for perfect information |
Contain without destroying evidence
Disconnect an affected device from networks when safe, but do not wipe, reset or reformat it. Preserve suspicious emails, full headers, phone numbers, payment instructions, access logs and screenshots. Write down the time, who noticed the problem and what action was taken.
The small-business record-keeping guide provides a model for access-controlled evidence files. Keep originals and work from copies where possible.
First-hour checklist
- Notify the designated incident lead through a trusted channel.
- Isolate affected accounts or devices without wiping evidence.
- Reset compromised credentials from a known-clean device.
- Contact the bank immediately about suspicious payments.
- Preserve messages, logs, call details and transaction records.
- Assess whether customer, employee or supplier data is involved.
- Report through the appropriate UAE official channel.
Protect payments and supplier accounts
If bank details changed unexpectedly, use a previously verified phone number to contact the supplier. Alert the bank as soon as a suspicious transfer is discovered; delay can reduce the chance of stopping or tracing funds. Suspend affected online banking access only through the bank’s official channel.
The business expense-records guide explains how approvals and supporting evidence fit together. For disputed commercial instructions, use the record structure in the Dubai business-dispute guide.
Communicate on a clean channel
If business email may be compromised, move the response team to a verified alternative. Limit details to people who need them and keep one person responsible for external statements. Do not accuse an employee or supplier before the facts are established.
Customers should receive clear, factual instructions when their information or account security may be affected. Avoid speculation, unnecessary personal data and promises that cannot yet be kept. Legal, contractual and regulatory notification duties depend on the incident and the organisation.
Report facts, not theories
Prepare the business name, contact person, incident time, affected service, suspected loss, accounts involved and evidence already preserved. Use the official channel appropriate to the emirate and crime. An active threat to life or public safety is different from a non-emergency online complaint.
The UAE emergency numbers guide explains the distinction between urgent and non-urgent reporting. If a device is physically missing, also record its serial number and assigned user.
Recover and learn
Before reconnecting systems, confirm they are clean and credentials are changed. Review backups, payment limits, administrator access, supplier verification and staff training. A short after-action report should state what happened, what contained it, what failed and who owns each improvement.
Keep response instructions offline as well as online. A plan stored only in the compromised system may be unavailable at the moment it is needed most.
Questions people often ask
Where can a UAE business report a cybercrime?
Use the police or Ministry of Interior channel applicable to the emirate and incident. TDRA’s linked incident-response service is intended for eligible government entities.
Should an infected computer be wiped immediately?
No. Isolate it when safe and preserve evidence. Wiping can destroy information needed for investigation and recovery.
What should happen after a suspicious bank transfer?
Contact the bank immediately through a verified official channel, preserve transaction records and report the suspected crime.
Can staff discuss the incident in normal work email?
Not if email may be compromised. Use a known-clean, authorised communication channel and limit information to the response team.
What evidence should the business keep?
Preserve original messages, headers, logs, phone details, payment records, screenshots and a time-stamped action timeline.






