Back to all retail news

From Dubai to Manila: Spinneys to launch Philippines stores in 2026

After its Riyadh debut last year, the UAE grocer is teaming with Ayala Corporation to open its first stores in the Philippines, marking its maiden step into Southeast Asia

Gareth van Zyl
Gareth van Zyl

30 September, 2025

From Dubai to Manila: Spinneys to launch Philippines stores in 2026
Entrance to a Spinneys supermarket in Dubai, UAE. (Credit: Getty Images)

TT

16

Spinneys, which first opened its doors in Dubai’s Al Nasr Square in 1961, is now set to expand into Southeast Asia.

The UAE-based premium grocer has signed a joint venture with conglomerate Ayala Corporation to launch a series of supermarkets in the Philippines, marking a new chapter in its international growth story.

Under the agreement, Ayala will hold a 60 per cent stake and Spinneys a 40 per cent. The first store is scheduled to open in the fourth quarter of 2026, with a pipeline of further outlets to follow. The joint venture will adopt a two-phased approach: Spinneys will initially support the venture with operational expertise before handing over day-to-day management to the new entity.

The move builds on Spinneys’ regional momentum. In June 2024, it opened its first Riyadh store in the upscale An Nuzha district, with plans to launch as many as 12 outlets across Saudi Arabia by 2028.

This year, the retailer also announced plans to expand into Kuwait alongside opening ten new stores in the UAE.

Read more: Spinneys expands regional footprint with new store in Riyadh

Sunil Kumar, CEO of Spinneys, said the Philippines offered the right fundamentals for the brand’s first step outside the GCC.

“The Philippines offers significant long-term growth potential, with strong economic fundamentals, a growing affluent population, and increasing demand for high-quality offerings,” he said.

“Our partnership with Ayala combines its deep local knowledge with our operational expertise, providing a strong foundation to grow in a measured way. As we enter this next phase, we’re delighted to be bringing our high-quality and fresh offering to a new region.”

Ayala, one of the Philippines’ oldest and largest conglomerates, has a diverse presence across real estate, banking, telecommunications, energy, and logistics. The group has been expanding its retail footprint by partnering with global brands.

“We are honoured to be the first partner of Spinneys as it ventures outside the GCC,” said Cezar P. Consing, president and CEO of Ayala Corporation.

“We hope this investment will catalyse trade and investment between the Philippines and the GCC.”

The tie-up aims to blend Ayala’s access to prime sites in mixed-use developments with Spinneys’ expertise in premium fresh food retailing. The Philippine market, with its expanding middle and upper-income classes, is seeing rising demand for modern, high-quality retail experiences, making it a strategic entry point for the brand.

Spinneys currently operates over 80 outlets across the UAE, Oman, and Saudi Arabia (including Waitrose stores), and has become synonymous with quality produce. Its 2024 IPO on the Dubai Financial Market raised Dhs1.4bn, fuelling an expansion drive that now stretches beyond the Gulf.

FIVE Holdings: From Dubai roots to global leadership in sustainability

FIVE Group’s ESG milestones accentuates its role as a global sustainability leader

Gulf Business
Gulf Business

30 September, 2025

FIVE Holdings: From Dubai roots to global leadership in sustainability
Image credit: Supplied

TT

16

Established within the Emirates’ dynamic landscape and helmed by Kabir Mulchandani, chairman and chief executive of FIVE Holdings, FIVE has grown into a global leader in environmental, social, and governance (ESG) excellence, earning an ISS ‘A’ rating, the highest worldwide, and surpassing industry leaders such as Apple, Microsoft, Tesla, Hilton and Marriott.

FIVE sets a global precedent as the only hospitality group powered entirely by green energy across its properties in Dubai, Ibiza and Zurich. In Dubai, FIVE has avoided over 46,000 tonnes of CO2 emissions since 2022 through its I-REC partnership with DEWA. Additionally, SENSORIA in JBR is unveiling the world’s largest and first ONYX Solar facade, spanning 2,800sqm, further advancing sustainable innovation. Additionally, FIVE Palm Jumeirah and FIVE Jumeirah Village hold the Gold Stamp from Dubai Sustainable Tourism, representing the top 1 per cent of Dubai hotels.

Read more-FIVE Holdings secures $460m facility to drive global expansion

Image credit: Supplied

According to the 2024 Cornell Hotel Sustainability Benchmark Index, FIVE achieves a carbon footprint five times more efficient than the average Dubai five-star resort. Since 2020, FIVE has reduced its carbon intensity by 65 per cent. The Pacha Group, acquired by FIVE, has reduced its carbon emissions by 34 per cent in 2024, with Pacha Ibiza cutting emissions per entry by 31 per cent and Pacha Hotel reducing emissions by 39 per cent in 2024.

FIVE outperforms industry standards with water efficiency three times better than the average Dubai five-star resort, as verified by the 2024 Cornell Hotel Sustainability Benchmark Index. In Dubai, the group recycled over 47 million litres of water in 2024, with FIVE LUXE set to recycle over 25 million litres in 2025 as its newest addition.

Recognised by the Emirates Environmental Group as the #1 recycler in the UAE, FIVE was awarded the number one glass recycler in the 2023 EEG OROC Campaign, out of over 2,300 participants, and has achieved a 44 per cent waste reduction since 2020. In 2024, FIVE reduced general waste by 22 per cent compared to 2023 and recycled over 590 tonnes of waste and has planted over 120 native trees in UAE bee reserves.

Image credit: Supplied

FIVE fosters equitable wealth distribution by including 270 employees as shareholders, ensuring shared success across all levels of the organisation. Through FIVE’s long-term incentive plan (LTIP), valued at $91.6m, eligible employees – from entry-level to leadership – are invited to participate in a discretionary programme designed to recognise performance and foster long-term value creation.

FIVE’s green portfolio, valued at Dhs13bn, is a cornerstone of Dubai’s net zero future. Through a $350m Green Bond, FIVE acquired The Pacha Group, scaling its global sustainable entertainment ecosystem and driving sustainable development through innovative investments.

FIVE offers 1,571 environmentally sustainable LEED Platinum hotel rooms, five times more than the entire US’ 295 (LEEDv4+). Pacha Hotel is the first and only hotel in Ibiza to earn LEED Platinum, with Destino Five Ibiza and Pacha Ibiza on track to achieve LEED Gold or higher. Furthermore, FIVE Zurich was Switzerland’s first LEED Platinum hotel, while FIVE LUXE in Dubai holds the world’s highest score for five-star hotels under LEED v4 BD+C.

CG Developers launches Dubai’s first JW Marriott Residences on Dubai Islands

Dubai Islands is emerging as one of the emirate’s most sought-after destinations

Gulf Business
Gulf Business

30 September, 2025

CG Developers launches Dubai’s first JW Marriott Residences on Dubai Islands
JW Marriott Residences at Dubai Islands (render)/Image: Supplied

TT

16

CG Developers, the real estate arm of multinational conglomerate CG Corp Global, has officially launched the first JW Marriott Residences in Dubai. The milestone event featured the formal signing, the unveiling of JW Marriott Residences at Dubai Islands, Central, and the reveal of CG Developers’ new global brand identity.

Founded in Nepal in 1935, the Chaudhary family built CG Corp Global into Nepal’s first and only multi-billion-dollar multinational conglomerate, with a 100-year legacy spanning four generations. CG Developers Global, established in 1995, has delivered over 2 million square feet of developments worldwide, with sales exceeding $1bn. Having established a strong presence in the Middle East for more than two decades, the group is now expanding its development footprint with a new benchmark in ultra-luxury living.

Its hospitality arm, CG Hospitality Global, operates and manages a diversified portfolio of over 209 hotels and resorts across 130 destinations in 12 countries, with nearly 15,000 keys. Several properties are operational or under development across Dubai, the Maldives, Sri Lanka, India, Nepal, New York, and Kenya.

L to R: Erden Kendigelen, Marriott International regional vice president, Rahul Chaudhary, MD, CG Corp Global & CGDevelopers Global, Jaidev Menezes, regional vice president, Mixed-Use Development (EMEA) Marriott International, Varun Chaudhary, MD, Corp Global, Jismon Thomas, development manager and CFO, CG Developers Global

The JW Marriott Residences at Dubai Islands, Central will feature 115 exclusive ocean-view residences, including one-, two-, and three-bedroom homes. Designed as a landmark on the islands, the project embodies wellness-driven island living with a rooftop pool overlooking the Arabian Gulf, spa rooms, a fitness center, lounges, a JW Market Café, and bespoke concierge services. Completion is expected by early 2028.

“Our upcoming development on the Dubai Islands is a milestone we are truly excited about, as it reflects and aligns with the vision of Dubai. Each step has been about raising standards and pushing boundaries, and this new project is another testament to our commitment,” said Rahul Chaudhary, managing director, CG Corp Global & CG Developers Global.

CG Corp Global’s collaboration with Marriott extends beyond Dubai. It includes converting The Farm at San Benito in the Philippines into the first Autograph Collection property in the country, and partnering on Series by Marriott, Marriott’s new global collection brand, which will include Fern Hotels (a CG Hospitality brand). Fern Hotels currently operates 87 hotels, with 57 more signed across India, and aims to reach 500 by 2030.

Sandeep Walia, COO – Middle East & Luxury – Europe, Middle East & Africa at Marriott International, added: “Dubai remains one of the most dynamic residential markets globally, and we are proud to expand our relationship with CG Hospitality to bring our first JW Marriott Residences to the city. JW Marriott Residences at Dubai Islands, Central will enhance luxury living in Dubai by offering owners thoughtfully designed living spaces that foster mindfulness and elevate everyday living.”

Dubai Islands is emerging as one of the emirate’s most sought-after destinations, supported by new infrastructure, scenic waterfronts, and alignment with the Dubai 2040 Urban Master Plan. The JW Marriott Residences will not only redefine premium waterfront living but also create long-term value for investors.

Dubai rolls out new productivity system for government workforce

The first phase will assess workforce productivity using recognised performance metrics, comparing service outputs against workforce size

Gulf Business
Gulf Business

30 September, 2025

Dubai rolls out new productivity system for government workforce
Image credit: DWTCA

TT

16

In a major step to enhance public sector efficiency, Sheikh Hamdan bin Mohammed bin Rashid Al Maktoum, Crown Prince of Dubai, Deputy Prime Minister, Minister of Defence, and Chairman of The Executive Council of Dubai, has issued Executive Council Resolution No. (67) of 2025, introducing a Workforce Productivity Measurement System across government entities.

Read more-Dubai’s government entities 4-day workweek: What we know so far

The resolution mandates a phased implementation of the system, with timelines and scope determined by the Dubai Government Human Resources Department (DGHR). The first phase will assess workforce productivity using recognised performance metrics, comparing service outputs against workforce size, total salaries, working hours, and other relevant data, a WAM report said.

Insights gathered during this phase will drive the development of efficiency-enhancing initiatives. The final phase will focus on evaluating the overall effectiveness of the system. A comprehensive procedural guide will outline the steps and responsibilities for each phase of the rollout.

Roles and responsibilities defined

The General Secretariat of The Executive Council has been tasked with classifying and updating government services, coordinating with entities like the Department of Finance, Dubai Digital Authority, and DGHR. It will also validate performance indicators and provide technical support throughout implementation.

Meanwhile, DGHR will manage and supervise the system, including the preparation and updating of procedural guidelines, development of productivity indicators, and collaboration with financial authorities to align budgets with performance outcomes. DGHR will also assess compliance, monitor results, and submit reports to the General Secretariat.

Digital tools and data integration

The Dubai Digital Authority will play a critical role in providing technical support for the system’s digital platform, including data analysis tools and database integration, key elements in ensuring real-time tracking and transparency.

All government departments are required to adhere to the procedural guide, submit regular productivity data, and act on recommendations aimed at improving efficiency and financial performance. The Director-General of DGHR will issue implementing decisions in coordination with relevant authorities.

This Resolution takes effect upon publication in the Official Gazette and nullifies any prior conflicting provisions.

AI-powered malware PromptLock signals a new era of cyber risk

While large enterprises may afford advanced defences, smaller businesses remain especially vulnerable

Rajiv Pillai
Rajiv Pillai

29 September, 2025

AI-powered malware PromptLock signals a new era of cyber risk
Qrator Labs’ CTO Andrey Leskin/Image: Supplied

TT

16

The cybersecurity industry is facing a seismic shift with the emergence of PromptLock, the world’s first adaptive AI-powered virus. Built on open-source models, PromptLock can reconfigure itself each time it runs, making it virtually impossible to detect through traditional antivirus methods. It targets critical system files across Windows, macOS, and Linux, encrypting them for ransom while behaving differently on every machine. For small and mid-sized businesses in particular, this raises profound questions about resilience, cost, and strategy.

In an exclusive interview with Gulf Business, Qrator Labs’ CTO Andrey Leskin unpacks how AI is reshaping the malware landscape, why legacy defences are no longer enough, and what practical steps enterprises and SMEs alike must take to stay ahead of the threat.

Signature-based detection is obsolete

Traditional cybersecurity relies heavily on signatures — static patterns embedded in executables that allow antivirus engines to flag malicious software. PromptLock’s adaptive design undermines this approach.

“Traditional signature-based detection relies on static patterns in executables — for example, looking for embedded cryptographic modules or techniques used to hide resident processes,” said Leskin. “AI-driven malware like PromptLock undermines this model because the malicious code is not hardcoded in the binary. Instead, it is generated dynamically at runtime by the AI model.”

This dynamism makes detection nearly impossible. Even when antivirus engines can identify AI components, their ubiquity in everyday applications blurs the line between legitimate and malicious use. “The real difference lies in the prompts fed to the model — but unpacking or analyzing them is an extremely complex task,” Leskin explained. As a result, behaviour-based and intent-focused detection is emerging as the only sustainable path forward.

AI-driven DDoS: indistinguishable from real users

Another alarming dimension is how AI enables large-scale Distributed Denial of Service (DDoS) attacks. Traditionally, botnets flood systems with uniform traffic, which defenders can filter out. AI now makes it possible for bots to emulate human-like browsing at scale.

“When generating prompts targeting a specific website — for example, an online shop — attackers can instruct one bot to search for groceries, another to browse for home care products, and so on,” said Leskin. “Because AI is inherently non-deterministic, every request looks slightly different, emulating genuine user behaviour at scale.”

The implications are stark. Web application firewalls and anti-DDoS systems that depend on signatures or CAPTCHAs cannot distinguish this traffic. “Modern AI can now solve such challenges with ease,” Leskin warned.

For defenders, the traditional reliance on network telemetry has lost much of its utility. Encrypted sessions look legitimate, making it nearly impossible to flag anomalies at the packet level. Leskin argues the solution lies in profiling authentic user behaviour.

“Behavioural baselining becomes the only effective countermeasure: profiling how genuine users interact with the site, identifying normal patterns, and flagging deviations,” he said. By focusing on whether activity aligns with meaningful goals, rather than raw traffic volume, enterprises can filter out AI-driven bots that otherwise appear indistinguishable from real customers.

While large enterprises may afford advanced defences, smaller businesses remain especially vulnerable. Leskin points out that antivirus-heavy strategies are no longer viable on their own. “The priority for SMEs is to strengthen the fundamentals. Four measures stand out: strong access control, user-action monitoring, anti-phishing measures, and reliable backups,” he said.

Backups are non-negotiable: “Even if malware succeeds in encrypting files and databases, recovery is still possible, turning a crisis into a temporary setback.”

PromptLock’s ability to compromise multiple operating systems highlights a deeper challenge for endpoint protection. The best strategy, according to Leskin, is strict application control.

“The most effective safeguard for organisations would be to strictly control what software can be installed and executed on endpoints,” he said. Only approved applications from corporate repositories should be allowed. BYOD cultures, where employees use personal laptops and smartphones, make this approach difficult. “Enterprises able to issue and manage all equipment — including corporate phones with enforced policies — should do so. Where this is not feasible, endpoint protection becomes effectively non-existent.”

Surprisingly, Leskin believes large cloud and CDN providers face minimal risk from AI-powered DDoS attacks. “Large cloud and CDN providers are resilient enough and unlikely to be taken down,” he said. “In fact, for them such events may even drive short-term revenue.”

The real burden falls on their customers, who may quickly hit capacity limits or face soaring bills. Smaller ISPs and CDN operators, meanwhile, are more exposed. “They will need to seek cybersecurity partnerships, expand capacity, or risk losing customers through deplatforming when attacks spill over,” Leskin cautioned.

Information-sharing: awareness, not solutions

While cyber threat intelligence (CTI) sharing is often touted as a solution, Leskin notes its limitations. “Information-sharing helps organisations at least become aware of emerging threats and attack vectors, which is valuable in itself. But coordinated threat intelligence has clear limits: practical defence strategies rarely transfer well between organisations with different infrastructures, products, and policies,” he said. For now, CTI serves mainly as early warning, not a direct line to ready-made solutions.

With PromptLock built on open-source AI, questions inevitably arise about regulation and governance. Leskin is skeptical that bans or restrictions will work.

“Attempts to restrict open-source models are unlikely to succeed. History shows it is nearly impossible to stop people from exchanging code, especially when some are willing to break the law to do so,” he said. “In practice, the Pandora’s box is already open and must be treated as such.”

Instead, the focus must shift to resilience: encouraging information-sharing, publishing defensive guidelines, and fostering cross-industry collaboration. “It is too late to rely on bans; the more effective path is to strengthen defences,” Leskin concluded.

The new normal

PromptLock may be just the first of many AI-powered malware strains. Its polymorphic, adaptive design forces organisations to accept that antivirus-based security is no longer adequate. For businesses, the priority is now behavioural defences, resilient backups, strict access control, and pragmatic endpoint policies.

For SMEs, that may feel like a steep climb — but as Leskin makes clear, it is the only way forward in a world where malicious AI is already rewriting the rules of cyber risk.

Resilience redefined: Chedid Re’s long game in volatile markets

From geopolitical shocks to regulatory shifts, Raymond Kairouz, GM of UAE at Chedid Re, explains how resilience means staying power, not short-term playbooks

Raymond Kairouz
Raymond Kairouz

29 September, 2025

Resilience redefined: Chedid Re’s long game in volatile markets
Raymond Kairouz, GM of UAE at Chedid Re/Image: Supplied

TT

16

For an industry built on guaranteeing resilience, its own has been put to the test repeatedly, severely, and differently in nearly every global market. From geopolitical instability to inflationary pressures to regulatory growing pains, there have been plenty of reasons and motives to retreat from (re)insurance – in the region as much as elsewhere. Where others did just that, we consolidated and doubled down.

Markets defined by volatility demand a long-term playbook that is invested in their continuity, grounded in regulatory agility, and enabled by portfolio versatility. Over the last decade, many reinsurance players in the region have responded in kind to boom-bust cycles; they would enter, exit, and re-enter, largely placing sentiment over strategy. This short-termism has created gaps in local service delivery and, sometimes, even put regulatory trust at stake. Operating across different political, economic, and sociocultural landscapes requires a level of commitment that cannot be outsourced or short-lived. It’s why we invest in people and platforms, but most importantly, presence.

Chedid Re’s timeline of staying power is proof that resilience is as much about timing and trust as it is about capital or compliance. With each expansionary move, our goal has remained clear and become clearer: establish early, operate locally, and stay long enough to scale responsibly. In the UAE, where we’ve planted deep roots since 2007 and launched our DIFC subsidiary in 2024, our focus has been on cross-border innovation, collaboration, and expansion. In Saudi Arabia, where we established our office in 2010 and then our regional headquarters in 2023, we’ve built on a different kind of momentum, led by vision first, volume potential next.

The truth is, where market nuances and dynamics come into play, there is not one single definition of resilience. In one market, it looks like cautious and conservative growth. In another, it’s about simply standing your ground. And in others, it’s about scaling fast and furious. From our vantage point, with exposure to nearly every kind of operating climate across Europe, the Middle East, Africa, and parts of Asia, it’s clear that resilience is becoming more situational and less static.

This realisation, tough as it is, requires the local expertise to predict and experience to preempt. Our local teams have consistently identified regulatory shifts, anticipated compliance developments, and flagged emerging risks ahead of the market. Rather than ‘plug-and-play’ models exported from headquarters, we’ve adapted our brokerage and claims strategies to market-level risk understanding – whether that’s political upheaval, energy exposure, or foreign exchange volatility. This means, for instance, reengineering placement strategies at speed, or retaining underwriting capacity through policy structures that can help mitigate currency swings. And it most certainly, almost always, means clearing licensing hurdles and reshaping how coverage is placed to comply with local rules.

The ability to operate compliantly and grow competitively is often overlooked and understated in our industry. Our network in more than 85 countries is supported by a governance model aligned with international best practices and regional nuances. This depth of regulatory understanding is what sets us apart in markets like the UAE, where we’re fully licensed under the DFSA, one of the region’s most stringent and forward-looking frameworks. It’s also why we’ve strengthened our boards and leadership teams with experienced advisors and industry veterans, reinforcing our compliance and governance frameworks across jurisdictions. But you don’t last long here only by mastering reinsurance and regulations. You do it by also understanding risk and boardroom priorities in every sector you secure. What audit committees need. How corporates think about capital adequacy. Where shareholders see exposure. Resilience for any reinsurance broker today is about knowing everyone else’s business as well as they do their own. In practical terms, this means advising on business continuity, capital efficiency, and regulatory alignment as expertly as we do on coverage gaps.

Now, as we expand and reinforce our presence in new and existing markets, our goal is to build credibility and capacity for the long term. While the same operational DNA that has worked for us in other markets applies – local knowledge, governance-first approach, and specialised expertise – we know the rules may and will be entirely different in other fast-growing but complex regions. We’ll bring the lessons of the past two-plus decades, but never the same strategy or playbook.

Sometimes, the opportunity lies in striking while the iron is hot. Other times, it’s about seeing long-term potential in short-term volatility. But it’s always, always about knowing how to stay there once you’re there. That’s the heart of resilience. And that’s our commitment to our clients, our partners, and our markets.

More news in retail