Cybercriminals, the thinking goes, save their effort for the big players: the banks, the multinationals, the household names. Uzair Gadit, CEO of Secure.com, argues that this assumption is precisely what leaves smaller retailers exposed. Attackers don’t hunt by size; they hunt by weakness, and for criminals running automated, increasingly AI-powered campaigns, dozens of under-protected SMEs make an easier prize than one well-defended enterprise.
The danger sharpens during peak periods like Ramadan, Eid and the holidays, when transaction volumes spike and digital storefronts expand, and a breach at that moment can mean lost revenue, locked systems and lasting reputational damage.
We spoke to Gadit about why SMEs have become prime targets and what a peak-season attack really costs.
We often hear about major enterprises being targeted, but you’ve said retail SMEs are increasingly vulnerable, especially during peak seasons like Eid and the holidays. Why are smaller retailers becoming prime targets?
Conventional thinking assumes cybercriminals primarily target large enterprises. In reality, attackers go after the easiest opportunities, and increasingly, that means SMEs. Many smaller retailers still believe they are “too small to be noticed,” which often leads to minimal security preparation, even at a basic level. That perception makes them low-hanging targets.
For attackers, it’s a game of volume. Instead of trying to breach a single well-defended enterprise, they can target dozens of SMEs, exploiting weak systems for ransomware, payment fraud or data theft.
The risk becomes even greater during peak seasons like Ramadan and Eid. Transaction volumes surge, online purchases can jump by 46 per cent in fashion and 64 per cent in cosmetics, temporary staff are hired, and digital storefronts expand. SMEs today face the same digital attack surface as large enterprises but lack comparable resources to defend it.
With attackers now using AI to scale their exploits, smaller retailers have never been more exposed.
You’ve mentioned cases where cyberattacks during high-traffic sales periods have pushed some SMEs toward bankruptcy. What does that typically look like in practice: revenue loss, reputational damage, operational shutdown?
According to Mastercard research, 77 per cent of UAE SMEs that experienced a cyberattack had to spend time rebuilding trust with customers and partners, while a quarter ultimately filed for bankruptcy, and 19 per cent were forced to close their businesses. For an SME, a cyberattack during a peak sales period is particularly devastating because these moments often generate a significant share of annual revenue.
The first impact is immediate revenue loss. If an e-commerce platform, payment gateway or inventory system goes offline during a high-traffic period like Eid promotions, even a few hours of downtime can translate into thousands of lost transactions — losses that smaller retailers operating on tight margins may struggle to recover.
Next comes operational disruption. Ransomware can lock retailers out of point-of-sale systems, order management tools or customer databases, effectively halting operations during their busiest days.
Finally, reputational damage compounds the crisis. When customer or payment data is compromised, trust erodes quickly. Customers hesitate to return, partners question reliability, and regulators may require disclosure — turning a short-term incident into a long-term business threat.
Many small retailers simply can’t afford a full-time cybersecurity team. How does your model bridge that gap without pricing them out?
What many SMEs need is operational capacity without the cost of actually building it. That’s the core premise behind our Digital Security Teammates (DST) model.
DST works within a small retailer’s existing infrastructure, with no additional investment required to replace tools already in place. It eliminates the manual triage and alert noise that overwhelms lean IT teams, correlating alerts, enriching context and surfacing what genuinely requires attention.
With DST, a retailer gets a continuously operating digital teammate that amplifies whoever they already have, even if that’s one person covering five roles. By reducing noise and cutting response time, it lowers breach risk without enterprise-level cost.
From your experience, what are the most common misconceptions retail SMEs have about cybersecurity, particularly in fast-growth or seasonal sales periods?
One of the most common is the belief many micro-entrepreneurs hold that their business is too small to be noticed. As I said, attackers don’t look at size, only at weak points, and with automation tools now prevalent, they run their scripts at scale. Small business owners should re-evaluate that position; their size doesn’t make them invisible; it can actually make them easier to exploit.
The second is treating cybersecurity as an IT problem rather than a business-continuity issue. If an attack takes your website or checkout systems offline during an Eid weekend, that’s no longer just technical downtime; it’s lost sales during the most important trading days of the year.
Then there’s the timing trap: “We’ll deal with it after peak season.” But peak season is precisely when exposure is highest. Rapid growth periods, new payment integrations, pop-up storefronts and seasonal staff quietly widen security gaps. It’s always better to prepare before you’re most vulnerable. The UAE Cybersecurity Council has already flagged 128 confirmed incidents in 2026 alone, most linked to financially motivated groups. This is not a future risk; it’s a clear and present danger.
Do you expect cyber threats against retail SMEs to intensify as AI-driven attacks rise, and how should smaller businesses realistically prepare without overextending financially?
Without a doubt. AI is making it easier for attackers to automate phishing, credential stuffing and exploit discovery at a scale and speed that manual defences simply can’t match. The UAE has already recorded AI-powered cyberattacks targeting vital sectors, and the volume of attacks on high-transaction businesses like retail will only increase.
For some, the answer is hiring more experts. The problem is that there aren’t enough people to hire anywhere on the planet, and the cost is counterproductive. The more strategic response is to use AI defensively — for continuous monitoring, context-aware alert prioritisation, clear incident-response plans, and reducing the noise so real threats aren’t missed.
Practical preparation doesn’t require an unlimited budget. It requires the right tools, applied intelligently and matched to the scale and risk profile of the business. SMEs that act now, before the next peak season, will be in a fundamentally stronger position than those who treat this as someone else’s problem.
Read: The end of the password? GCC cybersecurity leaders sound the alarm on identity’s new frontline