In partnership with Dynova.
Ping. Ping. Ping.
The engineer looked up at what seemed like hundreds of tabs open across their browser, searching for the source of the interruption.
LinkedIn.
They silently groaned.
Regardless, they clicked.
Another recruiter. Another startup. Another role that, at first glance, looked virtually identical to the dozens of unsolicited approaches engineers receive every month. Still, there was enough in the message to give them pause for thought, so they replied.
An answer whizzed back quickly. More information followed, then another question, another response. Before long, the exchange had taken on the shape of a well-matched tennis rally, until a GitHub link appeared in the thread.
A short technical interview, the recruiter explained.
Nothing out of the ordinary there, and the instructions were simple: download the project, fix a handful of bugs and send it back for review.
The engineer shrugged their shoulders. Why not?
They clicked through to GitHub, opened the repository and downloaded the files.
There was only one problem.
The recruiter wasn't a recruiter, and the technical interview wasn't a technical interview.
Buried inside the project was malware designed to extract credentials from the engineer's laptop, which, as it happened, was a particularly useful machine to compromise.
They were the team lead at a startup of roughly 20 people, with broad access to its code, databases and other systems.
The consequences could have been catastrophic had the timing not fallen rather improbably in the company's favour.
Less than a week earlier, Dynova, a Dubai cybersecurity company working with the startup, had installed endpoint protection on the machine. When the project ran, the software caught the malware attempting to send passwords and other information from the laptop. Dynova's team isolated the laptop, rotated every credential it held and checked whether anything had already left.
Had the ping arrived a week earlier, the company would've had no idea.

The attacks you never hear about
There's a reason the history of startup cybersecurity is easier to reconstruct from its catastrophes.
In January 2018, attackers gained access to a system containing the account information of Careem's customers and drivers. By the time the Dubai ride-hailing company disclosed the breach several months later, it encompassed the names, email addresses, phone numbers and trip data of 14 million users. Careem was by then operating across 78 cities with more than half a million drivers on its platform.
Smaller incidents tend to disappear into the companies where they happen. A compromised employee account at a 30-person startup is highly unlikely to produce a press release pitched indiscriminately far and wide.
In some cases, the company has every reason to keep quiet. In others, it may simply never know.
"You mostly hear about the huge breaches," said Denis Yakimov, Dynova's founder. "With startups, you just don't see them."
Dynova encountered a rather literal version of that problem at another startup. Its team had just enabled a web application firewall when the new system began registering attempts to brute-force the password of an internal CRM.
"We turned on the firewall and immediately saw someone trying to brute-force the password," Yakimov recalled. "We couldn't tell how long it had been happening. The startup simply couldn't see it before."
The unnerving part was not that the attack began at the precise moment somebody started looking. It was that, until then, nobody had been looking.
For much of the startup era, that trade-off has been relatively easy to understand. A young company has engineers to hire, customers to win, a product held together by considerably less than its client logos suggest, investors asking when the next round will close and cash disappearing every month.
Amongst those competing priorities, cybersecurity sits somewhere on the long list of things a company promises itself will become more sophisticated when the company becomes more sophisticated.
The underlying assumption has never been that security doesn't matter, so much as that there'll be a time and place further down the line when it'll make more sense to talk about it.
That assumption is becoming harder to make, and over a matter of days this summer, two of the companies building the world's most capable AI systems offered an accidental demonstration of why.
During an internal cybersecurity evaluation in July, OpenAI models found a previously unknown vulnerability in software intended to keep them inside a constrained testing environment, used it to reach the open internet and ultimately chained vulnerabilities into Hugging Face's production infrastructure, all in pursuit of the answer key to the very benchmark they were being tested on.
Anthropic then examined more than 141,000 of its own cybersecurity test runs and discovered three instances in which Claude models had gained unauthorised access to the systems of real organisations after a misconfiguration inadvertently left the test environment connected to the internet.
The techniques weren't particularly groundbreaking; an exposed debug page and a basic SQL injection flaw were among what sufficed. What was more jarring was that the access only came to light when Anthropic's own retrospective review uncovered it and the company notified those affected.
Neither was an attack in the usual sense, and in both cases the models were running without the safeguards applied before public release. But they offered a glimpse of how quickly the rules of the game are changing.

"The average time to patch a vulnerability or zero-day vulnerability found in the wild is 55 days," Nikesh Arora, the chief executive of Palo Alto Networks, said in a recent interview. Models, by contrast, are increasingly capable of finding weaknesses and constructing attacks around them in seconds.
The same capability is comforting when it belongs to the person patching the hole, but becomes rather less so when the cost of searching for that hole is falling dramatically for everybody else.
The problem is that the symmetry is false. A defender has to worry about the whole system. An attacker needs one forgotten endpoint, one misconfiguration, one password, one developer who answers the wrong LinkedIn message.
Closer to home, the numbers have moved too.
In February, before the regional conflict began, Mohamed Al Kuwaiti, chairman of the UAE Cyber Security Council, said the country was dealing with between 90,000 and 200,000 attempted breaches of its infrastructure each day. Since the escalation, he has said, that daily figure has roughly tripled, to around 600,000.
StormWall, measuring DDoS attacks across its own network, recorded a 574% year-on-year increase across MENA during the first quarter of 2026, with the bulk of the acceleration arriving in March after the regional conflict escalated.
Yakimov says Dynova noticed the change itself. There was more traffic, more probing and, around financial companies in particular, more fraud activity.
It doesn't mean every UAE startup suddenly finds itself under siege, nor that every packet of malicious traffic ends in anything consequential. Most don't.
But it adds another complication to a model of company building that has traditionally depended, in no small part, on being able to put certain things off.
A bank or multinational can respond to that change in the familiar way, by hiring more specialists, buying more software and building another layer of monitoring around the layers already there.
For a startup with 20, 50 or 100 employees, the problem is less accommodating. There may be nobody whose job title contains the word security, never mind a team capable of watching systems around the clock.
The buying problem
The trouble often begins when a founder decides it's time to roll up their sleeves and actually do something about it.
That'll often mean finding the website of one of umpteen large managed security providers, clicking through a thicket of services and eventually arriving at a generic contact form.
Somewhere in the box marked How can we help?, a founder of 50 people is expected to explain what kind of cybersecurity company they need.
The issue, of course, is that they usually can't.
Sure, they know what the business does, which customers matter, where the next round is supposed to come from. They may even know that an enterprise client is asking for ISO 27001, or that a regulator has started probing and asking uncomfortable questions they're struggling to answer.
What they're unlikely to know is whether the answer lies in endpoint protection, a penetration test, a firewall, managed detection, a security operations centre, or some medley of things they hadn't heard of until that afternoon.
"Who is going to call you back?" Yakimov asked me.
A salesperson.
"Exactly," he said. "You're a 50-person startup. How are you supposed to know exactly what you need to buy?"
It was more or less this contradiction that led Yakimov into the business in the first place.
After moving to Dubai in 2022, he was working in cybersecurity for a financial trading company when the founder of a small UAE startup asked whether he might help with security part-time.
Yakimov set about creating a company so that he could. By the time the paperwork was done, roughly a month later, the startup had already found somebody else.
What remained was a company with no clients and a question Yakimov couldn't quite shake: why had a startup of around 50 people been looking for someone like him in the first place?
He began asking other founders, and it turned out they weren't alone.
The initial version of Dynova was built around the virtual-CISO (vCISO) model, the increasingly common idea that a company too small to employ a senior security executive might borrow one for part of the week instead. On paper, it fit the economics of a startup neatly. His first clients had other ideas.
"They didn't need just a fractional adviser," Yakimov said. "They needed someone to sit with them and actually take care of everything, including the hands-on work and the controls, and answer for the result".
That realisation pulled Dynova towards what Yakimov now calls an all-in-one cybersecurity service: a virtual CISO backed by a delivery team and 24/7 monitoring, all on a fixed monthly subscription. Dynova provides the security people and builds the processes, then helps choose and implement the technology around them. The founder isn't expected to become good at buying cybersecurity in order to buy cybersecurity.
The companies turning up at Dynova's door, increasingly through the investment networks where it's now an official provider, Hub71 and Shorooq among them, also make it difficult to construct a neat profile of the startup that finally "gets serious" about security.
Yakimov has encountered teams of five thinking about it before a product has properly launched, and companies that've spent years in production before an impending licence or audit brings the subject abruptly into focus.
Sometimes the prompt is an investor. Sometimes it's an enterprise customer conducting due diligence. Sometimes a regulator wants evidence that certain controls exist, which in the UAE tends to mean VARA, the Central Bank, DFSA or FSRA.
And sometimes the company has simply grown large enough that the founder can no longer keep a reliable mental inventory of who has access to what.
What security actually looks like inside a startup
"How do you make money?"
It's an unexpectedly commercial first question from a cybersecurity company.
Before Dynova starts talking about malware, firewalls or certificates, Yakimov says his team spends time reconstructing the business.
"What exactly do you do? How do you make money? Where does the money go? Where is the data stored? Who approves things? If you understand what creates the revenue, you can start to understand what could break it."
It's difficult to secure a startup in the abstract because startups are unusually good at creating exceptions to their own systems. A new employee needs production access for a weekend and keeps it for a year. A founder opens an account using a personal email because procurement would take too long.
The temporary has a canny habit of acquiring permanence in startup land.
Security work begins, in part, by discovering just how much of the company has been built out of those little accommodations.
From there, Yakimov reduces an industry of intimidating acronyms to three categories: people, process and technology.
Technology is the easiest to see, and therefore the easiest to buy. Multi-factor authentication can be switched on. Endpoint protection can be installed. A firewall can be purchased.
The other two are less visible.
"What's the point of implementing a tool if there's no one who can review it, understand whether it's configured correctly, explain how people should use it and act when something happens?" Yakimov said. "Very often, the people and the process are more important than the technology."
What if there's no security budget?
Suppose you're a founder, you've got no meaningful cybersecurity budget and you've just read far enough into an article like this to become slightly concerned.
You're not about to hire a CISO, and you're probably not buying an all-in-one security service either. What should you actually do?
Yakimov paused.
"It's a good question, actually," he said. "There isn't one answer, and I'd be careful with anyone who gives you one ".
For somebody who sells cybersecurity, the admission was refreshing.
He did eventually offer the obvious places to start. Two-factor authentication should be switched on. Company laptops need endpoint protection. If you've got an application exposed to the internet, some form of web application firewall probably belongs in front of it.
None of this is terribly expensive, particularly exotic or likely to get a founder excited enough to mention it at an all-hands.
Yakimov compared the question, eventually, to asking somebody how to build a successful business. There are sensible things almost everybody should do, but the usefulness of a universal prescription deteriorates fairly quickly once you encounter an actual company.
A five-person payments company handling customer money is not the same security problem as 50 people building HR software, which isn't the same problem as an adtech startup with hardware sitting in public places around Dubai. One business may have spent heavily securing its infrastructure and barely thought about privacy. Another may have collected every certificate an enterprise procurement department could reasonably ask for while an old contractor still has access to something they probably shouldn't.
Which brings us back to where Dynova starts in the first place: "How do you make money?"
Follow that question through the business and things begin to sort themselves out. Which systems have to remain online for money to keep coming in? What customer information passes through them? Who can access those systems, and from where?
The point isn't that every founder should spend the next morning manically drawing up an elaborate threat model instead of speaking to customers. It's that cybersecurity becomes rather easier to reason about once it stops being treated as an enormous technical category and starts being treated as a question about the particular company you've actually built.
Start there, Yakimov's argument goes, and the technology comes afterwards.
Cybersecurity, like most industries selling against risk, has every incentive to make the shopping list longer. Startups have the opposite problem. They can't buy everything, don't need everything, and very often wouldn't know what to do with everything if they did.
What they can do is get considerably better at knowing what they've got.
The engineer at the beginning of this story hadn't suddenly become more security-conscious in the week before the LinkedIn message arrived. The fake recruiter was no less convincing, the GitHub repository no less plausible, and the laptop still carried the same privileged access to the company's code and databases.
Had the message arrived seven days earlier, they probably still would've clicked.
Very little about the attack had changed.
Somebody had simply started looking.
Learn more about Dynova's all-in-one vCISO service for startups.
This article is part of FWDstart's partner programme series. We follow stringent editorial standards and, while we collaborate closely with our partners, final editorial control rests solely with FWDstart to ensure the authenticity and creativity of our content. All partnerships are disclosed clearly, and we only collaborate with organisations we genuinely admire. Dynova is one of them. Founders who'd rather hand the whole problem to someone else can start a conversation with Denis and the team here.




