Civil Law And Uae Critical Infrastructure Cyber Liability .

Civil Law and UAE Critical Infrastructure Cyber Liability

1. Introduction

Critical infrastructure cyber liability concerns the civil, contractual, regulatory and potentially criminal consequences arising when a cyber incident affects infrastructure that is essential to the functioning of society or the economy.

In the UAE context, this is particularly important because critical information infrastructure can support services such as energy, ICT, government, electricity and water, finance and insurance, emergency services, health, transportation, and food and agriculture. The UAE's Critical Information Infrastructure Protection (CIIP) framework uses a risk-based approach to identify critical assets, assess threats and vulnerabilities, establish security requirements, and monitor implementation.

Cyber liability can arise from several different relationships:

Operator → Customer
Operator → Government/regulator
Operator → Supplier/contractor
Supplier → Infrastructure operator
Attacker → Victim
Data controller → Data subject
Insurer → Infrastructure operator

The important point is that a cyberattack does not automatically make the infrastructure operator civilly liable. Liability generally depends on the applicable statutory duties, contractual obligations, causation, fault or other applicable basis of responsibility, and proof of loss.

2. Meaning of Critical Information Infrastructure

The UAE CIIP Policy describes Critical Information Infrastructure as physical and virtual information assets supporting a critical function and delivery of a critical service. The framework seeks to identify critical sectors and national services, identify supporting information infrastructure, assess risks and establish security requirements.

This is broader than merely protecting a computer.

For example:

Electricity

A power-grid control system may involve:

  • SCADA systems;
  • operational technology;
  • network communications;
  • remote monitoring;
  • substations;
  • cloud services;
  • authentication systems.

A cyberattack could therefore create both:

digital damage + physical/economic consequences.

The same principle applies to:

  • water-treatment systems;
  • airports;
  • hospitals;
  • banks;
  • telecommunications;
  • oil and gas facilities;
  • government systems.

3. Sources of UAE Cyber Liability

Cyber liability is not contained in one single UAE civil-law statute.

A claim may involve several legal frameworks.

Principal sources include:

  1. Federal Decree-Law No. 25 of 2025 — Civil Transactions Law
  2. Federal Decree-Law No. 34 of 2021 — Countering Rumors and Cybercrimes
  3. Federal Decree-Law No. 45 of 2021 — Personal Data Protection
  4. Federal Decree-Law No. 46 of 2021 — Electronic Transactions and Trust Services
  5. sector-specific legislation and regulations;
  6. contractual cybersecurity obligations;
  7. insurance contracts;
  8. DIFC or ADGM legislation where applicable;
  9. emirate-specific cybersecurity requirements;
  10. regulatory requirements applicable to financial, health, telecommunications, energy or other critical sectors.

The current UAE Civil Transactions Law came into force on 1 June 2026 and repealed the 1985 Civil Transactions Law.

4. Civil Liability Under the 2025 Civil Transactions Law

The 2025 Civil Transactions Law provides the general civil-law foundation for compensation for harmful acts.

For a cyber incident, the central questions may include:

  • Was there a legally relevant harmful act or omission?
  • Was there a duty?
  • Was the defendant's conduct wrongful?
  • Did the conduct cause the claimant's loss?
  • What losses were legally compensable?
  • Did the claimant contribute to the loss?
  • Was the loss foreseeable or a natural consequence under the applicable legal framework?

Cybersecurity negligence may therefore become a civil-liability question.

Example

Suppose a critical water operator fails to maintain an important security control and an attacker exploits the known vulnerability.

If the claimant can establish the necessary elements of civil responsibility, the resulting losses could potentially include:

  • emergency restoration costs;
  • investigation expenses;
  • system reconstruction;
  • business interruption;
  • certain third-party losses;
  • property damage;
  • other legally recoverable losses.

The precise outcome depends on the applicable law and evidence.

5. Cybercrime Law and Civil Liability Are Different

The Cybercrime Law is principally concerned with prohibited conduct and criminal sanctions.

Federal Decree-Law No. 34 of 2021 addresses conduct such as hacking and unauthorised interference with information systems. For example, Article 2 addresses hacking and aggravates consequences where hacking causes damage, destruction or interruption of operation, or affects data or information.

But:

Criminal responsibility of the attacker and civil responsibility of an infrastructure operator are separate questions.

Suppose an attacker hacks a hospital.

There could potentially be:

Criminal proceeding

State v attacker

and separately:

Civil claim

Hospital/patient/business → responsible party

and potentially:

Regulatory proceeding

Regulator → infrastructure operator

The existence of one proceeding does not automatically determine all the others.

6. Personal Data Protection

Critical infrastructure frequently processes sensitive information.

Examples include:

  • patient records;
  • banking information;
  • identity information;
  • employee data;
  • customer accounts;
  • location information;
  • biometric information.

Federal Decree-Law No. 45 of 2021 defines personal data broadly and expressly includes sensitive and biometric data within its framework.

Consequently, a cyber incident involving critical infrastructure may generate two separate categories of harm:

Infrastructure harm

For example:

destruction of operational systems.

Data harm

For example:

unauthorised disclosure of patient information.

A single incident may therefore generate multiple legal claims and regulatory consequences.

7. Security as a Continuing Duty

Cybersecurity is not a one-time obligation.

A critical infrastructure operator may need continuing measures involving:

  • vulnerability management;
  • access controls;
  • authentication;
  • network segmentation;
  • monitoring;
  • incident response;
  • backup systems;
  • disaster recovery;
  • employee training;
  • vendor management;
  • logging;
  • patching;
  • penetration testing;
  • business continuity.

The UAE's information-assurance framework adopts a risk-based approach and contemplates technical controls, sector-specific requirements, continuous monitoring and compliance assessment for designated critical entities.

Therefore, liability analysis should normally examine the security position at the time of the incident, rather than asking simply whether the organisation had "a cybersecurity policy."

8. Duty of Care

A major civil-law question is whether the defendant owed a relevant duty toward the claimant.

Possible relationships include:

Contractual

A telecommunications provider promises to maintain specified security standards.

Regulatory

A regulated financial institution must comply with cybersecurity requirements.

Tortious/civil responsibility

A party's conduct causes legally compensable damage to another.

Data protection

A controller or processor has obligations relating to personal data.

Professional responsibility

A cybersecurity contractor fails to perform its agreed security services with the required standard.

9. The Importance of Foreseeability

Critical infrastructure creates an unusually high level of foreseeable cyber risk.

For example:

  • a hospital knows that ransomware could interrupt clinical systems;
  • a bank knows that account compromise can cause financial loss;
  • an airport knows that disruption of digital systems can affect operations;
  • an electricity operator knows that control-system compromise could affect physical infrastructure.

However:

Foreseeability of cyber risk does not mean that an operator guarantees absolute cybersecurity.

Cybersecurity regulation itself recognises the need for risk management rather than absolute elimination of every possible cyber threat. Dubai's cyber strategy, for example, expressly recognises that absolute security cannot be achieved and emphasises consideration of risk.

10. Causation

Causation is often one of the most difficult issues in cyber litigation.

Consider:

Known vulnerability

Attacker exploits vulnerability

Malware enters system

Operational system becomes unavailable

Service interruption

Customer losses

The claimant must connect the defendant's legally relevant conduct to the claimed loss.

A court may have to determine whether the loss resulted from:

  • the defendant's security failure;
  • the attacker's independent conduct;
  • the claimant's own negligence;
  • a third-party supplier;
  • an unrelated system failure;
  • multiple contributing causes.

11. Contributory Conduct

Cyber incidents frequently involve multiple actors.

For example:

  • operator fails to patch;
  • employee clicks a phishing link;
  • supplier misconfigures cloud security;
  • attacker exploits the vulnerability;
  • customer fails to activate available security controls.

The allocation of responsibility therefore becomes fact-sensitive.

The Aegis Resources decision discussed below provides a particularly useful example of how the court examined the security practices of both parties and considered whether the customer's own conduct contributed to the loss.

12. Case Law 1 — Graciela Ltd v Giacobbe

Graciela Limited v Giacobbe [2014] DIFC CFI 027

This is one of the most directly relevant UAE/DIFC authorities on cyber liability.

The claimant's IT system was deliberately sabotaged by a former senior IT employee. The system contained numerous servers and was essential to the claimant's business.

The court relied heavily on:

  • event logs;
  • forensic evidence;
  • IP information;
  • server evidence;
  • expert evidence;
  • witness testimony;
  • evidence concerning the defendant's knowledge of the system.

The court concluded that the defendant had sabotaged the system and held that the conduct constituted wrongful interference with property under the applicable DIFC law. Compensation included costs associated with restoring and investigating the IT system, emergency servers, network reconstruction and certain employee time. The damages awarded were USD 690,533.

Importance

Graciela demonstrates that cyber liability can involve traditional civil-law concepts.

The court did not need a special "critical infrastructure cyber tort."

Instead, the existing law concerning:

wrongful interference + property + causation + loss

was applied to an IT-system attack.

Critical-infrastructure relevance

If a cyberattack damages a power, water, transport or healthcare information system, similar legal reasoning may become relevant to determining recoverable system-restoration losses, subject to the governing law.

13. Case Law 2 — Aegis Resources DMCC v Union Bank of India

Aegis Resources DMCC v Union Bank of India (DIFC Branch) [2020] DIFC CFI 004

This is another major UAE cyber-liability authority.

A fraudster hacked the customer's email system and sent fraudulent payment instructions to the bank. The bank made payment based on those instructions.

The court described the case as involving the emerging realm of cyber fraud and examined the question:

Who should bear the loss—the bank or the customer?

On the facts, the court concluded that the loss fell upon the bank and awarded some consequential loss to the customer.

Importantly, the court examined the security of the customer's email system and the conduct of the parties rather than adopting an automatic rule that hacking always transfers responsibility to the victim.

Critical-infrastructure relevance

The case is particularly useful for financial infrastructure.

It illustrates that courts may examine:

  • authentication procedures;
  • email security;
  • bank controls;
  • employee conduct;
  • cyber-security arrangements;
  • causation;
  • contractual duties;
  • contributory conduct.

14. Case Law 3 — Gate MENA DMCC v Tabarak Investment Capital

Gate MENA DMCC & Huobi MENA FZE v Tabarak Investment Capital Ltd & Christian Thurner [2020] DIFC TCD 001

The dispute concerned cryptocurrency and alleged losses involving digital assets.

The court considered DIFC negligence principles, including:

  • duty of care;
  • breach;
  • causation;
  • loss;
  • contributory negligence;
  • contractual and regulatory obligations.

The court applied the DIFC Law of Obligations and concluded that the relevant defendant was not liable in negligence on the evidence presented.

Importance

The case demonstrates that sophisticated digital assets do not eliminate the traditional requirements of civil liability.

A claimant must still establish:

duty → breach → causation → loss.

Critical infrastructure relevance

The same reasoning can become relevant where a critical infrastructure operator alleges that a technology vendor, platform provider or financial intermediary failed to meet an applicable duty.

15. Case Law 4 — Shihab Khalil v Shuaa Capital

Shihab Khalil v Shuaa Capital PSC [2009] DIFC CFI 017

The case concerned DIFC jurisdiction and tort principles.

The court explained that, for a negligence claim, the claimant must establish both:

  1. lack of appropriate care; and
  2. loss caused by that lack of care.

The court emphasised that the relevant "incident" may include an essential component of the cause of action, including the occurrence of loss.

Cyber-liability significance

This reasoning is particularly useful in cyber disputes because the following may occur in different locations:

  • the vulnerable system is located in one jurisdiction;
  • the attacker operates from another;
  • the data is stored in another country;
  • the financial loss occurs elsewhere.

The jurisdictional analysis may therefore become complex.

16. Case Law 5 — Al Khorafi v Bank Sarasin-Alpen

Al Khorafi v Bank Sarasin-Alpen (ME) Ltd [2011] DIFC CA 003

The DIFC Court of Appeal examined the concept of an "incident" in the context of DIFC jurisdiction and explained that an incident may encompass an essential element of the conduct or loss necessary to establish a tort or statutory-duty claim.

Cyber relevance

Cyber incidents are inherently capable of being cross-border.

For example:

UAE infrastructure

foreign cloud provider

foreign attacker

UAE operational loss

A jurisdictional court may therefore need to identify where the legally significant incident or loss occurred.

Important qualification

This is primarily a jurisdictional authority, not a case establishing a general cyber-security duty.

17. Case Law 6 — Muzoon Holding LLC v Arif Naqvi

Muzoon Holding LLC v Arif Naqvi [2018] DIFC CFI 080

The court considered the DIFC jurisdictional gateway concerning claims arising from incidents or transactions connected with DIFC activities. The judgment relied upon earlier authority including Al Khorafi and examined the relationship between an incident, the cause of action and DIFC activities.

Cyber relevance

A critical infrastructure cyber claim involving a DIFC entity could raise similar jurisdictional questions where:

  • the cyber incident occurred partly in DIFC;
  • the claimant operates from DIFC;
  • the relevant transaction was performed in DIFC;
  • the damage arose in connection with DIFC activities.

Again, this is an analogical jurisdictional authority, rather than a dedicated critical-infrastructure case.

18. Case Law 7 — R.E. Lee International v Imran Khan

R.E. Lee International (Middle East) Ltd v Imran Khan [2022] DIFC CFI 087

The case included allegations concerning a data breach, although the court ultimately examined whether the claim was adequately pleaded and whether loss and damage could be established.

Importance

The case highlights an important principle for cyber litigation:

Alleging a data breach is not the same as proving actionable damage.

A claimant should identify:

  • what data was accessed;
  • how it was accessed;
  • who was responsible;
  • what legal obligation was breached;
  • what loss resulted;
  • how the loss was caused.

This is especially important for critical infrastructure operators because cyber incidents may be extensive while the legally recoverable loss remains narrower.

19. Case Law 8 — Al Buhaira National Insurance v Arab War Risks Insurance Syndicate

Al Buhaira National Insurance Company v Arab War Risks Insurance Syndicate [2024] DIFC CFI 013

This case involved insurance coverage and an express cyber-attack exclusion clause in the insurance documentation. The court considered the contractual insurance framework and the effect of policy provisions on coverage.

Importance for critical infrastructure

Cyber liability frequently produces an insurance dispute.

The operator may argue:

"The cyber incident caused an insured loss."

The insurer may respond:

"The policy contains a cyber-attack exclusion."

The court must then examine:

  • policy wording;
  • exclusions;
  • endorsements;
  • causation;
  • applicable law;
  • factual characterisation of the incident.

Thus:

Cyber liability and cyber insurance coverage are separate but interconnected legal questions.

20. What Graciela Teaches About Cybersecurity Evidence

Graciela v Giacobbe is particularly valuable because it demonstrates the importance of forensic evidence.

The court considered:

  • server logs;
  • IP addresses;
  • account activity;
  • hidden virtual servers;
  • deleted data;
  • expert analysis;
  • system architecture;
  • password information.

The court concluded that the evidence established responsibility on the balance of probabilities.

For critical infrastructure litigation, evidence preservation should therefore include:

Digital evidence

  • SIEM logs;
  • firewall logs;
  • authentication logs;
  • endpoint logs;
  • network traffic;
  • access records;
  • backups.

Physical/operational evidence

  • equipment status;
  • control-system records;
  • maintenance records;
  • incident reports.

Governance evidence

  • cybersecurity policies;
  • risk assessments;
  • vulnerability assessments;
  • audit reports;
  • training records;
  • vendor agreements.

21. Third-Party Vendor Liability

Critical infrastructure increasingly depends on suppliers.

For example:

Electricity operator

→ cloud provider

→ managed security provider

→ software vendor

→ hardware manufacturer

A cyber incident may result from a vulnerability in one of these layers.

Potential claims may involve:

  • breach of contract;
  • professional negligence;
  • breach of confidentiality;
  • indemnity;
  • warranty;
  • service-level agreement;
  • cybersecurity obligations;
  • insurance.

The contract should therefore ideally specify:

  • security standards;
  • incident reporting;
  • vulnerability disclosure;
  • audit rights;
  • access control;
  • subcontracting;
  • data location;
  • business continuity;
  • recovery time;
  • liability caps;
  • exclusions;
  • indemnities.

22. Contractual Allocation of Cyber Risk

A sophisticated critical-infrastructure contract may allocate responsibility through:

Security warranty

Supplier warrants that its systems comply with specified cybersecurity standards.

Incident notification

Supplier must notify the operator within a specified period.

Indemnity

Supplier indemnifies the operator for specified cyber-related third-party claims.

Audit right

Operator may audit compliance.

Business continuity

Supplier must maintain disaster-recovery capabilities.

Liability cap

Liability is capped at a specified amount.

Super-cap

Certain cyber events may receive a higher liability cap.

Insurance

Supplier must maintain specified cyber insurance.

23. Liability for Regulatory Non-Compliance

A critical infrastructure operator may face regulatory consequences if it fails to comply with applicable cybersecurity requirements.

The UAE's CIIP framework expressly contemplates:

  • national risk assessment;
  • sector risk assessment;
  • security requirements;
  • sector plans;
  • implementation;
  • monitoring;
  • compliance and enforcement mechanisms. 

Therefore, a civil damages action and regulatory enforcement should be analysed separately.

Civil question

Did the breach cause compensable loss?

Regulatory question

Did the entity comply with mandatory cybersecurity requirements?

Criminal question

Did a person commit a cybercrime?

One incident may trigger all three.

24. Critical Infrastructure and Physical Damage

One of the most important characteristics of critical infrastructure cyber liability is that cyber harm can become physical harm.

For example:

Cyberattack

Manipulation of industrial controls

Equipment failure

Fire or explosion

Property damage

Personal injury

Business interruption

The resulting legal claims may involve:

  • property damage;
  • personal injury;
  • contractual loss;
  • environmental damage;
  • business interruption;
  • third-party claims.

This makes cyber liability significantly more complex than a simple data-breach claim.

25. Business Interruption

Business interruption is often one of the largest consequences of a critical infrastructure cyberattack.

Potential losses may include:

  • lost production;
  • lost revenue;
  • emergency outsourcing;
  • replacement systems;
  • overtime;
  • restoration;
  • cybersecurity investigation;
  • customer compensation;
  • regulatory costs where legally recoverable.

However, a claimant must establish the legal basis and prove the loss.

Graciela is useful because the court accepted certain system restoration, emergency infrastructure and employee-time costs where supported by evidence.

26. Data Breach and Infrastructure Failure Are Different

A cyber incident can involve:

Type of harmExample
ConfidentialityPatient records disclosed
IntegrityOperational data altered
AvailabilityElectricity control system disabled
AuthenticityFraudulent instructions accepted
PhysicalEquipment damaged
FinancialMoney transferred
OperationalAirport systems unavailable
ReputationalCustomer confidence damaged

A single incident can involve all eight.

27. Insurance and Cyber Liability

Insurance becomes increasingly important in critical infrastructure.

Policies may cover:

  • incident response;
  • forensic investigation;
  • data restoration;
  • business interruption;
  • cyber extortion where legally permitted;
  • third-party liability;
  • privacy claims;
  • regulatory response expenses.

But coverage depends heavily upon the wording of the policy.

Al Buhaira National Insurance v Arab War Risks Insurance Syndicate demonstrates the importance of analysing contractual exclusions where cyberattack is involved.

28. Force Majeure and Cyberattacks

A critical infrastructure operator may argue that a sophisticated cyberattack constituted:

  • force majeure;
  • an external event;
  • an unforeseeable event;
  • an event beyond reasonable control.

But this does not automatically eliminate liability.

The court may need to ask:

  1. What does the contract define as force majeure?
  2. Was cyberattack included?
  3. Was the attack reasonably foreseeable?
  4. Were reasonable preventative measures taken?
  5. Did the party comply with notification requirements?
  6. Could the consequences have been mitigated?

Thus:

Cyberattack ≠ automatic force majeure.

The answer depends on the contract and governing law.

29. Cloud and Supply-Chain Cyber Risk

Critical infrastructure increasingly depends on:

  • cloud providers;
  • SaaS platforms;
  • telecom networks;
  • managed service providers;
  • software libraries;
  • hardware vendors;
  • remote-access tools.

A vulnerability in one supplier can therefore propagate through the infrastructure chain.

This creates the concept of:

supply-chain cyber liability.

The legal analysis may require identifying the exact failure point.

30. Government and Public Infrastructure

Where government infrastructure is involved, additional issues may arise concerning:

  • public authority status;
  • statutory duties;
  • sovereign immunity;
  • administrative law;
  • procurement contracts;
  • public-private partnerships;
  • national-security restrictions;
  • confidentiality;
  • evidence disclosure.

A civil claim against a private contractor supplying a government critical system may be legally different from a claim directly against a governmental entity.

31. DIFC Versus Onshore UAE

The case law discussed above requires an important qualification.

Onshore UAE

The principal substantive civil framework is now the 2025 Civil Transactions Law, effective from 1 June 2026, together with applicable federal and emirate-specific legislation.

DIFC

The DIFC has its own common-law-influenced legal framework.

Therefore:

Graciela and Aegis are highly useful UAE cyber-liability authorities, but they are DIFC decisions and should not automatically be treated as binding precedent for an onshore UAE court.

Their reasoning can nevertheless be valuable by analogy, especially for:

  • cyber causation;
  • evidence;
  • IT-system damage;
  • professional negligence;
  • contractual risk allocation;
  • cyber fraud.

32. Critical Infrastructure Cyber Liability Framework

A useful analytical model is:

Step 1 — Identify the asset

Is it:

  • electricity;
  • water;
  • telecommunications;
  • finance;
  • healthcare;
  • transport;
  • government;
  • energy;
  • food/agriculture?

Step 2 — Identify the legal relationship

Is the defendant:

  • operator;
  • employee;
  • supplier;
  • cloud provider;
  • cybersecurity provider;
  • bank;
  • insurer?

Step 3 — Identify the duty

Possible sources:

  • statute;
  • regulation;
  • contract;
  • professional duty;
  • data-protection obligation.

Step 4 — Identify the cyber event

For example:

  • ransomware;
  • DDoS;
  • phishing;
  • credential theft;
  • insider attack;
  • supply-chain attack;
  • destructive malware.

Step 5 — Establish breach

Was there:

  • inadequate security;
  • failure to patch;
  • inadequate access control;
  • failure to monitor;
  • failure to respond;
  • contractual non-compliance?

Step 6 — Establish causation

Connect:

security failure → cyber incident → damage

Step 7 — Quantify loss

Identify:

  • restoration;
  • interruption;
  • property damage;
  • data-related loss;
  • third-party claims.

Step 8 — Examine defences

Consider:

  • contributory conduct;
  • force majeure;
  • contractual limitation;
  • exclusion;
  • third-party causation;
  • illegality;
  • lack of causation.

33. Practical Example — UAE Electricity Infrastructure

Suppose an electricity operator's industrial control system is attacked.

Facts

A known vulnerability existed for six months.

The operator received a security advisory but did not implement the available patch.

An attacker exploited the vulnerability.

The control system failed for 48 hours.

Consequences

  • emergency repairs;
  • electricity interruption;
  • equipment damage;
  • investigation costs;
  • customer claims.

Potential legal analysis

Duty

→ statutory/regulatory/contractual cybersecurity obligations.

Breach

→ alleged failure to implement appropriate security measures.

Causation

→ vulnerability → attack → system failure.

Loss

→ repair + restoration + legally recoverable consequential losses.

Defences

→ sophistication of attack, third-party conduct, force majeure, contractual allocation and contributory conduct.

The actual outcome would depend upon the governing law, regulatory requirements, evidence and contractual arrangements.

34. Practical Example — Hospital Cyberattack

Suppose a UAE hospital's patient-management system is encrypted by ransomware.

The attack causes:

  • loss of access to patient records;
  • cancellation of appointments;
  • diversion of patients;
  • emergency IT expenditure;
  • possible disclosure of personal data.

There may be several legal dimensions:

Civil

Compensation for legally established losses.

Data protection

Potential obligations relating to personal data.

Cybercrime

Investigation and prosecution of the attacker.

Contract

Claims involving the hospital's IT/security vendors.

Insurance

Coverage under cyber or property/business-interruption policies.

Regulatory

Compliance with sector-specific requirements.

This demonstrates why cyber liability is multi-layered.

35. Six Major Principles from the Case Law

The eight authorities discussed above collectively illustrate the following principles:

PrincipleAuthority
Cyber sabotage can constitute actionable interference with IT propertyGraciela v Giacobbe
Cyber fraud liability depends on the particular security arrangements and conduct of the partiesAegis Resources v Union Bank
Negligence requires duty, breach, causation and lossGate MENA v Tabarak
An essential part of a tortious cause of action may determine jurisdictionShihab Khalil v Shuaa Capital
Cyber disputes can raise cross-border jurisdictional questionsAl Khorafi v Bank Sarasin-Alpen
DIFC jurisdiction depends on statutory jurisdictional gatewaysMuzoon Holding v Naqvi
Data-breach allegations must be connected to a properly established cause of action and lossR.E. Lee International v Imran Khan
Cyberattack exclusions and insurance wording can determine coverageAl Buhaira National Insurance v Arab War Risks Insurance Syndicate

36. Key UAE Cybersecurity Policy Context

The UAE's national cybersecurity framework identifies protection of critical assets as a major objective. The National Cybersecurity Strategy identifies nine critical sectors: energy; ICT; government; electricity and water; finance and insurance; emergency services; health services; transportation; and food and agriculture.

The current CIIP Policy describes a governance framework for CII entities involving identification of critical assets, national risk profiles, baseline security requirements, assurance and enforcement mechanisms.

This means that critical-infrastructure cyber liability should not be analysed solely as a conventional negligence dispute. It exists within a wider system of:

cybersecurity governance + sector regulation + civil liability + contracts + data protection + criminal law + insurance.

37. Important Distinction: Cybersecurity Duty vs Guaranteed Security

A critical legal distinction is:

Security obligation

"The operator must implement specified reasonable or mandatory security measures."

versus

Security guarantee

"The operator guarantees that no cyberattack will ever succeed."

The first is common in legal and regulatory frameworks.

The second is much harder to establish.

The UAE's cybersecurity policy itself recognises risk management and the impossibility of achieving absolute security.

Therefore, the occurrence of a successful cyberattack alone should not automatically establish civil liability.

38. Challenges in Proving Cyber Liability

Critical infrastructure cases may face significant evidentiary difficulties.

Attribution

Who actually conducted the attack?

Technical causation

Which vulnerability caused the failure?

Multiple causes

Did several failures contribute?

Loss quantification

How much economic damage actually occurred?

Counterfactual

What would have happened if the security measure had been implemented?

Evidence preservation

Were logs preserved before systems were rebuilt?

Confidentiality

Can sensitive infrastructure information safely be disclosed in litigation?

These issues make expert evidence particularly important.

39. Recommended Cyber Liability Evidence

An infrastructure operator involved in litigation should preserve, where legally appropriate:

  • incident-response reports;
  • forensic images;
  • SIEM records;
  • firewall logs;
  • access logs;
  • authentication records;
  • vulnerability scans;
  • patch records;
  • security policies;
  • employee training records;
  • vendor contracts;
  • service-level agreements;
  • penetration-test reports;
  • business continuity plans;
  • disaster recovery records;
  • insurance policies;
  • regulatory correspondence;
  • loss calculations.

Graciela demonstrates the importance of forensic and system evidence in proving responsibility for an IT attack.

40. Conclusion

UAE critical-infrastructure cyber liability is an emerging intersection of civil responsibility, cybersecurity regulation, data protection, contractual liability, insurance and cybercrime law.

The central legal analysis is:

Critical asset → applicable duty → security failure → cyber incident → causation → legally recoverable damage → defences → remedy.

The most directly relevant UAE/DIFC authorities include Graciela Ltd v Giacobbe, Aegis Resources DMCC v Union Bank of India, Gate MENA DMCC v Tabarak Investment Capital, Shihab Khalil v Shuaa Capital, Al Khorafi v Bank Sarasin-Alpen, Muzoon Holding v Arif Naqvi, R.E. Lee International v Imran Khan, and Al Buhaira National Insurance v Arab War Risks Insurance Syndicate. These cases demonstrate that courts can apply established principles of property interference, negligence, causation, jurisdiction, contractual responsibility, data-related loss and insurance interpretation to technologically complex disputes.

Important current-law qualification: the 2025 UAE Civil Transactions Law has applied since 1 June 2026, replacing the 1985 Civil Transactions Law. Older UAE cases should therefore be treated as historical or persuasive authorities where they interpret the repealed legislation, while current disputes should be analysed first under the 2025 Law and applicable sector-specific rules.

LEAVE A COMMENT