Training & Security Leadership
Live And IRL Hacking Contest Captured Attention at Vast GISEC Global Expo

The GISEC Global cybersecurity conference and expo in Dubai, which took place last month, served as a thrilling backdrop for a notable capture-the-flag (CTF) hacking contest. This event captivated numerous local attendees, highlighting intense competition among various government agencies vying for cash prizes. With the stakes high and excitement palpable, the contest symbolized both talent and innovation in the field of cybersecurity.
According to Hamad Abdullah, a senior cyber vulnerability assessment executive at the Dubai Electronic Security Center (DESC), 33 government and semi-government entities participated in this year’s Dubai Cyber Challenge. The range of participants was diverse, with teams originating from organizations such as the Dubai Public Prosecutors’ Office and the airline Fly Dubai. This year marked the second iteration of the Dubai Cyber Challenge, which saw a significant increase in both scale and complexity compared to its inaugural event.
Reflecting on last year’s competition, Abdullah noted that the previous challenge was notably less ambitious, featuring fewer contestants and easier challenges. He explained that the DESC engaged a renowned capture-the-flag contractor to introduce a more expansive range of challenges that would push participants’ skills to new heights. Instead of simple tasks, the 2026 edition adopted a “Jeopardy-style” format, characterized by a series of increasingly difficult contests aimed at assessing the capabilities of the contestants.
“This year, we went to ‘insane’ level,” Abdullah stated, referring to the most challenging aspects of the competition. Each team was limited to a trio of members, who were selected based on their skills as guided by the DESC. While competing in the contest, teams were permitted to utilize artificial intelligence to a limited extent—specifically, as a tool for decision-making and analysis rather than as a fully automated solution.
The audience included both local visitors and international delegates who gathered to observe the competitors engrossed in their screens during the two intense four-hour sessions held on September 16 and 17. Notably, an impressive scoreboard displayed real-time progress, reflecting the teams’ performances throughout the competition.
Distinctively, the cyber challenge area within the expansive 300,000 square foot exhibit space attracted attention. Greg Gastaud, a representative from Try Hack Me, the contractor tasked with designing and staging the CTF, remarked on the visually engaging nature of the contest area, which featured custom scoreboards and animated graphics. “Being there in person and seeing the engagement, that’s my favorite part of the job,” Gastaud expressed, underscoring the satisfaction derived from organizing a successful CTF after years of experience in the field.
A dedicated team of three coordinated the contest content, while additional staff supported various operational aspects, including scoreboard systems and animations. The event required the collaborative effort of multiple individuals, particularly during peak moments of competition. Gastaud explained that a total of eight or nine personnel contributed to the event’s operational success.
The contest included 32 unique challenges meticulously designed to align with the requisite skillsets of cyber defenders. Categories encompassed web hacking, operational technology challenges, cloud security, artificial intelligence, and network analysis, along with boot-to-root exercises. The latter involved a virtual machine where contestants had to gain initial access and escalate their privileges to assume control.|Gastaud highlighted that the challenges were intentionally tiered, with at least one relatively simple task in each category to ensure participants felt a sense of accomplishment. “Being unable to solve even a single challenge is always demotivating,” he stated, emphasizing the importance of allowing every team a chance to achieve something within the competition.
The challenges were grounded in real-world vulnerabilities, with the CTF based on unique flags—codes that prove a contestant has accessed a specific location within the target network. To enhance the participants’ experience and efficacy, multiple flags were incorporated into the larger challenges. “By adding multiple flags in the bigger challenges, we could affirm that contestants were on the right track,” Gastaud said, illustrating the strategic planning that went into the competition’s design.
Operational technology challenges proved particularly complex, as constructing realistic scenarios for these systems in a virtual format posed considerable difficulties. “Operational technology is very hard to virtualize because they are these large physical industrial control systems,” Gastaud explained, discussing the inherent challenges of replicating such systems digitally.
Ultimately, the competition concluded with three outstanding teams, who collectively earned a prize pool of 100,000 dirhams (approximately $27,220). Digital Dubai, the agency responsible for the ambitious task of virtualizing not only government services but daily life, successfully clinched the top position. The UAE Federal Authority for Identity, Citizenship, Customs, and Port Security secured the second place, while the Dubai Roads and Transport Authority took third place. This successful event not only showcased the skills of the participants but also highlighted the growing importance of cybersecurity initiatives in the region.

