Hacking Contest Pits Dubai Government Agencies Head-to-Head | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


Training & Security Leadership

Live And IRL Hacking Contest Captured Attention at Vast GISEC Global Expo

Contestants from the Dubai Public Prosecutors’ Office compete in the Dubai Cyber Challenge at GISEC Global Sept 16-17, 2026. (Image: GISEC Global)

For many of the local visitors to the vast GISEC Global cybersecurity conference and expo in Dubai last month, one of the highlights was a capture-the-flag hacking contest pitting small teams from different government agencies against each other for cash prizes.

See Also: Webinar | Is Your Encryption Strategy Ready for the Cryptographic Reset?

Teams from 33 “government and semi-government entities” took part in this year’s Dubai Cyber Challenge, one of the organizers, Hamad Abdullah, a senior cyber vulnerability assessment executive at the Dubai Electronic Security Center, told ISMG.

Contestants ranged from the Dubai Public Prosecutors Office, to Fly Dubai.

DESC, the local cybersecurity authority, which sets cyber standards for government agencies and public-sector contractors in the desert kingdom, staged a much less ambitious challenge last year, Abdullah said.

The event last year was half the size, with many fewer entrants, and the “challenges were much easier,” he said. This year, for the second edition, DESC had engaged a top capture-the-flag contractor to expand the range and difficulty of the challenges, which is organized as a “Jeopardy-style” CTF, with a succession of different contests.

“This year, we went to ‘insane’ level,” he said, referring to the most difficult challenges of all.

Teams were limited to a maximum of three people, he added, saying it was up to the agency who they included, but that DESC provided them with a list of the skills required for the challenges. Teams were allowed to use AI “to a limited extent,” he said, only as a decision or analytical support tool, “not as a fully automated solution.”

Local visitors and international delegates came by to watch the participants hunched over screens for the two four-hour sessions on Sept. 16 and Sept. 17, and check out the large scoreboards, which reflected the teams’ achievements in the contest in real time.

Even among the 750-plus exhibitors on the more than 300,000 square foot exhibit floor, the cyber challenge area stood out visually, Greg Gastaud, from Try Hack Me, the contractor that designed and staged the CTF, told ISMG.

“We had some really cool custom scoreboards, animation, and visual stuff,” he said.

Being there in person and seeing the engagement, “That’s my favorite part of the job,” said Gastaud, who has been organizing CTFs for three years. “Most of them are online, but when you are able to actually be there with all the players and everyone and see it be successful, that makes all the hard work pay off.”

A core team of three worked on the contest content, while others stepped in as needed to work on, for example, the scoreboard systems and animations. A total of eight or nine staff were involved at the height, he said.

The 32 different challenges in the contests were designed to align with the skillsets required by cyberdefenders: A web hacking contest, an OT challenge, cloud security, AI and “a bit of forensics and network analysis, and then boot to root,” said Gastaud. Boot-to-root was a standalone virtual machine which contestants had to get from initial access to total control. “You have to figure out a way in, get an initial foothold and then escalate your privileges to the admin or root user,” he explained.

“In each category, we try to have at least one relatively easy challenge,” Gastaud said, “Just to ensure that everyone could feel like they were able to solve something.” Being unable to solve even a single challenge was “always demotivating,” he explained, “So the goal was really to make sure that everyone got on the scoreboard, and then obviously since it’s a big competition and they sent over some talented people, we had to make sure we had some insane challenges, as well.”

The challenges all involved real vulnerabilities, Gastaud said.

In a jeopardy style CTF, the flags are often small, unique pieces of code: A way to prove the contestant got access to a particular location on the target network. Gastaud said the Dubai Cyber Challenge had several flags in each challenge, because in the relatively short eight-hour duration of the game, contestants needed a little bit of guidance.

“If you have an insane challenge with one flag, that’s the end result, and it’s a very long way to get there, and there are so many possibilities to go down rabbit holes and lose a lot of time. … By adding multiple flags in the bigger challenges, we were able to show participants they’re on the right track. If I find flag two, or flag three, I know I am on the path. Whereas if we just had that final fourth flag, they would have had to get there in one step and that could be much more complicated.”

Gastaud said the operational technology challenge was one of the easier ones because making realistic contest challenges for OT was hard.

operational technology is “very hard to virtualize because they are these big physical industrial control systems. … So to be able to replicate that in a virtual machine hosted somewhere in the cloud is quite challenging,” he said.

The three winning teams, who between them received 100,000 dirhams – $27,220 – were in first place Digital Dubai, the agency charged with the virtualization not just of government services but of daily life.

In second place was the Dubai branch of the UAE Federal Authority for Identity, Citizenship, Customs and Port Security. Bringing up the rear in third place was the Dubai Roads and Transport Authority.



Click Here For The Original Source.

——————————————————–

..........

.

.