Quantitative modeling of cyber risks in Gulf banks and FinTech platforms
-
DOIhttp://dx.doi.org/10.21511/bbs.21(2).2026.19
-
Article InfoVolume 21 2026, Issue #2, pp. 275–288
- 15 Views
-
2 Downloads
This work is licensed under a
Creative Commons Attribution 4.0 International License
Type of the article: Research Article
Abstract
FinTech growth in the Gulf has expanded digital access to banking services, but cyber-risk governance has not advanced at the same pace. This study develops and applies a quantitative framework to evaluate institutional, systemic, predictive, and probabilistic dimensions of cyber risk across Gulf financial technology ecosystems, including commercial banks, digital wallets, and payment platforms. The empirical design combined an application-level sample of ten leading mobile financial platforms with a vulnerability-level observation dataset generated through repeated static and dynamic security assessments between July 2024 and May 2025. The analysis integrated comparative statistical testing, extreme value modeling, dependency analysis, machine learning classification, and Bayesian estimation. The results revealed significant institutional divergence in vulnerability severities (p < 0.01), with Saudi Arabian Android banking applications recording the highest mean score (8.12) and UAE iOS applications the lowest (7.29). The risk distribution displayed a heavy-tailed structure, with a shape coefficient of 0.22 and a scale coefficient of 0.78, indicating that rare but severe vulnerabilities dominate exposure. Dependency modeling identified systemic linkages between platform type, regulatory environment, and vulnerability category, with correlations ranging from 0.29 to 0.36. Machine learning classification achieved 85% accuracy and 84% precision, while Bayesian estimation produced narrow 95% credibility intervals. The findings highlight distinct, quantifiable cyber-risk patterns across Gulf banks and FinTech platforms and support the need for integrated, data-driven supervisory frameworks.
- Keywords
-
JEL Classification (Paper profile tab)C38, G28, O33, L86
-
References58
-
Tables12
-
Figures1
-
- Figure 1. QQ-plot illustrating the fit of the GPD to exceedances above CVSS 8.0
-
- Table 1. Selected mobile financial applications (Dec 2025 – Mar 2026)
- Table 2. Measurement of constructs and variables
- Table 3. Grouped mean vulnerability severities by platform and country
- Table 4. Posterior contrasts across platform-country groups
- Table 5. EVT threshold sensitivity
- Table 6. Copula-based dependency estimates
- Table 7. Final copula selection by variable pair
- Table 8. Machine learning classification performance
- Table 9. Extended model performance
- Table 10. Hierarchical posterior summaries of mean vulnerability severities
- Table 11. Posterior probability comparisons
- Table 12. Summary of hypotheses testing results
-
- Abbas, S. K., Hussain, M., & Rimal, Y. N. (2025). Machine learning-based analysis of technology acceptance in FinTech: A behavioral study using digital wallet data. SN Computer Science, 6(6), 674.
- Afzal, A. M., Abu Khalaf, B., Al-Naimi, M. S., & Samara, E. (2025). The impact of Fintech on the stability of MENA banks. Risks, 13(6), 106.
- Afzal, F., Pan, H., Afzal, F., & Gul, R. F. (2024). Analyzing risk contagion and volatility spillover across multi-market capital flow. Heliyon, 10(21), e39918.
- Ahmad, A. K., Nahar, H. M., & Manajreh, M. M. N. (2024). Effect of social media on shaping the agenda of the communicator in the Jordanian TV channels. Middle East Journal of Communication Studies, 3(2), Article 3.
- Alamleh, H., Estremera, L., Arnob, S. S., & AlQahtani, A. A. S. (2025). Advanced persistent threats and wireless network security. Journal of Cybersecurity and Privacy, 5(2), 27.
- Al-Ansari, K. A., Aysan, A. F., & Syarif, M. F. (2024). Islamic FinTech and CBDCs. In K. Tsanis, H. C. Webb, A. Kaddour, & O. David-West (Eds.), The Palgrave handbook of FinTech in Africa and Middle East (pp. 53-70). Palgrave Macmillan.
- Albakri, M., Bello, M., & Al Rashdi, S. (2025). Digital transformation and cybersecurity fears in GCC. In M. Albakri (Ed.), Perspectives on digital transformation in contemporary business (pp. 25-60). IGI Global.
- AlBenJasim, S., Takruri, H., Al-Zaidi, R., & Dargahi, T. (2024). Cybersecurity framework for FinTech innovations: Bahrain case study. International Cybersecurity Law Review, 5(4), 501-532.
- Al-Hajri, A., Abdella, G. M., Al-Yafei, H., Aseel, S., & Hamouda, A. M. (2024). Digital transformation in the Arabian Gulf’s oil and gas sector. Sustainability, 16(15), 6601.
- Al-Hourani, S., & Weraikat, D. (2025). AI and ML in pharmaceutical supply chain resilience. Sustainability, 17(14), 6591.
- Al-Muntasir, M. (2022). The phenomenon of information flow from traditional and new media about the Corona pandemic from the perspective of newly graduated media professionals in Yemen. Middle East Journal of Communication Studies, 2(2), Article 1.
- Alshehadeh, A. R., Abu Nahleh, I. T., & Al-Zyoud, I. A. (2025). The impact of financial and non-financial information on investment decision-making in the Jordanian business environment. Al-Zaytoonah University Journal of Business, 1(1), 1-8.
- Alsmadi, A. A., & Alrawashdeh, N. (2025). The role and implications of finance revaluation: A comprehensive literature review. Al-Zaytoonah University Journal of Business, 1(1), 1-12.
- Anish, P. R., Verma, A., Venkatesan, S., & Ghaisas, S. (2024). Governance-focused classification of security requirements. In D. Mendez & A. Moreira (Eds.), Requirements engineering: Foundation for software quality. REFSQ 2024 (pp. 92-108). Springer.
- Arnone, G. (2024). Predictive analytics and ML in FinTech. In AI and chatbots in FinTech (pp. 41-54). Springer.
- Aslam, M., Abbasi, M. A. K., Khalid, T., Shan, R. U., et al. (2022). Improving data security and privacy in smart cities. Sensors, 22(23), 9338.
- Bader, A., Qtaish, A., Odeh, K., & Sa’d, H. (2025). Artificial intelligence and big data in accounting: The case of commercial banks in Jordan. Al-Zaytoonah University Journal of Business, 1(3), 1-18.
- Barelli, R., D’Onghia, M., & Longari, S. (2025). Toward secure electronic voting: A survey on E-voting systems and attacks. IEEE Access, 13, 89600-89626.
- Bhatia, M. (Ed.). (2022). Cloud adoption. In Banking 4.0 (pp. 129-146). Springer.
- Campisi, G., Muzzioli, S., & De Baets, B. (2024). Predicting U.S. stock market direction. International Journal of Forecasting, 40(3), 869-880.
- Çera, G., Khan, K. A., & Solenički, M. (2024). Antecedents of mobile banking usage. Global Business Review, 25(5), 1150-1170.
- Chang, C.-H. (2024). Exploring the effect of the government interventions on the information asymmetry in the post-pandemic. Journal of Applied Business and Economics, 26(6), 22-38.
- Chen, X., Wang, C., & Li, S. (2023). Supply chain finance and CSR. Supply Chain Management, 28(2), 324-346.
- Chen, Y., Wang, G.-J., Zhu, Y., Xie, C., & Uddin, G. S. (2024). Systemic risk drivers of FinTech institutions. The European Journal of Finance, 30(18), 2157-2190.
- D’Innocenzo, E., Lucas, A., Schwaab, B., & Zhang, X. (2024). Modeling extreme events. Journal of Business & Economic Statistics, 42(3), 903-917.
- Endress, T. (2025). Financial inclusion in Southeast Asia. In T. Endress & Y. F. Badir (Eds.), Business and management in Asia: Finance and investments in the digital age (pp. 191-204). Springer.
- Ghouse, S. M., Shekhar, R., & Chaudhary, M. (2025). Mobile wallet adoption in Oman. Journal of Islamic Marketing, 16(4), 1229-1257.
- Giudici, P., Centurelli, M., & Turchetta, S. (2024). AI risk measurement. Expert Systems with Applications, 235, 121220.
- Gounari, M., Stergiopoulos, G., Pipyros, K., & Gritzalis, D. (2024). PSD2 compliance and cybersecurity. International Cybersecurity Law Review, 5(1), 79-120.
- Haq, I. U., Lee, B. S., Rizzo, D. M., & Perdrial, J. N. (2024). Automated ML for detecting anomalies. Machine Learning with Applications, 16, 100543.
- He, P., Zhou, H., Jiang, C., Anand, A., & Zhou, Q. (2025). Responsible leadership and knowledge hiding. Journal of Knowledge Management, 29(1), 49-71.
- Heranval, A., Lopez, O., & Thomas, M. (2024). Bayesian credibility and cyber insurance. European Actuarial Journal, 14(3), 749-776.
- Idayani, R. W., Nadlifatin, R., Subriadi, A. P., & Gumasing, M. J. J. (2024). Cyber risk and FinTech. Procedia Computer Science, 234, 1356-1363.
- Jong, S. C., & Ong, D. E. L. (2024). A novel Bayesian network approach for predicting soil-structure interactions induced by deep excavations. Tunnelling and Underground Space Technology, 152, 105865.
- Khader, M., Chai, W. X. T., & Neo, L. S. (2021). Introduction to cyber forensic psychology: Understanding the mind of the cyber deviant perpetrators. World Scientific.
- Koop, G., McIntyre, S., Mitchell, J., & Poon, A. (2024). Using stochastic hierarchical aggregation constraints to nowcast regional economic aggregates. International Journal of Forecasting, 40(2), 626-640.
- Lawrence, T. B., & Shadnam, M. (2008). Institutional theory. In W. Donsbach (Ed.), The international encyclopedia of communication. Wiley.
- Mahmud, I., Wei, J., & Summerfield, N. (2025). Mobile banking risk assessment. Journal of Computer Information Systems.
- Meraj, M., Ishrat, I., & Kaur, M. (2025). FinTech adoption in UAE. Qualitative Research in Financial Markets, 18(3), 640-671.
- Morshed, A., & Khrais, L. T. (2025). Cybersecurity in digital accounting systems. Journal of Risk and Financial Management, 18(1), 41.
- Ndlovu, T., & Chikobvu, D. (2024). The GARCH-EVT-Copula approach to investigating dependence and quantifying risk in a portfolio of Bitcoin and the South African Rand. Journal of Risk and Financial Management, 17(11), 504.
- Niankara, I., Hassan, H. I., Traoret, R. I., & Islam, A. R. M. (2025). Consumer savings and digital remittance in open banking: Insights from bibliometric and geospatial econometric analysis. Human Behavior and Emerging Technologies, 2025(1), Article 9352257.
- Oreqat, A. (2021). The degree of satisfaction of Facebook users about its features, usage motives and achieved gratifications: An applied study on students of the Faculty of Mass Communication at the Middle East University. Middle East Journal of Communication Studies, 1(1), Article 1.
- Rahman, M. M., Pokharel, B. P., Sayeed, S. A., Bhowmik, S. K., Kshetri, N., & Eashrak, N. (2024). riskAIchain: AI-driven IT infrastructure-Blockchain-backed approach for enhanced risk management. Risks, 12(12), 206.
- Schetakis, N., Aghamalyan, A., Boguslavsky, I., Rees, H., Rakotomalala, S., & Griffin, L. (2024). Quantum machine learning for credit scoring. Mathematics, 12(9), 1391.
- Shaban, O. S., & Omoush, A. (2025). AI-driven financial transparency and corporate governance: Enhancing accounting practices with evidence from Jordan. Sustainability, 17(9), Article 3818.
- Shi, Y., & Jin, Y. (2025). How FinTech impacts urban economic resilience: Evidence from China. Sustainability, 17(17), 7717.
- Sneha, Malik, P., Sharma, R., Ghosh, U., & Alnumay, W. S. (2023). Internet of Things and long-range antennas: Challenges, solutions and comparison in next-generation systems. Microprocessors and Microsystems, 103, 104934.
- Syarif, M. F., & Aysan, A. F. (2025). Enabling crowdfunding platforms in Qatar: A regulatory framework for growth and sustainable innovation based on network analysis and Monte Carlo simulation. Journal of Islamic Marketing, 16(3), 759-785.
- Taqa, S. B. A. (2025). The mediating role of remote communication on the relationship between electronic human resource management practices and organizational performance in Iraqi commercial banks. Middle East Journal of Communication Studies, 5(1), 1-52.
- Tawfik, O. I., Ahmed, M. A., & Elmaasrawy, H. E. (2024). The mediating role of mobile banking-based financial inclusion disclosure on the relationship between foreign investment and bank performance. International Journal of Financial Studies, 12(4), 128.
- Van Asselt, M. B., & Renn, O. (2011). Risk governance. Journal of Risk Research, 14(4), 431-449.
- Wu, M., Subramaniam, G., Li, Z., & Gao, X. (2025). Using AI technology to enhance data-driven decision-making in the financial sector. In S. Dixit, M. Maurya, V. Jain, & G. Subramaniam (Eds.), Artificial intelligence-enabled businesses: How to develop strategies for innovation (pp. 187-207). John Wiley & Sons.
- Xia, L., Semirumi, D. T., & Rezaei, R. (2023). A thorough examination of smart city applications: Exploring challenges and solutions throughout the life cycle with emphasis on safeguarding citizen privacy. Sustainable Cities and Society, 98, 104771.
- Ye, W., Chaiyapa, W., & Li, Y. (2024). A comparative study of energy governance on energy resilience: Process tracing of China and Thailand’s solar power development. Energy Strategy Reviews, 55, 101500.
- Zakki, M. N., Iftikhar, N., Khan, S. S. U., Nishat, F., & Arshi, O. (2025). Reviewing theoretical perspectives on IT governance and compliance in banking: Insights from U.S. regulatory frameworks. In F. Rehman, I. U. Khan, O. Arshi, & S. K. Gupta (Eds.), Emerging trends in information system security using AI & data science for next-generation cyber analytics (Vol. 32, pp. 119-133). Springer.
- Zhang, X., Antwi-Afari, M. F., Zhang, Y., & Xing, X. (2024). The impact of artificial intelligence on organizational justice and project performance: A systematic literature and science mapping review. Buildings, 14(1), 259.
- Zhao, M., & Park, H. (2024). Bidirectional risk spillovers between Chinese and Asian stock markets: A dynamic Copula-EVT-CoVaR approach. Journal of Risk and Financial Management, 17(3), 110.


