Skip to main content

Security Advisor Middle East - June 2026

Page 1


BUILDING ECONOMIC RESILIENCE

MASTERCARD, DELINEA, AND COMMVAULT ON WHY RESILIENCE IS NOW A BOARD-LEVEL ECONOMIC PRIORITY

Radisson Blu Hotel & Convention Center Riyadh Minhal

30th August 2026 06:30 PM onwards

In August, CPI will be hosting the inaugural Future Enterprise Awards in Riyadh. The awards are designed to recognize IT and business leaders that are driving rapid digital transformation across the Kingdom.

The KSA Awards want to acknowledge those who are championing change, whether it be from a private or public sector organization, we want to pay tribute to the fearless trailblazers forging a new path and a new identity for the KSA. For more information about the event and nomination details, please visit the event website below :https://tahawultech.com/ksa-futureenterpriseawards/2026/

OFFICIAL PUBLICATIONS HOSTED BY GOLD SPONSOR

Next leap in ITSM isn’t replacing your teams, it’s multiplying them

Fortinet achieves 1 million people trained in cybersecurity goal ahead of schedule

In alignment with International Women’s Day 2026, TahawulTech.com, organised by CPI, invites you to the Women in Technology Forum & Awards 2026 — a flagship platform dedicated to advancing leadership, inclusion, and impact across the technology ecosystem.

The forum brings together CEOs, technology decision-makers, innovators, policymakers, and trailblazers to explore how organisations that actively invest in women — through mentorship, leadership pathways, skills development, and visibility — gain stronger innovation, resilience, and long-term growth.

Whether you are a technology leader, changemaker, or organisation committed to shaping a more inclusive digital future, this forum offers a powerful space to contribute, connect, and lead.

We look forward to welcoming you to Dubai this April as we come together to Give to Gain.

OFFICIAL PUBLICATIONS HOSTED BY

For more information about the event and nomination details, please visit the event website below :https://www.tahawultech.com/women-in-tech/2026/ Dubai 2026 6:00 PM onwards Give to gain. Powering women in tech Gala Dinner Event

E-mail: sandhya.dmello@ cpimediagroup.com Talk

RESILIENCE BECOMES ECONOMY’S QUIET FOUNDATION

Every transaction that clears and every service that stays online rests on something customers rarely notice. The quiet ability of digital systems to absorb a shock and keep running. Across the Middle East, that capacity has moved from the server room to the boardroom, and this issue explains why. Our cover story brings together Mastercard, Delinea and Commvault around a single argument. Cyber resilience and business resilience are now the same thing. Mastercard’s inaugural Cyber Pulse report puts hard numbers behind the claim, with the average regional breach reaching $7.29 million and the UAE countering more than 800,000 attacks each day. Spending is rising, yet breaches climb with it, a sign that the real gaps sit in governance, skills and execution rather than tooling alone.

AI runs through almost everything we cover this month. Attackers have weaponised it, collapsing the exploit window from months to hours, while enterprises race to adopt agentic systems

that create fresh identities and fresh exposure. Voices from SentinelOne, SANS Institute, Commvault and MAST Consulting set out what disciplined adoption looks like, from autonomous defence and embedded guardrails to human accountability that cannot be handed to a machine.

Research from Optro, Nutanix, HP and Darktrace sharpens the picture, showing how shadow AI, embedded tooling and abused remote access tools are widening the surface security teams must defend. Our opinion pages, featuring BeyondTrust, Qualys, OPSWAT, Sophos, Censys and Cequence Security, return to the fundamentals that still decide outcomes, privileged access, visibility and risk quantified in language the board understands.

Resilience is no longer a defensive afterthought. Resilience is the foundation on which continued economic activity now rests, and the organisations that treat it that way will be the ones still trading when others falter.

LINKSHADOW ACCELERATES AFRICAN EXPANSION THROUGH STRATEGIC DISTRIBUTION PARTNERSHIP WITH REDINGTON

LinkShadow, a leading AI-powered cybersecurity company, announced a strategic pan-African distribution partnership with Redington, a leading technology aggregator and innovation catalyst. The collaboration marks a significant milestone in LinkShadow’s global growth strategy and will enable enterprises across Africa to strengthen cyber resilience through advanced threat detection, data security, and identity protection capabilities.

As organisations across Africa rapidly embrace cloud computing, artificial intelligence, digital banking, smart infrastructure, and connected services, cyber risk has emerged as one of the most critical business challenges facing enterprises today. The increasing sophistication of cyberattacks, coupled with expanding digital footprints and evolving regulatory requirements, is driving demand for intelligent, scalable, and integrated cybersecurity solutions that can provide visibility across increasingly complex environments.

Through this partnership, Redington will leverage its extensive regional channel ecosystem and market reach to bring LinkShadow’s nextgeneration cybersecurity platform to enterprises, government entities, critical infrastructure providers, and managed security service providers (MSSPs) across the continent. Together, the two organisations will empower customers to proactively identify threats, reduce security blind spots, accelerate incident response, and strengthen overall cyber resilience.

Founded with a vision to transform how organisations detect and respond to cyber threats, LinkShadow initially pioneered AIdriven Network Detection and Response (NDR) capabilities that provided deep

visibility into network activity and threat behavior. LinkShadow is positioned in the Visionaries Quadrant in the 2026 Gartner® Magic Quadrant™ for NDR, further reinforcing its commitment to innovation and its ability to help organisations address evolving cybersecurity challenges. As enterprise attack surfaces expanded, the company broadened its cybersecurity portfolio to include Data Security Posture Management (DSPM), enabling organisations to discover, classify, monitor, and protect sensitive data across hybrid and multi-cloud environments. Recognising the growing prevalence of identity-centric attacks, LinkShadow further introduced Identity Threat Detection and Response (ITDR), helping organisations mitigate identity compromise, privilege abuse, insider threats, and account takeover risks.

Today, these capabilities converge within CyberMeshX (CMX), LinkShadow’s next-generation cyber intelligence platform. CMX unifies network, data, and identity security into a single adaptive framework that delivers contextual visibility, AI-powered threat correlation, and actionable intelligence across the entire enterprise environment. By breaking down traditional security silos and integrating seamlessly with existing security investments, CMX enables organisations to build a more connected, resilient, and future-ready cybersecurity architecture.

“Trust has become one of the most valuable currencies of the digital economy,” said Jim Mathew, President, Africa & Egypt, Redington. “As organisations across Africa continue to invest in cloud, AI, and connected digital services, cybersecurity must remain at the heart of that journey. Through our partnership with LinkShadow, we are empowering our ecosystem with the intelligence, visibility, and expertise needed to support sustainable digital growth across the continent.”

“As cyber threats become more sophisticated, organisations need security platforms that not only detect threats but also provide the intelligence needed to respond quickly and effectively,” said Hishamul Hasheel, Vice President, Software Solutions Group, Africa, Redington. “By bringing LinkShadow into our cybersecurity portfolio, we are enabling partners throughout our regional ecosystem to deliver advanced threat detection and security analytics capabilities that help customers improve resilience, strengthen operations, and secure their digital transformation initiatives.”

Africa’s cybersecurity market continues to experience significant growth, fueled by increasing digital adoption, cloud-first initiatives, expanding critical infrastructure projects, and heightened awareness of cyber risk at the boardroom level. As organisations modernise operations and embrace emerging technologies, the demand for unified, intelligence-driven cybersecurity solutions continues to accelerate.

“Redington’s appointment as LinkShadow’s Distributor for Africa is a significant step in expanding our channelled growth across the region. With Redington’s strong partner ecosystem,

market reach and value-added distribution capabilities, we will enable more partners to deliver LinkShadow’s AI CyberMesh Platform for Digital Trust to enterprises and governments, helping them strengthen cyber resilience and address evolving threats across Africa,” said Sajin Yousuff Kutty, Chief Partner Officer at LinkShadow.

As threat actors increasingly leverage

automation, artificial intelligence, and sophisticated attack techniques to evade traditional defenses, organisations require cybersecurity platforms capable of correlating signals across network, data, and identity layers in real time.

LinkShadow’s AI-driven architecture empowers security teams with deeper context, accelerated threat investigations, and improved operational efficiency,

enabling them to respond faster and more effectively to emerging threats.

The partnership underscores LinkShadow’s continued investment in high-growth international markets and reinforces both organisations’ commitment to advancing cybersecurity innovation, digital trust, and cyber resilience across Africa’s rapidly evolving digital economy.

UNIFONIC AND IDEEM FORGE STRATEGIC PARTNERSHIP TO DEFINE FUTURE OF DIGITAL IDENTITY IN GCC

Unifonic, the region’s leading AI-native CX Platform, has entered into a strategic partnership with Ideem to establish a secure digital ecosystem for enterprises across the Gulf Cooperation Council (GCC) with next-generation, passwordless authentication.

Unifonic has established itself as a trusted partner to the region’s largest brands, enabling them to navigate the complexities of customer communication across telecom, conversational messaging, digital messaging and social media messaging channels. With the GCC organisations championing digital maturity potential, Unifonic strives to address the challenges associated with ‘authentication,’ which is emerging as one of the biggest hurdles in the customer journey.

Michael Falorni, Vice PresidentGrowth and Business Development of Unifonic, said: “At Unifonic, we aim to provide solutions that facilitate seamless connection between businesses and their customers. By collaborating with Ideem, we are advancing this mission. Together we are creating a passwordless ecosystem for our clients that helps reduce friction, increase security, and build more trust with their users.”

By partnering with Ideem, Unifonic is enabling its clients to move away from the ‘password burden’ and the growing frustrations of SMS-based OTPs. This

move enables businesses to offer a frictionless authentication experience, reducing the risks associated with traditional OTPs.

Toby Rush, CEO at Ideem, said: “Unifonic plays a pivotal role in driving customer engagement across the region. With broad local market insights and a clear understanding of friction points, the company can support clients by streamlining the customer journey. We are excited to collaborate with Unifonic and support them in strengthening the region’s enterprise landscape with passwordless authentication.”

Under the partnership, Unifonic and Ideem will launch a Zero-Trust approach

in the GCC market to address challenges posed by traditional passwords and OTPs, which are vulnerable to phishing. As part of this approach, Ideem will deliver bank-grade security solutions originally designed for top-tier financial institutions via a simple software integration.

This move will benefit Unifonic’s clients at multiple levels. It ensures higher conversion rates by preventing users from dropping off due to password resets or OTP non-receipt. Similarly, it reduces fraud as cryptographic device binding makes takeovers nearly impossible. This approach will also contribute to reducing costs associated with password management and data breaches.

TENABLE UNVEILS AI-POWERED

CLOUD DETECTION AND RESPONSE CAPABILITIES

New threat detection and response capabilities reduce investigation time and mean time to remediation by transforming disjointed alerts into precise action.

Tenable Holdings, Inc., the exposure management company, announced new AI-powered cloud threat detection capabilities that extend the Tenable One Exposure Management Platform, enabling security teams to prioritise and remediate the exposures attackers are actively targeting. As part of Tenable One, Tenable One Cloud Exposure correlates runtime telemetry with deep exposure context, transforming threat investigations and empowering teams to reduce risk before attacks impact the business.

Static defenses cannot keep up with attackers who have weaponised AI, collapsing the exploit window from months to hours. Compounding the issue, fragmented security tools leave organisations overwhelmed with alerts while struggling to identify which risks require immediate action. Without intelligent correlation and prioritisation, security teams burn critical cycles on endless triage, rather than reducing the exposures most likely to lead to compromise.

Tenable addresses these operational inefficiencies by bridging the gap between cloud threat activity and unified risk visibility for proactive exposure management. Tenable goes beyond static misconfigurations and vulnerabilities, contextualising runtime telemetry within the broader attack surface, empowering security teams to stop chasing theoretical risks and prioritise remediation based on true business impact.

Tenable One Cloud Exposure delivers a new way to respond to threats with AI-powered threat stories, an AI-driven investigation layer that automatically correlates related detections across

time, identity and cloud resources, transforming hundreds of raw alerts into a clear narrative of how an attack unfolded. Validated against near-realtime exposure context and risk insights, threat stories give defenders a clear, prioritised picture of what happened, what’s at risk and where to act first.

Tenable One Cloud Exposure expands enterprise-wide risk visibility with new cloud detection and response (CDR) capabilities, including:

• Vulnerability Validation and Runtime: Uses active scanning to confirm cloud resources that are reachable from the internet, delivering validated exposure context that sharpens alert prioritisation and reduces noise.

• Dual Coverage: Combines agentless, Tenable-authored detections with an optional eBPF runtime sensor, giving security

teams comprehensive visibility across cloud workloads without sacrificing deployment flexibility or coverage.

• Guided Response with Tenable Hexa AI: As the agentic engine of Tenable One, Tenable Hexa AI is the intelligence layer that reasons across live exposure context, threat findings, and environment history to deliver a prioritised, actionable response plan, in plain language, at attacker speed.

“Security teams don’t need more alerts. They need to know which exposures are actually putting the business at risk,” said Eric Doerr, Chief Product Officer, Tenable. “By combining runtime cloud telemetry with the exposure intelligence already inside Tenable One, we’re helping customers move from investigation to remediation faster and with greater confidence.”

Eric Doerr, Chief Product Officer, Tenable.

COHESITY MAESTRO: DATA

PROTECTION, RECOVERY, AND SECURITY INTELLIGENCE — INSIDE EXISTING ENTERPRISE AI WORKFLOWS

Cohesity will deliver the industry’s first headless data security architecture by extending protection, real-time telemetry, autonomous agents, and AI search directly into the AI-driven workflows enterprises have already built.

Cohesity, the leader in AI-powered data security, today announced Cohesity Maestro, making the full Cohesity Data Cloud — cyber resilience operations, real-time telemetry, autonomous agents, and Cohesity Gaia, its AI-powered enterprise search and knowledge engine — natively accessible through Model Context Protocol (MCP). With Cohesity Maestro, we’re pioneering a headless architecture for cyber resilience — a capability no vendor in the industry has yet brought to market: one in which key Cohesity actions, telemetry signals, and data assets can be driven through agents, with no Cohesity interface required. Just as companies like Salesforce pioneered headless enterprise software, making their entire CRM platform commandable by external AI agents through open standards, Cohesity brings that same architectural shift to data security.

new. Enterprises aren’t evaluating AI platforms anymore. They’ve chosen them. Their teams continue to build workflows around Claude, Gemini, and ChatGPT that grow more capable every week. The question they’re asking vendors isn’t “can you give us AI?” It’s simpler: can your product reach us where we already are?

Built on the open MCP standard, Cohesity Maestro integrates natively with the AI platforms enterprises have already standardised on, including Anthropic Claude, OpenAI ChatGPT, and Google Gemini, without custom integrations or proprietary connectors. While some competitors have created a walled garden of agentic experience, Cohesity Maestro is open by design, giving enterprises broad choice over their AI stack and the flexibility to use the agentic tools best suited to their needs.

“Our customers have already chosen,” said Sanjay Poonen, CEO, Cohesity. “Claude, Gemini, and GPT already run operations on these platforms, which

grow in capability every day. Cohesity Maestro gives those platforms direct access to our data protection capabilities. No new console. No workflow changes. Just the power of Cohesity, wherever their AI already lives. This is what headless data protection looks like, and Cohesity is the first in our industry to deliver it.”

Cohesity has long believed that technology should adapt to how people work, not the other way around. Cohesity’s platform already has the ability to act as an Agent to drive autonomous actions and orchestration, all within the user experience of the platform. For example, Cohesity Copilot, launched in 2024, introduced natural-language administration for data protection before the industry followed suit. Cohesity RecoveryAgent, launched in 2025, delivered intelligent cyber recovery when others were still selling manual runbooks.

That conviction now points somewhere

For enterprises creating their own AI-driven workflows and assembling models, tools, and dashboards tailored to how their teams work, Cohesity Maestro fits inside whatever that looks like, while being governed by the same role-based access controls, authentication, and audit framework that apply to direct platform access. Cohesity doesn’t prescribe the AI experience; it participates in the one customers are already building on their own security terms.

IT and security operations teams can now ask what changed across their environment in the last 24 hours and surface a prioritised view of businesscritical risks and recovery gaps. From there, they can trigger restores, hunt threats, and orchestrate recovery directly from the AI tools they already use, without switching to a separate console. With Cohesity Maestro, customers will have native access to Cohesity platform capabilities, including:

• Cyber resilience orchestration — data protection actions, including protection, restores, status, reporting, query status, recovery groups, blueprints, threat hunting, and more

• Telemetry and threat signals —

Sanjay Poonen, CEO, Cohesity.

real-time security telemetry and operational signals, surfaced into any AI workflow, enabling a custom intelligence layer integrated with existing operations

• Cohesity Gaia — semantically enriched search over all protected data, powered by NVIDIA enterprise AI and a deep metadata catalog,

delivering enterprise data insights for developing better agents (available to Cohesity Gaia customers)

• Cohesity AI agents — including Cohesity Copilot for conversational reporting, anomaly detection, and operational actions, and Cohesity RecoveryAgent for recovery group

and blueprint orchestration, with more agents to follow

As enterprise AI agents become more capable, Cohesity Maestro lays the foundation for a new model of autonomous business resilience: one in which an agent detects an issue, decides the appropriate response, and acts without waiting for human instruction.

DELINEA INTEGRATES WITH CYERA TO PRIORITISE DATA-AWARE IDENTITY SECURITY IN AI ERA

New integration connects privileged identity access to sensitive data exposure intelligence in one unified view, prioritising the highest-risk threats.

Delinea, the identity security control plane that secures access across human, machine, and AI identities, and Cyera, the fastest-growing AI Security Platform, have announced a product integration that connects privileged access to sensitive data exposure, automatically correlating identities with the data they can access. Together, Delinea and Cyera help security teams identify, prioritise, and remediate the highestrisk access paths across every human, machine, and AI agent.

As identities multiply and AI agents interact with data at machine speed, security teams struggle to govern which privileged identities can reach critical data, and act on that risk before a breach occurs. With Delinea and Cyera, identity security becomes data-aware: accounts with access to mission-critical data are automatically elevated in risk scoring, and teams can prioritise access reviews and least-privilege enforcement based on the sensitivity of the data at stake.

identities multiply, security teams need better context to prioritise risk and govern access with confidence. Delinea and Cyera help bring identity and data context together so teams can focus on the risks that matter most.”

context flow from Cyera into Delinea, where each identity is automatically correlated with the data it can access, translating data classifications and exposure context into a continuously updated risk picture. Security teams can then prioritise remediation, access reviews, and privileged access controls based on the sensitivity and exposure level of the underlying data.

With Delinea and Cyera, security teams can:

• Remediate the exposures that matter most: Risk scoring automatically reflects data classifications, so teams close the highest-impact gaps first rather than working through an undifferentiated queue of privileged accounts.

“Organisations cannot afford to manage access risk in one tool and data risk in another and hope someone connects the dots,” said Chris Kelly, president of Delinea. “As human, machine, and AI

The Delinea Platform and Cyera Data Security Posture Management (DSPM) integrate via API to deliver data-aware identity security at scale. Cyera continuously discovers, classifies, and monitors sensitive data across cloud and on-premises datastores. Data classification labels and exposure

• Spend less time chasing every alert: Entitlements alone no longer drive the alert queue, only accounts with real exposure to critical assets require immediate attention.

• Get the full picture, in one place: Human, machine, and AI identities connected to their complete exposure context, giving teams a single source of truth for identity and data risk.

Chris Kelly, President, Delinea.

NETAPP, CISCO PARTNER TO BOOST DEFENSE-IN-DEPTH FOR ENTERPRISE CYBER RESILIENCE

New NetApp Splunk SOAR playbook helps contain ransomware attacks and limit data loss.

NetApp, the Intelligent Data Infrastructure company, and Cisco announced an expansion of their collaboration to help customers strengthen defense-in-depth strategies for customers.

Combining Intelligent Data Infrastructure with advanced analytics and observability capabilities, NetApp and Splunk have delivered deep, realtime visibility into storage and infrastructure health. Together, they are helping customers turn operational data into actionable insights that improve reliability, security, and business outcomes. By expanding their collaboration with the new NetApp Splunk Security Orchestration, Automation, and Response (SOAR) playbook, NetApp and Splunk are helping joint customers contain ransomware attacks and limit data loss at the storage layer, enhancing the containment of the blast radius of cyberattacks while increasing the speed and reducing the cost of recovery.

on data stored in NetApp ONTAP, we’re helping make a defense-in-depth security strategy simpler and more effective.”

Utilised as part of the organisation’s defense in depth security strategy, the NetApp Splunk SOAR playbooks help to strengthen collaboration between security and storage teams.

Automating the response and recovery actions against cyber threats with the NetApp Splunk SOAR playbook improves security team metrics like mean time to contain (MTTC) and reduces the manual effort and skills required to protect data. As a result, NetApp and Cisco are making it faster and more efficient for enterprises to achieve cyber resilience.

“Effective security strategies require visibility and action across the entire technology stack, including the data layer,” said David Dalling, GVP, Splunk Security at Cisco.

“With AI accelerating both the speed and sophistication of cyberattacks, the window to respond has never been smaller,” said Sandeep Singh, Senior Vice President and General Manager, Platform at NetApp.

“To limit the cost and impact of ransomware, organisations must act the moment a threat is detected, which means extending security automation into the storage layer where data lives. As the company delivering the most secure storage on the planet, NetApp is uniquely positioned to make storage an active part of a defense-in-depth strategy. By working with Cisco to enable Splunk SOAR workflows to take direct action

To give customers the resiliency and flexibility they need to protect their data, Cisco and NetApp are releasing the NetApp Splunk SOAR playbook. Splunk Enterprise Security is already integrated with NetApp Ransomware Resilience to collect analytics from the data layer, enhancing incident triage and prioritisation. With the new playbook, Splunk SOAR users can now use those signals as well as signals from other solutions to automatically take incident response actions directly on NetApp ONTAP storage as an integral part of their incident response. These actions include blocking a suspicious user, taking snapshots of the data and taking data volumes offline to protect against further infection. As a result, customers will be better able to contain ransomware attacks and limit data loss at the storage layer.

“With the new NetApp Splunk SOAR playbook, ONTAP storage becomes an active participant in the security ecosystem, enabling organisations to contain threats directly targeting enterprise data. By connecting NetApp storage into Splunk SOAR workflows, we’re helping security and storage teams collaborate more seamlessly and respond to incidents with greater speed and confidence.”

“The partnership between Splunk and NetApp helps customers run their businesses more securely and effectively, connecting operations across storage and security teams,” said Dallas Olson, Chief Commercial Officer at NetApp. “By giving customers real-time visibility into what’s happening across their environments, NetApp and Splunk enable enterprises to reduce disruption and optimise performance so they can use their data to drive measurable business outcomes.”

Sandeep Singh, Senior Vice President and General Manager, Platform, NetApp.

CEQUENCE SECURITY’S ZERO TRUST APPROACH TO AI SECURITY BECOMES INDUSTRY STANDARD

Major players adopt behaviour-driven principles Cequence AI Gateway has followed from the start.

Cequence Security, the leader in application, API, and Agentic AI protection, highlighted a significant convergence in the AI security industry. In a striking show of consensus, three leading voices in AI security, Anthropic, Dr. Chase Cunningham, and Cequence Security, have independently converged on a shared conviction: the biggest risk with AI agents isn’t access, it’s what they do once they’re in. Anthropic’s recently published frameworks, Dr. Cunningham’s Agentic Zero Trust research, and Cequence’s AI Gateway architecture all emphasise the need to focus security efforts on controlling agent behavior, not just authentication.

The key insight driving this convergence is that conventional security tools fixate on the login action, but for AI agents that can think, act, and cause damage autonomously, that’s guarding the wrong door. The real risk is an agent misusing legitimate access to take harmful actions, manipulate APIs, or exfiltrate data. That’s the security gap Cequence’s AI Gateway was purpose-built to close, by extending zero trust principles to cover not just who the agent is, but what it does.

“Most security teams are still trying to tackle AI risk with prompt detection and short-lived tokens – basically, really tight sign-in security. But that misses the point entirely. You can nail authentication and still get burned by an agent running amok inside the castle,” said Shreyans Mehta, CTO at Cequence Security. “Anthropic, Dr. Cunningham, and Cequence all recognised early on that the gamechanger is securing agent behavior. Seeing the whole industry pivot hard toward that truth, toward the approach we baked into the AI Gateway from day one, is the ultimate validation. It crowns the AI Gateway as the new

reference architecture for the space.”

“Traditional security controls focus obsessively on the front gate – who gets in. But with AI agents, the real damage happens after the front gate, through totally authorised channels,” said Dr. Chase Cunningham, a leading expert on Zero Trust security. “You have to extend zero trust inside, to cover not just authentication, but every action an agent takes. Cequence’s AI Gateway is a huge leap toward that goal, toward getting zero trust to fully cover the AI agent threat model.”

Behaviour Convergence

Anthropic’s published frameworks, Dr. Cunningham’s research, and Cequence’s AI Gateway all recognise that for AI agents, authentication is necessary but nowhere near sufficient. Their core focus is on runtime behavior: intercept, analyse, and tightly control what each agent is allowed to do, with what resources, in what context, with policy enforcement and threat detection at every step of every transaction. It’s a fundamental reframing of the AI

security problem around agent actions, not agent identity.

They also agree that behavioral monitoring and policy enforcement must be dynamic and real-time, because AI agents can chain together individually legitimate steps into harmful patterns too complex to predict in advance. The line between good behavior and bad must be redrawn constantly, reactively, in the moment.

Extending CIS Controls to Cover AI Agent Behavior

This convergence aligns with the guidance in the newly released Model Context Protocol (MCP) Companion Guide from the Center for Internet Security (CIS), which frames MCP as a critical control point for governing AI agent behavior. The guide, published on April 20, 2026 and co-announced by CIS and Cequence, adapts the CIS Controls to cover the unique risks created when AI agents interact with enterprise tools, data, and systems.

“The CIS MCP Companion Guide defines what enterprises should do; the Cequence AI Gateway operationalises it,” said Mehta. “The guide calls for explicit tool-level permissions, auditable interactions, and real-time sensitive data protection. AI Gateway delivers by generating leastprivilege agent personas, logging every API call, and applying DLP scanning to tool requests and responses. It takes the CIS framework from theory to practice.”

Why Securing AI Agent Behavior Matters Now

AI agents are rapidly shifting from sandbox experiments to key players in production. They routinely access sensitive data, critical infrastructure,

Shreyans Mehta, CTO, Cequence Security.

and powerful capabilities. Even carefully trained models can stitch together toxic patterns that evade static detection, while prompt-hacking techniques make it trivial to slip malicious instructions past login safeguards. Strict authentication matters, but it’s only the first line, not the front line.

At the same time, AI-powered attacks are drastically compressing threat timelines. What used to take adversaries months now takes hours. That means defenders have to spot and block threats in real time. Security must live where the agents live, at the level of API calls and data flows, in the moment, at machine speed.

Cequence’s AI Gateway delivers by extending zero trust security into the heart of agent operations – every API call, every data flow, every decision point, continuously analysed and gated by find-grained policy. Questionable agent actions are surfaced, scored, and blocked immediately, before damage is done.

COMMVAULT’S SHIFT DUBAI EMPOWERS ORGANISATIONS TO BUILD CYBER RESILIENCE FOR AI ERA

Industry leaders explored AI-driven threats, cyber resilience, and the strategies needed to support modern enterprises.

Commvault, a leader in unified resilience at enterprise scale, successfully hosted today its annual SHIFT Dubai event at the Museum of the Future, bringing together more than 350 industry leaders, government representatives, customers, and technology partners to explore the evolving cyber challenges shaping the future of enterprise security. The event highlighted the growing importance of cyber resilience in enabling organisations to confidently embrace AI, cloud technologies, and digital transformation while protecting critical operations and data.

into the cloud infrastructure that powers it, to achieve true resilience operations.”

The discussions at SHIFT Dubai comes at a pivotal time for the UAE, as organisations face an increasingly sophisticated and fast-evolving cyber threat landscape. Recent regional developments have driven a surge in cyber activity targeting critical infrastructure and enterprise systems, with the UAE Cyber Security Council reporting that the country is countering more than 800,000 cyberattacks daily. As businesses accelerate digital transformation, strengthening cyber resilience is becoming essential to protecting operations, safeguarding critical data, and sustaining business continuity. This evolving landscape underscores the need for a unified approach to resilience,

which Commvault delivers through its cloud-native, AI-enabled platform, helping organisations protect critical data, strengthen recovery, and maintain business continuity across increasingly complex environments.

“Cloud technologies and AI are redefining how organisations operate, innovate, and compete. But as enterprises distribute critical applications and AI workloads across hybrid and multi-cloud environments, resilience becomes a strategic necessity,” said Fady Richmany, Corporate Vice President & General Manager, Emerging Markets – CEE, CIS & META at Commvault. “The ability to secure data, recover rapidly from disruption, and maintain business continuity across complex cloud ecosystems will define the next generation of digital leaders. Building trust in AI starts with building resilience

Throughout the day, SHIFT Dubai featured keynote presentations and expert-led discussions exploring the impact of AI on enterprise security, AI governance, cyber recovery, threat intelligence, and securing hybrid and multi-cloud environments. Sessions were led by Commvault executives and leading regional and global cybersecurity specialists, including Mohammed Aziz, Country Manager, UAE, Commvault; Fady Richmany, Corporate Vice President & General Manager, Emerging Markets, CEE, CIS & META, Commvault; Ravi Baldev, Senior Director, Systems Engineering, Emerging Markets CEE, CIS & META, Commvault; Bassam Hemdan, AVP, SaaS, EMEAI & APAC, Commvault; Hazem AbuShaban, Senior Systems Engineer & Cyber SME, UAE, Commvault; and Yahya Kassab, Senior Director & General Manager, Gulf & KSA, Commvault. The agenda also featured strategic partner sessions and industry perspectives from Microsoft, HPE, Everpure, Core42, CPX, Malcrove, and leading global cybersecurity experts, highlighting the importance of public and private sector collaboration in advancing cyber resilience and securing digital transformation across the UAE.

DIGITAL RESILIENCE HOLDS KEY TO ECONOMIC CONTINUITY

MASTERCARD’S INAUGURAL CYBER PULSE REPORT REDEFINES CYBERSECURITY AS ESSENTIAL FOR ECONOMIC STABILITY, FEATURING INSIGHTS FROM DELINEA AND COMMVAULT ON INTERNAL ORGANISATIONAL IMPACT.

Every transaction that clears, every service that stays online, every business that opens for trade tomorrow rests on something most customers never see. The quiet ability of digital systems to absorb a shock and keep running. Digital resilience has become the invisible infrastructure of the modern economy, and across the Middle East it is fast emerging as the single factor that separates organisations that keep moving from those that stall.

The logic is straightforward, economies now run on digital rails. Payments, supply chains, public services and the daily operations of almost every enterprise depend on

systems that must stay available, trustworthy and recoverable. When those systems hold, commerce continues and confidence holds with it. When they falter, the cost is no longer measured in downtime alone but in lost revenue, broken trust and a direct hit to economic activity. Resilience, on this reading, is not a security feature bolted on at the edge. Resilience is the condition that allows the economy to keep functioning at all.

Cyber resilience and business resilience are the same thing. For the thousands of organisations across the Middle East that now run on digital infrastructure, the capacity to withstand and recover from disruption has become inseparable from the capacity

to keep trading, serving customers and contributing to the wider economy.

Mastercard’s inaugural Cyber Pulse report lands with a simple argument that deserves a permanent seat in the boardroom, and the evidence behind it makes the case hard to ignore. The report offers a full-year view of the threat landscape across Eastern Europe, the Middle East, and Africa, drawing on Mastercard’s Cyber Insights platform, the RiskRecon external assessment tool, and intelligence from Recorded Future. What emerges is less a catalogue of threats and more a thesis about where value is created and where it is now at risk. Selin Bahadirli, Executive Vice President for Services across the region, puts the point plainly. Cyber resilience, she argues, is synonymous with business resilience and operational wellbeing.

The economic stakes have moved well beyond the IT budget line. Analysis cited in the report from IBM’s 2025 cost of a data breach study puts the average breach in the Middle East at $7.29 million, some 64% higher than the global average of $4.44 million. Closer to home, the UAE Cyber Security Council reports that the country now counters more than 800,000 cyberattacks every day. A breach against that backdrop is no longer a technical inconvenience. Such a figure represents lost revenue, eroded trust, regulatory exposure and, in the worst cases, a question mark over an organisation’s ability to keep operating.

Resilience as economic participation Mastercard’s reading of resilience

reaches further than the enterprise. The company frames secure, reliable access to the digital economy as a precondition for inclusion and longterm growth, particularly for the micro, small and medium-sized businesses that make up the backbone of most regional economies. Having already surpassed its goal of bringing 50 million such enterprises into the digital economy, Mastercard has set a new ambition to connect and protect 500 million individuals and small businesses by 2030.

Underpinning that commitment is sustained investment. The company has put approximately $12.6 billion

into cyber security innovation since 2019, and in 2025 processed 175 billion transactions, using the resulting insight to detect vulnerabilities faster and with greater precision. Resilience, on this reading, is not a defensive cost. Resilience is what allows more people and more businesses to participate in the economy with confidence.

Continuity made visible

The clearest illustration of the theme sits inside the report’s payments data. Mastercard’s Stand-In authorisation acts as a back-up decisioning capability for card issuers. When an issuer is unavailable or cannot respond within required timeframes, Mastercard can authorise transactions on the issuer’s behalf using predefined parameters, keeping payments moving when systems come under operational stress.

During a recent period of heightened pressure on issuer systems, Stand-In volumes rose as organisations leaned on that back-up layer. The result was

Selin Bahadirli

continuity rather than disruption. Customers kept transacting, and what could have become visible outages were quietly absorbed. Few examples capture the economic continuity argument more directly. Resilience, properly built, is the difference between a problem that stays inside the engine room and one that reaches the customer.

Spending more, gaining less

The report surfaces an uncomfortable truth for leadership teams. Organisations are spending more on security, with regional investment rising at a compound annual growth rate of around 10%, yet breach frequency and cost continue to climb. More tooling, on its own, is not translating into better outcomes.

The reason, the report suggests, is that the persistent gaps sit less in technology and more in governance, skills and execution. A structural talent shortage compounds the problem, with industry estimates pointing to more than 300,000 unfilled cyber security roles across the wider region. Resilience, then, cannot be delegated downward as a purely technical concern. Resilience belongs at chief executive and board level, tied directly to business continuity, regulatory exposure and customer trust.

Mortada Ayad, Vice President for the Middle East, Türkiye and Africa at Delinea, sees the same disconnect from the practitioner’s side, and offers a route through it. When pressure rises, he argues, boards look for clarity rather than conjecture, and security leaders serve them best with an evidence-based view of risk grounded in data. Calm, structured updates carry more

THE CONVERSATION SHOULD CENTRE ON OPERATIONAL RESILIENCE.

MORTADAAYAD,VICEPRESIDENTFORTHEMIDDLE EAST,TÜRKIYEANDAFRICA,DELINEA.

weight than dramatic forecasts.

“The conversation should centre on operational resilience,” Ayad says, pointing to how identity is controlled, how privileged access is governed, how threats are detected, and whether incident response plans are tested and ready. Linking cyber posture directly to business continuity planning, he adds, demonstrates that security is proactive and aligned to organisational priorities.

Resilience in the AI era

The continuity question takes on a new

dimension as enterprises adopt AI at speed. Cloud and AI are redefining how organisations operate and compete, but distributing critical applications and AI workloads across hybrid and multicloud environments widens the surface that has to stay resilient.

The shift was the central theme when Commvault gathered more than 350 industry leaders, government representatives and technology partners at its annual SHIFT Dubai event at the Museum of the Future, alongside voices from Microsoft, HPE, Core42 and CPX, a turnout that signals how firmly continuity has moved up the regional agenda.

Fady Richmany, Corporate Vice President and General Manager for Emerging Markets across CEE, CIS and META at Commvault, framed the stakes directly. “As enterprises distribute critical applications and AI workloads across hybrid and multi-cloud environments, resilience becomes a strategic necessity,” he said. “The ability to secure data, recover rapidly from disruption, and maintain business continuity across complex cloud ecosystems will define the next generation of digital leaders. Building trust in AI starts with building resilience into the cloud infrastructure that powers it.” Resilience, on that account, is not a brake on AI adoption but the very thing that makes it safe to pursue.

Mortada Ayad

What attackers see first

Where should organisations concentrate effort? The report’s outside-in analysis offers a sharp answer. Using RiskRecon, Mastercard benchmarked 397 organisations across the region against a global baseline of roughly 396,000, scoring each across nine security domains. The regional picture is reassuring in parts, with email security and system reputation holding up well against the global average.

Four domains, however, stand out as both high-impact and lower in maturity: software patching, web application security, web encryption and network filtering. Each maps directly to a realworld attack chain. Unpatched systems hand attackers a known route in. Weak application configurations open the door to account takeover and data leakage. Poor encryption exposes data in transit. Gaps in network filtering let malicious traffic move and persist once inside. The common thread is that these weaknesses are externally observable, and the same domains that score lowest are the ones most often exploited.

Ayad’s guidance aligns closely with that conclusion. The most effective response, he says, is to double down on fundamentals and reduce exposed attack surfaces, starting with privileged access. Standing administrative rights remain the fastest route to large-scale compromise. Eliminating persistent privileges, enforcing least privilege across the estate, and introducing justin-time elevation for sensitive tasks can

significantly shrink the blast radius of any intrusion. Tightening control over privilege, in his view, is often the single most powerful risk-reduction lever available.

A regional imperative

For the Middle East specifically, the case carries extra weight. The region absorbed the largest share of threat activity across EEMEA over the period, reflecting its growing role as a financial and digital hub. The public, technology and financial sectors together account

BUILDING TRUST IN AI STARTS WITH BUILDING RESILIENCE INTO THE CLOUD INFRASTRUCTURE

for 44% of targeted industries, drawn by their concentration of high-value data and their central role in economic infrastructure. The most attractive targets, in other words, are the very institutions on which economic continuity depends.

The recommendation that follows is one of rebalancing rather than spending more. Technology matters, but people, skills and operational discipline matter just as much. Digital growth has made resilience the precondition for staying in the game, for keeping payments flowing, for protecting customer trust, and for ensuring that businesses of every size can participate in the digital economy with confidence. Building that resilience is no longer a defensive afterthought. Resilience is the foundation on which continued economic activity now rests, and the organisations that treat it as such will be the ones still standing, and still trading, when others falter.

INTO NEW WORLDS YOU’RE

ONE LEAP AWAY

From 31 Aug - 3 Sept 2026 Riyadh Exhibition and Convention Center - Malham, Saudi Arabia

IDENTITY SECURITY IS CRITICAL TO PROTECT

OT FROM NEXT MAJOR CYBER INCIDENT

DELINEA EXPERTS OUTLINE WHY PRIVILEGED ACCESS, THIRDPARTY IDENTITIES, AND VISIBILITY GAPS ARE INCREASING RISK ACROSS CRITICAL INFRASTRUCTURE, AND WHAT

ORGANISATIONS NEED TO DO TO STRENGTHEN OT RESILIENCE.

Identity security is rapidly emerging as one of the most important priorities for organisations operating critical infrastructure and industrial environments. Increased connectivity, remote access requirements and the growing convergence of IT and operational technology (OT) have created new opportunities for attackers to exploit trusted access pathways into essential systems.

A growing reliance on connected industrial systems, third-party access and digital transformation initiatives formed the backdrop to a webinar hosted by CPI Media Group in association with Delinea, titled From Credentials to Catastrophe: Securing OT Before the Next Colonial Pipeline. The session featured Andrea

Scott, Product Marketing Manager; Alex FitzGerald, Product Marketing Manager; Brance Spradlin, Global Identity Specialist; and Albert Beattie, Senior Technical Partner Manager at Delinea, who examined the changing OT threat landscape and the growing role of identity in securing critical operations.

OT security has become a business issue

Cybersecurity threats targeting industrial environments have evolved significantly over the past decade. Traditional assumptions that OT systems could remain isolated from external threats no longer hold true in a world of remote monitoring, cloud-connected systems, predictive maintenance and third-party support services.

Threat actors continue to exploit the gaps that exist between IT and OT environments. Many organisations still manage these domains separately, creating blind spots that attackers can leverage to move between networks and gain access to critical assets. This reality is driving a shift towards unified governance models that provide a consolidated view of cyber risk across the organisation.

Boardrooms are increasingly involved in these discussions because the consequences of a successful attack extend far beyond technology. Production downtime, supply chain disruption, revenue loss, regulatory scrutiny and safety concerns can quickly transform a cybersecurity incident into a major business continuity event.

Lessons

from major cyber incidents

Several high-profile attacks illustrate the risks facing industrial organisations today. The panel referenced incidents such as Triton, which targeted safety systems at a petrochemical facility in Saudi Arabia, Shamoon’s destructive attack on Saudi Aramco, the Colonial Pipeline breach in the United States and the activities of the Volt Typhoon threat group. Each incident demonstrated how trusted access, compromised credentials or poorly governed identities can become entry points into critical environments. One of the strongest messages from the discussion was that attackers increasingly rely on legitimate credentials rather than sophisticated malware. Valid accounts allow malicious actors to blend into normal

Andrea Scott.

operational activity, making detection significantly more challenging. Put simply, many modern attacks begin not with a breach of the perimeter but with access that appears legitimate.

Identity has become the new control plane

Network segmentation remains an important component of OT security. However, the speakers argued that identity has become the most effective lens through which organisations can understand and manage risk.

Every engineer, contractor, vendor, administrator, application, machine identity and service account represents a potential access pathway. Growth in automation, cloud services and artificial intelligence is accelerating this challenge, creating a rapidly expanding population of non-human identities that require the same level of governance as human users.

Visibility into who has access, what they can do, when they can perform actions and how quickly permissions can be revoked has become essential. Organisations that fail to govern identities consistently across IT and OT

environments leave dangerous gaps that can be exploited by attackers.

Third-party access remains a major challenge

Third-party access emerged as one of the most significant concerns discussed during the webinar. Industrial operations frequently

depend on equipment manufacturers, contractors, service providers and maintenance teams that require remote connectivity to critical systems. Many organisations continue to provide access through persistent VPN connections and shared accounts, often with limited oversight once access has been granted.

Problems often arise when vendor relationships end but accounts remain active. Dormant credentials can persist for months or even years, creating unnecessary exposure and expanding the organisation’s attack surface. Limited visibility into vendor activity further compounds the challenge.

According to the panel, stronger governance of third-party access represents one of the fastest and most effective ways to reduce OT identity risk.

Roadmap to stronger OT identity security

Building a mature identity security programme does not require organisations to replace existing infrastructure or undertake disruptive transformation projects.

Alex FitzGerald.
Brance Spradlin.

The speakers described a maturity journey that begins with basic visibility and progresses towards comprehensive governance. Earlystage environments often rely on shared credentials and have limited auditing capabilities. More advanced organisations implement privileged access management, just-in-time authorisation, session monitoring, multi-factor authentication, rolebased controls and identity governance processes.

The desired end state is a zero-trust model in which access is granted only when needed, credentials remain protected from users, privileged sessions are monitored and recorded, and permissions are automatically revoked once work has been completed.

Delinea outlined three core pillars for achieving this outcome: protecting privileged credentials, securing remote access through brokered connections rather than traditional VPNs, and providing comprehensive visibility into privileged activity through monitoring, auditing and session recording.

Visibility should come first

A consistent recommendation from all panellists centred on visibility. Organisations need a clear understanding of the identities operating within their OT environments before they can effectively manage risk. Discovery of privileged accounts, vendor access pathways, service accounts and remote sessions provides the foundation for stronger governance and better decisionmaking.

Quick wins can often be achieved by focusing on high-risk areas such as third-party access and privileged accounts. Improved visibility enables organisations to move from assumptions to evidence-based risk management while creating the groundwork for a broader identity

security strategy. Identity security is no longer solely an IT concern. Modern industrial environments depend on trusted access to maintain operations, support innovation and drive efficiency.

Organisations that can govern those identities effectively will be better positioned to protect critical infrastructure, strengthen resilience and reduce the likelihood of the next operationally disruptive cyber incident.

Albert Beattie.

AGENTIC AI DEMANDS STRONGER GOVERNANCE AND HUMAN ACCOUNTABILITY

ABHAY

PANDEY

EXPLAINS WHY ENTERPRISES MUST EMBED COMPLIANCE, CYBERSECURITY, TRANSPARENCY, AND HUMAN OVERSIGHT INTO AGENTIC AI SYSTEMS TO BALANCE AUTOMATION WITH TRUST, CONTROL, AND REGULATORY ALIGNMENT.

Enterprises adopting agentic AI are entering a new phase of automation where AI systems are no longer limited to generating recommendations or content, but are increasingly capable of interacting with enterprise environments, triggering workflows, accessing systems, and making operational decisions autonomously.

This shift is creating fresh challenges around governance, cybersecurity, compliance, accountability, and risk management, particularly in environments handling sensitive enterprise, financial, customer, or government data. Organisations are now under growing pressure to ensure that AI systems operate within clearly defined legal, ethical, and operational boundaries while remaining transparent, explainable, and auditable.

Abhay Pandey, founder and CEO, MAST Consulting, shares insights into how businesses can securely deploy agentic AI while maintaining human oversight and organisational control.

Pandey discusses the importance of governance frameworks, Zero Trust principles, international standards such as ISO/IEC 42001, and risk-based human

approval models in helping enterprises balance automation with accountability and regulatory compliance.

Interview Excerpts

How can organisations ensure that agentic AI systems operate within defined compliance, legal, and ethical boundaries, especially when they are capable of making autonomous decisions?

Agentic AI should not enter the enterprise as an open-ended tool. It needs to be deployed within a defined operating model, where the system knows what it can do, what it cannot do, and when human approval is required. That means clear decision boundaries, approval

THE GOAL SHOULD BE TO EXPAND HUMAN CAPABILITY, NOT REMOVE HUMAN RESPONSIBILITY FROM DECISIONS THAT REQUIRE JUDGMENT.

hierarchies, access controls, audit trails, and risk thresholds before the first use case goes live.

Compliance, legal, cybersecurity, and business teams need to review use cases together, because the risk is rarely technical alone. Fairness, privacy, transparency, and accountability should be built into the design process rather than added later. Regular risk reviews, bias testing, monitoring, and alignment with standards such as ISO/IEC 42001 can help ensure AI remains useful without becoming uncontrolled.

What are the key cybersecurity, data privacy, and governance risks associated with deploying agentic AI in enterprise environments, and how can businesses mitigate them effectively? The important thing to remember is that agentic AI does not just produce content or recommendations. It can access systems, use data, call APIs, trigger workflows, and take actions across the enterprise. That changes the risk profile quite significantly. The main risks include data leakage, prompt injection, excessive access privileges, insecure integrations, biased outputs, and actions that may violate internal policy or regulation. A loosely defined AI agent flow can create

Abhay Pandey, founder and CEO, MAST Consulting.

operational risk very quickly, especially if it has access to sensitive systems.

Businesses should treat agentic AI as part of their security and governance architecture. Zero Trust principles, strict identity and access management, encrypted data handling, API security, continuous monitoring, and human approval for high-risk actions are essential. Regular testing, adversarial simulations, privacy impact assessments, and model validation should also become part of the deployment lifecycle.

In a typical workplace, which compliance-sensitive or security-critical tasks should never be fully delegated to agentic AI without human oversight?

Any decision with legal, financial, ethical, regulatory, or reputational consequences should not be fully delegated to AI.

This still includes many things, even at this stage of AI adoption - regulatory approvals, employee termination, legal interpretation, financial authorisation, fraud investigations, disciplinary actions, medical recommendations, and the handling of highly sensitive customer or government data.

AI can still be useful in these areas. But the final decision should remain with qualified people who understand context, liability, and consequence. AI can support the process, but it should not own the judgment where the outcome is sensitive, irreversible, or legally significant.

How should responsibilities and accountability be defined when an AI agent makes an incorrect, biased, or non-compliant decision?

Organisations should be very clear on one point, which is that accountability does not move from people to the AI system. Agentic AI is still an enterprise tool, even if it can act with a degree of autonomy. Responsibility sits with the organisation, the business owners, and the teams that approved and deployed the system. This is especially important when AI agents are operating across multiple systems or departments.

Every AI-driven action should be traceable through logs, decision records, approval workflows, and documented policies. There should also be a response process for AI failures, whether the issue is bias, inaccuracy, unauthorised action, or non-compliance. Vendor contracts can define certain obligations, but internal accountability cannot be outsourced.

From a regulatory and audit perspective, how important are transparency, explainability, and traceability in agentic AI systems operating within enterprises?

If an AI agent takes an action, the organisation must be able to explain what happened, what data was used,

what control was in place, and who was responsible for the deployment. Regulators and auditors will increasingly expect organisations to demonstrate how AI decisions are made, what data was used, who approved deployments, and how risks are managed. Without traceability, organisations may struggle to investigate incidents, justify decisions, or prove compliance during audits.

Enterprises should maintain detailed logs, model documentation, decision histories, and governance records. Transparent AI operations will strengthen trust among customers, regulators, and stakeholders while supporting accountability and responsible use of autonomous systems.

What role will international standards and frameworks such as ISO/IEC 42001, AI governance frameworks, and data protection regulations play in shaping responsible adoption of agentic AI?

Standards like the ISO/IEC 42001 help businesses define how AI should be governed, monitored, reviewed, and improved over time. Data protection

REGULAR RISK REVIEWS, BIAS TESTING, MONITORING, AND ALIGNMENT WITH STANDARDS SUCH AS ISO/IEC 42001 CAN HELP ENSURE AI REMAINS USEFUL WITHOUT BECOMING UNCONTROLLED.

laws such as GDPR and regional privacy regulations are equally important because agentic AI will often interact with personal, financial, operational, or customer data.

Early alignment with recognised standards will help businesses build trust with customers, regulators, boards, and partners. Putting these systems in place early will be a competitive advantage at this point of the enterprise AI journey because it positions organisations to scale AI without constantly reacting to risk.

How can businesses balance automation and efficiency gains from agentic AI while still maintaining human judgment, accountability, and decision-making authority?

The right approach is a human-led, AIassisted model. Agentic AI is well suited to repetitive analysis, data correlation, workflow orchestration, monitoring, reporting, and operational support. Human beings should continue to own strategic, ethical, financial, legal, and regulatory decisions.

One model that could help with this is risk classification - low-risk tasks can be automated with monitoring, medium-risk tasks may require review, and high-risk

AI CAN SUPPORT THE PROCESS, BUT IT SHOULD NOT OWN THE JUDGMENT WHERE THE OUTCOME IS SENSITIVE, IRREVERSIBLE, OR LEGALLY SIGNIFICANT.

tasks should require explicit human approval. Right now, this is the surest way to gain speed and efficiency without losing control. Clear escalation paths, governance structures, access controls, and regular performance reviews are important. The goal should be to expand human capability, not remove human responsibility from decisions that require judgment.

What could a real-world enterprise environment look like where agentic AI is securely integrated into operations while remaining compliant, auditable, and aligned with organisational policies?

In a mature enterprise environment, agentic AI operates within tightly governed boundaries integrated across business, cybersecurity, compliance, and IT operations. AI agents may assist with customer support, risk analysis, compliance monitoring, threat detection, workflow automation, and reporting, while all critical decisions require human approval. Every AI action is logged, monitored, and traceable through centralised governance dashboards.

Access to sensitive systems is controlled through Zero Trust principles and role-based permissions. Policies, standards, and risk controls are embedded into AI workflows from the design stage itself. Regular audits, model reviews, and compliance assessments ensure the AI ecosystem remains secure, transparent, accountable, and aligned with organizational and regulatory expectations.

UAE’S AI AMBITIONS ARE CREATING A CATALYST FOR CYBERSECURITY TRANSFORMATION

SENTINELONE CHIEF AI OFFICER GREGOR STEWART EXPLAINS WHY AUTONOMOUS SECURITY, CONTINUOUS CYBER EDUCATION AND EMBEDDED AI GUARDRAILS WILL BE CRITICAL TO SECURING THE NEXT PHASE OF THE UAE’S DIGITAL FUTURE.

Artificial intelligence is rapidly reshaping the cybersecurity landscape, creating new opportunities for innovation while introducing complex challenges around governance, visibility, data protection and accountability.

Organisations across government and enterprise sectors are exploring how to harness agentic and autonomous AI systems without compromising security, privacy or compliance.

Gregor Stewart, Chief AI Officer at SentinelOne, believes the UAE’s coordinated, top-down approach to AI adoption is creating a strong foundation for cyber resilience. With nearly two decades of experience spanning machine learning, generative AI, agentic systems and cybersecurity, Stewart offers a unique perspective on how organisations can navigate emerging risks such as Shadow AI, prompt injection attacks, data exfiltration and AI-driven software supply chain threats.

Stewart spoke to Sandhya D’Mello, Technology Editor, Security Advisor Middle East on the importance of continuous user education, embedded security guardrails, autonomous cyber defence, and the critical role of accountability as organisations move towards an AI-first future.

Interview Excerpts:

Below is a cleaned Q&A draft based on the interview transcript.

Interview Excerpts

How do you view the UAE’s approach to cybersecurity as it accelerates its digital-first ambitions?

The UAE occupies a unique position, with cybersecurity being shaped by a clear national vision and strong leadership commitment. Ambitious goals around AI adoption and digital transformation are driving security programmes to evolve at the same pace as innovation.

Cybersecurity has become an integral component of major government and enterprise initiatives across the country. Close collaboration among policymakers, government entities, businesses and technology providers is helping create a more unified security framework. Such alignment enables faster decisionmaking, stronger standards, and greater resilience, giving the UAE an advantage in navigating an increasingly complex digital landscape.

Does the move towards agentic AI create new opportunities for the region to strengthen cyber resilience?

When a country commits to deploying agentic AI at scale, security also has to become agentic. Traditional approaches will not be enough because the technology is moving too quickly. The UAE’s ambition forces organisations to modernise their security posture. It creates momentum for new ways of securing systems, data, users and AI-driven workflows. In that sense, the

national AI mandate becomes a catalyst for improving cybersecurity across the country and the wider region.

Shadow AI is becoming a growing concern. How can organisations balance employee innovation with governance and risk management?

Shadow AI is often misunderstood. Employees are rarely trying to bypass corporate policies; most are adopting tools they believe can help them work more efficiently, whether AI-powered note-taking applications, meeting assistants or content-generation platforms. Risks arise when sensitive conversations, corporate information or personal data are shared with external

servers or model providers without the organisation’s knowledge or oversight.

Stronger industry standards remain essential for AI application development, particularly around visibility, model provenance and observability. Until such frameworks become widely adopted, organisations must deploy solutions capable of identifying AI usage, improving transparency and supporting effective governance.

Governance should not be overly restrictive. Excessively harsh policies often drive users towards unsanctioned workarounds rather than compliance. A more effective strategy involves providing approved enterprise AI tools, educating employees on responsible usage and

creating secure pathways for innovation. Such measures enable organisations to balance productivity gains with security, privacy and compliance requirements.

With hybrid work and BYOD models, how should organisations draw the line between personal and professional use of AI tools?

The line has become very blurred. For years, people have mixed personal and work activity on the same devices. With AI, this creates a new challenge because people are entering very detailed prompts that may include personal, professional or confidential information.

When organisations monitor AI usage, they may also collect private

Gregor Stewart.

information from employees. That makes observability a privacy issue as well as a security issue.

The solution is not purely technical. Secure BYOD tools are readily available, but effective security also depends on clear user awareness and guidance. Employees need a strong understanding of what belongs in a work profile, what should remain within a personal profile, and what information the organisation can monitor or control. Security solutions should also provide real-time education and feedback, helping users make informed decisions rather than simply blocking activity.

Which AI security risks should CISOs prioritise over the next 12 months?

Two risks stand out. The first is data exfiltration through AI tools. Employees may accidentally leak sensitive information by entering detailed prompts into external AI systems.

The second is software supply chain risk linked to agentic coding. AI coding tools can pull in libraries, dependencies and components that may be vulnerable or poisoned. Organisations will need stronger controls over what can be imported, curated lists of approved components, and endpoint protection capable of detecting suspicious behaviour.

Model poisoning is less of a near-

STRONGER INDUSTRY STANDARDS REMAIN ESSENTIAL FOR AI APPLICATION DEVELOPMENT, PARTICULARLY AROUND VISIBILITY, MODEL PROVENANCE AND OBSERVABILITY.

term concern for most enterprises because many will use validated models through trusted providers rather than downloading random models from unverified sources.

How can organisations accelerate AI adoption without increasing cyber risk?

The first line of defence is the person. Security controls must educate users continuously. Traditional quarterly training or periodic phishing simulations are no longer enough. Organisations need continuous learning through realtime guidance, red-teaming and safe simulations.

Cyber guardrails should also be embedded at the lowest possible level, including endpoints, browsers and AI gateways. Security should operate where the user is doing the work, not only in the cloud. This allows organisations to detect, redact or block risky prompts before sensitive data leaves the environment.

Controls should be helpful rather than hostile. For example, if an employee accidentally enters an employee ID into a prompt, the system should be able to redact that information and allow the rest of the request to continue if it is compliant with policy.

How is SentinelOne helping organisations in the UAE and wider META region build secure foundations for autonomous systems?

SentinelOne is focused on two areas. The first is providing the foundation for autonomous security applications. Autonomous systems need fast, dense access to core security telemetry. The Singularity platform is being optimised to be agent-first, allowing agents built by SentinelOne, customers or third parties to access the data they need quickly and effectively.

The second area is delivering autonomous security capabilities directly. SentinelOne

already provides autonomous detection, response and rollback on endpoints, and is extending that approach into cloud and investigation workflows. The goal is to allow systems to investigate alerts, trigger responses and reduce manual effort. However, accountability cannot be automated. As autonomous systems do more work, organisations still need confidence that actions are aligned with their policies and expectations. SentinelOne is working on ways to help security teams remain accountable by giving them clear, concise reasons to trust autonomous decisions, rather than forcing them to review thousands of actions manually.

What is SentinelOne’s regional commitment in META?

SentinelOne has had a presence in the region for over nine years, with teams in the UAE and Saudi Arabia. The company has also brought its autonomous platform into Saudi Arabia on Google Cloud, making it available in-country.

The focus is on helping customers with their autonomous security journey, supporting hybrid models, and working with partners and managed service providers. In this region, local presence matters. Customers want to see long-term investment, local expertise and solutions that can support cloud, on-premises and hybrid environments.

AI ACCELERATES CYBER THREATS FASTER THAN ORGANISATIONS CAN DEFEND

FADY RICHMANY , CORPORATE VP AND GM FOR EMERGING MARKETS AT COMMVAULT, EXPLAINS WHY CYBER RESILIENCE, IDENTITY PROTECTION, AND INTEGRATED RECOVERY STRATEGIES HAVE BECOME ESSENTIAL FOUNDATIONS FOR SECURE AI ADOPTION IN AN ERA OF ESCALATING CYBER RISK.

Artificial intelligence is reshaping the cyber threat landscape at an unprecedented pace, creating new challenges for organisations as they accelerate AI adoption across their operations. From AI-powered cyberattacks and autonomous digital agents to the explosion of enterprise data, businesses are navigating a rapidly expanding attack surface while striving to maintain compliance, business continuity, and trust.

Fady Richmany spoke to Security Advisor Middle East at SHIFT Dubai 2026 on how AI is transforming modern cyber threats, why cyber resilience has become the cornerstone of successful AI adoption, and what organisations must do to protect data, identities, and critical systems in an increasingly complex hybrid and multi-cloud environment. Richmany also shares insights into the emerging concept of Resilience Operations (ResOps) and explains why recovery, identity protection, and data security must now operate as a single, integrated discipline.

Interview Excerpts

With the UAE facing nearly 800,000 cyberattack attempts daily, how is AI changing the scale, speed, and sophistication of modern cyber threats? Cyberattacks have risen sharply, and AI is the reason the curve is bending the way it is. H.E. Dr. Mohammed Al Kuwaiti, head of the UAE Cyber Security Council revealed during our SHIFT event in Dubai this week that the UAE is fending off around 800,000 cyberattacks each day, and two things are happening at once behind that number. The first is what frontier AI does to the speed of an attack. The same cutting-edge capability that makes a business faster also makes exploitation faster, and the time an attacker needs to move from a vulnerability becoming known to exploiting it has fallen from weeks to barely a day. That changes how you defend, because an incident that once gave you days of warning can now unfold in the middle of the night. In fact, CrowdStrike has found that roughly 76% of organisations cannot keep pace with the speed and sophistication of AI-

powered attacks, and that figure tells you how wide the gap has become.

The second shift comes from AI itself generating an unprecedented volume of data. AI breeds data, and all of it has to be protected, because every new store of it is something an attacker can reach for. Agentic AI then adds another layer. Every autonomous agent we deploy is, in effect, a new identity, a non-human one that lives on data and becomes its own point of exposure. The scale is hard to overstate. Salesforce has talked about deploying a billion AI agents, not a million, a billion, and each of those is another surface an attacker can probe.

What are the biggest cyber

risks

organisations should consider when deploying generative AI, autonomous agents, and AI-driven workflows across the enterprise?

The first risk sits with identity. However, you run it, whether through an onpremises directory or a cloud identity provider, that identity layer has to be protected and resilient, because it is the doorway everything else depends on. Protecting identity in isolation is no

Fady Richmany, Corporate VP and GM for Emerging Markets, Commvault.

longer enough, though. Identity, data security and cyber recovery have to work as one integrated discipline, and the more you integrate that resilience, the more you escape the silos most organisations are still trapped in.

That silo problem is the biggest risk of all, and it shows up most clearly in large enterprises, where the work is split across separate teams. One team runs the productivity and collaboration platforms. Another runs the infrastructure. Another handles backup and recovery. Another runs security operations, and another runs security analytics. On a normal day that division of labour looks fine. The moment a cyber incident lands, it becomes chaos, because suddenly five or six departments who have never spoken to each other have to coordinate while forensics are still trying to establish what happened, why, and how much damage was done. We call that the IT collision, and if those teams have never run the drill together, it is the hardest situation an organisation can face.

Generative and agentic AI make this harder rather than easier. Every new agent you create is another identity that breathes on data, and that data may not be clean, may be malicious, may not be protected at all. So you are widening the exposure at exactly the moment the complexity of responding is climbing.

Why has cyber resilience become a critical foundation for successful AI adoption, and how does it differ from traditional cybersecurity approaches? Simply put, cyber resilience begins where cybersecurity ends. You can build the highest walls around your castle, add the cameras, post the guards and put in every defense you can think of, and

someone still finds a way in. At that point the question is no longer how strong your walls were, it is how quickly you can change the locks and get back to basics. Recovery is exactly that, going back to the basics, and what matters is how long it takes you and whether you can do it at all.

That is the real difference from traditional cybersecurity. Ten or fifteen years ago, business continuity was built almost entirely around natural disasters, flooding, earthquakes, power outages, the once-in-a-blue-moon events. That thinking is why organisations are increasingly building disaster recovery sites a hundred kilometers from production, sometimes in another country altogether, simply to keep the business running. A natural disaster might strike once in a very long while. A cyberattack happens every second, and AI has made each one faster, more pervasive and more sophisticated. So, resilience is no longer optional, and it is no longer only about cyber recovery. It has to bring identity and data protection into the same picture. That is what integrated resilience means, and it is why we talk about resilience operations, or ResOps, as the next-generation operating model. It works as an active, ongoing discipline that keeps you resilient and ready, rather than a one-off solution you bolt on and forget.

How can organisations protect the data, identities, and operational systems that power AI while maintaining compliance and business continuity across hybrid and multi-cloud environments? It comes back to the discipline and the mechanism to discover and classify your data so that you genuinely understand what you hold. You protect it to keep it clean. You keep detecting any malicious activity. Then you have to be able to restore and recover. That full cycle, running continuously, is what resilience operations actually means, and it is what holds identity and cyber recovery together as a single capability.

THAT SILO PROBLEM IS THE BIGGEST RISK OF ALL, AND IT SHOWS UP MOST CLEARLY IN LARGE ENTERPRISES, WHERE THE WORK IS SPLIT ACROSS SEPARATE TEAMS.

Done properly, that is what keeps you prepared and ready across hybrid and multi-cloud environments, so that when something does go wrong you can recover yourself rather than

depend on improvisation. My message to customers is that they need to change their approach. Whatever measures they already have in place are good, but they are no longer good enough for the level of AI exposure we are dealing with today. This is the moment to wake up to that.

Looking ahead, what should business leaders prioritise today to build AIready cyber resilience and innovate with confidence in an increasingly AI-driven economy?

It comes down to one honest question

every leader should be able to answer. If I am attacked this morning, can I withstand it, and can I recover quickly?

Answering yes means having the right discipline already in place, because this is a protocol, and a protocol is never about technology alone. It is about people and process just as much. That is why we have been working with peers and other organisations across the industry to come together on this, and it is the thinking behind the Commvault Cloud Unity platform we recently announced, alongside

resilience operations. Together they bring customers to a genuine state of resilience, prepared and ready for the day something goes wrong. There is a foundation to work through, five pillars in all, and behind them sits a great deal of technology, but also a great deal of process and a great deal of people. What we are building is the next generation of resilience, integrating what used to be known simply as recovery with data security and identity resilience so they operate as one. ResOps is the solution.

BUILDING CYBER RESILIENCE IN AGE OF AI, CLOUD AND QUANTUM RISK

SANS

INSTITUTE’S

NED BALTAGI DISCUSSES

AI

GOVERNANCE,

CRITICAL

INFRASTRUCTURE

SECURITY, CYBER

QUANTUM READINESS, AND THE PRACTICAL

RESILIENCE,

SKILLS

ORGANISATIONS NEED TO NAVIGATE AN INCREASINGLY COMPLEX THREAT LANDSCAPE ACROSS THE MIDDLE EAST.

Artificial intelligence, cloud computing, and industrial digitalisation are transforming organisations across the Middle East at an unprecedented pace. While these technologies are unlocking new opportunities for innovation, efficiency, and growth, they are also introducing complex cybersecurity challenges that demand greater resilience, governance, and operational readiness. From securing AI-powered systems and critical infrastructure to preparing for emerging quantum risks, organisations are under increasing pressure to strengthen their cyber defences while maintaining business agility.

Ned Baltagi, Managing Director, Middle East, Africa, and Turkey at SANS Institute, shares his perspectives on the region’s evolving cybersecurity landscape. He discusses the growing importance of practical

skills development, the impact of geopolitical tensions on critical infrastructure security, the governance challenges surrounding AI-enabled industrial environments, and the steps organisations should take today to build long-term cyber resilience. He also outlines what participants can expect from SANS’ upcoming regional training events and how frameworks such as the AI Security Maturity Model can help organisations securely accelerate their AI journeys.

Interview Excerpts

Looking ahead to your training events coming up in September and October, what are SANS’ key priorities for these initiatives, and what can participants expect from them?

The priority is helping organisations move from strategy to execution. Across the region, organisations

are accelerating AI adoption, cloud transformation, and digital innovation, but many are still determining how to secure those environments at scale. What participants can expect from our events like SANS Riyadh AI and Cloud Security in September, Cyber Safari and SANS Gulf Region in October is a strong focus on practical capability development. That includes securing AI-powered applications, cloud environments, critical infrastructure, and modern security operations. We want to not only discuss emerging technologies, but help practitioners, leaders, and organisations build measurable security capability through hands-on training, real-world exercises, and frameworks that can be operationalised immediately. As AI becomes embedded into business processes, cloud platforms, and security operations, organisations need practical guidance on everything from

Ned Baltagi, Managing Director, Middle East, Africa, and Turkey, SANS Institute.

AI governance and risk management to AI-enabled detection and response.

How does heightened geopolitical uncertainty impact the cybersecurity posture of critical infrastructure organisations?

Geopolitical uncertainty is making resilience a top priority for critical infrastructure operators. At the same time, industrial environments are becoming more connected, automated, and reliant on cloud services, remote access, analytics, and AI-enabled systems.

This expands the attack surface and increases the need for visibility across IT, OT, industrial control systems, AI-driven processes, and third-party dependencies. The organisations best positioned to withstand disruption are those that treat cybersecurity as an operational capability, with clear ownership, accountability, incident response, and recovery plans in place. The reality is that resilience comes down to preparation. Organisations that understand their assets, dependencies, and response procedures before an incident occurs will be far better positioned than those trying to answer those questions during a crisis.

What key OT security challenges do you expect AI-powered industrial transformation to create for Middle Eastern organisations over the next few years?

The most significant challenge will be governance and control of increasingly autonomous systems. One of the central concepts in the SANS AI Security

Maturity Model is the rise of agentic AI, systems that can take actions rather than simply generating outputs. As AI becomes embedded into industrial environments, organisations will need to think carefully about identity, authority, accountability, and oversight.

Questions that were previously theoretical become operational. What systems can an AI agent access? What actions can it perform? Who owns that agent? How are decisions audited? How do organisations distinguish between a security incident, a reliability issue, and an operational failure?

The model introduces concepts such as Non-Human Identity management, documented ownership for AI agents, human-in-the-loop controls, execution guardrails, and structured logging for AI actions. These capabilities become increasingly important in OT environments where decisions can affect safety, production, and critical services. The challenge is not simply securing AI itself. It is ensuring that AI-enabled industrial transformation occurs with the same discipline, visibility, and governance that organisations apply to other mission-critical systems.

What practical steps should government entities and enterprises take now to build quantum-resilient security strategies?

The first step is to stop treating quantum risk as a future-only issue. SANS’ quantum readiness guidance emphasises assessing quantum risk, identifying “Harvest Now, Decrypt Later” exposure, mapping cryptographic dependencies,

ORGANISATIONS THAT UNDERSTAND THEIR ASSETS, DEPENDENCIES, AND RESPONSE PROCEDURES BEFORE AN INCIDENT OCCURS WILL BE FAR BETTER POSITIONED THAN THOSE TRYING TO ANSWER THOSE QUESTIONS DURING A CRISIS.

understanding regulatory timelines of regional frameworks such as SCyWf, and building a phased quantum-safe migration plan before 2030.

Practically, organisations should inventory cryptography across applications, infrastructure, VPNs, PKI, cloud services, and vendors. They should prioritise long-lived sensitive data, update procurement requirements for cryptoagility, test post-quantum migration paths, and build executive reporting that explains quantum risk in business terms.

How can frameworks like the SANS AI Security Maturity Model help organisations across the Middle East strengthen AI governance, enhance security, and build long-term resilience?

The AI Security Maturity Model is built on a simple principle: As AI adoption grows, maturity is determined less by how much AI an organisation uses and more by how effectively it manages the risks, security, and governance that come with it.

As AI adoption accelerates across government, energy, financial services, and critical infrastructure, many organisations are moving from experimentation to operational deployment. The challenge is ensuring governance, security, and accountability evolve at the same pace as adoption.

The AI Security Maturity Model provides a structured framework to help organisations assess their current state, identify capability gaps, establish accountability, and align with recognised frameworks such as SCyWf.

Ultimately, resilience comes from balancing all three pillars: protecting AI systems from emerging threats, leveraging AI to strengthen security operations, and governing AI through clear ownership, risk management, and oversight. Organisations that mature across all three areas will be best positioned to innovate securely while building long-term trust and resilience.

IDENTITY MANAGEMENT HOLDS KEY TO SHUTTING DOWN PATHS TO PRIVILEGE

MODERN ATTACKERS MOVE THROUGH ENVIRONMENTS BY ESCALATING PRIVILEGES, SO TAKING CONTROL OF THE FULL IDENTITY LIFECYCLE IS NOW THE MOST EFFECTIVE DEFENCE FOR UAE ORGANISATIONS.

The United Arab Emirates (UAE) has long been a preferred target by cybercriminals and other digital adversaries around the world. According to government sources, the country fends off almost 150,000 attacks daily. The success of legitimate organisations in the face of this onslaught depends on a deep understanding of the threat they face. To prevail, they must examine what attackers do and how they do it, which means breaking down all their paths to privilege.

When attackers gain a foothold in an environment, their route to a lucrative payday is limited only by access. Their first goal will be to equip themselves with the highest-possible permissions level. They do this through privilege escalation, a process of promotion from the rights of their stolen credentials to increasingly broader rights. When a threat actor compromises a low-level account (or an insider chooses to act with ill-intent) within a well-managed IT suite, that account will not have access to monetisable resources and data. The attacker must set out on a chain of steps that exploit vulnerabilities in privilege management (bugs, misconfigurations, or insufficient controls) if they are to go any further.

As cybersecurity professionals will tell you, the traditional image of hackers writing code in real time to burrow through defenses is outdated. Modern threat actors compromise accounts so they can move about digital environments like they belong. They escalate their privileges in one of two ways – horizontal (compromising another account, human or non-human, with more rights than the captured one) or vertical (broadening the access of the captured account).

Order and method

Attackers use five main methods to gain an initial foothold and then go from their shore-landing position to the point at which they possess admin or root privileges. The exploitation of credentials involves taking advantage of a hijacked account to log in normally and leverage the privileges of that account to move laterally. A second method is to leverage unpatched applications or services that allow tunnelling into further areas. A third is to go after systems where settings have been improperly configured, and a fourth is to drop malware that executes a lay-of-the-land attack – surveilling systems and mapping networks prior to infiltration.

Finally, the attacker can tap into the weakest link in any security apparatus

– us. Social engineering techniques become more sophisticated every year and this escalation has accelerated with the arrival of readily available generative AI tools. We humans can be duped into helping attackers gain the initial foothold. Because assailants have so many options with which to escalate privileges, CISOs across the UAE find themselves wondering where to start in blocking paths to privilege. Confronted monthly with figures on the likelihood of an incident and its potential financial impact, security leaders must focus on maximising their own impact. By tackling the problem of privilege escalation, the SOC indirectly overcomes the problem of the large number of starting points and advancement opportunities observed in modern attacks. And by tackling privilege escalation through an identity-centric approach, the security function can simplify what previously seemed like an insurmountable challenge. Privileged access management (PAM) has become the de facto standard for protecting organisations against multiple types of incursions in a global ecosystem where digital identity is not as secure as we would like.

Closing doors (and windows)

Instead of the revolving doors currently

enjoyed by attackers, let us imagine blocking entry points by deploying identity management best practices at scale. We must take control of the full identity lifecycle. This includes the provisioning and de-provisioning of all identities to eliminate the vulnerability of orphaned accounts. The organisation’s audit of accounts must capture all human and non-human accounts, and surveyors must remember to include the accounts set aside for agentic AI.

Similarly, we must take control of our secrets. If possible, implement a password and secrets management solution as these traditionally enforce credential management policies like the requirement for strong passwords; additionally, they look after discovery, vaulting, central management, check-in, and check-out across human, machine, and AI agent accounts.

Every active account must be reviewed for the privileges it holds and amended to hold only the privileges it needs. This principle of least privilege ensures that low-level accounts hijacked by attackers do not grant them the keys to the organisation’s crown jewels. Admin rights should reside where they are functionally necessary – with those identities that could not otherwise perform their assigned tasks. Justin-time access goes hand in hand with least privilege. Persistent and standing privileges remain a common vulnerability. If we make sure that each privileged account is only granted access for a strictly enforced time window, we drastically narrow the opportunities the account offers our adversaries.

Going further

Extend the identity management posture to granular control over application access and connectivity. This is another way to block elevation attempts, as is the monitoring of privileged sessions to detect and address suspicious activity in real time. We can also harden our systems and applications by using

configuration options to, for example, close software ports. Many backdoor options for attackers originate from failures to review software configuration. Part of the configuration review should be an overhaul of vulnerability management. The enterprise must prioritise the continuous identification of vulnerabilities and manage their mitigation. They must look at each flaw through the lens of risk, prioritising those that would allow privilege escalation regardless of how easy they would be to exploit.

Finally, the business must enact ways of securing remote access in the era of distributed teams. These methods

must also reflect the risk posed by the overprovisioning of privileges, as some remote access attacks can be used for horizontal and vertical escalations.

‘Privilege’ means ‘privilege’ “Privilege” implies an exclusivity that protects sensitive material from unauthorised eyes. Paths to privilege must be watched and protected through strong privilege access management because attackers have found a range of ways to capture and escalate permissions to the point that they can go anywhere and see anything. The best practices laid out here will ensure your organisation does not fall prey to their methods.

INTELLIGENCE IN, RISK OUT: SECURING LOCAL AI IN HIGHSTAKES ENVIRONMENTS

THE ORGANISATIONS THAT LEAD ON AI WILL BE THE ONES WHO REDESIGN THEIR ARCHITECTURES SO INTELLIGENCE CAN FLOW IN WHILE RISK IS STRUCTURALLY DESIGNED OUT.

SEGMENTATION,

FIREWALLS AND ACCESS POLICIES ARE DESIGNED TO ENSURE DATA FLOWS AS INTENDED

Every board today is asking the same question: “How are we using AI to stay competitive?” However, for CISOs and IT leaders in sectors such as defence, critical infrastructure, and financial services, this question comes with a pertinent caveat: how do we effectively embrace AI without increasing our risk profile?

For these organisations, AI adoption is not simply a technology upgrade. It is a decision that touches on regulated data, operational resilience, intellectual property and, in some cases, national security. The appetite for innovation is real, as is the growing intolerance for uncontrolled exposure.

Increasingly, the answer lies in rethinking architecture at a fundamental level. Hardware-enforced one-way mechanisms, such as data diodes, are emerging as a critical control point for enabling AI safely. A data diode is a physically enforced, one-directional data transfer mechanism, allowing information to move in a single direction while making reverse flow impossible, regardless of software behaviour, misconfiguration or compromise. In the context of AI, this means organisations can feed systems the data they need without creating any path for that data, or derived outputs, to leave.

A Familiar Pattern: From Cloud to AI

This architectural shift is not happening in isolation. We have seen this tension before. When public cloud first emerged, critical industries hesitated. The solution was not to reject the cloud entirely, but to reshape it. In time, private cloud, sovereign cloud and hybrid architectures allowed these organisations to modernise while retaining control.

AI is now following a similar path. Rather than sending sensitive data to external platforms, many organisations are deploying agentic AI on local machines and within tightly controlled environments. Advances in high-performance chips and more efficient models mean powerful AI capabilities can now run directly on workstations and edge systems. This

promises real-time analysis, low latency, and data that never leaves the perimeter. However, architecture still determines whether that promise holds, or if it simply provides a false sense of security. AI systems do not operate in isolation. They rely on continuous inputs: logs, telemetry, sensor outputs, threat intelligence feeds, operational reports and external updates. To make local AI effective, organisations must feed it, which inevitably creates pathways for information to enter the environment.

The Illusion of Control

In theory, these pathways can be tightly controlled. Segmentation, firewalls and access policies are designed to ensure data flows as intended. In practice, however, these controls remain softwareenforced and therefore inherently fallible. Misconfigurations occur. APIs expose more than expected. Even the most mature environments operate under layers of complexity where absolute certainty is difficult to maintain. Introduce agentic AI into this equation, and the stakes rise further. These systems do more than passively analyse data. They summarise, correlate, generate outputs and, in some cases, initiate actions. They can transform sensitive inputs into structured insights and interact with external content streams. They are also susceptible to manipulation techniques such as prompt injection or maliciously crafted inputs. In this context, any bidirectional pathway, no matter how well governed, becomes a potential conduit for unintended data movement. The risk is not simply malicious insiders or external attackers; it is architectural ambiguity. When connectivity exists, even under strict policy control, the possibility of unintended outbound flow remains. This is precisely where data diodes move from being a niche control to a strategic enabler. By enforcing one-way data transfer at the hardware level, they remove ambiguity entirely. Instead of asking teams to configure, monitor and continuously

validate complex rulesets, they eliminate the very possibility of reverse flow.

In practical terms, this means an AI-enabled system can ingest threat intelligence feeds, operational telemetry or lower-trust network data, but cannot transmit anything back across that boundary. There are no firewall rules to maintain, no policies to interpret, and no reliance on application behaviour to preserve directionality. The constraint is absolute.

Real-World Impact Across Critical Sectors

The real-world impact of this approach is already becoming clear across critical sectors. In manufacturing and industrial environments, local AI can analyse machine telemetry for predictive maintenance while ingesting supplier updates or vulnerability alerts, without creating any path for proprietary production data to leak outward.

In security operations centres, AI can assist analysts by correlating alerts and consuming external threat intelligence feeds. Even if the system were manipulated or compromised, it would have no ability to transmit findings, summaries or sensitive logs beyond its designated boundary.

In defence and government settings, where classified networks have long been isolated for good reason, local AI can reason over imported datasets while preserving absolute containment. Meanwhile, in financial services and R&D environments, proprietary models, fraud analytics and intellectual property can be analysed without introducing new exfiltration channels.

Inhibiting Transmission, Accelerating Innovation

If high-impact sectors hope to ride the next wave of technological progress, they will need to accelerate AI adoption. The organisations that lead will not be those who block AI out of fear, nor those who connect it recklessly in pursuit of speed. They will be the ones who redesign their architectures at the outset, ensuring intelligence can flow in, while risk is structurally designed out.

IT IS TIME FOR C-SUITE TO BE FLUENT IN RISK

BOARDS NO LONGER NEED TECHNICAL DETAIL, THEY NEED RISK EXPRESSED IN MONEY, AND CYBER RISK QUANTIFICATION GIVES SECURITY LEADERS THE COMMON LANGUAGE TO BALANCE AGILITY AGAINST SAFETY, WRITES IVAN MILENKOVIC OF QUALYS.

We often hear that our scientific community knows more about the depths of space than about the depths of our own oceans. This is underpinned by the relatively small amount of submarine environment we have mapped when compared to the night sky. The same could be said of our software. The vulnerabilities that are most successfully exploited are those that have yet to be discovered due to lack of visibility, already forgotten, or lost in the sea of new ones. And for businesses, risks most commonly stem from an inability of technical staff to communicate the dangers clearly, and in ways that are relatable for line of business executives.

The ideal way to deliver software vulnerability reports to non-technical audiences is through business-related terminology. Transparent metrics can more easily be weighed against risk appetite so leaders can balance agility and competitiveness against legal and technical safety. When we consider the extremes of risk-free operations and security-free operations, neither is sustainable. The former is prohibitively expensive, and the latter is unlikely to be profitable over the long term. Balance is a must.

Sailing on the specific

The eventual goal is targeted investment: the right budget devoted to the right

resources and the right actions. To that end, risk appetite should not be used as a phrase to explain away underinvestment in cybersecurity. CISOs must quantify consequences and present them as business impacts. This means risk appetite itself must be quantified.

The practices of issuing high-level declarations on unmeasured acceptable levels of risk must change. Organisations need to use more specific metrics that track risk levels over time and compare them against clearly stated tolerances, such as a maximum of four hours per quarter of unplanned downtime for a core system. Risk thresholds must also be established to trigger critical actions. For example, if downtime exceeds agreedupon limits, notify the CIO. If it exceeds them by more than an hour, the CIO should notify the board.

All stakeholders must agree to declare war on ambiguity. Where possible, teams should measure risks, impacts, and outcomes in monetary terms. This leads to the formation of a common language for discussing risk and risk management. General discussions of comfort levels are replaced with specific questions like, “can we absorb an AED 5 million loss from a 24-hour downtime period?” Questions like this will emerge naturally from a risk audit, where the business and its most critical issues come under the microscope. Of course, some risks will be harder to convert into dirhams than

others. By attempting to operationalise risk management, however, we take an important step towards guided action. As time goes on, we will improve accuracy as we gain more real-world experience.

See the ROC

As with all changes in business culture, it is advisable to form a single, central entity with the authority to promote new, data-based conversations. Just as the Security Operations Centre (SOC) did this for IT intrusions, the Risk Operations Centre (ROC) will gather risk signals and present them in a common monetary language so that the best possible decisions can be made. The SOC performed a largely forensic role, identifying the sources of errors that led to damage. The ROC takes a dataled approach to prevent catastrophic incidents from occurring. Doing sideby-side comparisons of monetary data and risk tolerance, the ROC is equipped to make meaningful recommendations when changes in risk levels are detected and exceed formally stated thresholds. Data is critical. It must be used to provide a unified risk view that the board can easily use for strategic oversight. The three most important metrics are risk arrival, risk departure, and risk survival. Risk arrival rate measures the volume of new material risks entering the environment over a given period. It exposes the effectiveness of preventive controls

TRANSPARENT METRICS CAN MORE EASILY BE WEIGHED AGAINST RISK APPETITE SO LEADERS CAN BALANCE AGILITY AND COMPETITIVENESS AGAINST LEGAL AND TECHNICAL SAFETY.

alongside business growth factors. Risk departure rate, or burndown velocity, is the volume of risks your team successfully closes or accepts over that same period. Crucially, departure is a rate of volume, not a measure of time. If your arrival rate consistently outpaces your departure rate, your risk debt is compounding. Finally, risk survival is the persistence time of a specific risk; the lifespan from discovery to departure. Survival measures the actual efficacy and capacity of your remediation engine. If risks survive longer than your agreed business tolerance, you are operating outside your risk appetite. If presented visually, accompanied by incident costs, the board will be able to see if the organisation is making real progress on risk. Where investments have been made, decision-makers will be able to visualise if they are bringing adequate returns. They will see if the remediation engine can deal with the volume of new arrivals and if critical issues are being addressed in a timely manner. Stakeholders will be able to participate constructively in the risk conversation. They will be able to make suggestions about the prioritisation of critical issues that may stand in the way of revenue generation. They may direct the security team to concentrate on those issues and allow lower-risk threats to be addressed by automation.

Je parle Risk

The currency of risk is money. If the CISO can craft a narrative around profitability, impact, downtime, costs, and benefits, they will attract more decision-makers to their corner. Managing risk is orders of magnitude more effective than managing technology in the current threat landscape. The security function must evolve to become a risk function; one that makes better decisions, faster decisions, and decisions that can be readily defended. In an expat heavy region, it is not uncommon for people to want to learn a foreign language. Why don’t we all learn to speak Risk? Let Cyber Risk Quantification be your Babel fish.

NEXT LEAP IN ITSM ISN’T REPLACING YOUR TEAMS, IT’S MULTIPLYING THEM

SALMAN KAZMI, AREA VICE PRESIDENT, MIDDLE EAST, TURKEY & AFRICA AT BMC HELIX SHARES HOW AI AGENTS IN ITSM ARE MAKING IT EASIER FOR SERVICE MANAGEMENT TEAMS.

Salman Kazmi.

Each era of enterprise technology adapts with tech evolution, such as the shift from on-premises infrastructure to the cloud, or the rule-based automation to machine learning. In IT Service Management, the next shift follows service management. AI agents in ITSM are autonomous and goal directed systems, with the capacity to reason, plan and execute multiple tasks without any human instructions that are the next shift in process. In 2025, Gartner predicted 40% of enterprise apps will feature task-specific AI agents by 2026, up from less than 5% in 2025. ITSM sits at the centre of every organisation. It is responsible for keeping systems running, employees productive and services reliable at scale. For most CIOs, AI still means assistance, a suggested response or a dashboard that displays what a skilled analyst used to deliver manually. In the Middle East, AI is still mostly an enablement layer: Deloitte finds that more than 80% of organisations feel pressure to adopt AI, but nearly half still lack the talent and technology needed to scale it, and a third are not yet seeing returns. AI Agents in ITSM are few levels ahead to improve the service management support team and there are a few areas where their benefits are hard to ignore.

Transforming Frontline Support

The shift of AI Agents in ITSM started over the past decade, where service desks largely operated on phone-based processes. A service request could take hours or sometimes even days to route and resolve. With the introduction to ITSM platforms automation tooling later reduced resolution times for service tickets. Today, AI Agents in ITSM can manage the complete lifecycle of a service ticket as they can autonomously

ADOPTING AN AI AGENT

classify, prioritise, triage and resolve routine incidents which helps in reducing average response times up to 50%. This was true for tickets resolved through service and automation in documented deployments by ITSM supporting companies such as BMC Helix.

Adopting an AI agent in ITSM connects the knowledge systems and policy driven actions to perform autonomously. When service tickets hit a bottleneck, the AI agents in ITSM escalate the concern to the designated team with a full summary of what it has already performed for the query and what the next recommended steps are for the team to perform manually.

AI Agents in ITSM follow up with the customers thoroughly to ensure it has received all the accurate and necessary detail it needs to perform a diagnosis to produce an accurate result for the issue.

Reducing Staff Workloads

One of the most under-discussed challenges in enterprise ITSM is the recurring incidents problem. A support team resolves a ticket, but the underlying issue was not addressed thoroughly which causes a team member to generate another ticket a week later. Organisations that are managing high ticket volume across multi system environments become an example of this pattern that consumes an analyst’s capacity. Sometimes, due to insufficient time or data incidents can create hundreds of behind the curve issues, increasing staff workloads.

Troubleshooters work by continuously analysing the clusters of tickets using AI to locate those underlying issues autonomously, while giving problem managers and major incident managers early visibility into before it compounds. This type of analysis typically requires

IN ITSM

CONNECTS THE KNOWLEDGE SYSTEMS AND POLICY DRIVEN

ACTIONS TO PERFORM AUTONOMOUSLY.

a qualified person to execute results manually instead. With the help of these troubleshooters experienced staff can now freely work on more impactful and strategic tasks.

Proving AI Value

Integrating a service collaborator helps you support teams faster and smarter with thorough interaction. AI agents can handle the monotonous, high volume and pattern-based work autonomously so the experts can focus where their judgement matters. AI agents are not diminishing it.

A useful way to express this is with the digital full-time employee (FTE) concept. A digital FTE represents a combination of expertise and output, and when an AI agent delivers comparable expertise at dramatically higher productivity, working multiple tickets in parallel and across as many as you put in front of it, the capacity created can be a significant multiple of your existing team.

The practical application of these benefits can be viewed in the case of BMC Helix servicing Network International, a payment services company clearing over 1 million transactions daily across the Gulf, Middle East and North Africa. Through BMC Helix, they carried out nearly 80% of requests with AI powered service management which resulted in measurable and immediate results. Ticket creation time dropped from 20 minutes to 5 minutes (a 75% decrease) and the average response time fell from 60 minutes to 15 minutes resulting in an 80% improvement. The priority 1 tickets were consistently resolved within 30 minutes, and the root cause analysis was reduced from an average of 2 days to 15 minutes. The organisation also reported a decline in recurring issues.

The enterprises integrating agentic AI into their service operations now are building service management that is more resilient, responsive and scalable for businesses. When experienced analysts are freed from the cycle of reactive, repetitive work, they become architects of better service.

FORTINET ACHIEVES 1 MILLION PEOPLE TRAINED IN CYBERSECURITY GOAL AHEAD OF SCHEDULE

FORTINET’S CERTIFICATION PROGRAM HELPS EXPAND CYBER SKILLS AS ORGANISATIONS FACE PERSISTENT TALENT GAPS.

Despite cybersecurity being a critical business priority, many organisations still struggle to find, develop, and retain the skilled professionals needed to protect their organisations. Fortinet is helping address that challenge through a long-standing commitment to cybersecurity training and workforce development. Today, we are marking a major milestone in that effort: Fortinet has fulfilled its pledge made in 2022 and trained more than 1 million people in cybersecurity over five years.

This achievement, reached before the end of 2026, reflects more than just a number. It signals growing demand for practical cybersecurity education, recognised credentials, and clear pathways for people at every stage of their cybersecurity journey. The challenge goes beyond filling open roles. Organisations also need to help existing employees build practical skills, adapt to evolving technologies, and stay prepared for a threat landscape shaped by AI, cloud adoption, hybrid work, and increasingly complex digital operations.

This is why cybersecurity training and education matter. They are not optional. They are essential to building a safer digital world.

Fortinet has long understood that bridging the cyber skills gap requires more than technology alone. It also

requires accessible training, recognised credentials, and clear pathways for learners at every stage, from beginners to experienced cybersecurity professionals. That belief led Fortinet to establish the NSE Certification program in 2015 to deliver practical, real-world cybersecurity skills and knowledge.

Certifications Remain a Critical Pathway to Cyber Readiness

The 2026 Fortinet Global Cybersecurity Skills Gap Report highlights the value of industry-recognised, certification-based training. According to the report, 91% of IT decision-makers prefer candidates with technology-focused certifications, and 92% would pay for an employee to become certified. The report also found that 92% are likely to invest in AI-related cybersecurity training or certifications over the next 12 months.

These findings underscore a critical point. Certifications are not merely résumé enhancers. They help organisations identify practical capabilities in a field where technologies, threats, and job requirements change rapidly. They also provide employees with a structured way to build skills that can be applied directly to security operations, network defense, cloud security, secure access, and other critical areas.

This matters because the skills gap continues to undermine organisational

resilience. Fortinet’s 2026 report found that 73% of respondents say boards are making cybersecurity a high business priority, even as many organisations continue to face hiring challenges and skill shortages. And as cyber risk becomes more visible at the executive and board levels, the ability to develop talent internally becomes a strategic requirement.

Building Skills for Every Stage of the Cybersecurity Career Path

The Fortinet Training Institute supports a broad range of learners, from those exploring cybersecurity for the first time to experienced professionals seeking to deepen their expertise. The program provides training in foundational concepts, technical skills, and advanced-to-expert cybersecurity disciplines, helping learners and professionals build the knowledge needed to achieve real-world security outcomes.

This broad approach is essential. The cybersecurity workforce cannot grow fast enough if organisations rely solely on traditional hiring pipelines. Expanding the talent pool requires multiple pathways, including upskilling current employees, reskilling people from adjacent fields, supporting students and career changers, and helping security professionals validate and expand their expertise.

Fortinet’s certification program addresses that need by providing learners

with a clear, structured process and helping employers evaluate skills with greater confidence. The Fortinet training and certification site reports that 91% of organisations prefer to hire certified candidates and that 85% of IT decisionmakers say they have someone on their team with a technology-focused certification.

For organisations, certifications create practical value. Certified employees can help strengthen security operations, improve the deployment and management of security technologies, and support more consistent execution across teams. For individuals, certifications can create new opportunities, validate capabilities, and provide a recognised path into or upward within the cybersecurity profession.

A Milestone Built on Long-Term Commitment

Reaching 1 million trained individuals signifies more than just a number. It highlights over 10 years of commitment to cybersecurity education and workforce growth. Fortinet’s achievement also showcases how increasing accessibility, practicality, and relevance of training benefits both learners and employers.

The timing is crucial. AI is transforming not only how organisations secure their environments but also expanding what attackers can accomplish. Modern security teams require experts who understand networks, cloud platforms, identity management, applications, operations, and emerging AI-related threats. They also need a proven pathway for ongoing learning as these technologies continue to evolve.

That is why Fortinet’s commitment to training, upskilling, and reskilling people in cybersecurity remains so important. While the 1 million milestone marks measurable progress, it is not the endpoint. It is momentum.

The Fortinet Training Institute will continue to build on this success by helping learners gain practical cybersecurity skills, earn recognised certifications, and prepare for the demands of today’s and tomorrow’s digital environments.

AI IN ENTERPRISE: WHY

CISOS CAN NO LONGER CARRY RISK ALONE

Across the Middle East, artificial intelligence is moving from experimentation to execution at remarkable speed. From conversational assistants and document automation to predictive analytics and business copilots, AI is now being embedded into daily workflows across government, financial services, healthcare, retail, energy, and other critical sectors. For regional business leaders, the question is no longer whether AI will be adopted. It is whether organisations can adopt it securely, responsibly, and at the pace the market now demands.

This urgency is particularly evident in the Middle East, where national digital transformation agendas and enterprise innovation priorities are accelerating AI adoption faster than many organisations can build the governance structures around it. According to Deloitte’s Digital Consumer Trends 2025 report, 58% of consumers in the UAE and Saudi Arabia have already used generative AI tools, significantly higher than adoption levels seen across many European markets. That momentum is now entering the enterprise, transforming usage patterns, decision-making processes, and the way sensitive data moves across organisations. As a result, it is becoming increasingly unrealistic to expect CISOs to carry AIrelated risk alone.

A shift in risk that is redefining the CISO’s role

Historically, the role of the Chief Information Security Officer was to protect infrastructure, access, and sensitive data. Their remit was clearly defined around preventing cyberattacks and controlling technical risk.

But with the rise of generative AI, the issue is changing in scale. Artificial intelligence does not simply create a new cyber risk. It changes how people work, accelerates data flows, and in some cases even transforms decision-making mechanisms within companies.

This shift is also disrupting a major pillar of modern cybersecurity: digital identity. Today, identity has become the primary

attack surface for organisations. User accounts, cloud access, APIs, automated assistants, and AI agents are multiplying the number of potential entry points. In many companies, security teams are already struggling to keep pace with the creation and management of privileges.

This trend is being amplified further by the rapid emergence of non-human identities. The pace of AI deployment is creating a governance challenge for organisations across the region. Deloitte reports that more than 80% of Middle Eastern organisations feel significant pressure to adopt AI, while 69% plan to increase investment in AI initiatives. However, many leaders acknowledge that governance, skills, and operational readiness have not matured at the same speed as adoption. AI agents, bots, and automated systems are gaining access to sensitive resources at a pace that security teams can no longer always control effectively. This proliferation of technical identities is creating a new imbalance between the speed of adoption and organisations’ actual ability to govern these uses.

The CISO is therefore becoming far more than a technical expert. They are now expected to act as a coordinator of digital trust, capable of assessing AI-related risks, preventing data leaks, supervising internal usage, and contributing to regulatory compliance, particularly under new European requirements.

AI governance must become collective

The main paradox is that companies still often treat AI as a purely technological or cyber issue, when in reality it is first and foremost a broad organisational transformation.

AI governance concerns business units just as much as legal teams, human resources, compliance, IT, and executive leadership. The issues at stake include data confidentiality, intellectual property, accountability for automated decisions, as well as ethics and corporate reputation. In this context, the CISO can no longer be seen as the sole line of defense against AI-related risk. No security leader can, on

their own, define acceptable use, arbitrate the organisational impacts of automation, or carry the full weight of the regulatory obligations now emerging.

This lack of clear governance is already encouraging the emergence of a phenomenon comparable to shadow IT, now commonly referred to as “shadow AI.” Employees are using AI tools without internal approval and sometimes with sensitive data, driven by the immediate pursuit of productivity gains. These behaviors are rarely malicious, but they reveal a growing gap between the speed at which technologies are adopted and the maturity of organisations in framing and governing them.

Banning AI tools would be unrealistic. Companies that choose a purely restrictive approach would risk pushing usage outside any official framework. The challenge is therefore no longer to block, but to organise. That means putting clear policies in place, raising employee awareness, classifying the data that can be used, and above all sharing responsibility for governance across all business functions.

The challenge is particularly significant in the Gulf, where governments are investing heavily in becoming global AI leaders. The UAE continues to rank among the world’s most advanced AI adoption markets, while Saudi Arabia’s Vision 2030 agenda is accelerating AI deployment across public and private sectors. As AI becomes embedded into critical business processes, the question for organisations is no longer whether they will use AI, but whether they can govern it effectively and responsibly.

The arrival of artificial intelligence is profoundly transforming the security function. The CISO’s role is no longer just to protect the information system, but also to contribute to digital trust and to dialogue with business, legal, HR, and strategy teams. This evolution requires collective governance of AI, because its risks extend far beyond the cyber perimeter alone. More than just a technology to secure, AI is transforming how companies produce, collaborate, and make decisions.

WHEN ATTACKER HAS AI AGENT, VISIBILITY BECOMES YOUR FIRST DEFENCE

EAST,

AND

AT CENSYS, SHARES HOW FRONTIER AI IS RESHAPING THE ATTACK LANDSCAPE AND THE ORGANISATIONS THAT SURVIVE WILL BE THOSE THAT SEE THEIR EXPOSURE BEFORE THE ADVERSARY DOES.

The threat landscape has always rewarded speed. What has changed is the order of magnitude. Frontier AI models and agentic tools are now capable of autonomously scanning infrastructure, probing services, testing vulnerabilities and spinning up attack campaigns at a scale no human team could sustain manually. An EY study released in March this year mentions that 96% of senior security leaders globally say AI-enabled cyberattacks are already a significant threat to their organisations. The chase between attacker and defender has always existed. The difference today is that the attacker has a thousand clones running in parallel.

For the UAE, this shift arrives at a particularly charged moment. The country is now fending off around 600,000 cyberattacks per day, three times the volume recorded before recent regional tensions, with state-linked actors increasingly leveraging AI tools to execute more layered, coordinated campaigns. At the same time, the speed of digital transformation across the Emirates through rapid AI adoption, smart city integration and significant cloud migration has created a rapidly expanding attack surface, complicated

by a “digital debt” problem, with nearly 50% of exploited vulnerabilities in the country being more than five years old.

The combination of a wider attack surface, older unpatched vulnerabilities and adversaries equipped with AI automation is precisely the environment where traditional reactive security postures fall short.

The problem with only watching the door you expect

Most organisations have a reasonable grasp of their approved, visible infrastructure. What they tend to underestimate is the sprawl that exists around it. Subsidiaries, contractormanaged systems, forgotten test environments, AI tools spun up by data science teams, GPU instances provisioned for a week and left running are some that don’t show up neatly in a CMDB or a cloud console. But they are reachable and that is all an attacker needs.

Most organisations realistically cannot remediate them all and it no longer takes expert talent to be an attacker, just an AI model and a willingness to probe at scale as highlighted in the Fortinet FortiGuard Labs. It reported 36,000 scans per second, a 16.7% year-over-year

increase in 2025, showing how automated probing is happening at machine speed rather than requiring expert-only effort.

When vulnerability discovery is this automated, the organisations that will feel the impact first are those that don’t know what they’re exposing.

This is why exposure management, involving the continuous practice of finding, validating, and prioritising internet-facing risk has moved from a security best practice to an operational necessity.

Shadow AI is the new shadow IT

Organisations are grappling with the rapid adoption of AI tools and the associated risk of employees sharing sensitive data with public chatbots, which has been termed “shadow AI”. According to a survey conducted by Red Hat 70% of UAE organisations are experiencing a “shadow AI” problem. This is the exposure problem in miniature. A data scientist provisions a toolthat allows the sharing of live code, visualizations, mathematical equations, and descriptive text to test a model. An engineer stands up a local LLM interface for a demo. A product team spins up an AI workflow on a non-standard port. Each of these may be legitimate in isolation. None of them

may be monitored, approved, or visible to the security team. And all of them are potentially reachable from the internet.

The more important question security teams need to be asking is whether those tools are being operated in a way that creates unmonitored exposure.

Detecting this requires visibility beyond standard ports and known services, into the full public-facing footprint of an organisation.

From static indicators to living intelligence

One of the more durable lessons of the AI-enabled threat era is that static defences age badly. An IP blocklist, a known-bad domain feed, a onetime vulnerability scan are useful but insufficient when adversaries can rotate infrastructure, mutate campaigns and redeploy at machine speed.

The share of security leaders expecting agentic AI to run core functions like threat detection is set to roughly double within two years according to EY’s study released in March 2026. If attackers are using automation to move faster, defenders need equally dynamic intelligence, but continuously updated context about what is exposed and what adversarial infrastructure looks like right now.

Organisations that are most suited to adapt to this kind of situation are those that consider security not as an intermittent activity but treating it as a continuous operational function. That means live visibility into what they expose, the ability to act quickly when a new vulnerability is disclosed and intelligence about attacker infrastructure that updates as fast as the threat does.

Regional stakes remain high. The Middle East, primarily the UAE and Saudi Arabia, consistently ranks second globally for average breach costs, with the latest IBM findings putting the figure at $7.29 million per incident. That cost pressure alone makes the

Meriam ElOuazzani, Vice President – Middle East, Turkey and Africa at Censys.

case for shifting from reactive patching cycles to continuous, live visibility into what an organisation is exposing at any given moment.

The UAE has built real cyber resilience. Despite sustained exposure to phishing links and other malicious campaigns across 2025, malware

execution rates in the UAE fell progressively over the year, indicating that local defences are maturing and more attacks are being blocked earlier in the kill chain. The next challenge is ensuring that resilience extends to the parts of the attack surface organisations don’t yet know they have.

YOUR ACCOUNT TAKEOVER DEFENCES ARE FAILING AND ATTACKERS ALREADY KNOW IT

There is a silent crisis playing out across corporate security leaders. Attackers are walking through the front door of user accounts and the locks built to stop them are either letting them in or blocking the wrong people out. The root cause is that many of the bot detection mechanisms still in use today were built for a threat environment that has fundamentally changed. Log into certain banking platforms or loyalty programs today and the traditional methods are still standing guard: a challenge, a CAPTCHA puzzle, an SMS code, or an email link. For years, that was good enough. Today, however, these methods present a significant vulnerability that attackers are exploiting to launch account takeover fraud, or ATO, where they gain unauthorised access to a legitimate account to steal data, make fraudulent purchases, or use the compromised account to launch further attacks.

The Illusion of Defence

The problem with traditional bot detection methods is that bots have gotten considerably better at pretending. They now crack image-based CAPTCHAs more reliably than the average person. SMS-based verification has been quietly

undermined by SS7 exploits and SIM farms that security teams rarely talk about publicly. Email codes just add steps that frustrated users abandon. What happens next is predictable. Security teams see the collateral damage, the blocked legitimate users, the support tickets, the drop-off and they start dialing back. Thresholds get loosened. Policies get softened. The attacker never needed to break the system. They just needed to make the Defence harder to sustain than the attack.

The Bot Traffic Problem Is an ATO Problem

The problem with the old “bot or not” binary is breaking down as AI agents and automated bots make up a growing share of all traffic. Automated traffic now accounts for 57.3% of worldwide HTTP requests to HTML content, compared with 42.7% for humans, according to Cloudflare’s data.

This trend is particularly evident in the GCC region. In the UAE, for example, 92% of organisations planned to deploy AI agents in 2025, with 41% expecting these agents to work alongside employees within the year.

Within this context, every genuine customer blocked during a suspicious login presents a multi-layered business issue. The friction added to compensate, extra steps, extra clicks, extra codes, costs real users and gives security teams a reason to soften their own thresholds over time. The attacker doesn’t need to do anything clever. They just wait for the defence to become too disruptive to enforce properly.

The answer is a verification method

that works as needed, at the moment risk actually appears, one that real users barely notice and automated attacks can’t replicate.

Biometrics as the Non-Automatable Checkpoint

Hardware-bound biometric authentication changes the equation. Instead of a CAPTCHA or SMS code, the system requests a biometric: a fingerprint or face scan action through the user’s registered device (often a phone), completed in under a second.

What makes it structurally different is what happens behind the scenes. The biometric itself never leaves the device. Instead, the device generates a cryptographic proof confirming that a real person, on that specific registered device, completed the action. This turns step-up verification moments, suspicious logins, account recovery and high-risk transactions into checkpoints that are significantly more difficult to automate or bypass, offering a different category of proof, instead of relying on another harder puzzle. As a result, this helps close one of the most common gaps exploited in account takeover attacks: the ability to act as a legitimate user without proving human presence.

Human-in-the-Loop, Extended to Agents

The concept of a human-in-the-loop establishes a checkpoint requiring explicit human authorisation before an agent crosses a certain action boundary. It’s what keeps autonomous systems accountable when the stakes are high. An agent browsing product pages can roam freely. The same agent attempting

THE PROBLEM WITH THE OLD “BOT OR NOT” BINARY IS BREAKING DOWN AS AI AGENTS AND AUTOMATED BOTS MAKE UP A GROWING SHARE OF ALL TRAFFIC.

a checkout, modifying account settings, or calling a financial API? That’s where the checkpoint belongs, at the action boundary, not at the door. This isn’t about blocking agents. Agents are useful when they operate within scope. The goal is proportional trust: low friction for low-risk actions, a human-in-the-loop gate before the ones that can’t be undone.

A few places where this matters now:

• Financial services – AI agent that manages your bills is fine, but one that initiates a wire transfer without explicit human re-authorisation is a different story.

• Healthcare and benefits – Agents navigating insurance portals on behalf of patients can remove real friction, but that same capability creates liability if sensitive records can flow without a trust signal at the point of retrieval.

• B2B API workflows – A misconfigured or compromised agent can trigger bulk orders, expose pricing data, or modify contract terms, and enterprises largely don’t have good verification options before those irreversible calls yet.

• E-commerce – Flash sales and limited-inventory events have always attracted automation, and a checkout checkpoint, whether the buyer is human or an authorised AI agent, raises the structural cost of gaming them.

As the UAE accelerates its AI ambitions through investments in AI infrastructure, sovereign AI initiatives, and the rapid adoption of AI agents across both the public and private sectors, the conversation must extend beyond what problems AI agents can solve to how their actions are authorised and secured. The organisations that succeed will be those that can balance seamless user experiences with strong safeguards against account takeover fraud, ensuring that innovation and security advance together rather than in competition.

ORGANISATIONS NOW USE EMBEDDED AI TOOLS, RAISING NEW GOVERNANCE BLIND SPOTS

NEW STUDY FROM OPTRO FINDS EMBEDDED AI AND EVERYDAY

EMPLOYEE BEHAVIOUR ARE RAPIDLY EXPANDING ENTERPRISE

RISK EXPOSURE BEYOND THE LIMITS OF CONVENTIONAL GRC FRAMEWORKS.

New research from Optro (formerly AuditBoard) reveals that the greatest artificial intelligence (AI) risks facing enterprises no longer stem primarily from catastrophic model failures, but from the accumulation of everyday employee interactions with increasingly invisible AI systems operating across the organisation.

“At this early stage, AI risk is being driven as much by human behaviour, as it is from the technology itself,” said Guru Sethupathy, GM of AI Governance at Optro. “Lack of sufficient review of AI output, moving too quickly without sufficient guardrails and shadow AI are examples of human behaviours that increase the surface area of AI risks.”

While much of the AI governance conversation remains focused on generative AI tools, the research identifies embedded AI inside enterprise software platforms as an equally significant, and potentially more dangerous, source of exposure. More than half (56%) of organisations already use embedded AI capabilities within vendor tools, approaching the adoption levels of generative AI itself (63%). Yet unlike standalone AI tools, employees often do not recognise embedded functionality as “AI usage,” creating major governance blind spots. Fortyfour percent of respondents said they are concerned about employees’ lack of awareness regarding AI embedded inside enterprise tools.

At the same time, most governance, risk and compliance (GRC) structures appear fundamentally unprepared for this new reality. Only 34% of organisations maintain a formal AI model inventory, while just 31% have implemented AI

incident response procedures. Nearly two-thirds (64%) of audit, GRC and IT decision-makers said they feel only somewhat confident, or outright unconfident, in their organisation’s visibility into third-party cyber risk, including risks introduced through vendor AI capabilities.

The research also reveals growing concern among security leaders that current governance approaches are failing to keep pace with emerging AI-enabled threats. More than a third of respondents (35%) believe overly permissive AI governance policies will accelerate AI-enabled social engineering and impersonation attacks.

“Traditional GRC frameworks are static and slow to update, but that is insufficient to keep up with how quickly AI technology and risks are evolving. For instance, few standards or guardrails consider agentic AI and need to be quickly updated to stay relevant. At many companies, governance is a point-in-time exercise, meanwhile

AT THIS EARLY STAGE, AI RISK IS BEING DRIVEN AS MUCH BY HUMAN BEHAVIOUR, AS IT IS FROM THE TECHNOLOGY ITSELF.

AI risks are evolving in real time,” said Sethupathy.

The Future of GRC AI Governance

The report further indicates that organisations are rapidly approaching the limits of human-led governance models. Across security, audit and compliance functions, respondents consistently identified shortages in AI expertise, continuous monitoring capabilities and operational capacity as major barriers to effective oversight. Among CISOs, 23% said a lack of personnel with expertise in AI security and emerging risks represents their single biggest obstacle. This suggests practitioners could greatly benefit from implementing emerging AI-powered technologies such as autonomous agents. Optro’s recent acquisition of Midship directly addresses this demand, deploying AI agents capable of automating up to 87% of manual controls tasks.

“AI sits on both sides of the risk coin— it will significantly increase the surface area of risk for all organisations, and at the same time, AI will be a critical component of the governance stack,” added Sethupathy. “We believe smart AI Governance will be a differentiator, enabling speed and trust.”

WHO HAS THE REMOTE? ATTACKERS ARE TURNING LEGITIMATE REMOTE ACCESS TOOLS INTO BACKDOORS

HP THREAT RESEARCHERS FOUND ATTACKERS USING TAX YEAREND PHISHING LURES, FAKE DATING APP DOWNLOADS, BOGUS CRYPTO WALLET RECOVERY TOOLS AND SPOOFED AUDIO FILES TO TAKE OVER PEOPLE’S PCS.

HP Inc. issued its latest Threat Insights Report, which shows attackers using trusted software, disguised malware and increasingly believable lures to gain

access to user devices. The research highlights a growing challenge for both users and defenders as malicious activity becomes harder to distinguish from legitimate behaviour.

The report provides an analysis of real-

world cyberattacks, helping organisations keep up with the latest techniques cybercriminals are using to evade detection and breach PCs in the fastchanging cybercrime landscape. Based on the millions of endpoints running

HP Wolf Security*, notable campaigns identified by HP Wolf Security threat researchers include:

Legitimate Remote Access Tools

Abused for Backdoor Access: Cybercriminals are abusing applications like LogMeIn and ScreenConnect to take control of victim devices without raising suspicion. Campaigns first used tax year-end phishing emails and fake desktop app downloads – including dating websites – to then persuade users into installing legitimate remote access tools. These tools are controlled by the attackers and help them to blend in with normal IT activity, giving total control over user devices.

Attackers Preying On Desperate Users Trying to Recover Lost Crypto Wallets: Fake crypto wallet recovery tools are being spread by attackers who claim to be helping users locate lost wallets but instead steal them. Often shared via code-sharing platforms and media download sites, the emoji-filled infostealer scripts appear to be “vibecoded”, capable of harvesting credentials, wallet and system data before packaging it into archive files for exfiltration.

ClickFix Campaigns Hide Malware in ‘Audio’ Files: Attackers behind recent ClickFix campaigns are disguising malware as audio files to evade detection. Victims are guided through realistic CAPTCHA prompts on well-designed fake websites, triggering malicious commands that quietly execute disguised payloads in the background.

Patrick Schläpfer, Principal Threat Researcher, HP Security Lab, comments: “What stands out in these campaigns is how easily legitimate remote access tools are being turned into entry points for attackers. By combining trusted software with carefully designed social engineering – tied to events like the end of the tax year – it’s getting even harder to distinguish what can and can’t be trusted.”

By isolating threats that have evaded detection tools on PCs – but still allowing malware to detonate safely inside

secure containers – HP Wolf Security has insight into the latest techniques used by cybercriminals. To date, HP Wolf Security customers have clicked on over 60 billion email attachments, web pages, and downloaded files with no reported breaches.

The report, which examines data from January-March 2026, details how cybercriminals continue to diversify attack methods to bypass security tools revealing that:

At least 11% of email threats identified by HP Sure Click bypassed one or more email gateway scanners.

Executable files were the most popular malware delivery type (39%), followed by archive files (38%) and PDF documents (10%).

PDF-based malware increased 2%, with attackers using a wide range of lures such as court documents and bonus payments to create urgency and drive clicks.

Alex Holland, Principal Threat Researcher, HP Security Lab, said:

“These attacks don’t look like break-ins –they look like business as usual, blending in with normal IT activity and avoiding the warning signs associated with malware. To secure the future of work and reduce risk, organisations should restrict unnecessary privileges, control software installation, and isolate risky activity such as downloads and unknown links. Detection alone is not enough when legitimate tools are being turned into backdoors.”

AI ADOPTION IN FINANCIAL SERVICES ACCELERATING, BUT GROWING GOVERNANCE GAPS AND INFRASTRUCTURE CHALLENGES ARE SLOWING SCALE

Nutanix, a leader in hybrid multicloud computing, announced the findings of its eighth annual Financial Sector Enterprise Cloud Index (ECI) report. The findings reveal that while financial services organisations are rapidly adopting AI, many are struggling to scale effectively as governance, infrastructure and operational readiness lag behind. The findings point to an inflection for the financial services industry, as organisations race to scale AI amid

increasing regulatory and operational pressures.

As organisations push forward with deployment, 68% acknowledge that their infrastructure is not fully equipped to support AI workloads on-premises, while nearly two-thirds (64%) rely on third-party providers to bridge that gap. To move from adoption to scale, organisations will need to better align infrastructure, governance, and operational processes to ensure AI can be deployed securely and compliantly.

“Across the Middle East and Africa,

financial institutions are moving beyond AI experimentation and increasingly embedding AI into core business operations - from customer engagement and risk management to fraud detection and regulatory compliance. However, as adoption accelerates, many organisations are discovering that scaling AI successfully requires more than access to models and data. The findings highlight a growing need for modern infrastructure, stronger governance frameworks, and greater operational readiness to ensure AI can be deployed

Key findings:

• Shadow AI is widespread and poses a significant risk: 66% of IT executives report employees using unsanctioned AI, while 86% say it creates business risk.

• Governance and process are the biggest barriers: Process complexity (38%) and organisational factors, including leadership and skills (34%), outweigh technical limitations (28%) when scaling AI.

• Data sovereignty is creating growing tension: While 79% prioritise data sovereignty, 62% still run containerised workloads in the public cloud, creating a growing "Sovereignty Debt"

• Containerisation is accelerating as a foundation for AI: 90% say AI is accelerating container adoption, with 89% expecting containerisation to grow.

securely, compliantly, and at scale. As regulatory expectations around data sovereignty continue to evolve across the region, financial services organisations must strike the right balance between innovation, control, and resilience to unlock the full value of AI, “ said Mohammad Abulhouf, VP & GM, Middle East & Africa at Nutanix.

For the eighth consecutive year, Nutanix commissioned a global research study to assess the state of cloud adoption, containerisation, and GenAI application deployment. Conducted in November 2025 by Wakefield Research, the survey gathered responses from 1,600 cloud, IT, and engineering executives with at least a manager-level title. Respondents represent organisations with 500 or more employees across Australia, Brazil, France, Germany, India, Italy, Japan, Mexico, the Netherlands, the Kingdom of Saudi Arabia, Singapore, Spain, the United Kingdom, and the United States.

80% OF PROFESSIONAL SPORTS ORGANISATIONS IMPACTED BY CYBER INCIDENTS IN LAST 12 MONTHS

Darktrace, a global leader in AI for cybersecurity, released new research showing 84% of professional sports organisations have experienced a cyber incident in the past 12 months. More than half (57%) were hit multiple times.

As the 2026 FIFA World Cup puts professional sport into the global spotlight, the new report Cybersecurity in Global Sport: Threats, Signals, and Strategic Implications for a Digitised Industry highlights how AI is changing the risk landscape for professional sports. Attackers are using AI to create more convincing phishing emails, tailor lures to real teams, venues, sponsors, executives, and events, and move faster across complex digital environments. At the same time, sports organisations are adopting AI across their own operations, creating new blind spots for security teams.

Darktrace found that 83% of cybersecurity professionals in professional sports surveyed believe they have detected AI use in cyberattacks against them in the past 12 months, while 72% believe AI will increase cyber risk over the next year. That risk is amplified in professional sports, where live events, high-value data, public pressure, fixed schedules, and large networks of partners and suppliers all intersect at once to offer attackers maximum publicity, profit and potential impact. According to the survey, the average cyber incident cost sports organisations $169,000 (USD) over the past 12 months.

However, the real financial impact compounds: 57% reported being hit more than once, and 43% reported between six and 10 incidents in a single year. For each of those organisations, the cumulative annual cost could climb to as much as $1.7 million.

The wider impact goes beyond financial loss. In sport, a compromised executive account, fake fan communication, disrupted ticketing system, or exposed athlete data can create deep and immediate public, financial, and reputational damage.

Security concerns increasing as AI adoption rises

Within professional sports organisations, AI adoption is growing rapidly from the backroom to pitch.

Security professionals surveyed for Darktrace’s research reported that stadium operations would cause the greatest impact if compromised in a cyberattack (cited by 34%). Yet more than a third (35%) said they are already deploying AI into those same operations or plan to in the next 12 months, bringing new risks in the area they can least afford to lose.

A similar pattern follows in other operational areas. One-third of respondents said they are using or planning to use AI for ticketing operations and fan engagement, and 32% are using it for marketing operations and content generation. At the same time, many remain concerned about integrating AI into those critical systems. Nearly half

of security professionals cited risks introduced during AI development and deployment (47%) and AI prompt risks and attacks (47%), while 35% pointed to shadow AI as a concern.

As sports organisations expand AI use into increasingly critical operations, security teams need visibility into what AI tools can access and what actions they can take, how they interact with sensitive systems and data, and whether the underlying AI infrastructure itself is being targeted or misused.

Phishing and identity remain high risks

Darktrace telemetry data shows that email and identity remain key attack paths for the sector. The report found that sports organisations are particularly exposed to email phishing attacks, with Darktrace sports sector customers receiving nearly 20% more phishing emails than those in other industries. Darktrace / EMAIL detected more than 116,000 phishing emails targeting sports sector customers across 6 months spanning from October 2025 to March 2026. Of those, 21% targeted VIPs, 38% were spear-phishing attempts, 84% successfully passed DMARC authentication, and 37% contained novel social engineering features.

“Professional sport is a highpressure environment where timing matters,” said Nathaniel Jones, VP, Security and AI Strategy at Darktrace. “A suspicious login, unusual data movement, or unexpected AI agent action may look small in isolation, but during a live event it can become

operationally significant very quickly. The most effective way to mitigate the risks facing sports organisations both internally and from external actors today is to adapt a behavioural approach to security. That means shifting away from rules and signatures and focusing on understanding both human and AI behavior inside your environment.”

Taking action to stay ahead of evolving risks

As the sports industry enters a new phase of exposure, behavioral approaches

become increasingly vital to securing organisations and events. Security teams need to understand what normal looks like across the environments that matter most to sport: people, identities, email, stadium systems, suppliers, and AI tools. That behavioral understanding helps them detect threats designed to blend into normal activity, whether the risk comes from an external attacker, a compromised account, or an AI agent acting outside its intended role.

In this environment, AI systems like Darktrace / SECURE AITM, which uses

Highlight:

• New Darktrace sports sector threat report reveals 57% of professional sports organisations experienced multiple cyber incidents in the last 12 months.

• 72% believe AI will increase cyber risk over the next 12 months as AI adoption grows in high stakes areas including stadium operations, ticketing and fan engagement, and business operations.

• 35% of professional sports organisations have either deployed AI technology into stadium operations, or plan to in the next 12 months

• Darktrace sports sector customers receive nearly 20% more phishing emails than those in other industries.

a behavioral AI approach to enable and secure AI agent creation and usage, provide a vital foundation for security operations, providing unified, realtime visibility across environments and machine speed response to potential threats.

Building on that behavioral AI foundation, Darktrace highlights six priority actions for professional sports organisations to stay ahead of evolving threats:

• Threat modeling for emerging technologies, including AI misuse

• Rigorous supply chain governance and vendor access control

• Strong segmentation across IT, OT, and fan facing systems

• Identity centric security with anomaly detection and universal multi-factor authentication (MFA)

• Phishing resilience across all channels, including QR based vectors

• Operational playbooks aligned to live event constraints

HDI GLOBAL STRENGTHENS MIDDLE EAST BUSINESS WITH SENIOR APPOINTMENTS IN CYBER UNDERWRITING AND CONSTRUCTION RISK ENGINEERING

Corporate & Specialty lines

insurer HDI Global is strengthening its Dubai office and expanding specialist capabilities in the Middle East by appointing two senior leaders in cyber underwriting and construction risk engineering. These appointments reflect the company’s ongoing growth ambitions in the region.

Jessica Heaume has joined HDI Global as Head of Cyber, Middle East, while Lloyd Lui has been appointed Senior Risk Engineer Construction, Middle East. The appointments add further depth to HDI Global’s regional platform at a time when clients across the Middle

Highlight:

• HDI Global strengthens Dubai hub to scale Middle East growth with senior cyber and construction hires

• Growing cyber risk and megaprojects drive demand for specialised underwriting and engineering

• Builds position as long-term partner in increasingly complex GCC market

East are navigating increasingly complex risk environments, driven by digital transformation, large-scale infrastructure development, regulatory evolution and the need for more specialised insurance expertise.

Jessica Heaume has over eight years of experience in cyber and financial lines underwriting, with extensive expertise in the Middle East and Africa markets. She joins from AIG, where she most recently served as Head of Cyber for the region, leading

the development and execution of the cyber underwriting strategy and supporting portfolio growth. Prior to this, she held senior underwriting roles spanning cyber and financial lines facultative reinsurance, and began her career at Beazley in London. Her appointment aligns with rising cyber risk on executive agendas across the GCC, as organisations face a rapidly changing threat landscape, increased digital adoption, greater operational connectivity, and evolving regulations. For businesses in the region, cyber insurance is increasingly viewed not only as a risk transfer solution, but as part of a broader resilience strategy requiring technical underwriting discipline, market knowledge and close collaboration between clients and key stakeholders.

“Businesses across the Middle East are navigating a fast-changing cyber threat environment, and they need underwriting partners who can bring clarity, consistency and strong technical judgement,” said Jessica Heaume, Head of Cyber, Middle East at HDI Global. “HDI Global’s focus on disciplined underwriting, technical excellence, and long-term partnership aligns with the region’s needs. I look forward to working closely with

clients to support resilient growth and help address the gap between cyber exposure and effective risk transfer.”

HDI Global is also reinforcing its construction risk engineering capabilities through the appointment of Lloyd Lui as Senior Risk Engineer Construction in its Dubai office. Lloyd brings more than 13 years of experience across engineering, project risk management and insurance, with a career spanning Australia, the United Kingdom and the Middle East. He has worked with leading organisations including Marsh McLennan, Berkshire Hathaway Specialty Insurance and Allianz Commercial, supporting brokers and underwriters on construction risk engineering. Most recently, he was based in Saudi Arabia, where he worked on major giga-projects across the GCC.

Construction and infrastructure remain central to the region’s economic development agenda, with major projects becoming increasingly complex in scale, design, delivery and stakeholder requirements. In this environment, engineering-led risk insight plays an important role in improving project resilience, strengthening risk quality and supporting more informed underwriting decisions.

“The scale and complexity of development across the GCC demands risk engineering that is practical, collaborative and focused on outcomes,” said Lloyd Lui, Senior Risk Engineer Construction at HDI Global. “My focus will be on working closely with clients and stakeholders to translate technical risk insights into clear actions that can improve resilience, strengthen risk quality and support better project performance.”

Willem van Wyk, Senior Executive Officer and Director, Middle East at HDI Global, said the appointments reflect the company’s continued investment in specialist expertise to support clients and stakeholders

across the region.

“These appointments mark an important step in strengthening our Dubai office and expanding the specialist depth we bring to clients and stakeholders in the Middle East,” said Willem van Wyk. “Cyber and construction are two areas where technical excellence, disciplined underwriting and local market understanding are critical. Jessica and Lloyd each bring a strong track record and highly relevant regional expertise, which will be instrumental as we continue to drive growth and further establish HDI Global as a leading Corporate & Specialty insurer and a long-term partner in transformation for brokers and clients in the region.”

The regional expansion is supported by HDI Global’s strong global performance in the first quarter of 2026. In its three-month results, HDI Global reported operating profit (EBIT) of EUR 207 million, compared with EUR 195 million in the same period of 2025, while net income rose by 8 percent to EUR 152 million.

The company’s combined ratio improved slightly to 91.0 percent, supported by disciplined underwriting, favourable large loss experience and a strong contribution from investment income. Insurance revenue remained broadly stable at EUR 2.5 billion, while large loss payments stood at EUR 58 million, significantly below the pro rata budget for the period.

The results underline HDI Global’s continued focus on profitability, disciplined underwriting and technical excellence as it expands its capabilities in key markets, including the Middle East.

Willem van Wyk

INFOBLOX APPOINTS HENRIK SMITH AS CISO

FORMER AMAZON, SALESFORCE AND AWS SECURITY LEADER TO STRENGTHEN INFOBLOX SECURITY STRATEGY AND CYBER RESILIENCE.

Infoblox, a leading platform for preemptive security and critical network services, announced the appointment of Henrik Smith as chief information security officer (CISO). Smith will lead the company’s global security strategy, focusing on strengthening cyber resilience, advancing risk management and supporting the secure growth of the business. He joins Infoblox at a time when organisations are navigating an increasingly complex threat landscape shaped by AI-driven attacks, expanding digital infrastructure and the growing adoption of autonomous technologies.

Smith brings nearly 30 years of security leadership experience spanning cloud security, enterprise security and risk management. He joins Infoblox from Amazon, where he served as head of Security for Devices and Services, leading efforts to secure Amazon’s consumer device ecosystem.

Smith also served as vice president of security at Salesforce, where he led security strategy, risk remediation and security integration efforts across the enterprise. Earlier in his career, he held multiple leadership positions within AWS Security, including as one of the founding members of the Office of the CISO and

Security Assurance organisations.

“Henrik is a proven security leader with deep experience building and scaling security programs at some of the world’s most influential technology companies,” said Scott Harrell, president and CEO, Infoblox.

“As AI transforms how organisations

INFOBLOX PLAYS A CRITICAL ROLE IN HELPING ORGANISATIONS SECURE AND MANAGE THE INFRASTRUCTURE THAT POWERS MODERN BUSINESS.

operate, security and resilience have become foundational to innovation itself. Henrik’s expertise will help strengthen our security posture, safeguard the trust our customers place in us and ensure Infoblox remains resilient in an increasingly complex threat landscape.”

“Infoblox plays a critical role in helping organisations secure and manage the infrastructure that powers modern business,” said Smith. “I’m excited to join the team and help further strengthen the company’s security program while supporting its continued innovation and growth.”

Henrik Smith

Turn static files into dynamic content formats.

Create a flipbook
Security Advisor Middle East - June 2026 by CPI Media Group - Issuu