Accelera Digital Group’s Mohammed Ashoor on identity-led security, distributed environments and the changing nature of enterprise trust
24 LOCAL ADVANTAGE
SentinelOne’s Ezzeldin Hussein on Saudi Arabia’s cybersecurity shift, data sovereignty, and why AI is forcing a rethink of the SOC
38 WHEN THE CAMERA LIES
Axis Communications’ Andrea Sorri on deepfakes, video authenticity, and the growing challenge of trust in digital systems
26 MAKING ROOM FOR AI
Seagate explores the infrastructure and storage demands emerging as AI adoption continues scaling
28 BUILDING SOVEREIGNTY
IBM on digital sovereignty, operational control and why resilience is becoming a board-level priority
42 TEST OF COMMAND
Check Point Software Technologies on operational resilience, adaptability and leadership under pressure
How leadership clarity and operational visibility are shaping enterprise momentum
50 The latest gears and gadgets to keep you ahead of the curve
HOLDING THE LINE
The past couple of months have brought a noticeable resilience. As organisations continue accelerating AI adoption, modernising infrastructure and expanding digital services, the environments supporting those environments, communications networks, suppliers and third-party platforms are becoming increasingly difficult to separate, while disruption no longer arrives in isolated ways. Increasingly, operational pressure spreads across
That shift comes through strongly in our cover feature this month, which examines how enterprise leaders are reassessing continuity, adaptability and operational discussion moves beyond traditional recovery planning and towards a more continuous approach centred on
Elsewhere in the issue, Ezzeldin Hussein of SentinelOne discusses how localisation, sovereignty and AI-driven
while Mohammed Ashoor of Accelera Digital Group examines the growing importance of identity-led security in distributed enterprise environments. Andrea Sorri from Axis Communications explores the rise of deepfake-driven enterprise risk and the growing challenge of maintaining trust and authenticity in digital systems.
We also feature perspectives from IBM, Endava, Informatica, Seagate and Submer on sovereignty, interoperability, infrastructure resilience and the growing operational demands emerging as AI adoption continues scaling.
At a time when conditions continue shifting, resilience is becoming increasingly tied to clarity, adaptability and operational discipline. .
Adelle
Managing Editor Adelle Geronimo
Commercial Director Merle Carrasco merlec@insightmediame.com +97155 - 1181730
Operations Director Rajeesh Nair rajeeshm@insightmediame.com +97156 - 4110215
Designer Anup Sathyan
While the publisher has made all efforts to ensure the accuracy of information in this magazine, they will not be held responsible for any errors
Starlink has landed in Kuwait, with Sama X rolling out high-speed satellite internet across the country. Promising fast, low-latency connectivity even in hard-to-reach areas, the move opens new ground for enterprises, remote operations and sectors long constrained by limited network access.
Pay is widening its remittance reach, adding Saudi Arabia and Türkiye to its money transfer network. The expansion gives UAE users faster in-app international transfers while strengthening Careem’s ambitions to become a larger player in the region’s rapidly evolving digital payments market.
Core42 has appointed former Microsoft executive Sherif Tawfik as Chief Business Officer to lead its global commercial operations and accelerate adoption of its sovereign AI cloud platforms. The move strengthens Core42’s international expansion strategy as demand grows for trusted, production-scale AI infrastructure.
SAP has rebranded SAP Emarsys as SAP Engagement Cloud, signalling a broader shift towards AI-driven customer engagement at enterprise scale. The platform now combines marketing, commerce and customer data capabilities to help organisations deliver more connected, real-time experiences across channels.
Uber is expanding support for local businesses across Dubai and Abu Dhabi, giving SMEs greater visibility on its platform and access to a wider customer base. The move aims to drive demand, boost discovery, and strengthen the role of neighbourhood merchants within the UAE’s growing digital economy.
Cisco has appointed Bader Almadi as Vice President for Saudi Arabia, reinforcing its focus on AI infrastructure and digital transformation in the Kingdom. He will lead local strategy and operations, supporting Vision 2030 priorities and expanding Cisco’s role across key sectors including finance, energy and public services.
Careem
Kuwait connects to the sky with Starlink launch
Uber puts UAE’s local businesses in the fast lane
Core42 appoints Sherif Tawfik as Chief Business Officer
Cisco names Bader Almadi VP for Saudi Arabia
SAP rebrands Emarsys as SAP Engagement Cloud
Careem Pay extends cross-border transfers to Saudi Arabia, Türkiye
OpenAI plans desktop ‘super app’ to streamline user experience
OpenAI plans to combine its web browser, ChatGPT application, and Codex coding app into a single desktop super app as the company moves to streamline its expanding product
Presight, NodeShift partner to scale sovereign AI globally
ecosystem, according to reports
The initiative will be overseen by Fidji Simo, CEO of Applications at OpenAI, with support from Greg Brockman, President and Co-Founder of OpenAI.
Presight has partnered with NodeShift to scale sovereign AI solutions globally, combining enterprise AI deployment with infrastructure designed for regulated environments.
The agreement includes joint go-tomarket collaboration, investment support, and international expansion. NodeShift has also secured backing from the $100 million Presight–Shorooq AI fund. The partnership follows NodeShift’s participation in Presight’s AI Accelerator Programme, where its platform was evaluated for technology readiness, data sovereignty, regulatory compliance, enterprise scalability, and market fit.
NodeShift’s platform enables organisations to deploy open-source and commercial AI models through a governed interface, supporting onpremises and air-gapped environments. The platform is designed to ensure sensitive data remains within enterprise infrastructure while integrating AI into operational workflows.
The unified desktop application is intended to simplify the user experience and reduce fragmentation across OpenAI’s products. The reported move follows internal discussions around company priorities and a growing focus on productivity-driven AI applications.
“Companies go through phases of exploration and phases of refocus; both are critical,” said Fidji Simo, CEO of Applications at OpenAI.
The report said OpenAI has recently expanded its portfolio with new products including Codex and its browser as competition intensifies with rivals such as Google and Anthropic.
OpenAI has reportedly confirmed that its ChatGPT mobile app will remain unchanged. The report added that it remains unclear whether the company will continue expanding other mobile offerings, including a mobile version of its Atlas browser.
The companies said the partnership will support the deployment of sovereign AI solutions across regulated sectors, including government and financial services. NodeShift is also delivering a proof of concept with the Central Bank of the UAE as part of its ongoing deployments. The collaboration is focused on expanding the availability of secure, compliant AI infrastructure across global markets.
Thomas Pramotedham, CEO, Presight AI, and Mihai Marcuta, Co-Founder and COO, NodeShift
Nusuk app surpasses 51 million users as Saudi Arabia advances digital pilgrimage
Dubai Chamber drives talks on tech sector resilience
Dubai Chamber of Digital Economy has organised 72 meetings with companies operating across the technology sector to assess current business conditions and address challenges linked to ongoing global developments.
The meetings brought together representatives from companies specialising in artificial intelligence, fintech, cloud computing, cybersecurity, and e-commerce. The discussions focused on gaining direct insights into the evolving business landscape and identifying practical solutions to strengthen the resilience of Dubai’s digital ecosystem. Participants exchanged updates on developments shaping the digital economy and explored ways to support business continuity in a rapidly changing global environment. Discussions also examined opportunities to strengthen the digital business environment and enhance Dubai’s attractiveness as a destination for startups and technology entrepreneurs.
Saudi Arabia’s Nusuk app has surpassed 51 million users, marking a significant milestone in the Kingdom’s efforts to digitise the pilgrimage experience.
The milestone was announced by Minister of Hajj and Umrah Tawfig Al-Rabiah, during the opening ceremony of the third Umrah and Ziyarah Forum in Madinah, according to the Saudi Press Agency.
Developed by the Ministry of Hajj and Umrah, Nusuk offers more than 130 digital services designed to support pilgrims throughout their journey. These include issuing Umrah permits, booking visits to Al-Rawdah Al-Sharifah, checking crowd density, and accessing support services.
The platform also enables users to manage travel logistics such as hotel bookings, Haramain train tickets, and flights within a single interface. In addition, it provides spiritual tools including Qur’an access, prayer times, daily athkar, and Qibla direction.
The app is positioned as a comprehensive digital ecosystem aimed at improving the overall pilgrimage experience.
The meetings reviewed a range of practical solutions aimed at helping digital companies respond to emerging challenges, improve adaptability to global shifts, and expand their business activities and product offerings.
“We remain committed to empowering technology companies in Dubai and ensuring they can adapt rapidly to evolving global circumstances. By engaging in close collaboration with all relevant stakeholders, we are implementing swift and effective solutions to strengthen the resilience and
sustainability of Dubai’s digital ecosystem,” said Saeed Al Gergawi, Vice President, Dubai Chamber of Digital Economy.
He added that these efforts further strengthen Dubai’s position as a global hub for technology and innovation and a preferred destination for startups and entrepreneurs.
The meetings form part of wider engagement with the private sector focused on assessing business conditions across the ecosystem, anticipating future developments, and supporting sector readiness to respond to global challenges.
Eight Saudi cities ranked in IMD Smart City Index 2026
Several cities across Saudi Arabia improved their positions in the IMD Smart City Index 2026, published by the International Institute for Management Development, reflecting ongoing development efforts and investments in digital infrastructure
and urban services.
Riyadh advanced to 24th place globally, rising from 27th in the previous edition of the index. Makkah ranked 50th, while Jeddah secured 55th place. Al Khobar ranked 64th and Madinah placed 67th globally.
Oman ramps up efforts for 6G rollout
The Oman Telecommunications Regulatory Authority has launched a preliminary study to assess the readiness for deploying sixth-generation telecommunications networks in Oman as part of efforts to prepare for the next phase of digital connectivity.
According to the authority, the study aims to evaluate the national preparedness required to introduce 6G technology and support advanced digital infrastructure across the sultanate.
The study will focus on several areas, including the infrastructure requirements needed to support 6G networks, identifying suitable radio frequency spectrum bands, and examining potential applications of the technology across different sectors.
The initiative forms part of wider efforts to strengthen Oman’s digital ecosystem and ensure early readiness for emerging communication technologies. The study will also review technical, regulatory, and operational aspects that could help shape future strategies for integrating next-generation connectivity into national development plans.
TRA said the project seeks to support innovative technologies within the telecommunications sector while ensuring Oman remains aligned with global developments in advanced connectivity.
Riyadh climbed three places to secure 24th position globally
AlUla recorded one of the strongest gains among Saudi cities, climbing from 112th to 85th position. The improvement reflects the rapid pace of development and tourism projects underway in the city.
The index also included Hail and Hafar Al-Batin for the first time. Hail ranked 33rd globally, while Hafar AlBatin placed 100th among 148 cities evaluated worldwide.
The IMD Smart City Index measures how cities are adopting modern technologies by assessing residents’ perceptions of service quality, digital infrastructure, and the impact of technology on daily life.
Among the objectives outlined for the study are enhancing preparedness for 6G adoption, enabling next-generation digital services, and supporting local value creation through advanced telecommunications capabilities.
Globally, 6G is expected to deliver ultra-fast speeds, low latency, and advanced connectivity applications across sectors including smart cities, healthcare, transportation, and industry.
Ayman Zaid / Shutterstock.com
Switch to Speed. Scale Without Limits.
Meet the SwitchBlade x908 GEN3
The SwitchBlade x908 GEN3 is our most advanced modular switch, delivering blazing speed and scalable growth for future-ready enterprise and data center networks.
Blazing Bandwidth: Up to 400G connectivity for high-performance workloads.
Scale Without Limits: 12.8 Tbps of power in a compact 3U chassis.
Flexible & Modular: Compact chassis with versatile interface options.
Smart Management: Zero-touch provisioning and centralized control with AlliedWare Plus™.
Whether you’re scaling a data center or optimizing enterprise networks, the SwitchBlade x908 GEN3 keeps your network fast, flexible, and fail-proof.
Take control. Stay ahead. Transform your network today.
587,500
Meta cuts jobs as company shifts focus from metaverse to AI
Meta is reportedly planning to cut up to 15,800 jobs as the company redirects investments from metaverse initiatives toward artificial intelligence development and infrastructure.
According to reports, the layoffs impact teams across recruiting, sales, global operations, Facebook social, wearables, and advertising divisions. The job cuts are reportedly part of a broader company reorganisation and
affect fewer than 1,000 employees.
“Teams across Meta regularly restructure or implement changes to ensure they’re in the best position to achieve their goals,” a Meta spokesperson said in a statement.
“Where possible, we are finding other opportunities for employees whose positions may be impacted,” the spokesperson added.
The layoffs follow earlier workforce reductions within Meta’s Reality Labs division
expenses between $162 billion and $169 billion for 2026.
Earlier this year, Mark Zuckerberg, Chief Executive Officer of Meta, said AI would significantly reshape the company’s operations.
“We’re starting to see projects that used to require big teams now be accomplished by a single very talented person,” Zuckerberg said in a January Facebook post.
Meta said it continues investing in AI agents, recommendation systems, smart glasses, and wearable technologies.
Lenovo opens META regional headquarters in Riyadh
Lenovo has officially opened its Middle East, Türkiye and Africa (META) Regional Headquarters in Riyadh, marking a strategic expansion of the company’s regional operations and long-term investment in Saudi Arabia.
The opening ceremony was attended by Fahad bin Abduljalil Al-Saif, Minister of Investment of Saudi Arabia, alongside senior government officials, strategic partners, and Lenovo executives.
“Lenovo’s decision to establish its Middle East, Türkiye and Africa Regional Headquarters in Riyadh reflects the strength of the Kingdom’s partnership with leading global technology companies and the effectiveness of the Regional Headquarters Program,” said Fahad bin Abduljalil Al-Saif, Minister of Investment of Saudi Arabia.
The Riyadh headquarters will serve
The opening of our META Regional Headquarters in Riyadh is a proud moment for Lenovo and a clear statement of our long-term commitment to Saudi Arabia”
TAREQ ALANGARI Lenovo META
as Lenovo’s central hub for regional strategy and operations across the META region. The company said the move will support closer collaboration with customers and partners across more than six regional markets while enabling faster and more localised decision-making.
“The opening of our META Regional Headquarters in Riyadh is a proud moment for Lenovo and a clear statement of our long-term commitment to Saudi Arabia,” said Tareq Alangari, Senior Vice President and President of Lenovo Middle East, Türkiye and Africa.
As part of the occasion, Lenovo hosted a visit to its Riyadh manufacturing facility, where officials met 28 Saudi graduate engineers who recently completed Lenovo’s Saudi Smart Manufacturing Graduate Program in China.
The RHQ forms part of Lenovo’s wider strategic collaboration with ALAT and sits alongside investments including an advanced manufacturing facility, research and development centre, customer experience centre, and talent enablement initiatives.
“WE REMAIN COMMITTED TO EMPOWERING TECHNOLOGY COMPANIES IN DUBAI AND ENSURING THEY CAN ADAPT RAPIDLY TO EVOLVING GLOBAL CIRCUMSTANCES”
Saeed
Al Gergawi, Vice President, Dubai Chamber of Digital Economy
“EMERGING TECHNOLOGIES ARE NO LONGER AN EXPERIMENTAL OPTION, THEY HAVE BECOME A FUNDAMENTAL PILLAR FOR ACHIEVING THE EFFICIENCY OF GOVERNMENT PERFORMANCE, INCREASING PRODUCTIVITY, AND ACCELERATING COMPLETION, WHICH IS REFLECTED IN IMPROVING THE BENEFICIARY EXPERIENCE”
HE Eng. Ahmed bin Mohammed Alsuwaiyan, Governor, Saudi Arabia Digital Government Authority
SKILLS OVER HEADCOUNT
THE REAL PRESSURE POINT IN CYBERSECURITY
Cybersecurity teams are under pressure in ways that recruitment alone is no longer fixing. Organisations may have people in place, but many are struggling to keep those teams aligned with the pace, complexity, and volume of what security operations now demand.
The 2026 SANS | GIAC Cybersecurity Workforce Research Report from SANS Institute reflects an industry dealing with a different kind of workforce strain than the one it spent years talking about. Based on responses from almost 1,000 cybersecurity practitioners, HR professionals, and security leaders across six global regions, the report shows capability gaps overtaking staffing shortages as the dominant concern across security teams.
Sixty percent of organisations said their biggest workforce issue was “not having the right staff”, while 40 percent said the problem was “not enough staff”. A year ago, the difference between those figures was minimal as per the report. The shift is significant because it suggests organisations are becoming less concerned with how many people they employ and more concerned with whether those teams can realistically manage the environments in front of them.
“The industry has been running around saying there are millions of unfilled cybersecurity jobs,” Rob T. Lee, Chief AI Officer & Chief of Research, SANS Institute. “That narrative misses the more fundamental problem. If everyone walks away with one thing from this room, it’s this: it is more about skills now than headcount.”
The findings arrive at a time when AI is changing the structure of security operations faster than many organisations appear prepared for. Nearly three quarters of respondents said AI is already affecting cybersecurity team structures and role allocation. Most organisations described the impact through workflow automation, reduced manual analysis, and operational efficiency rather than direct workforce cuts, although some traditional security functions are already beginning to shrink. SOC analysts, threat intelligence analysts, and incident responders were among the roles most affected in organisations reporting workforce restructuring linked to AI adoption. Those positions have long acted as the operational entry point into cybersecurity, giving junior practitioners exposure to investigations, detection work, and incident handling before progressing into senior roles.
Meanwhile, organisations are building entirely new functions around AI oversight and governance. Roles tied to AI security engineering, machine learning security, and AI governance are becoming increasingly common as companies try to establish internal controls around systems that many teams are still learning to manage safely.
The report repeatedly returns to the gap between deployment and preparedness. Only 21 percent of organisations said they have a comprehensive AI security framework in place. Some reported having governance policies documented without corresponding training programmes, while others admitted they still have no formal AI policy at all.
The report also captures the scale of regulatory influence now shaping cybersecurity hiring. In 2025, 40 percent of organisations said compliance requirements were influencing cybersecurity hiring decisions. In this year’s report, that number climbed to 95 percent. Frameworks and regulations including NIS2, DORA, CMMC, DoD 8140, and SEC requirements are now reshaping hiring priorities, forcing organisations to recruit specialist expertise around governance, compliance, and reporting obligations.
The operational consequences are becoming harder to dismiss as 27 percent of organisations said workforce capability gaps had contributed directly to security breaches. Delayed projects, slower response times, weaker monitoring coverage, and rising levels of burnout appeared throughout the findings.
The report also points to a quieter problem developing underneath the immediate pressures. Organisations are hiring heavily for experienced roles while entrylevel positions become harder to access. Over time, that risks weakening the pipeline that produces the senior practitioners the industry is already struggling to find.
The number of organisations reporting that regulations are now directly influencing cybersecurity hiring decisions
The percentage of companies that experienced security breaches linked directly to workforce capability gaps
The proportion of businesses where AI is already reshaping cybersecurity team structures and roles
REDEFINING RESILIENCE
Why enterprises across the Middle East are rethinking resilience around adaptability, operational continuity
The current situation in the region has brought operational resilience back into sharper focus for governments, enterprises and critical industries alike. Leadership teams are revisiting assumptions that, until recently, felt relatively stable. Supply chain exposure, cloud dependencies, communications resilience, workforce continuity and recovery planning are now being examined far more closely as organisations respond to mounting operational pressure.
At the same time, businesses are still expected to keep moving. Governments continue expanding digital services, enterprises are accelerating AI adoption, and industries ranging from finance and energy to logistics and healthcare are becoming increasingly dependent on interconnected digital infrastructure, cloud platforms and third-party ecosystems that many organisations only partially control.
As those dependencies deepen, resilience is no longer sitting quietly inside governance frameworks or disaster recovery documentation. It has become a broader operational question around continuity, decisionmaking and whether organisations can continue functioning effectively when multiple systems come under pressure at the same time.
For years, enterprise resilience largely sat inside governance frameworks, disaster recovery strategies and quarterly risk reviews. Most organisations understood the playbook: build redundancy into infrastructure, maintain backups, create continuity plans and run periodic simulations.
What many leadership teams are recognising now is that resilience cannot be treated as a static capability. Conditions change too quickly, and operational pressure rarely arrives in predictable ways anymore.
Most traditional resilience strategies were designed around disruptions that could be isolated and contained. A cyber incident would be handled by security teams. A cloud outage would trigger failover procedures. The underlying
assumption was that disruptions, while serious, would remain relatively independent of one another.
That assumption is becoming harder to defend. Supply chains, communications networks, cloud infrastructure and cybersecurity operations have become tightly interconnected. Critical business operations increasingly rely on third-party platforms, logistics providers, identity systems and
cloud environments that many organisations only partially control.
The result is a very different resilience challenge from the one enterprises prepared for a decade ago.
Pressure across interconnected systems
What happens when a cloud outage affects customer services while operational teams are simultaneously
dealing with communications disruption, delayed supplier access and heightened cybersecurity threats?
These are becoming board-level concerns across sectors including finance, energy, manufacturing, telecommunications and government.
Recent resilience assessments across the region have exposed a recurring problem. Many organisations appear prepared on
paper but struggle once disruption moves beyond controlled scenarios. They may have continuity frameworks, certifications, risk registers and recovery plans in place. Yet under pressure, organisations often discover that critical dependencies remain poorly understood, crisis decision-making structures are unclear and recovery assumptions were never tested under realistic conditions.
Technology matters, but resilience ultimately depends on how people operate, communicate and execute during disruption
“People often jump straight into technicalities when discussing crisis situations, but ultimately it’s about the business,” said Mohammed H Alabbadi, Group CISO, Fertiglobe. “You can have the best disaster recovery plan in place, but if the business itself cannot continue operating, then the organisation is not resilient.”
That distinction is changing how resilience is being approached inside executive leadership teams. The focus is no longer limited to whether systems can recover, but whether organisations can continue operating effectively as priorities, risks and operating conditions evolve.
In manufacturing and operational technology environments, that may mean keeping production lines running despite supplier disruption or communications constraints. In financial services, it may involve maintaining customer access while responding to infrastructure degradation or heightened regulatory pressure.
The shift is also forcing organisations to reassess longstanding assumptions around
MOHAMMED ALABBADI Fertiglobe
cloud infrastructure and recovery architecture.
For years, cloud adoption was framed primarily around scalability, efficiency and availability. Multiregion architectures, failover environments and disaster recovery tooling created confidence that resilience had materially improved.
Recent industry developments, however, have exposed how quickly operational assumptions can break down when recovery dependencies themselves become difficult to access. Analysts and resilience specialists increasingly warn that many organisations still rely on centralised identity systems, orchestration tooling, management planes and communications environments that may become inaccessible during large-scale disruption.
In other words, the issue is often not whether backup infrastructure exists. The issue is whether organisations can still operate the systems required to activate recovery.
“Traditional methodologies are being challenged,” said Jijish Gopi, Cybersecurity Specialist Officer, Dubai Department of Finance. “Resilience today is not just about recovery. It is about continuous adoption of technologies, continuous learning, continuous testing and continuous monitoring of changing conditions.”
Enterprises are also reassessing the pace at which resilience planning itself needs to evolve. Annual planning cycles are beginning to look increasingly outdated against conditions that can change within days or even hours.
“One of the biggest challenges organisations face today is eliminating guesswork,” said Stephen Fernandes, Chief Growth Officer, Planview. “Disruptions force organisations to quickly reassess those priorities. The key question becomes: how fast can organisations reprioritise?”
That reprioritisation challenge cuts across every layer of the enterprise.
Most organisations now operate across ERP systems, IT service
management platforms, cybersecurity operations, DevOps environments and collaboration tools that often remain disconnected from one another. During disruption, those silos slow visibility, complicate decision-making and make it harder for leadership teams to understand operational impact quickly.
“To respond effectively, organisations need transparent access to connected data in real time,” Fernandes said.
As a result, observability, operational visibility and integrated monitoring are moving higher on enterprise investment agendas as organisations seek a clearer understanding of how systems, suppliers and operational workflows interact during periods of stress.
Still, visibility alone does not create resilience.
“The first thing is understanding the impact,” said Sujoy Banerjee, Regional Business Director – UAE, ManageEngine. “Organisations need to know what has been affected, how critical that impact is and how they can recover from it.”
The challenge is that many continuity exercises still take place in controlled environments that fail to reflect how modern disruption actually unfolds. A disaster recovery test may validate that infrastructure can technically fail over between environments, but it may not account for supplier delays, communications breakdowns, access restrictions, regulatory escalations or operational decision bottlenecks occurring simultaneously.
Resilience as an operational discipline
Resilience is also being viewed through a much broader operational lens. Technology remains critical, but the real pressure often falls on how effectively leadership teams communicate, make decisions and coordinate execution once conditions begin to shift.
Who has authority to make decisions during a crisis? How quickly can leadership teams redirect resources? Which services take priority? How are customers
Automation still requires human intervention, especially during high-risk scenarios
JIJISH GOPI Dubai Department of Finance
informed? Which systems must remain operational regardless of conditions?
Those questions become difficult to answer if resilience planning remains isolated within technology teams.
“Organisational behaviour is crucial to ensuring resilience,” Alabbadi said. “Technology matters, but resilience ultimately depends on how people operate, communicate and execute during disruption, how quickly teams can align under pressure and whether leadership structures are clear enough to support fast, coordinated decision-making.”
Operational resilience is becoming increasingly tied to organisational discipline and leadership clarity. Preparedness is built through repetition, testing and operational discipline rather than policy documentation alone. Organisations that regularly rehearse escalation processes, test scenarios and continuously reassess assumptions tend to adapt faster when conditions shift.
“Preparedness cannot begin during disruption,” Banerjee said. “Organisations should conduct regular disruption drills, much like fire drills. Teams need to understand how systems interact, how departments
collaborate and how responsibilities shift during crisis situations. The more organisations rehearse these scenarios, the better prepared they become.”
Leadership expectations are also changing. Business continuity was once viewed primarily as an IT responsibility. That boundary has largely disappeared. Operational resilience now affects revenue continuity, customer trust, regulatory exposure and workforce coordination simultaneously.
Boards are paying closer attention because technology now underpins almost every core business function. AI adoption is adding another layer of operational complexity. Enterprises are increasingly exploring AI-driven operational analysis, automated response capabilities and scenario modelling tools to improve resilience decision-making, while remaining cautious about removing human oversight from high-risk operational decisions.
“AI is increasingly being used for scenario planning and rapid
decision-making,” explained Fernandes. “Agentic AI can help organisations analyse real-time data, model scenarios and support operational decisions quickly. But none of that works unless the underlying data is already structured, connected and prepared beforehand. However, AI readiness depends on data readiness.”
Disconnected systems, fragmented data environments and inconsistent operational visibility still limit how effectively AI can support organisations during disruption.
Gopi added that high-impact incidents still require human review and structured approvals. “It should never become fully autonomous,” he said. “Automation still requires human intervention, especially during high-risk scenarios. Lowrisk events may be handled automatically, but high-impact incidents must still go through business workflows, approvals and manual oversight.”
That balance between automation and human judgement may become
one of the defining operational questions for enterprises over the next several years.
Technology remains central to resilience strategies, but infrastructure alone is no longer enough. Leadership clarity, operational awareness, communication discipline and the ability to make decisions under pressure are becoming equally important.
The organisations operating most effectively under pressure are rarely the ones relying purely on static continuity plans or legacy assumptions. More often, they are the ones that understand their dependencies clearly, reassess conditions continuously, test regularly, communicate effectively and build adaptability into the way the organisation operates every day.
In practice, resilience is becoming less about reacting after disruption occurs and more about maintaining operational preparedness as conditions continue changing around the business.
LOCAL ADVANTAGE
Ezzeldin Hussein, Regional Senior Director, Solution Engineering, SentinelOne, on Saudi Arabia’s cybersecurity shift, data sovereignty, and why AI is forcing a rethink of the SOC
How important is Saudi Arabia to SentinelOne’s regional strategy, and how is the market evolving as investment accelerates?
The Saudi market is critical for us. With Vision 2030, cybersecurity and digital transformation are no longer
optional. Organisations across the Kingdom are scaling digital initiatives, which naturally expands the attack surface and makes cybersecurity a business enabler rather than a support function.
There’s also been a shift in how vendors approach the market. The model of operating from a distance
and offering global platforms doesn’t hold anymore. The expectation now is to move closer — to localise and align with how the market operates. That’s the approach we’ve taken.
We’ve made the SentinelOne Singularity Platform fully available locally through Google Cloud, alongside building a strong onground presence across engineering, sales, customer success, and support. Our regional HQ is now in the Kingdom, allowing us to work more closely with customers.
Equally important is investing in Saudi talent to ensure local capability continues to grow.
For regulated sectors, localisation removes a key concern. Data is stored and processed within the Kingdom, which not only supports compliance but also improves performance by reducing crossregion data movement.
How are data sovereignty requirements shaping security architecture and vendor strategy?
Data sovereignty isn’t just a regulatory requirement in Saudi Arabia — it’s starting to shape how systems are designed from the ground up. The conversation now begins with where data sits and how it moves, not just how it is protected.
That’s also where compliance comes in. It’s often seen as something that slows things down, but in practice, it forces you to think more carefully about how your architecture is put together and how data is handled across the environment.
You see this clearly in sectors like healthcare. There’s a concern that sensitive data, such as patient information, is being processed externally. In reality, most platforms are not working with the raw data itself. They rely on metadata, and
more of the detection is happening locally on the device. So, the amount of sensitive data that actually needs to move is much smaller than people assume.
Once you look at it that way, the approach becomes more straightforward. Keep sensitive data where it belongs. Process what you can locally. Be clear about how data is handled and where it goes.
How are you working with regulators and partners on the ground?
This is a key part of how we operate in the market. We work closely with our partners in Saudi Arabia — resellers, MSSPs — to make sure we are reaching different industries and customer segments in the right way. At the same time, engagement with regulators is just as important. Even before making the platform available locally, we worked alongside Google to ensure alignment with the regulatory landscape. That’s not a onetime exercise — it’s ongoing, as requirements continue to evolve.
From a customer perspective, the expectation is quite clear. They want to know that what they are adopting already meets local standards, whether that’s certification or compliance. Our role is to remove that uncertainty and give them that level of assurance from the start.
What does your partnership with Google Cloud enable in practical terms for customers in Saudi Arabia?
Our collaboration with Google Cloud is a big part of how we’re approaching the Saudi market. What it really comes down to is that now, the full SentinelOne platform is now available locally in the Kingdom, hosted on Google Cloud. For customers — especially in sectors like government, finance, and healthcare — that removes a major concern. They can move forward with an AI-driven security platform without having to question where their data sits or how it’s being handled.
At the same time, they’re not cut off from the bigger picture.
AI is driving both innovation and risk. It’s now part of the attack surface itself.
AI is driving both innovation and risk. It’s now part of the attack surface itself
They still have access to global threat intelligence and the wider AI capabilities that come with it. That balance is important — keeping data local, but not losing the benefit of global insight.
The platform itself is built to be AI-native, so it’s designed for autonomous detection and response, and for protecting modern workloads, including AI-driven environments. Running it locally helps from a performance standpoint, but more than that, it keeps everything aligned with regulatory expectations.
So it’s not just about hosting the platform in-country. It’s about making sure organisations can actually use these capabilities at scale, within the boundaries they have to operate in.
How is AI reshaping the threat landscape, and how is that changing security operations?
We’re seeing new attack types such as model manipulation, prompt injection, data poisoning, while existing ones are becoming more sophisticated. Phishing, for example, is far more convincing than it used to be. At the same time, attackers are shifting focus. Instead of just encrypting systems for ransomware, they may target AI-driven systems like fraud detection models, where the impact can be greater if manipulated.
Defending against this requires better AI. Traditional models are reaching their limits, with too many alerts and too much manual work. The SOC needs to move from being alert-driven to decision-driven, where AI can triage, correlate, and even act on incidents, allowing analysts to focus on higher-impact decisions. However, that doesn’t remove the human element. AI supports, rather than replaces. It improves efficiency, but the thinking still sits with the individual.
More broadly, resilience comes down to balance — applying global best practices while aligning with local requirements, and integrating both in a way that works in practice.
SOVEREIGN STACK
By Zane Ulhaq, Head of MENA, Endava
The start of every new year is typically awash with predictions about the ‘next big thing’ in technology. Over the years, these have ranged from automation and cloud computing to IOT and blockchain. Yet in the current decade, that annual exercise has centered around one key theme: artificial intelligence. And while AI will undoubtedly remain, the defining buzzword of 2026, its centre of gravity is shifting.
The AI conversation today is far more nuanced than it was even eighteen months ago. Early adoption was driven by competitive pressure and a fear of missing out. Organisations experimented fast, often without a clear understanding of risk, governance or long-term value. Most recently, this was apparent when open-source, self-hosted AI experiments have shown how quickly tools can move beyond their original intent, creating unintended security and trust risks as they spread. Much of this still comes down to how people use the technology rather than true autonomy, but the signal is clear: adoption is now outpacing institutional oversight.
Sovereign AI does not aim to stop this process, but to reduce systemic risk by setting clear boundaries on where and how AI can be deployed at scale, particularly within regulated environments and critical systems. With national security and economic resilience in the mix, AI is no longer just a commercial priority; it’s increasingly a government-backed agenda.
Geopolitics has played a decisive role in this shift. Rising tensions between global powers,
concerns over data sovereignty, and a growing distrust of offshore technology dependence have pushed governments to treat AI not merely as a solution, but as strategic infrastructure. This has been particularly visible in the Middle East, where AI is being positioned as a cornerstone of national development rather than a bolt-on innovation.
Throughout 2025 and prior to this, the early roots of this transition became visible worldwide. Governments began setting clearer rules around data residency, model training, inference, and ownership, and cross-border data flows. In the Gulf, these policies have been matched with capital. The UAE and Saudi Arabia have committed billions to AI-ready data centres, high-performance compute, and national AI strategies designed to ensure that data, models and value creation remain within their borders. This combination of regulation and investment has laid the foundations for what will define 2026: the rise of sovereign AI.
Sovereign AI goes beyond hosting models locally. It reflects a deliberate choice to control how AI systems are trained, governed and deployed within a national context. In practice, this means models that reflect local languages, values, legal frameworks and economic priorities, while operating on infrastructure subject to domestic law.
For governments, it offers strategic autonomy. For enterprises, the rise of sovereign AI promises clarity and stability in an increasingly fragmented regulatory environment. It does not mean building or owning national-scale capabilities, but instead introduces a more
complex decision environment around how AI is selected, integrated and governed within national and sectoral frameworks. In practice, most organisations will operate hybrid AI environments, combining global platforms, regional infrastructure and locally governed data in ways that respect data residency, regulatory oversight and domestic policy objectives, while remaining commercially viable. Success will depend less on the choice of any single model and more on the ability to design flexible architectures, adapt operating models and work with partners that can navigate multiple ecosystems without compromising compliance or control. In this sense, sovereign AI is not a destination, but a constraint within which effective execution becomes the real differentiator.
To understand what this means in practice for enterprises, it helps to look at an earlier parallel: cloud computing. A decade ago, some
enterprises were wary of the cloud for reasons strikingly like today’s AI concerns – data control, compliance and security. The emergence of sovereign and regional clouds addressed these fears, enabling organisations to modernise while meeting regulatory requirements. Sovereign AI follows the same logic. By aligning advanced capabilities with national governance, it allows enterprises to adopt AI at scale without exposing themselves to what they deem as unacceptable risk.
There are, however, consequences. One is model fragmentation. As countries pursue their own AI strategies, forks will inevitably emerge. We are likely to see country- or region-specific models, each governed by different standards and ethical frameworks. While this fragmentation may slow global convergence, it could also accelerate innovation within local
As AI becomes embedded into national infrastructure, sovereignty will no longer be a fringe concern in certain regions around the globe
how sovereign models can be developed and deployed at national scale, while Saudi Arabia’s HUMAIN initiative, including the ALLAM 34B Arabic large language model, shows how AI is being localised to serve strategic, cultural and economic priorities. Bahrain’s partnership with SandboxAQ to apply large quantitative models to biopharmaceutical research is another powerful example. By leveraging AI to accelerate drug discovery and create proprietary intellectual property, the country is using sovereign AI capabilities to move up the value chain. Strategies like this are only possible when nations control both the models and the compute that power them. Early leadership in this space could prove defining for decades.
National AI strategies will also reshape the competitive landscape for AI providers. Sovereign AI initiatives tend to favour scale, security credentials and long-term viability, making it more likely that governments will partner with established players such as OpenAI, Anthropic or major hyperscalers. While this consolidation brings stability, it also risks squeezing out smaller innovators as niche capabilities are absorbed into broader platforms.
Avoiding monopolies in the AI race will require deliberate policy choices. Governments must balance the need for trusted, largescale partners with mechanisms that sustain startup ecosystems, whether through procurement frameworks, regulatory sandboxes or targeted incentives. Without this, sovereign AI could unintentionally stifle the very innovation it seeks to protect.
contexts, particularly where models are tuned to sector-specific needs such as healthcare, finance or public services.
For governments with wellcapitalised sovereign wealth funds, sovereign AI also offers a clear competitive advantage. In the Gulf, this is already taking shape. The UAE’s Falcon LLM demonstrates
As AI becomes embedded into national infrastructure, sovereignty will no longer be a fringe concern in certain regions around the globe. In 2026, the question for governments and enterprises alike will not be whether to embrace sovereign AI, but how to do so in a way that balances autonomy, innovation and global collaboration. Those that get it right will not just adopt AI faster; they will shape the rules by which it evolves.
MAKING ROOM FOR AI
By Sameer Bhatia, Senior Regional Director, India and META, Seagate
Artificial intelligence dominates the technology conversation. Much of that conversation centres on compute. Faster processors, larger models and increasingly powerful GPUs capture the headlines and drive infrastructure investment.
Yet AI does not run on compute alone. It runs on data. And that data must be stored, retained and accessed at enormous scale.
As organisations race to deploy AI, a quieter but more consequential question is emerging. Can the world’s data infrastructure expand fast enough and efficiently enough to support it?
The answer will shape the economics of AI in the decade ahead.
But most of the data that fuels AI does not live in compute clusters. It resides in storage environments designed to manage massive datasets over long periods of time
sustainably as data volumes grow. This is where storage density becomes critical. Even modest improvements in how much data can be stored within a single device or rack can have a significant impact at scale. Higher density allows organisations to store more data within the same physical footprint while reducing energy and cooling demands.
At exabyte scale, these efficiencies translate into meaningful infrastructure savings.
The nature of enterprise data is also changing. Much of the world’s information was once treated as archival, stored primarily for compliance or record keeping.
Global data creation has already reached unprecedented levels. In 2005, the world generated roughly one zettabyte of data. By 2020, that figure had surged to more than 70 zettabytes. Industry forecasts suggest it could exceed 180 zettabytes within the next few years as AI, cloud computing and connected systems continue to expand.
For enterprises, this shift represents more than a technology cycle. Data has become a strategic asset, and the ability to store
and retain it efficiently is quickly becoming a competitive advantage.
AI is accelerating this trend. Modern AI systems depend on vast datasets for training and continuous improvement. At the same time, AI is generating new data through simulations, automation and analytics.
Much of this growth is coming from unstructured data such as video, images and sensor streams. As AI systems analyse and enrich these datasets with annotations, summaries and metadata, the volume of information that must be retained grows even further.
The result is a compounding effect. Each generation of technology produces more data than the one before.
When organisations design AI infrastructure, the focus often falls on compute performance. GPUs, specialised accelerators and model architecture tend to dominate the discussion.
But most of the data that fuels AI does not live in compute clusters. It resides in storage environments designed to manage massive datasets over long periods of time.
At hyperscale and enterprise scale, the economics of storing and retaining data become decisive. Cost per terabyte, energy consumption and physical data centre footprint determine whether infrastructure can expand
Today, that same data is increasingly becoming operational intelligence.
Video analytics provides a clear example. AI systems can analyse hours of footage to identify safety risks, detect patterns or accelerate investigations. Industrial sensors generate streams of machine data that feed predictive maintenance models, while retailers analyse behaviour across thousands of locations.
In each case, AI transforms previously passive data into actionable insight.
But this transformation also increases storage demand. High resolution video, sensor streams and machine generated data create large datasets that must be retained and accessible for longer periods. In many environments, organisations are preserving data not simply for compliance but so it can be searched, analysed and reactivated by AI systems over time.
This raises one of the defining infrastructure questions of the AI era. If global data volumes continue to grow at their current pace, can digital infrastructure scale efficiently enough to support them?
The next phase of the AI race will not be defined only by faster models or more powerful chips. It will also depend on how efficiently organisations can store, manage and extract value from the world’s rapidly expanding data universe.
THE RESILIENCE MANDATE
Mohammed Ashoor, Country Manager, Bahrain, Accelera Digital Group, discusses the shift to identity-led security and the growing focus on resilience
For years, enterprise security was designed around control. Systems were built to defend a perimeter, policies were written to enforce it, and compliance frameworks became the benchmark for whether organisations were doing enough.
With data moving constantly between platforms and workforces no longer tied to a single location, the perimeter has stretched beyond traditional boundaries. Furthermore, AI systems are now beginning to interact with enterprise environments in ways that don’t fit neatly into existing security models.
In that context, the assumptions that shaped cybersecurity architectures over the past decade are being reworked. “The security mentality has shifted from building a castle and hunkering in, to dealing with distributed systems in the cloud and elements not usually under the control of onpremise personnel,” says Mohammed Ashoor, Country Manager for Bahrain at Accelera Digital Group. “This mentality has to shift further toward always assuming risk in the cloud and dealing with data as it flows and is in transition.”
As infrastructure spreads across environments, the traditional markers of trust begin to weaken, pushing identity into a far more central role in how security is applied.
“Traditionally, enterprises anchored trust on network location—the IP address, or where someone was accessing systems from,” Ashoor says. “But with mobile devices, cloud
The security mentality has shifted from building a castle and hunkering in, to dealing with distributed systems in the cloud and elements not usually under the control of on-premise personnel
platforms and SaaS, location no longer matters; what matters is who is accessing the data.”
That shift would be significant on its own, but it becomes more complex as non-human actors enter the environment. AI systems are no longer confined to analytics or automation in the background. They are starting to initiate actions, access information, and interact with enterprise platforms alongside employees and partners. In practice, that means security teams are no longer just managing users; they are managing a growing mix of identities, some of which are autonomous.
“The next evolution is gaining clear visibility into exactly who, or what, has access to what,” explains Ashoor. In practical terms, that means treating AI systems less like tools
and more like participants in the environment. They require identities, defined permissions, and clear boundaries around what they can and cannot do.
“AI agents and autonomous systems should be treated as full digital actors,” he adds. “Just as human users have identities, permissions and governance frameworks, AI actors need the same - if not stricter - structured controls, especially as their autonomy increases and human oversight decreases.”
This introduces risks that existing security controls were not designed to handle, particularly where AI systems can be influenced or manipulated.
“Agentic identity management is about treating AI agents as firstclass identities, governed with the same rigour as human users,” Ashoor says. “But the risks are significantly higher because these agents can be hijacked, manipulated or redirected through techniques like prompt injection.”
That changes the scope of identity governance. It is no longer just about provisioning access and enforcing policies. It is about maintaining confidence that every actor in the system, whether human or machine, is behaving as expected in real time.
This is where the gap between compliance and resilience becomes harder to ignore. Compliance still plays a role by providing structure and accountability, but it is built around defined controls and periodic validation. It does not reflect how systems behave when data is moving continuously across cloud environments, SaaS platforms, and distributed networks.
“Compliance provides guardrails, but it does not account for data that is constantly shifting across cloud, SaaS and distributed networks,” explains Ashoor. “CISOs need a realtime, operational view of security to ensure resilience as systems and data continuously change.”
That shift is already visible in how access is managed. Long-standing privileges are being replaced with time-bound access, granted when needed and removed when they are not, reducing exposure without slowing down the business.
While it is a small change on paper, in practice it reflects a different way of thinking about security, assuming conditions are always changing.
Preparing for the next wave of risk Security leaders are also being pushed to think further ahead, as some risks are not immediate but are inevitable.
One risk that is increasingly part of security conversations is quantum computing, particularly its potential to break current encryption standards once the technology becomes mainstream.
“Quantum computing is not an immediate threat, but once it becomes one, it will be too late to react,” Ashoor says. “The speed at which quantum systems could decrypt harvested data means attackers collecting sensitive information today will be able to exploit it the moment quantum capabilities mature.”
The concern is not just about what can be accessed now, but what is being stored and could be exposed later. That is pushing organisations to assess where encryption is vulnerable and how they will transition to post-quantum standards over time.
“That is why enterprises need to take post-quantum cryptography seriously now, understanding their exposure, mapping where vulnerable encryption is used and planning migration paths,” says Ashoor.
Planning for this does not sit neatly within traditional security roadmaps. It requires anticipating scenarios that have not fully materialised, while still managing day-to-day risk. “This is not
something to address when the threat arrives; preparation has to start immediately,” he adds.
As AI becomes more embedded in business processes and data moves more freely across environments, how organisations structure security is coming under greater strain.
“Organisations stuck in old models of access and location-based security will be far more exposed,” Ashoor says, pointing to the combined impact of agentic systems and future decryption capabilities.
Organisations are better positioned when they move towards identity-led security, with stronger visibility and control that can adapt as conditions change. “They need to safeguard themselves against long-term threats, rather than reacting after the damage is done,” he says.
That shift also changes how security is measured in practice. It needs to be less about whether controls exist, and more about whether they hold up under pressure.
According to Ashoor, Zero Trust becomes more relevant here, moving beyond implicit trust based on network location and anchoring security in identity.
“If I am accessing data from five or six different devices, the system must continuously verify that it is still me throughout the entire session,” Ashoor says. “In the agentic era, this becomes even harder as AI agents must be authenticated, monitored and governed with strict guardrails to ensure they have not been taken over or altered during their access.”
Once AI systems are part of that equation, the challenge becomes harder to contain. Identities are no longer static, and neither is behaviour. The focus moves beyond defence to keeping systems aligned, access controlled, and decisions moving as conditions change.
For CISOs, that changes the mandate to ensuring they can continue to operate securely without interruption, even as conditions shift.
“As these agents become more autonomous, maintaining identity integrity across both humans and machines becomes a top priority for resilience,” says Ashoor.
DESIGNING FOR DECADES
By Hossam Hassanien, Data & AI Strategist, Informatica from Salesforce
Artificial intelligence is advancing at a relentless pace. Just as governments begin adapting to one breakthrough, another arrives to reset expectations. What feels like leadership today can quickly become table stakes tomorrow. This contrasts with the timelines of the national digital strategies
seen across the Gulf, which are designed with horizons measured in decades. Programmes such as Saudi Vision 2030, Qatar National Vision 2030, and the UAE’s longterm transformation agendas are not simply technology initiatives. They are national transformation programmes intended to reshape economies, institutions, and public services over generations.
That changes the question entirely. For governments, the challenge is not simply how to lead the next AI cycle, but how to ensure investments made today continue delivering value over the long term.
The answer will not be found in model leadership alone. It will be found in the institutional foundations beneath the models: trusted data, sound governance, and design choices that allow national AI capabilities to evolve as priorities change without forcing states to rebuild their digital core every time the technology landscape shifts.
When innovation becomes state fragmentation
This is where many National Data & AI programmes encounter their first structural risk.
As enthusiasm around AI accelerates, ministries and publicsector entities often begin pursuing initiatives independently. Each programme may create local value, but without shared standards and
governance, these efforts can quickly proliferate into isolated data environments, incompatible taxonomies, and fragmented AI deployments.
At first, this can look like progress. Over time, it creates fragmentation. Different entities begin working from different versions of the same facts. Crossgovernment collaboration becomes more complex, and what began as promising pilots turns into siloed capabilities that are difficult to scale nationally and offer little longterm ROI.
That is why the most resilient sovereign data and AI programmes treat trust not as a policy artefact, but as an architectural principle.
The nerves of government
Political scientist Karl Deutsch argued in The Nerves of Government that the strength of a state depends on its ability to sense, process, and act on information coherently. In many ways, this insight has become even more relevant in the AI era.
When public institutions operate without a shared framework for trusted data, the “nerves” of government begin to fray. The result is not simply inefficiency. It is a weakening of the state’s ability to coordinate, decide, and act with confidence.
For governments seeking to scale AI responsibly, this distinction matters. AI can be deployed quickly. National coherence cannot.
Trust-by-design, not policy alone
In many organisations, trust is framed primarily through regulation, compliance frameworks or ethical guidelines. While these are essential, they are insufficient on their own. True trust emerges when governance is embedded directly into the underlying data architecture, shaping how information is structured, shared and interpreted across institutions.
This is what governance by design makes possible: policies are not imposed as afterthoughts, but executed as second nature across the nerves of
Technologies will change. Models will evolve. Platforms will come and go
government — without introducing bureaucratic friction or disrupting institutional flow.
When trust is built into the operating model, institutions can retain their independence while still contributing to a coherent national ecosystem. The result is not centralisation for its own sake. It is alignment with autonomy: a model that allows government entities to move faster together because they are working from shared meaning, trusted data, and common standards.
The power of shared context For AI systems, trusted context is particularly important. Artificial intelligence does not simply require data. It requires meaning. Without consistent definitions, relationships, and ontologies, AI systems struggle to interpret information in ways that reflect real-world dynamics.
Establishing this contextual grounding allows AI models to understand national realities more accurately. It ensures analytics produced in one sector can be interpreted by another, and that new AI capabilities can be integrated without rewriting entire data foundations. This is what might be described as a Sovereign World Model: a trusted digital representation of the state, built on authoritative facts, governed relationships, and shared meaning across institutions. It is not a single product or technology category, but the outcome of a broader trustbased architecture that gives AI systems the context, constraints, and institutional memory required for public-sector decision-making. Without trusted data architectures, governments risk
creating ephemeral AI — systems that function within isolated environments but cannot evolve or interconnect over time. The result is AI that may appear technically impressive in pilots yet proves operationally fragile when exposed to the complexity and accountability demands of national governance.
Turning AI investments into national assets
Sovereign AI is often discussed in terms of computational capacity, local model development or control over data infrastructure. Those matter. But over time, true strategic advantage lies in the durability of the ecosystem itself. Governments that build trusted, interoperable data foundations create an environment where AI capabilities can continuously evolve as technologies advance.
True sovereign resilience is not only about redundancy. It is the ability of a nation’s trusted data and decision foundations to remain stable across changing models, changing platforms, and changing conditions.
That is what allows AI investments to stand the test of time. That portability matters. It means that as AI technologies evolve, the state’s core intelligence does not have to be reinvented.
The Gulf’s digital ambitions are among the most forward-looking in the world. By designing sovereign AI architectures that prioritise trust, interoperability and governance from the outset, the region has an opportunity to ensure that today’s investments remain productive long after the current generation of AI models has been surpassed. Technologies will change. Models will evolve. Platforms will come and go.
But nations that invest in trusted data foundations — where alignment, accountability, and shared meaning are built into the operational fabric — will be able to adapt without losing continuity. And in the long arc of national development, that may prove to be the most important data and AI advantage of all.
BUILDING SOVEREIGNTY
By Saad Toma, General Manager, IBM Middle East and Africa
For years, digital transformation was measured by speed, scale, and efficiency. Today, resilience is emerging as a defining metric.
Recent disruptions across critical digital systems show that digital infrastructure is no longer behind the scenes. It is part of a nation’s critical fabric. When systems fail, the impact doesn’t stay confined to IT. It disrupts economies, public services, and trust itself.
And yet, many organisations are still building for performance, without anticipating for disruption.
Redundancy is not resilience
Traditional architectures were designed to withstand localised technical failures. That assumption is now being tested and the results are clear.
Even highly distributed environments can experience simultaneous failures across multiple regions during major disruptions. Systems built for technical fault tolerance were not designed for systemic shocks – be it geopolitical, environmental, or economic.
Resilience today must assume simultaneous, rapidly changing scenarios: regional outages, supply chain disruptions, and impacts on essential services and infrastructure.
As a result, resilience has become a board-level concern.
Infrastructure alone does not create sovereignty
The question is no longer where systems are located, but whether they can continue to operate and under which pressure and circumstance.
Without control, there is no sovereignty
In this context, digital sovereignty is often misunderstood.
It is frequently reduced to data residency (where data is stored). But this narrow lens carries a strategic risk: location alone cannot ensure continuity or control.
Sovereignty is about demonstratable technical and strategic control: over encryption and access, over operations and decision-making, over how systems recover and continue under stress.
We’ve worked closely with clients to define what digital sovereignty looks like in practice and where to start. The same themes kept emerging, so we’ve distilled them into a set of practical starting points in this IBM digital sovereignty whitepaper.
Sovereignty is ultimately the ability to leverage technology on your own terms — maintaining authority over data, AI, and infrastructure while operating within a global ecosystem. This is not simply a policy question. It is an architectural one.
Dependency is a hidden risk
Related to control, is the less visible but equally important challenge of dependency.
Many organisations operate across global platforms without full visibility into where workloads run or how their technical dependencies are structured. What appears distributed can, in practice, be concentrated in a small number of providers or regions.
When disruption occurs, these dependencies are exposed. What was assumed to be designed for resilience can in practice act like a single point of failure.
Open standards and interoperable architectures make it easier to move workloads, preserve data in open formats, and switch providers without disruption—key to resilience and cost control. Open ecosystems also accelerate skills development and local capability, helping cultivate talent, build on shared innovations, and tailor solutions to national priorities. Open technologies can help turn sovereignty from an aspiration into an operating model.
Hybrid as a resilience
strategy
The answer is not to retreat from global technology, but to design for flexibility and
control, resulting in sovereignty you can actually prove.
Hybrid, multi-cloud architectures provide that foundation. They allow workloads to move across environments, keep critical systems within defined boundaries, and enable organisations to respond as conditions change.
This is why hybrid cloud is becoming the default model for mission-critical systems. It enables global scale and local control without forcing a trade-off between the two. It helps make resilience a design principle.
This is also where software like IBM Sovereign Core come in — giving organisations control over
where workloads run, how data is protected, and how systems continue to operate under changing conditions.
Observability is essential
Resilience depends on observability — because you cannot protect what you cannot see. Organisations need real-time visibility across applications, infrastructure, and dependencies.
In banking, even a short disruption can halt payments, delay transactions, or prevent customers from accessing accounts. When systems are spread across multiple environments, identifying whether the issue sits within the bank, the network, or an external provider is not always straightforward. Without clear visibility across the full stack, response slows at the moment it matters most.
Without that visibility, response becomes slower and less precise when it matters most.
Beyond infrastructure, build capability
Infrastructure alone does not create sovereignty.
There is a growing misconception that investing in data centres or hardware equates to independence. In reality, sovereignty depends on who can operate, adapt, and recover systems when conditions change. The organisations that succeed will focus as much on capability as they do on technology — building local expertise, maintaining operational control, and ensuring systems can evolve over time.
Without this, infrastructure becomes a dependency rather than a differentiator.
What matters now
Resilience is a strategic capability. And sovereignty is not something that can be achieved through one policy alone. It must be engineered — into architecture, operations, and capability.
In an increasingly uncertain world, the question is no longer whether disruption will occur. It is whether you can operate through it.
WHEN THE CAMERA LIES
Andrea Sorri, Segment Development Manager for Smart Cities – EMEA, Axis Communications, discusses how deepfakes are reshaping enterprise risk and why video authenticity is becoming a critical security challenge
The footage looks real. The voice sounds familiar. The instructions appear to come from someone with the authority to give them. By the time anyone thinks to question what they have seen or heard, the wire transfer has cleared, the announcement has circulated, or the damage has quietly taken root.
Deepfake fraud has undergone a fundamental shift in character. What began as a technically demanding discipline has become, through advances in generative AI, something far more accessible. According to Deloitte, the volume of deepfake content on social media platforms grew by 550 percent between 2019 and 2023.
“The scale of deepfakes as a threat to enterprises is rising every day as attacks become cheaper,
easier and more accessible,” says Andrea Sorri, Segment Development Manager for Smart Cities – EMEA, Axis Communications. “AI has been a key component in making deepfakes easier to generate and disseminate, and AI-generated videos are being used maliciously as part of disinformation campaigns, cyberattacks and attacks against highvalue business targets.”
The technologies enabling these attacks are the same ones organisations are investing in for competitive advantage. “AI and ML have become key enterprise technologies in unlocking the next stages of productivity and digital transformation,” says Sorri. “However, they are also enabling criminals to refine their attacks and produce more convincing malicious content. As enterprises continue to invest in and
scale their AI-powered systems and applications, they need to enhance their ability to protect themselves against actors who seek to use those same applications against them.”
There is a clear logic to why senior leadership has become the preferred impersonation target.
Executives carry institutional authority; their instructions move capital, shift strategy, and trigger operational responses across entire organisations. A fabricated directive from a CFO or CEO does not need to be technically flawless; it only needs to be believable long enough for someone to act on it.
The expansion of hybrid work and enterprise teleconferencing has compounded this. “The abstraction layer that comes with leaders communicating over a video link becomes a point of attack for
criminals looking to manipulate content,” says Sorri. “What this means is that leaders are regarded like any other business asset and are thus subject to the same monitoring and proactive security measures.”
A 2024 Medius survey found that 53 percent of finance professionals had been targeted by deepfake scamming attacks, with 43 percent admitting they had fallen victim, resulting in documented losses and several widely reported cases where employees transferred multi-million dollar sums to fraudsters posing as company leadership.
“Once an attack is carried out, organisations have to move very quickly to avoid escalation or reputational damage,” says Sorri. “They need to conduct internal investigations, assess when, where and how the attack was carried out, identify the vulnerability or point of failure that was exploited by the attackers, and adhere to previously established protocols and procedures.”
Threat beyond the balance sheet
The financial services exposure is well documented, but the use of synthetic media as a disinformation instrument aimed at critical infrastructure draws considerably less scrutiny. “Infrastructure in sectors such as mining, logistics, transportation and urban management can be impacted by disinformation campaigns and content that seeks to cause market unrest,” says Sorri. “At a time when geopolitical tensions are influencing business activity across the Middle East, manipulated video content can cause people, countries and markets to panic.”
The scenarios he describes are not speculative. In sectors tied closely to economic stability, public confidence and national operations, manipulated content has the potential to trigger consequences long before its authenticity is challenged.
“Oil and gas operations can be the victim of AI-generated content that purports to show infrastructure being attacked or destroyed. Another example is video content showing public spaces or urban environments
Authenticating video data and upholding the integrity of video systems is not going to be solved by one standalone product
with high volumes of foot traffic, where disruptions or incidents appear to threaten personal safety,” he says. Content designed not to steal but to destabilise can move markets and erode institutional confidence without a single technical system being compromised in any conventional sense.
The technical response has to start with treating video integrity the way financial systems treat transaction integrity: verified, not assumed.
“Signed video adds cryptographic signatures to a captured video, collecting information from previous frames and signing the information using a private encryption key. Users can then verify the information using that signature and the corresponding public key, thus ensuring the end-
to-end integrity of video data,” Sorri says. “Organisations can also improve their overall resilience through best practices, including protecting video data and using encrypted data transport. Safe data transmission, storage and encryption are how organisations build trust in their video systems.”
In 2021, Axis launched an open-source project for video authentication, prioritising shared standards over proprietary advantage. “By taking an open approach and advocating for shared standards, the industry is able to enshrine complete trust in video surveillance and organisations’ ability to verify content. If one system’s video data cannot be trusted, that distrust can extend to other systems as well,” Sorri says.
The company’s Edge Vault platform embeds cybersecurity at the hardware level, while its browserbased Signed Media Verifier allows organisations to validate footage independently of the camera vendor or system owner.
When a deepfake incident does occur, the first 24 hours determine how much of the damage remains containable. “Organisations need to immediately identify the manipulated content, the elements that feature, including location, personnel and information disseminated, as well as where and how that content originated. Once those details are confirmed, they can take action, issue orders and inform stakeholders, helping to minimise potential fallout,” Sorri says.
“Authenticating video data and upholding the integrity of video systems is not going to be solved by one standalone product. It requires vendors like Axis to rethink their solutions from top to bottom, and by doing so, we address the shared challenge of manipulated content head-on,” he adds.
As the tools to fabricate convincing video and audio become cheaper and more accessible, the gap between organisations that have built verification into their infrastructure and those that have not is becoming the most consequential security divide in the enterprise.
POWERING INTELLIGENCE
By Sami Alfaraj, MEA Head of Technology, Submer
What does it take to build efficient, future -ready AI infrastructure?
The industry is moving rapidly into the inference era, and the urgency is increasing. While opinions differ on how to get there, one point is clear: AI infrastructure must do more with less, and it must do so immediately.
The numbers illustrate the scale of the challenge. AI-driven data centre electricity consumption has grown at approximately 12 percent per year since 2017, more than four times the rate of global electricity demand growth overall. In the region as well, reports confirm that UAE data centre electricity consumption is set to double from approximately 3 TWh in 2025 to over 6 TWh by 2030.
What intelligence per watt really means
The environmental case for efficient AI infrastructure is well established, but framing this purely as a sustainability story misses the point. This is about infrastructure efficiency at system scale, and specifically about maximising intelligence per watt (IPW) across the full lifecycle.
AI is entering an agentic phase of inference, in which models no longer simply respond. They interpret, decide, and act continuously in real time. That shift is fundamentally changing what infrastructure needs to deliver, driving up compute demand and putting sustained pressure on energy, latency and system efficiency across the entire stack. NVIDIA’s model of AI infrastructure identifies five layers, with energy at the foundation, reflecting the fact that a system can only generate as much intelligence as the power available to run it.
That makes energy foundational to IPW. When IPW is higher, AI models deliver the same or better performance while drawing less electricity. This reframes the conversation: AI stops being an energy liability and becomes a driver of efficiency at scale, provided the infrastructure underneath it is designed with that
AI is entering an agentic phase of inference, in which models no longer simply respond. They interpret, decide, and act continuously in real time
outcome in mind. The applications are tangible. Higher IPW AI is better equipped to manage smart grids, reduce industrial waste and optimise resource-intensive systems.
The implications extend beyond operations. In the inference era, infrastructure efficiency shapes capital allocation, how quickly workloads can be deployed, and whether a system can scale without compounding its costs.
The role of edge in AI efficiency
Research indicates that running smaller, specialised AI models locally at the edge can cut energy consumption by 60 to 80 percent compared to large, generalpurpose models operating out of central cloud data centres. This decentralisation produces AI applications that are leaner, faster, and higher in IPW. It strengthens the case for designing data centres around efficient model architectures and purpose -fit hardware, rather than simply scaling existing infrastructure. However, the efficiency question cannot be reduced to a binary choice between centralisation and edge deployment. Energy is only part of the picture. True infrastructure efficiency also encompasses how materials are sourced, how capacity is planned and how lifecycle decisions are made over time. A genuinely sustainable data centre is one that compounds operational gains, each improvement in efficiency feeding into lower energy use and, in turn, higher IPW.
Translating the IPW imperative into infrastructure design
Moving into the inference era of AI highlights a fundamental challenge
in the design of data centres: Aircooled data centres were designed for an era of batch compute processing, not agentic AI. The more utilisation and rack density increases, so do inefficiencies in the form of increased energy consumption, water usage, and accelerated hardware lifecycles creating additional costs and carbon emissions.
Solving this problem requires a holistic approach to the infrastructure stack rather than a series of incremental improvements in an architecture designed for a different use case.
One such approach gaining traction is the adoption of liquidcooling technologies and modular architecture. By adopting liquidcooling in the architecture of a data centre, the thermal cap can be overcome, resulting in high compute density at a reduced energy expense. Additionally, by incorporating a modular approach, infrastructure need not go through complete replacements due to hardware updates and thus eliminates unnecessary expenses.
These tangible results can be quantified by looking at the following case study; Submer’s existing infrastructure assets have seen energy savings amounting to 913.68 GWh, water savings of 3,653.95 million litres, and CO2 equivalent emissions savings totalling 323,110 tones. These figures are derived from full lifecycle impact rather than point efficiency alone, making them particularly relevant when assessing the long-term consequences of infrastructure decisions made today.
The implication for operators planning AI infrastructure is significant: efficiency is not a feature to be added later; it is an architectural condition to be established at the outset. As AI workloads become as operationally critical as power or connectivity, the infrastructure supporting them will need to meet the same standard, delivering more intelligence per watt, consistently and at scale.
TEST OF COMMAND
By Diego Arrabal, Vice President, Eastern Europe, Middle East and Africa, Check Point Software Technologies
There is a noticeable shift happening across the GCC when it comes to cyber resilience. For years, it was treated largely as a technical domain, something handled within IT or security teams. That is no longer the case.
Today, resilience is being tested at a different level. It is being tested in how organisations respond under pressure, how decisions are made when information is incomplete and how well the business continues to operate when disruption does not follow a predictable path.
Most organisations across the GCC have already invested heavily in strengthening their environments. Cloud adoption has accelerated, infrastructure has been modernised and security capabilities have improved. These are important steps and they have raised the overall baseline.
But recent developments have exposed a more difficult question. Are organisations prepared for how disruption actually unfolds?
In practice, disruption rarely appears as a single event. It builds over time and often comes from multiple directions. Operational strain increases, teams are required to move faster and dependencies on external platforms and partners become more visible. What initially appears manageable can quickly become more complex when several issues overlap.
Recent events in the GCC have brought this into sharper focus. Disruption affecting cloud and data centre environments in the region has shown how physical incidents can quickly impact digital services. In some cases, organisations have had to reassess workload placement and continuity strategies while recovery efforts were still ongoing, reflecting how dynamic the operating environment has become. What these situations highlight is not just the disruption itself, but the importance of adaptability. Organisations that are able to respond quickly, maintain visibility and adjust their operations in real time are far better positioned to manage the impact. It reinforces a simple but important point: resilience is not defined only by where systems are hosted, but by how effectively organisations can adapt when conditions change.
At the same time, organisations across the GCC are dealing with a rise in opportunistic cyber activity. Phishing campaigns are being adapted to reflect real-world developments. Internet-facing systems are being probed more aggressively. In some cases, the intent is not subtle intrusion, but disruption, creating noise, slowing operations and stretching response teams.
This combination of operational and cyber pressure is where resilience is truly tested.
What becomes clear in these situations is that the biggest challenges are not always technical. Many organisations have strong controls in place. The difficulty often lies in how quickly the organisation can interpret what is happening and act on it.
Identity continues to play a central role. Compromised credentials and misuse of legitimate access remain among the most common ways attackers gain entry. This becomes more pronounced when employees are working under pressure and reacting to fast-moving situations. There is also a growing exposure that is still underestimated. Connected devices such as cameras,
This combination of operational and cyber pressure is where resilience is truly tested
building management systems and other internet-facing assets are now part of everyday operations across the GCC. They are often not managed with the same level of attention as core IT systems, yet they form part of the same environment.
Recent observations by Check Point Research have highlighted increased attempts to identify and access internet-connected cameras across parts of the Middle East, during periods of heightened regional tension. This activity has focused on widely deployed devices exposed to the internet or running known vulnerabilities, making them easier to identify and access at scale.
The lesson here is not that organisations need to become more complex. If anything, the opposite is true.
Organisations that navigate disruption well tend to focus on a small number of fundamentals and execute them consistently. This starts with a prevention-first mindset, reducing risk before it can be exploited rather than relying solely on detection after the fact. It requires a clear view of what is exposed to the internet and disciplined efforts to reduce that exposure. Identity is treated as a critical control point, not just a user convenience and connected devices are kept within defined boundaries so they do not become entry points into the wider environment.
Equally important is preparation. Not in the form of static plans, but in knowing how decisions will be made when pressure builds. When multiple systems are affected, clarity becomes more valuable than completeness. Priorities need to be clear and the ability to act quickly often determines the outcome.
This is where cyber resilience becomes a leadership issue in the most practical sense.
Technology enables resilience, but it does not replace judgement. It does not resolve competing priorities and it does not provide clarity in uncertain situations. Those responsibilities sit with leadership. For many organisations in the GCC, the next phase is not about increasing investment. The foundations are already in place. The real question is whether those foundations hold when disruption is not contained, when signals are unclear and when decisions have to be made quickly.
The organisations that manage this well are not necessarily those with the most advanced environments. They are the ones where accountability is clear, responses are coordinated and the business continues to operate even when conditions are far from stable.
That is the point at which cyber resilience stops being a capability and becomes a reflection of leadership.
PARTNERS IN DEFENCE
CSunil Paul, Co-Founder and MD, Finesse, examines the growing cybersecurity pressures facing regional enterprises and the strategic role MSSPs now play in strengthening organisational resilience
ybersecurity teams across the Middle East are operating under a level of pressure that would have seemed extraordinary only a few years ago. The frequency of attacks has increased sharply, but the larger concern is how persistent and coordinated many of these campaigns have become.
Check Point Research reported that organisations globally faced an average of 2,086 cyber-attacks per week in February 2026, ranging from ransomware and credential theft to DDoS attacks and attempts to exploit exposed cloud and edge infrastructure.
The current regional conflict has coincided with a sharp increase in coordinated cyber campaigns targeting organisations across the Middle East.
The UAE Cyber Security Council has also warned of a sharp rise in phishing and ransomware activity across the country. According to the Council,
more than 75 per cent of cyber breaches originate from phishing emails or fraudulent messages, while ransomware attacks in the UAE rose by 32 per cent. The nature of these threats is evolving as well. Threat actors are using increasingly convincing impersonation attempts, AI-generated content, and automated methods capable of exploiting vulnerabilities within hours of disclosure.
This is unfolding at a time when enterprises are managing highly complex digital environments shaped by cloud adoption, remote connectivity, AI integration, and interconnected supply chains. Security teams are expected to monitor threats continuously while also handling compliance obligations, identity security, vulnerability management, governance frameworks, and incident response
readiness. Even well-resourced organisations are struggling to maintain the visibility and consistency required across rapidly evolving environments.
The role of the Managed Security Services Provider has therefore become far more strategic. Organisations are no longer simply looking for outsourced monitoring capabilities. They are seeking security partners that can strengthen resilience, improve response readiness, and support continuity in environments where cyber risks no longer follow predictable patterns.
A mature MSSP contributes far more than a traditional SOC function. Effective partnerships combine threat intelligence, managed detection and response, cloud and identity security expertise, governance support, and continuous visibility across enterprise infrastructure. Equally important is the ability to reduce complexity. Many organisations today are managing fragmented security stacks that generate large volumes of alerts while still leaving critical blind spots.
At Finesse, we have seen this shift accelerate significantly across sectors including banking, healthcare, government, and energy. Conversations with enterprise leaders increasingly centre on resilience, readiness, and response capability rather than standalone security tools. There is growing recognition that cybersecurity can no longer operate as an isolated IT function. It is now closely tied to business continuity, trust, regulatory accountability, and organisational stability.
The time between vulnerability disclosure and exploitation continues to narrow, leaving very little room for delayed action. Organisations need the ability to detect abnormal activity early, investigate efficiently, and contain threats before disruption spreads across systems, users, or third-party connections. As cyber threats become more persistent and unpredictable, partnering with an experienced MSSP is increasingly becoming part of a broader strategy designed to maintain continuity under pressure.
DELL:
Pro 7
Dell Technologies has introduced the Dell Pro 7 series in 13-inch and 14-inch laptop and 2-in1 configurations, built with an aluminium chassis and redesigned form factor that is up to 18% thinner than the previous generation.
The 2-in-1 models feature an edge-to-edge Gorilla Glass touchscreen with brightness up to 500 nits. Display options include standard LCD and optional OLED panels for higher contrast and colour accuracy.
Premium configurations support up to 8MP cameras for higherresolution video conferencing and imaging. The systems also include mini-LED backlit keyboard
technology, designed to reduce keyboard power consumption while maintaining illumination.
The lineup is designed around portability-focused dimensions while supporting enterprise hardware configurations for business workloads. Convertible models support touch interaction and flexible usage modes for tablet and laptop operation.
The systems are available with multiple configuration options allowing variations in display technology, camera specifications, and keyboard power efficiency features.
BENQ: JRD280UG
BenQ has introduced the RD280UG programming monitor with a 28-inch 4K+ (3840 × 2560) panel using a 3:2 aspect ratio to increase vertical workspace for coding.
The display supports a 120Hz refresh rate for smoother scrolling and reduced motion blur, along with a 2000:1 contrast ratio, enhanced by local and pixel-level contrast optimisation for improved text clarity. It uses a Nano Matte panel to minimise glare and reflections.
The monitor includes multiple Coding Modes (Dark Theme, Light Theme, Paper Colour), which adjust contrast and visual tuning for different development environments. It also features USB-C connectivity with up to 90W power delivery, enabling single-cable power, data, and display output.
Additional hardware features include a built-in KVM switch for controlling multiple systems, MoonHalo rear bias lighting, and Night Hours Protection for lowbrightness viewing. Ergonomics include a +90° rotating hinge with auto pivot for portrait and landscape switching.
Software support is provided via Display Pilot 2, compatible with macOS, Windows, and Linux, with quick-access controls for display and eye-care settings.
VIVO: X300 ULTRA
vivo has introduced the X300 Ultra with a multi-camera system built around the ZEISS Master Lenses Collection, comprising 85 mm, 35 mm, and 14 mm prime lenses, each paired with high-resolution sensors.
The 85 mm telephoto camera uses a 200 MP sensor, with gimbal-level OIS (3° stabilisation) and 60 fps AF tracking for moving subjects. The 35 mm camera integrates a 1/1.12-inch Sony LYTIA 901 sensor with 200 MP output, while the 14 mm ultra-wide uses a large-aperture sensor for wide-field capture.
Telephoto capability is extended via optional 200 mm and 400 mm equivalent ZEISS telephoto extenders, with the 400 mm module using a multi-element optical design and supporting high-resolution output.
The device supports multi-focal 4K 120 fps 10-bit video, including Log and Dolby Vision formats, across all rear cameras. Imaging is supported by a 5 MP multispectral sensor with 12 colour channels for per-pixel light analysis and colour processing.
It features a 2K display with up to 4500-nit peak brightness, powered by Snapdragon 8 Elite Gen 5, with a 6600 mAh battery, 100W wired and 40W wireless charging, plus IP68/IP69 protection and ultrasonic fingerprint scanning.