JANUARY 2026 / CXO DX
1
2
CXO DX / JANUARY 2026
» EDITORIAL
A MATURING PHASE OF TECHNOLOGY ADOPTION Conversations with industry leaders and technology decision-makers indicate that enterprise technology adoption is entering a more mature phase. What once was driven mainly by speed and scale is now being reshaped by intent, control, and accountability. For much of the last decade, success in enterprise IT was often measured on the basis of the number of platforms deployed, tools added, and pilots launched. Speed itself became a metric. But speed is not necessarily progress if it comes without direction. Today, it seems that boards and CEOs are asking harder questions. They want to be sure that the technology will deliver measurable outcomes, reducing costs, improving decisions, or customer experience, and so on and so forth. Now, there is a significant shift from experimentation to execution. AI, cloud, automation, analytics are not new anymore. What is new is the expectation and requirement to make them work together, securely, and at scale. AI is no longer a side project for innovation teams. It is moving into the heart of operations, finance, supply chain, service, and compliance. But as AI becomes more powerful, it also becomes more dangerous if left unmanaged. The same systems that increase productivity can amplify risk if identity, access, and governance are not designed properly. On the cloud front, enterprises are learning that not every workload belongs in the same place. Cost, performance, regulation, and data gravity are forcing more thoughtful choices. And so the result is a more realistic future hybrid by design, and cloud-smart. Security is also being redefined. It is no longer just about building stronger walls. In a world of hybrid work, outsourced operations, APIs, and now AI agents, trust is about identity and behavior. Finally, digital transformation is no longer a program that can be launched, executed, and completed. It is becoming a way of running the enterprise. The future will not belong to the organizations that adopt the most technology, but to the ones that run it best.
R. Narayan
narayan@leapmediallc.com Mob: +971-55-7802403
SAUMYADEEP HALDER Co-Founder & MD
saumyadeep@leapmediallc.com Mob: +971-54-4458401
...................
RAMAN NARAYAN Co-Founder & Editor in Chief
...................
Editor in Chief, CXO DX
MALLIKA REGO Co-Founder & Director Client Solutions
mallika@leapmediallc.com Mob: +971-50-2489676
.........................................................................................................................................................................................................
Ali Raza Designer
Nihal Shetty Webmaster
PUBLISHED BY - Leap Media Solutions LLC
REGISTERED OFFICE: Office 10, Sharjah Media City | www.cxodx.com JANUARY 2026 / CXO DX
3
» CONTENTS INTERVIEW
14 » OPERATIONALIZING AI FOR THE ENTERPRISE
Manasi Vartak, Chief AI Architect & Vice President, Product Management at Cloudera discusses hybrid AI-anywhere strategies at Cloudera, workload portability, AI model training, and the role of low-code platforms in accelerating enterprise adoption of AI.
16 COVER STORY
16 » OUTLOOK 2026: THE ENTERPRISE IN TRANSITION Enterprise technology is entering a more mature phase. What was once driven mainly by speed and scale is now being reshaped by intent, control, and accountability.
NEWS INSIGHT
11 » GENETEC RELEASES 2026 GLOBAL STATE OF PHYSICAL SECURITY REPORT 12 » MILESTONE LAUNCHES VISION LANGUAGE MODEL (VLM) 13 » NCSC OF THE KINGDOM OF BAHRAIN AND SANDBOXAQ PARTNER TO ENABLE A QUANTUM-SAFE ECONOMY 4
CXO DX / JANUARY 2026
20 » ENABLING HIGH-PERFORMANCE DATACENTRES Khalid Aljamed, General Manager – Middle East, Turkey & Africa at Submer, discusses the rapid growth of AI-driven data center investments across the region, the rise of sovereign AI infrastructure, and the shift toward liquid-cooled, high-density data centers
COLUMN 24 » ONE WINDOW TO RULE THEM ALL Unified service platforms are more than digital conveniences—they’re the new governance architecture for a connected era, writes Yasir Naveed Riaz, Project leader digital transformation at Ports, Customs & Free Zone Corporation
26 » INSIDE THE NEW CYBER REALITY Ziad Nasr, General Manager, Acronis Middle East discusses how 2026 will redefine power, crime, and defence in a turbulent digital world
28 » WHY DATA PORTABILITY IS THE FOUNDATION OF SOVEREIGN CLOUDS Michael Cade, Global Field CTO, Veeam discusses why enterprises need to ensure that data portability is enshrined in their data resilience planning.
30 » FROM HYPE TO HARD TRUTHS Sarah Maina, Regional Manager, Middle East & France, AppsFlyer discusses trends that will redefine marketing in 2026
32 » THREE WAYS ORGANISATIONS CAN REDUCE RISK ON THEIR AI JOURNEY James Hendergart, Senior Director, Technology Research, F5 discusses three practices that will help de-risk the plunge into generative and agentic AI.
33 » CYBER MATURITY IS ONLY AS STRONG AS YOUR WEAKEST LINK
Gregg Petersen, Regional Director for the Middle East, at Cohesity says that the leaders of 2026 will be those who recognize that true resilience is built collaboratively, not defensively
34 » POST-QUANTUM CRYPTOGRAPHY: THE STATUS QUO AND NEED FOR ACTION Bas Westerbaan, Principal Research Engineer, Cloudflare says regardless of when Q-Day occurs—2034 or 2050—most experts agree it will come too soon for organisations that delay preparation
REGULARS
06 » NEWS 36 » TECHSHOW 38 » TRENDS & STATS
JANUARY 2026 / CXO DX
5
» NEWS
EDARAT GROUP AND DELL TECHNOLOGIES SIGN MOU TO EXPAND MULTICLOUD, CYBER RESILIENCE AND EDGE CAPABILITIES The partnership focuses on developing innovative client, edge, multicloud and cyber resilience solutions to support the Kingdom’s move toward a more digitally empowered economy. client, edge, multicloud and cyber resilience solutions to support the Kingdom’s move toward a more digitally empowered economy.
Dell Technologies and Edarat Group have signed a Memorandum of Understanding (MoU) to advance multicloud, cyber resilience and edge capabilities across Saudi Arabia. The agreement, signed during the annual Dell Technologies Forum in Riyadh, between Mohammed Talaat, VP, SENAL at Dell Technologies and Jihad Nehme, Chief Business Development Officer at Edarat Group, focuses on developing innovative
the Saudi market enabling broader access to modern cloud solutions across multiple sectors.
Edarat Group is a leading data center, cloud and technology services provider in Saudi Arabia offering advanced cloud architecture, data center engineering, co-location and managed services. By combining Edarat Group’s local expertise with Dell’s global capabilities, the collaboration will help organizations improve service delivery and enhance productivity.
Mohammed Talaat, VP, SENAL at Dell Technologies, said, “Our collaboration with Edarat Group advances our commitment to supporting Saudi Arabia’s digital transformation. By strengthening multicloud and edge environments, we are creating opportunities for organizations to operate with greater agility and innovation in line with the Kingdom’s vision for a digitally enabled future.”
Under the MoU, both parties will work together to identify and define the solutions needed to strengthen and secure multicloud infrastructure and emerging technologies across the Kingdom. The agreement aims to deliver greater scalability for organizations across the country and expand the reach of Dell’s multicloud offerings in
Jihad Nehme, CBDO at Edarat Group, said, “We are proud to work with Dell Technologies in supporting the Kingdom’s digital transformation agenda. This MoU reflects our shared mission to deliver advanced technologies that raise operational efficiency and help organizations thrive in an increasingly multicloud environment.”
ZOHO LAUNCHES SOLUTIONS FOR ENTERPRISE BILLING AND SPEND MANAGEMENT The solutions help UAE finance teams boost revenue, control spend, streamline procurement, and gain full financial visibility Zoho Corporation has announced the launch of Zoho Billing Enterprise Edition, an advanced billing solution for large enterprises, and Zoho Spend, an industry-first spend management solution that includes payroll. The two new solutions help finance teams in the UAE and wider region monetise with modern revenue strategies, improve spend controls, streamline procurement, and gain end-toend financial visibility. "As part of our transnational localism strategy, of being globally connected and locally rooted, we have been launching solutions tailor-made for the region," said Hyther Nizam, President, Zoho MEA. "As enterprises across the UAE scale in complexity and ambition, finance leaders are under pressure to move beyond fragmented systems and gain real-time, end-toend visibility across revenue and spend. With the launch of Zoho Billing and Zoho Spend, we are addressing a critical gap by bringing billing, payroll, procurement,
6
CXO DX / JANUARY 2026
and expense management together on a single, integrated platform built for scale, compliance, and agility. These solutions support the UAE’s vision for a digitally enabled, globally competitive business ecosystem.” Zoho Billing Enterprise Edition helps businesses gain high flexibility to monetise through any modern revenue strategy, with the scalability to handle any volume and solve the most complex billing scenarios. The enterprise billing solution gives businesses full control over what they charge (products, services, or projects), how they charge (standard, volume/ tiered, or consumption models), and when they charge. The solution offers 15 country-specific editions that are compliant with the regional tax regulations, including UAE's VAT laws. Zoho Spend, an all-in-one solution, unifies every major spend category—payroll, procurement, Accounts Payable (AP) au-
Hyther Nizam
President MEA, Zoho Corporation tomation, corporate travel, and employee expense—into a single platform, delivering holistic visibility and tighter spend controls. The comprehensive dashboard provides a consolidated view into each of these critical areas, allowing finance and business leaders to take control of their budgets, strengthen governance, and curb maverick spend, turning spend management into a strategic advantage.
» NEWS
NUTANIX EXPANDS CAPABILITIES TO HELP CUSTOMERS BUILD AND OPERATE DISTRIBUTED SOVEREIGN CLOUDS Enhancements to the Nutanix Cloud Platform empower customers to maintain security, control, and resilience across distributed environments Nutanix, a leader in hybrid multicloud computing, announced new capabilities in its Nutanix Cloud Platform (NCP) solution designed to give organizations greater flexibility to deploy and govern their infrastructure across distributed environments running traditional, modern, and AI applications. New capabilities in NCP give customers more choice in how they run and govern infrastructure – across their own environments and with cloud providers that offer sovereign services – enabling greater focus on resilience, security and control, and global management. These updates also strengthen the platform’s ability to support secure, governed cloud native and AI workloads through new security capabilities in the Nutanix Kubernetes Platform (NKP) and Nutanix Enterprise AI (NAI) solutions. NCP now provides orchestrated lifecycle management of multiple dark-site environ-
ments, along with on-premises deployment options for governance and control planes. The Nutanix Central solution, which simplifies distributed cloud management, can now run in customer controlled on-premises environments. New capabilities for NCP strengthen resilience by enabling customers to maintain application availability across sites and regions during outages, essential for sovereignty-aligned environments that must avoid single-site or single-vendor dependency and manage risk of exposure to actions by foreign jurisdictions. NCP now offers stronger management capabilities that streamline how distributed environments are deployed and operated. “Across the Middle East, we are seeing a decisive shift toward digital sovereignty as governments and enterprises modernize critical services, accelerate AI adoption, and strengthen national data strategies,”
Raif Abou Diab
General Manager - South Gulf & Sub-Saharan Africa at Nutanix said Raif Abou Diab, General Manager - South Gulf & Sub-Saharan Africa at Nutanix. “The latest enhancements to the Nutanix Cloud Platform directly answer these regional priorities by enabling organizations to operate highly secure, compliant, and resilient sovereign cloud environments—whether on-premises, in disconnected sites, or across trusted cloud providers—while retaining the operational simplicity needed to scale with confidence.”
VEEAM COMPLETES SECURITI AI ACQUISITION Creates unified and trusted Data Platform for accelerating safe AI at scale try’s most advanced data security, governance and AI Trust platform. Together, they form the first unified and trusted Data Platform: one system to see, secure, govern, and recover all data at AI speed.
Veeam Software, a global leader by market share in Data Resilience, announced the completion of its $1.725 billion acquisition of Securiti AI, the recognized leader in Data Security Posture Management (DSPM), privacy, governance and AI trust. The combination brings together the world’s leading Data Resilience platform – trusted by over 550,000 customers and 82% of the Fortune 500 – with the indus-
“AI investment is exploding, yet nearly 90% of enterprise initiatives fail because the data powering AI cannot be trusted,” said Anand Eswaran, CEO at Veeam. “Safe AI at scale requires more than great models – it demands trusted, governed, recoverable data. Veeam already leads the world in Data Resilience – unmatched in share, global footprint and innovation. By combining that foundation with Securiti AI’s leadership across DSPM, privacy, governance, and AI trust, we are delivering the first platform that can see everything, secure everything, and recover anything across the entire data estate.” AI has transformed previously dormant unstructured data into a source of competitive advantage - but also into a fast-moving, high-stakes risk surface. Fragmented security, governance, and protection tools
are too slow for machine-speed data access and AI agent behavior. Together, Veeam and Securiti AI will give customers: • Unified visibility across structured and unstructured, primary and secondary data • Continuous governance and compliance with identity-aware runtime enforcement • Zero-trust security and best-in-class resilience across production and backups • Guaranteed clean recovery of data, pipelines, models, and agents • Trusted data pipelines to safely accelerate AI adoption enterprise-wide This is resilience, security, governance, and privacy united to make AI safe, compliant, and auditable at scale. Veeam will welcome 600 Securiti AI employees, expanding its global expertise in AI security, DSPM, privacy engineering, and compliance. Rehan Jalil, Securiti AI founder and CEO, joins Veeam as President of Security and AI. JANUARY 2026 / CXO DX
7
» NEWS
ENTERPRISES ARE UNDERACHIEVING ON AI Mike Capone previews Qlik’s 2026 outlook on data, analytics and AI Qlik, a global leader in data integration, data quality, analytics, and artificial intelligence (AI), shared an early look at its 2026 outlook on data, analytics and AI, with CEO Mike Capone arguing that the debate about whether AI “delivers value” is asking the wrong question. The real problem, he says, is that most organizations are still dramatically underachieving on AI, with only small islands of value emerging in a sea of experimentation, pilots and noise. “Boardrooms keep hearing that only a tiny fraction of enterprises are truly ‘AIready,’” said Mike Capone, CEO of Qlik. “But walk the halls of any large company and you’ll find people quietly using AI in documents, slides and code every day. That’s real productivity. Right now, it’s dark matter. It shapes outcomes, but it’s invisible to the P&L, rarely based on complete data, and entirely outside governance.”
Recent research from Boston Consulting Group found that only around 5% of enterprises are structurally prepared for an AI future, even as generative tools are in everyday use at the edges of the business. Qlik’s analysis of customer environments shows the same paradox, a growing pool of “stealth AI value” that rarely survives the jump into audited metrics or risk models.
Mike Capone CEO, Qlik
Capone believes 2026 will be the year leading enterprises close that gap. Instead of asking which single model, cloud or platform to bet on, he argues that organizations should assume they will change those choices repeatedly and design their architecture so they can swap models and tools without rewriting their business logic or losing control of their data.
rebuild your operating model every time the market swings. The companies we see winning are practicing controlled decentralization: they keep definitions, governance and sovereignty non-negotiable, and push experimentation and automation out to the teams closest to the work.”
“The old pendulum between tight central control and chaotic self-service is breaking down,” Capone added. “You can’t
In parallel, Qlik expects intelligence, itself, to start behaving more like a utility than a feature.
ASUS HIGHLIGHTS AI-DRIVEN WORKPLACE SOLUTIONS AT EXPERT CONNECT EVENT The event brought together end-users for a look at current workspace solutions and a peek at upcoming products. ASUS recently hosted Expert Connect, an AI-driven workspace event that highlighted the company’s ExpertBook lineup. Select end-users from the healthcare, BFSI, education, and enterprise sectors attended the event, held at Topgolf Dubai. The guests got a chance to experience the latest product offerings from ASUS, including a preview of their 2026 lineup. The location provided a casual setting for attendees to experience ASUS Expert Connect while networking over a game of golf. “ASUS Expert Connect was held to engage with our target audience and show them how our devices can streamline their workflows for better efficiency. We were able to share the benefits of our latest commercial offerings and a preview of our next generation of products we plan to launch in 2026,” said Tolga Özdil, Regional Commercial Director, Middle East, Turkey & Africa (META) at ASUS. “Topgolf Dubai was the perfect venue for this as it offered a fun yet professional atmo-
8
CXO DX / JANUARY 2026
sphere.” The event focused on moving interest beyond just device specifications and towards real value delivered by the ExpertBook lineup. End-users were able to explore various use cases through product demos and business sessions. It aims to raise awareness of the company’s commercial devices and gather feedback on future campaigns and roadmaps. The ASUS ExpertBook series offers AI-powered features in a compact and durable business laptop. Powered by the latest Intel Core Ultra 7 processor, these notebooks include a dedicated 47 TOPS NPU (Neural Processing Unit). This enables the laptop to handle AI tasks locally without connecting online. With AI processing taking place on-device, battery
life remains efficient and ensures long usage without any performance issues. The ExpertBook series also stands out with its minimalist and lightweight design, making it the ideal device for any on-the-go professional. Expert Connect centered on ASUS’s mission to deliver tailored AI-ready devices in line with the UAE National Strategy for Artificial Intelligence 2031.
» NEWS
CONFLUENT LAUNCHES CONFLUENT PRIVATE CLOUD IN MIDDLE EAST The company also unveiled new capabilities in Tableflow, expanding real-time data integration for AI and analytics Confluent, Inc. the data streaming pioneer, announced the launch of Confluent Private Cloud, the simplest way to deploy, manage, and govern streaming data on private infrastructure. Confluent Private Cloud solves the challenge of scaling Apache Kafka on-prem in heavily regulated industries by bringing Confluent’s most advanced cloud-native features behind the firewall. Now generally available in the region, Confluent Private Cloud helps organisations scale faster, adapt quickly, and make decisions with real-time confidence. “Real-time data is the key to unlocking business growth. It’s what helps organizations modernize and stay ahead,” said Shaun Clowes, Chief Product Officer at Confluent. “The challenge is that strict regulations can make it harder to scale data streaming across the business. With Confluent Private Cloud, you get the best of both worlds—the agility and simplicity of
the cloud with the security and control of your own private infrastructure.” Confluent Private Cloud delivers the automation, performance, and governance enterprises need to run data streaming at scale on their own infrastructure. Designed for large scale deployments or customers in regulated industries, it reduces the operational burden of managing Kafka on-premises with centralized governance, unified cloud compliance and high-speed streaming as usage grows. This means teams can spend less time troubleshooting and more time building real-time applications and services that move the business forward.
Shaun Clowes
Chief Product Officer, Confluent
bleflow a fully managed, end-to-end solution that connects operational, analytical, and artificial intelligence (AI) systems across hybrid and multicloud environments..
Confluent also announced major enhancements to Confluent Tableflow, including the general availability of Delta Lake and Databricks Unity Catalog integrations, as well as early access support for Microsoft OneLake. These advancements make Ta-
These updates deliver a unified solution that connects real-time and analytical data with enterprise governance. Now, it's easier to build real-time AI and analytics that propel businesses ahead of their competition.
SENTINELONE AND RILIAN TECHNOLOGIES FORGE STRATEGIC PARTNERSHIP This partnership strengthens both companies’ commitment to delivering advanced cybersecurity capabilities and empowering organizations across the Middle East SentinelOne , a leader in AI-native cybersecurity, has announced a strategic partnership with Rilian Technologies to accelerate the delivery of advanced cybersecurity operations and AI-driven defense capabilities across the Middle East. This collaboration combines SentinelOne’s industry-leading autonomous cybersecurity platform with Rilian’s mission to accelerate secure technology adoption, enabling governments, enterprises, and critical industries to deploy, operate, and optimize next-generation security programs at scale.
formation Assurance and Data Protection laws in the UAE and national cybersecurity guidelines in Saudi Arabia and Qatar are reshaping compliance requirements for both public and private entities.
As digital transformation, AI adoption, and cloud modernization continue across the Middle East, organizations face increasingly complex threats; from nation-state attacks to ransomware, supply-chain disruptions, and AI-enabled social engineering. Critical sectors such as energy, transportation, finance, and government require modern protection models that deliver real-time detection, automated response, and sustained operational resilience. At the same time, new regulations, including In-
“By combining SentinelOne’s AI-native cybersecurity platform with Rilian’s proven capabilities in accelerating OT technology adoption, implementation, and regional delivery, we will help the region build autonomous, resilient cyber defense programs that stay ahead of emerging threats.”
“As organizations across the Middle East modernize at speed, they need partners who can deliver both world-class technology and deep regional services expertise,” said Meriam ElOuazzani, Regional Senior Director, Middle East, Turkey and Africa at SentinelOne.
Through this partnership, SentinelOne and Rilian Technologies plan to deliver fullstack cybersecurity services, including advanced deployment, integration, SOC
enablement, and operational technology (OT) security programs to help customers modernize and secure their platforms end-to-end. The partnership also expands support for air-gapped and mission-critical environments, enabling operators of critical services can deploy advanced security controls without compromising isolation or operational continuity. Together, they align global innovation with regional priorities to enhance data control, strengthen regulatory compliance and protect the critical infrastructure that underpins economic diversification and long-term national competitiveness. JANUARY 2026 / CXO DX
9
» NEWS
GROUP-IB AND VAS INTEGRATED SOLUTIONS PARTNER TO ENHANCE CYBERSECURITY IN KSA The partnership will establish a framework for joint market development, partner enablement, and awareness initiatives
Group-IB, a leading creator of cybersecurity technologies to investigate, prevent, and fight digital crime, and VAS Integrated Solutions, a value-added distributor (VAD) of leading brands, providing integrated IT solutions to the various market verticals, have signed an MoU to explore strategic cooperation and future channel-led expansion opportunities across the Kingdom of Saudi Arabia. The cooperation establishes a framework
for joint market development, partner enablement, and awareness initiatives, grounded in Group-IB’s adversary-centric and predictive approach to cyber threat and fraud intelligence. Through its Digital Crime Resistance Center (DCRC) model, Group-IB combines on-the-ground expertise in the Middle East and Africa with its global threat intelligence, and investigative capabilities, enabling organizations in Saudi Arabia to anticipate, prevent, and respond to complex cyber and fraud threats with local context and rapid response. Leveraging VAS’s local ecosystem, partner network, and market reach, the collaboration supports the effective delivery of these capabilities to organizations across the Kingdom, strengthening cybersecurity resilience in alignment with Saudi Arabia’s digital transformation priorities. Mohammad Flaifel, Regional Sales Director of KSA and Türkiye at Group-IB, said,
AMIVIZ PARTNERS WITH QUILRAI TO STRENGTHEN RESPONSIBLE AI ADOPTION QuilrAI is an autonomous decision engine that protects every agentic and human interaction
AmiViz has announced a new strategic partnership with QuilrAI, a pioneering provider of AI security technologies. This collaboration reinforces AmiViz’s core philosophy of promoting secure and responsible AI adoption in the region as enterprises increasingly integrate AI into mission-critical operations. AI-driven environments are becoming attractive targets for sophisticated cyber threats, from model manipulation to data
10
CXO DX / JANUARY 2026
poisoning and unauthorized inference attacks. Through this partnership, AmiViz will introduce QuilrAI’s advanced AI security portfolio to customers and channel partners across the Middle East, empowering them with tools to safeguard AI models, protect sensitive training data, and ensure trustworthy AI outputs. “At AmiViz, we recognize that AI innovation must be matched with equal advancements in security,” said Ilyas Mohammed, COO of AmiViz. “Our partnership with QuilrAI reflects our commitment to strengthening the region’s cybersecurity posture by bringing modern, AI-focused protection to enterprises as they accelerate their digital evolution.” QuilrAI’s solutions will be delivered
“This partnership represents an important step in strengthening our long-term channel strategy in Saudi Arabia and reflects our dedication to building a safer and more secure digital environment. By working closely with VAS, we aim to expand our footprint in the Kingdom, support our partners, and better serve customers with advanced cyber and fraud intelligence capaAnand Eswaran bilities CEO, tailored Veeam to the evolving local threat landscape.” Bilal Abdulrahman, Country Manager, KSA & GCC, VAS Integrated Solutions, said, “We are proud to partner with GroupIB to enhance cybersecurity awareness and tackle critical digital challenges across the Kingdom. Together, we aim to empower businesses with the tools and knowledge needed to stay ahead in an evolving threat landscape, reinforcing our commitment to impactful collaboration and advanced solutions across the wider region.”
through AmiViz’s strong regional ecosystem, supported by comprehensive pre-sales resources, technical enablement programs, and value-added services. Both companies will also collaborate on industry awareness initiatives, including workshops, demonstrations, and partner training sessions designed to elevate AI security readiness. “GenAI is now a pervasive enterprise reality, with 45% of organizations deploying solutions despite only 4% reporting high security confidence. This risk gap is driven by decentralized adoption, which has moved faster than the implementation of formal IT governance and security controls.” said Vidit Arora, CEO of QuilrAI. “QuilrAI is an autonomous decision engine that protects every agentic and human interaction. QuilrAI looks at content, context and intent of any action or data movement and makes intelligent decisions while coaching users.” he said. “AmiViz’s leadership in the cybersecurity distribution landscape makes them an ideal partner to expand QuilrAI ’s presence and support customers in managing emerging AI threats.” This partnership represents a significant step in AmiViz’s mission to help organizations adopt AI safely and confidently, ensuring resilience in the face of rapidly evolving cyber risks.
» NEWS INSIGHT
GENETEC RELEASES 2026 GLOBAL STATE OF PHYSICAL SECURITY Physical security has evolved into a strategic business function, strengthening IT collaboration and decision-making Genetec Inc. (“Genetec”), a global leader in enterprise physical security software released its sixth annual State of Physical Security report. Based on insights from over 7,300 physical security leaders worldwide (including end users, channel partners, systems integrators, and consultants), the report shows that physical security is playing a broader strategic role within organizations. The findings highlight closer collaboration across departments and greater interest in technologies that support better operational awareness and decision-making. Physical security is evolving from protection to empowering business outcomes The report shows a shift in how physical security systems are deployed and valued. They are no longer viewed only as a protection layer, and instead, are becoming an enterprise function that contributes to broader organizational goals. “As it becomes more tightly woven into the broader fabric of the enterprise, security is emerging as a genuine enabler of business outcomes—helping organizations work more cohesively, respond more effectively, and stay focused on long-term goals,” said Christian Morin, Vice President of Product Engineering at Genetec Inc. Modernization is accelerating as demand for unified systems grows Survey findings indicate that organizations are prioritizing modernization of their physical security systems to support this shift toward stronger collaboration and business decision-making. More than 70% of respondents are using unified or integrated systems, and 60% say their main motivation for replacing legacy technology is to integrate new capabilities. Fifty-one percent cite access to new features as another key driver. These trends reflect a growing interest in cross-functional systems that deliver operational insight and help teams achieve more with their existing investments. Long-term vendor stability is becoming a key selection factor Survey findings show that organizations place strong importance on choosing manufacturers they consider stable and trustworthy. Seventy-three percent of end users say the long-term viability and stability of the vendor is a key factor when evaluating solutions,
while product performance and price indicators followed behind, ranked at 45% and 43%, respectively. This points to a clear preference for partners who can provide continuity, support multiyear modernization efforts, and deliver reliable product development as systems evolve. Interest in AI is rising but teams want practical benefits AI is an area of growing focus. For the first time, AI ranked alongside access control and video surveillance as a top project priority for 2026. Interest in adopting AI has more than doubled among end users since last year’s report. They see value in technology that helps navigate alarms, support investigations, and reduce noise in busy environments. At the same time, 70% express concerns about how AI systems are designed and implemented, specifically around data use and understanding how AI works, reinforcing the need for clear guidance from vendors. Hybrid cloud is preferred, and defines the future of security infrastructure Cloud is playing a stronger role in how security infrastructure is designed and maintained. End users identify automatic updates, ease of deployment, and simpler maintenance as key benefits. Respondents expect continued cloud adoption in 2026, supported by the flexibility to choose which workloads remain on premises and which move to the cloud. JANUARY 2026 / CXO DX
11
» NEWS INSIGHT
MILESTONE LAUNCHES VISION LANGUAGE MODEL (VLM) The VLM powers video summarization for XProtect VMS and VLM-as-a-Service for third-party integrations
Andrew Burnet Acting Chief Technology Officer, Milestone Systems
Milestone Systems, a world leader in data-driven video technology, has released an advanced vision language model (VLM) specializing in traffic understanding and powered by NVIDIA Cosmos Reason. The VLM powers two new products: a Video Summarization tool for XProtect Video Management Software and a VLM as a Service for third party integrations. Video Summarization for XProtect allows users to search summaries from visual data and automates reporting. Today’s video systems capture vast amounts of data, and reviewing footage remains time consuming and largely manual. With Milestone Systems’ new Video Summarization tool – a generative AI-powered plug-in for the XProtect Smart Client – users and operators can now rely on a specialized product that automates operator workflows, saves valuable time, and reduces false alarm fatigue significantly. Early reports show video summarization could reduce operator false alarm fatigue by up to 30 %. The Video Summarization tool analyzes
12
CXO DX / JANUARY 2026
camera footage and describes what's happening. Users simply send a snippet of video and a prompt describing their request, and the model will generate a text summary in seconds.
With VLMaaS, the development of AI and analytics can be accelerated significantly – up to 70 times less effort than doing the work to fine-tune a VLM model to do the same.
Key capabilities: • Convert video segments into structured text summaries inside XProtect Smart Client • Search summaries based on video content, rather than timestamps or manual tagging • Bookmark and filter summaries to streamline review workflows • Integrate seamlessly with existing XProtect event and rule logic to trigger automated summaries based on specific alarms or alerts • Focus attention on valid events by filtering out irrelevant motion or noise • Access customized, sovereign VLM’s per region, starting with the US and EU. More regions to follow. • The Video Summarization is free to download and takes only a few minutes to install directly in the XProtect Smart Client. And users only pay when prompting the VLM.
Key capabilities: • Access high accuracy vision language model, fine-tune on traffic optimized data and built on NVIDIA Cosmos Reason • Follow prompt-based instructions for traffic-related operations • API-first delivery – simple integration via HTTPS • Fine-tuned models for US and EU markets, with more regions to follow • Designed to build standalone solutions or integrate with the Milestone product portfolio • 100% responsibly sourced training data with auditable data lineage, GDPRand EU AI Act-compliant, used for the fine-tuning of the model
VLM as a Service for developers: Add production-ready video intelligence to any application With Milestone’s Hafnia VLM as a Service (VLMaaS), developers, integrators and partners get API access to production-ready video intelligence built on NVIDIA’s latest technology and finetuned on responsibly sourced data. The VLMaaS helps developers create AI-powered solutions quickly without needing to set up, fine-tune or manage their own AI systems – it enhances any existing solutions with generative AI, regardless of the level of analytics currently in place. This makes it fast and simple to add advanced video intelligence features to applications, whether it’s testing a minimum viable product (MVP) or scaling a platform.
Pricing for the VLMaaS is pay-per-use (based on API calls) – no large upfront investments or custom training costs. Andrew Burnett, Acting Chief Technology Officer, Milestone Systems, said: “With the Vision Language Model as a Service and Video Summarization for XProtect, we’re tackling some of the most challenging bottlenecks: video overload and time-consuming manual work. Operators get immediate insight directly within XProtect; builders get API‑first access to production‑ready intelligence without bespoke training or heavy infrastructure. Because this model is specialized for real-world traffic video and fine-tuned on responsibly sourced data, customers can trust the results, deploy with confidence, and enhance all existing solutions in place. It’s the fastest, most advanced and impactful path to turning video into actionable outcomes.”
» NEWS INSIGHT
NCSC OF THE KINGDOM OF BAHRAIN AND SANDBOXAQ PARTNER TO ENABLE A QUANTUM-SAFE ECONOMY Under this partnership, the Kingdom of Bahrain will deploy SandboxAQ’s AQtive Guard platform, an AI-powered cybersecurity solution National Cyber Security Center of the Kingdom of Bahrain and SandboxAQ have signed a strategic Partnership to position Bahrain as one of the first countries to operationalise post-quantum protection at national scale National Cyber Security Center of the Kingdom of Bahrain and SandboxAQ, a global leader in AI-driven cybersecurity and cryptographic management, announced a landmark partnership, aimed at establishing a nationwide cybersecurity modernisation framework. The partnership marks one of the world’s first largescale commitments to transitioning towards a quantum-safe economy. As a founding member of the UNICC AI Hub on Post-Quantum Cryptography (PQC), SandboxAQ will support Bahrain in securing sovereign data, critical infrastructure and sensitive government and private-sector systems against rapidly evolving cyber, cryptographic, and quantum computing threats. The announcement comes as governments worldwide prepare for “Q-Day”, the point when cryptographically relevant quantum computers (CRQCs) will be capable of breaking today’s widely used encryption. While experts now estimate CRQCs to be feasible by as early as 2029, the threat is already present through “harvest-now, decrypt-later” attacks, where adversaries steal encrypted data today with plans to decrypt it once quantum capabilities mature. For governments, this includes classified communications, diplomatic cables, defence data, national identity records and decades of sensitive archives. Under this partnership, the Kingdom of Bahrain will deploy SandboxAQ’s AQtive Guard platform, an AI-powered cybersecurity solution designed to enable the safe, large-scale deployment of AI agents and modernise defenses for the post-quantum era. It provides complete visibility, assessment, and remediation of critical vulnerabilities stemming from weak encryption and the rapid proliferation of AI agents and non-human identities (NHIs). The deployment will span more than 60 distinct ministry environments across the Kingdom, requiring SandboxAQ’s platform to manage cryptographic security on a scale. His Excellency Shaikh Salman bin Mohammed Al Khalifa, CEO of the National Cyber Security Center (NCSC) of Bahrain, commented: “This partnership with SandboxAQ marks a significant milestone in our mission to secure our sovereign data, intellectual property, and other digital assets from both internal and external cyber threats. SandboxAQ’s world-class technol-
His Excellency Shaikh Salman bin Mohammed Al Khalifa CEO, National Cyber Security Center (NCSC) of Bahrain
ogies and expertise in AI-driven cybersecurity will help Bahrain protect its citizens, businesses, and government agencies and lay the foundation for a new era of security and economic growth in the Kingdom.” Mohammed Aboul-Magd, Vice President of Product, Cybersecurity at SandboxAQ, added: “Bahrain is taking a bold and much-needed step by not only setting policy, but by operationalising the technology required to secure the Kingdom against rapidly advancing threats. Our partnership establishes a dynamic framework that allows the country to adapt quickly as new vulnerabilities emerge, ensuring the nation stays ahead of attackers in a world where cryptographic risks evolve by the day. We are honoured to support Shaikh Salman and the Government of Bahrain in implementing this forward-looking programme, which sets a new benchmark for cyber resilience across the region.” This initiative forms a core pillar of Bahrain’s long-term cybersecurity strategy and reinforces the Kingdom’s commitment to safeguarding national data, promoting economic resilience and accelerating secure digital transformation. JANUARY 2026 / CXO DX
13
» INTERVIEW
OPERATIONALIZING AI FOR THE ENTERPRISE
Manasi Vartak, Chief AI Architect & Vice President, Product Management at Cloudera discusses hybrid AI-anywhere strategies at Cloudera, workload portability, AI model training, and the role of low-code platforms in accelerating enterprise adoption of AI. What advantages does a hybrid AI-anywhere approach offer compared to traditional cloud-only AI platforms? Cloudera serves multinational customers across oil and gas, financial services, healthcare, and other industries. If you are a multinational organization, you operate across the Americas, Europe, APAC, and other regions. Each region has different regulatory requirements around where data can live. There are also language considerations; LLMs trained in English may not work well for Arabic, Hindi, or other regional languages. Additionally, proximity to customers affects latency. All of this means you want to run AI where your data and customers are located. Our hybrid AI-anywhere approach allows customers to pick and choose where they run AI, based on where their data resides. This delivers the best experience and aligns with where the industry is heading, toward sovereign AI. Is this mainly about choosing the right hyperscaler, or does it also include on-prem deployments? It includes both hyperscalers and on-prem. We have a very large on-prem footprint. With AI, especially large language models, beyond a certain scale, it becomes cheaper to run models within your own data centers. We have case studies showing that if you have more than 100 models, it often makes more sense to run them on-prem. Depending on the workload, customers are increasingly moving in that direction. Does this mean data center investments will rise again, especially driven by AI and LLM workloads? Yes. We’re already seeing this. OpenAI, for example, is acquiring data center capacity globally, in the Middle East, Japan, and elsewhere. Oracle’s partnership with OpenAI is another example. AI and LLM inference are key reasons data centers are again in high demand. Enterprises themselves are also investing. For large-scale workloads, owning GPUs and infrastructure can be more cost-effective than renting cloud GPUs, which are priced by tokens and become expensive at scale. How effective is it for enterprises to move workloads between on-prem and cloud? Workload portability is a core design philosophy at Cloudera. You should be able to move workloads seamlessly. If you are run-
14
CXO DX / SEPTEMBER 2025
Manasi Vartak Chief AI Architect & Vice President, Product Management, Cloudera
ning an AI workload on-prem, moving it to the cloud should be a lift-and-shift operation, like a quick click. Your platform supports traditional ML, generative AI, and agentic AI with both low-code and full-code flexibility. How does this help enterprises accelerate AI application development? One of the biggest changes with Gen AI is that it’s no longer just coders building AI applications. Business users now participate as well. Business teams understand workflows deeply. For example, sup-
» INTERVIEW port teams know how they triage cases. With low-code tools and natural language interfaces, they can now build workflows themselves. Something that would have taken days or weeks can now be done in hours. This fundamentally changes how software is built inside organizations and significantly expands who can build AI solutions. Can you explain the role of AI Workbench in your portfolio? AI Workbench focuses on building AI applications and models. It supports research and development using notebooks, Jupyter, Python, and other tools. You can build applications, chatbots, or do data visualization. Workbench, combined with AI Inference, forms the foundation for our AI Studios, which are low-code and no-code tools for building AI applications. What role do AMPs play? AMPs are blueprints that help customers quickly get started with specific use cases. For example, for fraud detection, AMPs provide an end-to-end blueprint within the Cloudera AI platform. These are primarily directed at developers. Could you elaborate on AI Inference Service? AI Inference Service is developed in partnership with NVIDIA. NVIDIA provides optimized versions of open-source models for GPU infrastructure. Our service allows customers to select open-source models and run them at scale within the Cloudera AI platform. It is already available in the cloud, and we are bringing general availability for on-premises data services in January. How do you see the role of human workers evolving in the age of agentic AI? I view AI as enhancing human capabilities. AI still requires human judgment and guidance. Rather than replacing people, it enables teams to do more with the resources they already have. How do you address governance and security across the AI lifecycle? Governance is critical. Innovation moves fast, but governance ensures responsible adoption. Data governance includes access control, lineage, and understanding how data is used. Model governance includes approved use cases, data access, and whether data is shared externally. We’ve developed internal governance frameworks at Cloudera and are incorporating these practices into our products to help customers adopt similar standards. Can you elaborate on the role of synthetic data, especially in the context of training AI models? A lot of times, organizations have PII data, such as social security numbers, card numbers, or other sensitive information, that they do not want to expose to AI models. Synthetic data helps generate data that looks similar to real data without compromising user privacy. At Cloudera, we have built something called the Synthetic Data
Studio. Customers can provide typical examples of what a dataset looks like, and the system generates data that resembles it, without using actual PII. You can then scale this significantly, for example, generating millions of rows of synthetic data that can be used for training. Even in the largest foundation model labs, synthetic data is widely used to enable training at scale, and we are seeing this expand further. Can synthetic data be generated for most industries and use cases? Yes, it can be generated for any industry, as long as you have a clear understanding of what your prototypical data should look like. Synthetic data uses large language models to generate additional data that resembles what you already have. One of the technical nuances is ensuring sufficient diversity in the synthetic data so that it accurately reflects the population. You don’t want a situation where only one type of user or scenario is represented while others are missing. How do you ensure quality and avoid hallucinations in synthetic data? One approach is called ‘LLM as a judge,’ where one model evaluates the output of another. This allows quality control at scale. Humans can still be involved, but typically only for a small percentage of cases. How does Cloudera deliver enterprise-grade performance while maintaining cost control? Cost control becomes critical during inference. Cloud GPUs and token-based pricing become expensive at scale. Running models on-prem with Cloudera can significantly reduce costs. For scale, Cloudera’s DNA is managing large datasets; we manage 25 exabytes of data. Our platform is designed for extensibility and scale. Data Services 2.0 also enables faster adoption of new technologies. What challenges do enterprises face when moving from partial to full AI adoption? The first challenge is data readiness from the context of governance, access, and quality. The second is having a strong business case. Experimentation is fine, but eventually the CFO will ask whether it delivers value. The third is governance, especially managing hallucinations and risk. The fourth is enablement and talent. AI requires new skills, and organizations are still upskilling their workforce. Highlight a few roadmap priorities? We’re bringing general availability of AI Inference on-prem in collaboration with NVIDIA in January. We’re also expanding AI Studios with low-code and no-code tools that allow anyone to build agents quickly. Another focus is Data Services 2.0 and Anywhere Cloud, which lets customers deploy AI and data infrastructure flexibly across on-prem and cloud en
JANUARY 2026 / CXO DX
15
» COVER FEATURE
OUTLOOK 2026 THE ENTERPRISE IN TRANSITION
Enterprise technology is entering a more mature phase. What was once driven mainly by speed and scale is now being reshaped by intent, control, and accountability.
F
or enterprises, by and large, the last decade in technology was about adding more platforms, more tools, more dashboards, more pilots.
Across industries, leaders are saying the same thing in different ways. They are emphasizing less experimentation and more execution as well as less speed for its own sake, more speed with purpose. AI is no longer a side project for innovation teams. Cloud is no longer the automatic answer for every workload. Security is no longer just about higher walls. And digital transformation is no longer a “program” with a beginning and an end; it is becoming how enterprises are run.
From Tools to Operating Models For many years, enterprise IT followed a simple logic. It was about identifying a problem, buying a system, integrating it, and training people to use it. That logic is breaking down. Modern technologies, especially AI do not simply support work; they reshape how work itself is designed. Kevin Neogy, Group Head of Digital Transformation, AI & Robotics at The Kanoo Group (UAE & Oman), says, “In 2026, enterprise tech will be defined less by ‘new tools’ and more by a new operating model for work.” Instead of layering technology onto old workflows, enterprises are being forced to redesign processes around what technology, especially AI, can now do. The conversation is shifting away from choosing systems and toward rethinking how work itself should move in a world where machines can plan, predict, and act. This shift becomes most visible in how enterprises are rethinking GenAI.
From Copilots to Agents Early GenAI adoption in enterprises focused on copilots; tools that helped draft emails, generate code, summarize documents, or answer questions. These improved productivity at the edges, but they did not fundamentally change how work moved through the organization. Kevin explains, “First, GenAI will move from copilots to agentic systems of action—multi-Agent workflows that can plan and execute
16
CXO DX / JANUARY 2026
» COVER FEATURE across ERP/CRM/ITSM. The differentiator won’t be model size; it will be orchestration, permissions, auditability, and human-in-theloop controls. In short: Agents won’t replace processes – processes must be rebuilt for agents.” This is a major leap. Instead of humans doing the work and AI assisting, AI will increasingly do the work while humans supervise, validate, and intervene when necessary. That changes job roles, performance metrics, and accountability structures. Sameer Joshi, Sameer Joshi, Digitalization Director at Spimaco, sees this shift already happening across the region. He says, “AI is no longer a ‘program’ — it’s becoming invisible. By 2026, AI stops being something employees ‘use’ and starts being something they work with by default.” In practice, this means success will not look like people logging into “AI tools.” It will look like everyday systems including planning, finance, service, operations, all quietly using AI behind the scenes to prioritize work, adjust forecasts, flag risks, and trigger actions without fanfare.
Kevin Neogy Group Head of Digital Transformation, AI & Robotics, The Kanoo Group (UAE & Oman)
Data as Context, Not Just Storage As AI becomes more autonomous, the importance of data quality and governance rises dramatically. An agent acting on bad or biased context is worse than a human making a slow decision. Highlighting this shift, Kevin says, “Second, the real bottleneck becomes AI-ready data and context. Enterprises will shift from ‘data lakes’ to governed knowledge foundations—trusted retrieval, lineage, and policy-aware access - because Agents are only as reliable as the context you give them. The winning stack is not LLM vs. enterprise data; it’s LLM + governed enterprise context.”
AI-FinOps to control unit economics - cost per outcome, not cost per token.” Training and running AI models is expensive. GPU availability, energy costs, data movement, and latency now directly affect what an enterprise can afford to automate. Architecture choices become business choices. Sameer adds a geopolitical and competitive dimension when he says, “Enterprises are realizing that their proprietary data—not software—is their competitive advantage in the AI era.”
For years, organizations invested in collecting data. Now they must invest in trusting it. That means knowing where data came from, who owns it, who can use it, and for what purpose. It also means connecting structured and unstructured data such as documents, emails, images, logs into usable context for AI.
If data is the new advantage, then where it lives, who controls it, and how it is protected becomes a strategic decision, not just a technical one.
Jiju G.S., Head of IT at S.S. Lootah Group, sees this convergence happening inside core systems, “ERP systems are no longer just transactional backbones; they are evolving into orchestration platforms tightly integrated with analytics, automation, and AI-driven intelligence.”
As automation expands, trust becomes critical. Enterprises are no longer focused only on securing systems; they are securing the decisions those systems now help make.
ERP, analytics, and AI are converging into a single operational brain; one that senses, decides, and increasingly acts. This also changes leadership expectations. Executives no longer want static dashboards that show what happened last month. They want systems that explain what is happening now, why it is happening, and what should be done next.
When Infrastructure Becomes Strategy Infrastructure used to be something enterprises tried not to think about too much. It was plumbing; necessary but not strategic. AI changes that. Kevin makes this explicit. He says “Infrastructure becomes strategy as organizations invest in AI-capable compute (GPU capacity, hybrid architectures, and ‘AI factory’ patterns) while adopting
Trust Moves to the Boardroom
Kevin explains, “Fourth, trust becomes non-negotiable: AI security, digital provenance, confidential computing, and post-quantum readiness move from ‘future risk’ to board-level priorities as deepfakes, identity abuse, and model attacks escalate.” Security is no longer only about stopping intruders from breaking in. It is about verifying who or what is acting inside your systems. Humans, bots, agents, partners, APIs, and outsourced teams all need identities, controls, and accountability.
Acceleration, Correction, and Consolidation After years of rapid digital spending, enterprises are becoming more selective. Kevin says, “In my view, 2026 will be a ‘consolidation year with selective acceleration’ and a clear correction in hype and spend discipline.” JANUARY 2026 / CXO DX
17
» COVER FEATURE On productivity, Kevin mentions that Agentic systems shift AI from ‘drafting’ to ‘doing’ — planning, coordinating, and executing work across enterprise tools. He also highlights the escalating risk when he says, “The moment an agent gets tool access, the blast radius increases.” Jiju reinforces this when he says, “AI agents function like ‘digital employees,’ and governance, accountability, and defined operational boundaries must be in place.”
From Pilots to Proof
Sameer Joshi Sameer Joshi, Digitalization Director, Spimaco Where technology clearly improves outcomes such as automation, agentic workflows, cybersecurity, operational analytics, investment will grow. Where it produces demos but not value, budgets will shrink. Jiju sees the same shift. He says, “Most enterprises have already invested heavily in cloud, ERP, analytics, and automation. The focus is now shifting toward optimizing ROI, simplifying architectures, reducing tool sprawl, and strengthening governance.”
For the past few years, enterprise AI success was often measured in activity: how many pilots were launched, how many demos were shown, how many innovation labs were created. That phase is clearly ending. What boards and CEOs now want is evidence that AI changes how the business actually performs. The shift is from experimentation to execution. AI is no longer treated as a learning exercise; it is being treated like any other core business capability that must justify its cost, its risk, and its impact. This means fewer “interesting” use cases and more focus on the ones that touch real operational pain points such as cycle time, cost-to serve, accuracy, compliance, and cash flow. Kevin explains how this change is being institutionalized. “Every AI initiative is tied to a business outcome… and only scales when it demonstrates cost-per-outcome improvement with adoption and risk controls in place.”
Sameer captures the cultural shift when says, “Success won’t come from doing more—it will come from doing fewer things exceptionally well.”
This approach pushes teams to begin with a value hypothesis rather than a technical idea. The focus shifts from what a model can do to which business metric it is expected to move. Baselines are set before pilots begin, and success is measured by whether those metrics change in a meaningful way.
Digital transformation is moving from ambition-driven to outcome-driven.
Kevin says, “Boards don’t want ‘number of pilots’ — they want unit economics and risk control.”
Hybrid Work Is Here to Stay
That means measuring not just whether an AI system works, but whether it is cheaper, faster, safer, or more scalable than the human or automated process it replaces. It also means proving that governance, security, and oversight are built in from the start, not added later.
The debate about whether remote work “works” is largely settled. Jiju says, “Remote work is settling into a stable hybrid model. Most organizations are back on-prem for collaboration and culture, but flexibility is now permanent.” He adds, “Remote work is no longer about working from a single desk but about enabling secure, trusted, and fast access from anywhere.” This changes investment priorities. Instead of basic connectivity, enterprises now focus on identity, device trust, user experience, and resilience.
Agentic AI: Multiplier or Amplifier? Agentic AI introduces a new kind of risk. When machines can act, not just advise, mistakes scale faster. Kevin says, “In my view, inside most enterprises, Agentic AI will be viewed as both — a productivity multiplier and a risk amplifier — with the ‘winner’ determined by governance, data readiness, and identity controls.”
18
CXO DX / JANUARY 2026
According to Sameer who puts it more bluntly, “If AI doesn’t change decisions, it doesn’t create value.” Many early AI systems produced impressive predictions or insights, but managers continued to override them. Jiju looks at it from an operational lens when he says, “AI initiatives that do not deliver measurable operational or financial impact are increasingly deprioritized.” Together, these views point to a clear reality that AI is no longer an experiment. Like any production system, it must earn its place by proving that it delivers value, can be governed, and can be trusted at scale.
AI and the New Threat Model AI does not just help defenders; it also empowers the attackers. Kevin explains. “AI fundamentally changes the threat model be-
» COVER FEATURE cause it industrializes trust exploitation. The result is that identity and authenticity (not just perimeter vulnerabilities) become the primary battleground.” Jiju adds, “Traditional threat classification alone is insufficient; behavior analytics and continuous monitoring become critical.” Security in 2026 is less about blocking and more about verifying and responding.
Enterprise LLMs: Control Comes at a Cost The first wave of enterprise GenAI adoption was driven largely by public models. They were easy to access, powerful, and required little setup. Teams could experiment quickly, build proofs of concept, and demonstrate value without heavy upfront investment. But as usage grew, so did concerns about where data was going, how data was being used, and whether sensitive information was leaking outside organizational boundaries.
Jiju G.S Head of IT, S.S. Lootah Group
This is where many enterprises are now drawing a line. Convenience is no longer enough. Control is becoming the priority. Jiju explains the reality of this shift clearly, “Building enterprise-grade LLMs is challenging and costly, but provides better control and data security.” The real complexity, however, is not just in building or hosting the models. It lies in everything around them: integrating them into existing systems, defining who can access them, what data they are allowed to see, and what actions they are allowed to trigger. Enterprises must also ensure that these systems can be monitored, audited, and explained, especially when they influence decisions that affect customers, employees, or regulators.
Regulation as a Design Constraint As AI becomes more embedded in business processes, regulation is no longer something that comes at the end of a project. It is becoming one of the starting points. Kevin captures this shift when he says, “Regulations are turning AI and data into ‘governed infrastructure.’” In other words, AI and data are starting to look like utilities; critical systems that must be controlled, monitored, and audited, much like financial systems or safety systems. Enterprises are being asked not just to build intelligent systems, but to prove that those systems are safe, fair, explainable, and compliant. Jiju sees this changing how decisions are made inside IT and business teams. He says, “Technology decisions are increasingly driven by what is allowed, how it is governed, and how compliance can be demonstrated.”
From Cloud-First to Cloud-Smart Cloud is no longer an ideology. It is now a practical choice, shaped by cost, performance, regulation, and the specific needs of each workload. Kevin says, “‘Cloud-first’ matures into cloud-smart.” Cloud-smart means choosing where a workload runs based on business reality, not fashion. Latency, risk, compliance, data sensitivity, cost, and resilience all become part of the decision.
Jiju describes the practical version, “Customer-facing and scalable workloads are placed on public cloud, while sensitive or critical workloads remain on private cloud.” Sameer says, “The future isn’t cloud vs. on-prem. It’s hybrid by design.” Hybrid by design strategy accepts diversity of workloads and designs for movement, integration, and control across environments.
The Return of Sovereign and On-Prem There is a growing interest in on-prem and sovereign infrastructure today is not sentiment; rather, it is a necessity. Jiju says, “There will be a measured resurgence, especially in regulated industries and data-heavy AI use cases.” Sameer adds that “Some data is too sensitive, too large, or too regulated to move freely.” Highly regulated sectors cannot treat data location as a secondary concern. As AI systems consume massive volumes of sensitive, contextual data, the question of where that data sits becomes even more critical. AI training, national data strategies, and geopolitical risk are all pushing enterprises to rethink where their most valuable data lives.
The Enterprise in Transition What emerges from all these perspectives is not a single trend, but a pattern of change. AI is becoming part of how work happens, not a separate activity. Data is turning into governed context, not just stored information. Identity is becoming the real control plane. Cloud is becoming a choice, not a rule. Security is becoming behavioral rather than purely defensive. Regulation is becoming a design input rather than something added later. And value is replacing experimentation as the primary measure of success. The enterprise in transition is all about not chasing the future, but deliberately engineering it with control, trust, and purpose. JANUARY 2026 / CXO DX
19
» INTERVIEW
ENABLING HIGH-PERFORMANCE DATACENTRES Khalid Aljamed, General Manager – Middle East, Turkey & Africa at Submer, discusses the rapid growth of AI-driven data center investments across the region, the rise of sovereign AI infrastructure, and the shift toward liquid-cooled, high-density data centers coming utilities, similar to water or power. Leaders in this region are very clear about their ambitions. Saudi Arabia and the UAE aim to become global AI hubs. When you look at investments in power, land, and backbone infrastructure, it’s evident how resources are being reallocated toward AI data centers. Traditional industries, from government and education to healthcare and cloud services, stand to benefit enormously from AI. For the past 10 to 15 years, GCC governments have also been actively diversifying revenue sources beyond oil and gas, and AI data centers are a natural fit for this region. As AI workloads scale, could enterprises return to building their own data centers? It’s not as simple as cloud versus on-prem. Today, we talk about AI gigafactories and tokens almost as a form of currency. Governments are now measured by how much compute and AI capacity they have, similar to how gold reserves once defined economic strength.
Khalid Aljamed General Manager – META, Submer
How do you see the demand for new data centers evolving in the region? What is driving the forecasts around data center investments? Today, with the explosion of AI, most governments view AI data centers as a critical piece of national infrastructure. That is what’s driving demand.
You need both cloud and on-prem. Cloud offers shared services, redundancy, and scalability, but sovereign requirements prevent sensitive data from being hosted outside the country or region. That’s why governments are thinking about building both AI services and their own cloud infrastructure. How do you see the opportunity for your company in terms of data center growth in the region? We have been operating in the data center and AI space for some time, particularly across Europe. We initially focused on crypto about 10 years ago, which led us into advanced cooling technologies.
We’re seeing global data center expansion accelerating at nearly 30 percent year over year, and I believe this could increase to around 45 percent by next year. This growth is entirely fueled by AI expansion; how we generate, process, and consume information.
To meet high-performance compute requirements, optimization is critical in terms of energy, space, and performance, and liquid cooling has become essential. From there, we expanded our role. Today, we see strong demand in this region for advisory services such as helping governments and enterprises understand how to build modern, sustainable AI data centers.
This is why we now use the term AI gigafactories. These are be-
From advisory, we moved into boutique design, and finally into
20
CXO DX / JANUARY 2026
» INTERVIEW full construction and build. Our investment in the region is driven by this end-to-end capability including advisory, design, and build for AI data centers. We support governments, hyperscalers, colocation providers, telecom operators across Saudi Arabia, the UAE, Qatar, Kuwait, Africa, and Turkey, while collaborating with ecosystem partners like NVIDIA, Intel, AMD, Qualcomm, and Dell. Are enterprises also an opportunity for you, or is the focus mainly on large government-led projects? Governments today are focused on greenfield AI data centers, large-scale compute capacity measured in megawatts. But once momentum builds, attention will also shift to existing data centers in sectors like finance, oil and gas, and national security. Many existing data centers were built 10 to 20 years ago based on older architectures. Scaling them for AI workloads is a different challenge, but an important one. For us, it’s a balance between greenfield development and brownfield migration. Will existing data centers need redesigning to support AI workloads? Exactly. Modern data centers require modularity and sustainability. Modular designs future-proof investments, allowing scalability and accommodation of new technologies. At the same time, they introduce challenges related to energy, power, land, and connectivity. That’s why education, awareness, and experience-sharing among governments, enterprises, cloud providers, and chipset vendors are critical and we aim to sit at the center of that ecosystem.
bia and the UAE. We also see opportunities in North and South Africa, Turkey, and the wider GCC. Our approach combines local resources with global expertise, enabling rapid deployments and close alignment with customers and partners. Supply chain is a major challenge today, especially for chips, memory, and storage, and no single company or government can address this alone. We focus on building local and international ecosystems, including IT, mechanical, electrical, and plumbing partners. Traditional data centers took three years to build. AI data centers are now expected within 9 to 12 months, which requires strong partner ecosystems. Do you already have customers and deployments in the region? We work with sovereign funds and local governments. One of our largest public case studies is ADQ02, a 400-megawatt deployment. It’s a strong example of how Abu Dhabi leveraged excess power sustainably to generate new revenue streams through digitization, crypto, and data mining.
"Modern data centers require modularity and sustainability. Modular
How does liquid cooling change the game? There are two main types of liquid cooling today. The first is direct-to-chip. Heat is transferred from CPUs, GPUs, and memory chips through a cooling plate to a liquid medium, typically an oil derivative, not water. Major oil companies like Shell, Castrol, and Valvoline are now involved in this space.
designs future-proof
This approach has existed for years in high-performance gaming PCs, though at a much smaller scale. In data centers, the liquid exchanges heat with HVAC systems, which is essential in this region.
accommodation of new
The second approach is immersion cooling. Entire servers are submerged in dielectric liquid. The principle is the same, heat is transferred through liquid to a heat exchanger but at rack scale. With today’s compute loads, air cooling is no longer viable. It’s expensive and limits scalability, especially for new NVIDIA and AMD chipsets. That’s why almost all new data center designs globally now rely on liquid cooling.
time, they introduce
Tell us about your partner strategy and regional investments, particularly in Saudi Arabia. We’re investing across the region, with major hubs in Saudi Ara-
investments, allowing scalability and technologies. At the same challenges related to energy, power, land, and connectivity." JANUARY 2026 / CXO DX
21
» INTERVIEW
ENABLING PROACTIVE INTELLIGENCE David Noël, Regional VP at Dynatrace Middle East discusses how AI-driven observability is powering smarter operations, unified platforms, and regional growth across hybrid cloud environments Discuss your operations and growth in the region? Our growth mirrors the region's transformation ambitions. UAE Vision 2031 and Saudi Vision 2030 both prioritize advanced digital infrastructure and AI leadership. This is exactly where observability becomes mission-critical. We're seeing strong traction in the public sector, BFSI, and retail, where 68% of Middle East companies are migrating the majority of their operations to the cloud by 2025. With nearly 90% of GCC CEOs using generative AI, the question isn't whether to adopt AI, it's how to make it explainable and secure. We're enabling agentic AI and real-time observability in mission-critical environments, working closely with regulators and smart city initiatives to become the intelligence layer powering the region's digital future. What is the regional outlook for spend on observability solutions? Observability spending in the region is gaining momentum, driven by AI adoption and sovereign cloud strategies. Saudi Arabia's cloud-native observability market stands at $1.2 billion, while 76% of regional firms are increasing cloud budgets. Our global data shows 70% of enterprises increased observability budgets last year, and 75% of enterprises expect to increase more in the coming year. In the UAE and KSA, we're seeing even higher growth due to aggressive transformation roadmaps. CIOs are investing beyond monitoring because they want platforms that reduce mean time to repair and meet AI trust requirements. Where do you see the biggest blind spots when traditional cloud-first tools are applied to hybrid or physical data-center environments? Traditional tools create three critical blind spots. First, they reinforce silos when organizations need unified visibility. This explains why only 14-28% of Middle Eastern firms have scaled AI across business functions despite 60% reporting fast adoption. Second, they can't handle hybrid scale or deliver real-time observability across distributed systems. Third, AI capabilities now outrank cloud compatibility as the top selection criterion, signalling a shift away from legacy solutions. Organizations need comprehensive platforms that cut across infrastructure, security, and DevOps, not point solutions that create operational gaps. In a region racing toward AI leadership, these blind spots can become existential risks.
22
CXO DX / JANUARY 2026
David Noël Regional VP, Dynatrace Middle East
The latest State of Observability report shows enterprises juggling an average of ten monitoring tools. How is this level of tool sprawl actually slowing incident resolution and creating operational blind spots? Tool sprawl is the hidden tax on transformation. Ten monitoring tools don't give you ten times the visibility. They guarantee fragmented intelligence and persistent silos. When over 60% of GCC firms cite cybersecurity threats as their top risk, you can't afford slow remediation while correlating data across disconnected tools. Leaders expect observability to deliver shared intelligence driving cross-functional outcomes, such as cost control, security, and operational resilience. That's impossible with tool sprawl. Organizations are moving from monitoring point solutions to AI-driven intelligence layers that enable automated, proactive responses and eliminate the operational gaps fragmented tools create.
» INTERVIEW When you talk about moving from fragmented dashboards to a single, AI-driven view of the estate, what does it take in practice to unify those data streams into a platform that can truly cut mean-time-to-repair? It requires three shifts. First, AI capabilities have become the primary selection criterion—outranking ease-of-use or cloud compatibility. Second, you need unified observability across microservices, cloud workloads, user experience, and infrastructure. Third, focus on platforms that optimize model configurations and automate remediation. The goal is moving from dashboards to decisioning in order to use AI to proactively alert and trigger real-time remediation. Seventy-five percent of organizations increased observability budgets last year, reflecting a growing interest in platform unification and other modernization efforts. It's about applying AI to real-time data streams to detect issues, trigger automated responses, and improve system performance and reliability. When Middle East firms invest 5%+ of digital budgets on generative AI, which is double the global average, observability must be intelligent. From your perspective, how early in the design process should observability be built in, and what risks arise if it’s treated as an afterthought? Embedding observability early on sets the foundation for longterm success. It's shifted from a reactive IT tool to a proactive intelligence layer; and that demands architectural integration from the start. Without early observability, organizations face data quality issues, lack of explainability, and exposure to AI hallucinations and drift. Consider this: 99% of AI governance leaders use human oversight to validate decisions, with human verification covering 69% of AI-powered decisions. This underscores that observability needs to support decisions early in the process. Treating it as an afterthought results in poor visibility, security gaps, and limited automation. With the GCC cybersecurity market growing 8.09% CAGR through 2029, building observability in from the start is becoming regulatory necessity. Dynatrace has been highlighting the role of automation and embedded AI in its platform roadmap. How do these capabilities change the way IT teams detect, diagnose, and resolve issues compared with traditional monitoring? The transformation is from reactive firefighting to proactive intelligence. Traditional monitoring tells you something broke; AI-powered observability tells you why—and helps to prevent it. Up to 50% of DevSecOps teams actively use real-time automation, with 98% of security leaders using AI to manage compliance. AI is now embedded in threat detection, performance optimization, and anomaly alerting, which are far beyond threshold monitoring. Organizations are automating patching and using real-time intelligence to harden infrastructure. By 2030, 50% expect AI-powered encryption and risk assessment. The difference: AI-powered observability doesn't just alert teams—it guides remediation and safeguards automation workflows. How do you balance the need for deep, real-time insight with the cost and performance pressures of collecting and storing so much data? Collecting smarter, not less, is the future of observability. Real-time insight becomes sustainable when AI filters noise and surfaces what matters most. Today, organizations combine in-
frastructure metrics (CPU, memory, I/O) with cloud cost data to optimize performance and spend in tandem. More than 70% already use observability to monitor energy use and ESG outcomes, with cost reduction (50%) and efficiency (56%) as top priorities. The balance comes from platforms providing actionable, cost-aware insight at infrastructure and business levels simultaneously, optimizing cost and performance together, not separately. This evolution from raw data collection to decision intelligence, empowers enterprises to lead in both efficiency and sustainability. How does robust observability contribute to maintaining uptime, meeting service-level commitments, and protecting customer trust? AI-based automation driven by real-time data helps predict and avoid downtime, failures, and cyber threats before they impact users. Seventy-five percent of organizations increased observability budgets last year precisely for reliability. It enables faster detection of anomalies and system degradation, protecting service levels before users experience issues. In a region where the UAE government has implemented AI in 50% of public services, observability isn't just about preventing technical failures, it's about preserving citizen trust in digital transformation itself.
"Embedding observability early on sets the foundation for long-term success. It's shifted from a reactive IT tool to a proactive intelligence layer; and that demands architectural integration from the start."
JANUARY 2026 / CXO DX
23
» COLUMN
ONE WINDOW TO RULE THEM ALL:
HOW UNIFIED CITIZEN SERVICES ARE REDEFINING GOVERNMENT Unified service platforms are more than digital conveniences—they’re the new governance architecture for a connected era, writes Yasir Naveed Riaz, Project leader digital transformation at Ports, Customs & Free Zone Corporation
F
or many years, dealing with the government followed a well-known pattern: several offices, redundant documentation, frequent identity checks, and drawn-out approval processes. Applying for a public service, a construction permit, a company license, or a visa required residents and organizations to navigate disjointed systems that hardly ever communicated with one another. “Today, that model is being quietly dismantled.” Across the world, governments are implementing digital ecosystems known as Single Window or Unified Service Platforms, which combine several agencies, approvals, and procedures into a single, unified interface. Forms, offices, and follow-ups that were formerly necessary are progressively being replaced by a single digital journey.
Yasir Naveed Riaz
However, convenience is only one aspect of this change. Fundamentally, the Single Window paradigm is changing how economies function, how governments provide services, and how the public and institutions develop confidence.
Project leader digital transformation, Ports, Customs & Free Zone Corporation
Why Unified Services Matter In contemporary economies, time is the most valuable commodity. Opportunities for citizens are delayed when permits, registrations, or approvals are delayed. Inefficiency directly results in increased expenses, project risk, and decreased competitiveness for companies and investors. Unified service platforms address this friction by eliminating duplication and coordinating decisions across agencies. Instead of submitting the same information multiple times to different authorities, users interact with one platform that routes applications intelligently to the relevant stakeholders. But speed alone is not the true achievement. The real transformation shows up in transparency and accountability. When people can track their applications in real time—seeing what’s approved, what’s stuck in review, and what needs their attention—government services stop feeling like a black box. The system becomes predictable, even navigable. Trust doesn’t come from secrecy; it comes from clarity. That’s why Single Window platforms aren’t just being treated as another round of digitization. They’re increasingly recognized as deep structural reforms reshaping how public services operate.
How the Single Window Model Works At its foundation, a unified service platform integrates multiple government entities into one digital workflow. Whether the ser-
24
CXO DX / JANUARY 2026
vice relates to urban planning, business licensing, trade, taxation, healthcare, or citizen registration, the system follows a consistent pattern: One submission, many destinations: Instead of filling out the same details over and over, users enter their information once. From there, it’s securely shared with every agency that needs it, cutting out duplication and confusion. Smarter, automated validation: Digital checks handle the heavy lifting upfront—everything from zoning rules to regulatory requirements and compliance filters—so human reviewers focus only on what truly needs expert judgment. Real-time visibility: Both applicants and government teams get live status updates through intuitive dashboards, making it easy to track progress and spot bottlenecks before they become problems. Systems that speak the same language: Standardized integration frameworks allow data to move seamlessly across departments, turning isolated systems into a connected ecosystem. Designed for a mobile, digital-first world: Whether on a phone, tablet, or laptop, people can access services whenever they need them, without being tied to a physical office or working hours. Modern platforms stand apart from the first wave of e-government tools because they go far beyond putting paperwork on a screen. Their real strength is process orchestration—the ability to choreograph decisions, dependencies, and handoffs across multiple teams and systems.
What Changes in Practice When unified platforms are rolled out well, governments tend to
» COLUMN see a clear pattern of gains: • Significant reductions in approval timelines — many procedures that once dragged on for weeks are compressed into just a few days. • Higher regulatory compliance, thanks to automated validation and consistent, rule-based checks. • Stronger inter-agency coordination, which cuts down on conflicting decisions and eliminates the need for manual reconciliation. • Cleaner, more reliable data, making it easier to measure performance and maintain oversight. For businesses, these improvements translate into: • Faster project kickoffs • Lower administrative overhead • Less regulatory ambiguity • Greater confidence among investors and partners And for citizens, the impact is just as tangible: fewer trips to government offices, less paperwork to juggle, and a more predictable, less frustrating experience with public services.
The Cybersecurity Imperative: Why the Next Phase Must Be Zero Trust The next generation of unified platforms will hinge on adopting Zero Trust architecture - a security model built on the assumption that no user, device, system, or request is trustworthy by default. Every interaction must be authenticated, authorized, and continuously verified. At a national scale, that translates into: • Strict identity and access controls for employees, contractors, and external users • Segmented system architecture so a breach in one area can’t ripple across the entire ecosystem • Encrypted data flows between agencies and third-party systems • Continuous monitoring and anomaly detection to catch misuse or intrusion as it happens • Comprehensive audit trails that reinforce accountability and regulatory compliance As governments move toward AI-driven decision engines and predictive public services, these safeguards become even more critical. Without them, the efficiency gains of digital transformation can quickly be overshadowed by vulnerability, misuse, or a collapse in public confidence.
ies now coordinate approvals through one platform powered by automation, GIS capabilities, and integrated dashboards. It’s still evolving, but it shows how political will, modern infrastructure, and thoughtful process redesign can come together to transform complex public services. What sets the most successful initiatives apart isn’t the technology alone, it’s the execution. The real breakthroughs happen when policy, operations, cybersecurity, and leadership align around a shared digital architecture.
Why This Matters Beyond Government Unified service models aren’t just a modernization of public administration—they actively reshape entire economic ecosystems. For investors, greater predictability lowers exposure and uncertainty. For entrepreneurs, faster licensing becomes a catalyst for growth. For regulators, data-driven oversight strengthens compliance and reduces blind spots. For citizens, simpler interactions help rebuild trust in public institutions. When thoughtfully designed, Single Window platforms evolve into far more than service portals. They become economic accelerators, transparency engines, compliance backbones, and the digital foundations on which smart cities and future-ready nations are built. And when these platforms are reinforced with Zero Trust principles and strong governance, they deliver something rare in government technology: the ability to move fast without becoming fragile, and to scale widely without losing control.
A Global Pattern: Unified Services in Action
Why This Matters to You
Across the world, governments are already demonstrating how powerful the Single Window model can be.
If you’re a business owner, developer, policymaker, consultant, or simply someone tired of navigating slow, fragmented government processes, the Single Window model marks a genuine turning point in how public services can function. It signals a future where:
Estonia has become the benchmark, allowing citizens to tap into nearly every public service, from taxes to healthcare, using a single digital identity. India is rolling out national-scale platforms for trade, logistics, and business approvals, cutting through layers of administrative friction. Singapore and several European countries have unified construction, licensing, and planning processes into streamlined portals that coordinate multiple authorities in one workflow. Even major global cities are experimenting with centralized hubs for permits, compliance, and everyday service delivery. Closer to the region, Dubai offers a compelling example with its unified digital building permit ecosystem. Multiple regulatory bod-
• Data is submitted once • Decisions are coordinated digitally • Progress is visible in real time • Services are designed around users—not institutional boundaries This isn’t about stripping away governance. It’s about making governance work the way it should. Unified service platforms are more than digital conveniences— they’re the new governance architecture for a connected era. JANUARY 2026 / CXO DX
25
» COLUMN
INSIDE THE NEW CYBER REALITY
Ziad Nasr, General Manager, Acronis Middle East discusses how 2026 will redefine power, crime, and defence in a turbulent digital world
T
hrough 2025, it became increasingly clear that cybercrime no longer behaves like a predictable market of isolated actors. Instead, it has fused with geopolitics, business transformation and the accelerating race toward artificial intelligence. The year’s biggest incidents, from mass-scale data theft to GPS jamming that disrupted logistics across the Middle East, showed organisations that today’s threats exploit everything from the cloud platforms we depend on to the instability we live with. And nowhere is this interplay more visible than in the Middle East, where the ambition to build world-leading AI economies is unfolding against a backdrop of regional tension and global competition for talent. This convergence is shaping a cybersecurity landscape that will look markedly different as we enter 2026.
Bubbling closer to the surface The geopolitical turbulence of 2025 created conditions where cyber operations became more visible, more experimental and more intertwined with physical conflict. GPS interference affected aircraft and ships navigating the Levant and the Eastern Mediterranean. Disinformation campaigns spiked around conflict zones. The FBI’s unusually transparent disclosure of Salt Typhoon (an extensive foreign intrusion campaign targeting more than 200 telecom operators across 80 countries) only reinforced how deeply embedded advanced persistent threats have become. According to the FBI’s account, attackers could trace user movements, intercept communications and map infrastructure with near-military precision. These revelations matter because they mark a shift from speculation to public acknowledgement. The cyberwar that has simmered for a decade is gaining shape and definition. Amid ongoing conflicts and rising global competition, as the region moves into 2026, these operations will not disappear. Instead, they will set the stage for everything else that is coming.
26
CXO DX / JANUARY 2026
Ziad Nasr General Manager, Acronis Middle East
» COLUMN Criminal ecosystems begin to resemble industries The geopolitical picture bleeds directly into the criminal one. When nation-state actors push the boundaries of stealth and persistence, criminal groups tend to follow the same playbook — shaping the tools, marketplaces and alliances that feed downstream attacks. Over the past few years, ransomware gangs and malware-as-a-service groups have taken on the structure of proper companies, complete with customer support, HR roles and profit-sharing models. Now the ecosystem is consolidating. Groups like DragonForce have been absorbing smaller factions and forming coalitions that resemble corporate mergers. It’s part organised-crime expansion, part strategic business scaling. In contrast, collectives such as Shiny Lapsus Spider operate more like creative collaborations driven by shared ideology rather than strict hierarchy. But regardless of structure, the same tension applies: size creates capability, but it also creates vulnerability. This evolution matters because it directly shapes attacker behaviour, and that behaviour is already shifting in a far more consequential direction.
The real shift: intrusions without malware Whether driven by states or by criminals, attackers are steadily abandoning malware in the traditional sense. In 2026, the most damaging breaches will increasingly rely on what organisations already trust: identity systems, APIs, cloud consoles, remote management tools and native system binaries. A stolen session token, a compromised identity or a misconfigured API now offers more operational power than a bespoke piece of malware ever did. This “living off the land” approach allows attackers to blend in with legitimate activity. They escalate privileges through cloud-native workflows, move laterally using built-in utilities, and execute tasks that appear legitimate to most controls. It is subtle, fast and extremely difficult to detect with traditional tooling. And because these techniques are so effective, they are becoming the default. In many ways, this shift is the logical outcome of the trends shaping both the geopolitical and criminal spheres: stealth is rewarded, automation is accelerating, and visibility gaps are widening.
Combating threats with community-scale defence This is where defenders need to evolve just as quickly. When attackers automate reconnaissance across cloud, edge and virtualised environments, no single vendor or enterprise can see enough of the picture anymore. What appears as harmless telemetry for one organisation may be the missing puzzle piece for another.
That is why 2026 will mark the rise of community-driven intelligence platforms as a core layer of defence. When teams share signals, early indicators crystalise much faster. What used to take weeks, waiting for a patch, advisory or vendor report, can compress into hours when the industry exchanges patterns, anomalies and new tradecraft openly. These platforms also level the playing field. Many organisations lack in-house expertise in identity abuse or cloud intrusions, but the community does. Shared intelligence lets everyone benefit from that collective experience.
The coming convergence If 2025 exposed just how intertwined technology, geopolitics and crime have become, 2026 will be the year these forces fully converge. The threats will grow more subtle, more coordinated and more identity-driven. But the solutions will grow more collective too. In a world defined by interdependence, defence becomes a shared endeavour.
"Whether driven by states or by criminals, attackers are steadily abandoning malware in the traditional sense. In 2026, the most damaging breaches will increasingly rely on what organisations already trust: identity systems, APIs, cloud consoles, remote management tools and native system binaries."
JANUARY 2026 / CXO DX
27
» COLUMN
WHY DATA PORTABILITY IS THE FOUNDATION OF SOVEREIGN CLOUDS Michael Cade, Global Field CTO, Veeam discusses why enterprises need to ensure that data portability is enshrined in their data resilience planning. Enterprises need to address the reality that moving data across hybrid environments is far from straightforward. It’s not just about relocating primary data, you also must keep it protected while considering associated datasets like backups and the information used in AI applications. While some may need to address the protection of Large Language Model (LLM) training data, many organizations are instead turning to Retrieval-Augmented Generation (RAG) or AI agents to bring intelligence to their proprietary data without building models from scratch. Either way, data sovereignty is a valid approach to the pressures facing organizations today, but the focus should always be on data resilience first, no matter where it's stored. It’s a familiar tale - the cloud will give businesses more options and flexibility, but to take advantage of these properly, they’ll need some joined up thinking.
Today’s forecast
Michael Cade Global Field CTO, Veeam
T
he rise of sovereign clouds has become inevitable as regulatory demands, and geopolitical pressures push enterprises to rethink where their data resides. Localized cloud environments are increasingly becoming essential, allowing organizations to keep their data within specific jurisdictions to meet compliance requirements, and provide risk mitigation. But sovereign clouds can’t succeed without data portability, which is the ability to move data seamlessly between systems and locations. Today organizations shouldn’t wait to be pushed by regulations, they need to be ahead of the game.
28
CXO DX / JANUARY 2026
Regulators around the globe are driving organizations to look at their data differently, appearing at pace in response to increasing data globalization as countries try to get a better grasp on their data. The European Union (EU) has been particularly stringent, introducing the comprehensive General Data Protection Regulation (GDPR) that stipulates data sovereignty. Under it, the laws of the country where data is stored or processed are now applicable to the data, regardless of where the data was originally collected. Special attention is also being paid to the chain of custody of data in the EU with both the NIS2 and DORA regulations demanding robust risk management for data, especially when held or handled by third parties. As data, including highly sensitive and classified data, is being increasingly handled by these third parties, namely cloud providers, keeping it bound under privacy laws has become a priority for both organizations and governments as their data moves across borders. With this increased movement of data between countries, or even continents, global instability concerns have become unavoidable, especially for governments. Some have already adopted sovereign clouds to protect their most sensitive data from potential malevolent access. And some have taken it one step further. With cloud services completely reliant on data centre infrastructure,
» COLUMN some governments have started to divest their interest in foreign cloud and data infrastructure, reinvesting instead in their own. This way, they can avoid storing their most sensitive data with foreign providers.
own economic value. And with global instability as an ever-present factor, data sovereignty will only move higher up the priority list. But it’s not a task that can just be passed onto a third-party provider.
But cloud sovereignty is not a silver bullet. For those utilizing multinational cloud providers, there might be the option to stipulate where your data is ultimately stored and what countries’ laws it will be held under, but there is no guarantee that it will not change. The issue isn’t just solved by relocating the primary data. Sure, it needs to be protected, but what about all the related data? Backups and Large Language Model training data sets for example, all need to be carefully considered to meet data sovereignty – or alternatively, organizations can utilise RAG or AI agents to level up their data without having to deal with reams of AI training datasets in the first place.
Although organizations may not fully realise it yet, data sovereignty and operational clarity are closely linked. To start securing your data, you need to know exactly where it’s stored and how. Then, with this comprehensive understanding of your data landscape, you can pinpoint those operations or processes where data resilience might be lacking and tackle your data portability. By reworking data resilience from the ground-up, organizations can cement security, compliance, and sovereignty into their operations, and actively manage them through risk assessments, compliance audits, and strategies that take into account multiple suppliers.
Freedom of Movement
With this in place, organizations can start leveraging hybrid cloud environments effectively, perhaps storing the most sensitive data on-premises under precise data sovereignty regulations, while offloading less critical data to the cloud. But this can only be utilized by organizations that have prioritized data portability. Rather than waiting for regulations to enforce it, organizations need to be proactive to take advantage of the flexibility, longevity, and most importantly, security of the cloud.
But to do all of this, organizations need to ensure that data portability is enshrined in their data resilience planning. After all, there’s a fine line between protecting your data and inadvertently restricting it beyond the point of use. If organizations are unable to ensure data portability, then moving to a hybrid cloud environment to take advantage of both sovereign clouds and localization of data storage is a non-starter. There are SaaS (Software-as-a-Service) and DRaaS (Disaster Recovery-as-a-Service) providers that can simplify the process, but it’s not a task that can be completely offloaded to a third party. Organizations still need to take a hands-on approach, planning and managing it thoroughly to ensure data remains secure throughout the process. Otherwise, organizations will be unable to utilise sovereign clouds to adhere to the myriad data residency and sovereignty regulations.
"There’s no easy win, but what’s certain is that data portability will be an
It’s not without caveats though. For those larger, multinational organizations operating across countries and continents, multiple cloud environments will be required to house multiple sovereign clouds. But this also brings increased complexity for both the monitoring and management of data across jurisdictions. Not only will multiple cloud environments need to be considered, but also multiple sets of data regulations across countries. And, for those organizations that do get it right, the benefit of enhanced data resilience comes with the added risk of data fragmentation.
essential part of any solution
There’s no easy win, but what’s certain is that data portability will be an essential part of any solution that organizations settle on. Whichever approach is taken, being able to move data seamlessly across platforms and clouds will be a necessity as organizations wrestle with data sovereignty. And, as regulations continue coming down the line, data portability will give organizations a head start on future compliance, allowing them to flex more easily to meet regulations, where less portable counterparts will struggle.
data seamlessly across
Tying down the cloud
sovereignty."
that organizations settle on. Whichever approach is taken, being able to move platforms and clouds will be a necessity as organizations wrestle with data
Data globalization is showing no signs of slowing, with information flows now their own form of trade, even generating their
JANUARY 2026 / CXO DX
29
» COLUMN
FROM HYPE TO HARD TRUTHS
Sarah Maina, Regional Manager, Middle East & France, AppsFlyer discusses trends that will redefine marketing in 2026 If 2025 has taught marketers anything, it’s that telling the difference between hype and real transformation is becoming a survival skill. At the start of the year, the industry buzzed with talk of “Autonomous Everything”, a phrase that promised sweeping reinvention but delivered very little beyond conference headlines. As the months played out, marketers found themselves steering the same ship with the same tools, only under far greater pressure to prove impact. That frustration has set the tone for 2026. This is the year marketers stop chasing slogans and start following the numbers again. The data is clearer than ever and the lessons of the last year are the compass for what comes next. If brands can read those signals with discipline, they’ll find that the shifts already underway are less about novelty and more about precision, timing and the fundamentals of how people behave.
Seasonality Is No Longer a Vertical Problem For years, seasonality was seen as something contained neatly within verticals. E-commerce owned November. Travel had its summer peak. Gaming had its surge. But the data emerging over the past year shows a more intertwined reality. Seasonal behaviour doesn’t stay inside its lane anymore. When shoppers pour into e-commerce apps during major sale periods, gaming, subscription and entertainment platforms feel the dip almost instantly. When the shopping frenzy dies down, attention quietly swings back and those neglected categories surge. Marketers aren’t planning for isolated moments anymore, but for a shared, shifting calendar of consumer attention. If one vertical heats up, another cools. This ripple effect will define 2026. The real challenge isn’t spotting the next seasonal wave but choreographing the timing between overlapping ones. A brand running a high-stakes gaming UA campaign during November’s retail shocks will face inflated CPMs, distracted users and slower Omar Akar conversion velocity, not because their creative is poor, but beRegional VP, Middle East & Emerging cause attention has been pulled elsewhere. Understanding these Africa, Pure Storage cross-vertical feedback loops will determine who gets ahead next year. And once brands get the timing right, they quickly run into the next unavoidable question: what happens when the very nature of creativity changes?
30
CXO DX / JANUARY 2026
Sarah Maina Regional Manager, Middle East & France, AppsFlyer
Creativity Becomes Technical, and Technology Becomes Creative The old wall between creative thinkers and technical teams has crumbled. Marketers today are working in a world where generative tools let them test ideas, iterate rapidly and validate performance before a single campaign goes live. Creativity has become a technical discipline, built on data and experimentation. Likewise, technology, once purely the domain of engineers, now shapes storytelling, emotion and brand identity. Consumer behaviour is amplifying this shift. People discover, compare and decide at breakneck speed, especially through shortform video and creator-led content. A teenager scrolling TikTok
» COLUMN can spot an over-templated ad within seconds; a parent watching YouTube Shorts expects real utility, not fluff. Relevance has become a kind of respect. When content feels generic, attention evaporates. This is why dynamic, modular and personalised creatives are becoming the default. They feel alive, responsive and human because they adapt to the context in which users experience them. Brands no longer create one message, they create ecosystems of variations that learn and evolve. And increasingly, while AI is threaded through every part of that process, the advantage it gives is not as straightforward as it once was.
AI Is Becoming a Commodity, and Data Is Becoming the Moat By now, any company can stand up an “agent”. The barriers to running an LLM or deploying a generative workflow have dropped dramatically. The real differentiation lies elsewhere. The agents that will actually move the needle in 2026 will be those built on deep domain expertise and trained on large, clean, high-quality proprietary datasets. The AI layer itself is commoditising, but domain-specific data is not. After a decade of collecting anything and everything, the companies that thrive will be the ones that can govern, structure and activate their data clearly. Metadata, lineage and discoverability become strategic assets. Clean data turns AI from a clever assistant into a reliable decision-maker. Without it, AI is just a very confident intern making very confident mistakes. Of course, with AI becoming more embedded in everyday journeys, it is already reshaping how people behave, particularly in how they discover and choose brands.
LLMs Will Rewrite Discovery, Auctions and the Very Definition of Search At the C-suite level, a fascinating debate has already begun: should brands wall off their experiences or integrate deeply with LLMs such as ChatGPT? That single choice could redefine how users find information, where they make decisions and how much traffic ever makes it back to a brand’s own properties. If LLM-driven journeys scale as expected, classic auction-based search models may weaken significantly. Instead, discovery will depend on LLM ranking algorithms, which weigh context, preference and historical behaviour rather than bids alone. Vendors will inevitably emerge to help brands understand and optimise how they appear inside these models. As discovery shifts, so will measurement. The top of the funnel will increasingly start within AI systems and brands will need to connect that visibility to performance, retention and revenue in a way that is trustworthy, privacy-safe and measurable. This evolution brings us to the final reality of 2026: the way we measure impact must change just as dramatically as the way we earn it.
Why Measurement Will Become the New Growth Infrastructure The category once known as the “MMP” has outgrown its box. Marketers can no longer afford tools that only measure mobile or focus narrowly on last touch. In 2026, measurement platforms will become shared infrastructure across the whole growth stack spanning paid and owned media, apps and web, connected TV and emerging channels. Retailers, publishers and ad-tech partners are already breaking down their silos, building shared environments where discovery, engagement and purchase all connect. Customers experience their journey as one continuous flow, and measurement must finally catch up. The future of MarTech won’t be about adding more dashboards, but rather about creating one layer of truth that every team can build on. In a year full of noise, the marketers who stand out will be the ones who see what really matters. They’ll understand how attention shifts across verticals, they’ll shape creativity that keeps pace with people, and they’ll use AI that’s powered by real, trustworthy data. Most importantly, they’ll measure impact wherever it happens. That’s the MarTech reality taking shape for 2026.
"Marketers aren’t planning for isolated moments anymore, but for a shared, shifting calendar of consumer attention. If one vertical heats up, another cools. This ripple effect will define 2026. The real challenge isn’t spotting the next seasonal wave but choreographing the timing between overlapping ones"
JANUARY 2026 / CXO DX
31
» COLUMN
THREE WAYS ORGANISATIONS CAN REDUCE RISK ON THEIR AI JOURNEY
James Hendergart, Senior Director, Technology Research, F5 discusses three practices that will help de-risk the plunge into generative and agentic AI.
I
nnovation is one thing. Governance is another. A concerning mix of statistics from research surveys confirms that generative AI adoption by corporations is moving full steam ahead despite governance gaps that should cause pause.
According to PWC’s AI Agent Survey from May 2025, 79% of companies have adopted AI and only 2% are not considering agentic AI at all. Regardless of whether those agents display truly agentic characteristics—such as the ability to generate work plans and execute multi-step actions, evaluate results, and self-adjust—or if they are chat bots funneling one-off requests out to a selected large language model (LLM), adoption is very high, and nearly all of those companies are planning to increase spending on AI in the coming year. Compare with our own research—which uses an AI Readiness Index to quantify operational capacity to successfully scale, secure, and sustain AI systems—only 2% of organisations are highly ready to tackle the challenges inherent in AI-enabled system design, deployment, and operations. Still, IT and security teams have no choice based on EY research, which shows a majority of business leaders believe they must adopt agentic AI this year in order to get ahead of their competitors by this time next year. Organisations who slow down enough to thoughtfully close the security and governance gaps will find themselves further along with a less vulnerable business in 2026 than those who ignore them. The following three practices comprise a triumvirate that will help de-risk the plunge into generative and agentic AI.
1. Secure your models What’s new needs to be secured, and every form of generative AI has one or more LLMs at its core. Trusting the model creators to continually improve accuracy, reduce hallucinations, and prevent jailbreaking is not sufficient. Businesses must invest in prompt and model services, which can independently detect unwanted behaviours and stop them. Moreover, since every business using an LLM is actually using more than one, obfuscating applications from the inferencing API call is mandatory in order to provide for availability, routing, scaling, and cost control requirements of those applications.
2. Secure your data The enterprise data exposed to models may or may not be new data to the business. The fact remains it must be secured, and it is not merely securing data where it rests or encrypting it when it is moving across the network. Data existing in the private enterprise environment in any way, shape, or form, even to be used with an approved third-party service or by a third-party entity, must also be detected and protected. Do not misunderstand. Provenance is not the focus. Exit is the focus.
32
CXO DX / JANUARY 2026
James Hendergart Senior Director, Technology Research, F5
3. Secure your agents Agents change the game because they use LLMs to decide what actions to take to reach an end goal which they, themselves, decide. To operate, they need permission to do things, access resources, create, change, and delete information. They must be monitored and controlled by something outside the agent but close enough to it to effectively observe and evaluate it. Two primary approaches have emerged that deserve careful watch as they mature in the coming months: guardrail frameworks (such as MCP-Universe) and LLM-as-a-Judge frameworks (such as Microsoft LLM-as-aJudge Framework). The former defines ground truth using very specific task-based operations to compare the results of agent-initiated actions with separate actions pre-fetched by explicitly directed software. Its strength is the ever-growing domain of sample code to check for various facts like weather or historical facts using pre-selected and knowngood sources. It gathers the information then compares those results as ground truth against what a deployed agent comes up with. The latter uses a different LLM, even multiple LLMs, to analyse the behaviour of a deployed agent and evaluate the quality and propriety of its results as defined by the business. Both show promise, both are maturing rapidly, and both are under the control of the business. Even better, both can be reinforced with human-in-theloop controls, as needed. This triumvirate of controls covering models, data, and agents closes the gaps in cybersecurity and governance, which would otherwise expose a business to the new types of risk associated with generative AI and agentic systems.
» COLUMN
CYBER MATURITY IS ONLY AS STRONG AS YOUR WEAKEST LINK
Gregg Petersen, Regional Director for the Middle East, at Cohesity says that the leaders of 2026 will be those who recognize that true resilience is built collaboratively, not defensively As cyber threats grow more targeted and interconnected, resilience in 2026 will no longer be measured or defined by individual controls but the strength of the entire ecosystem and the operational capabilities it supports. Attackers in the region are increasingly exploiting the gaps that sit between cloud platforms, AI-driven applications, partners and suppliers, rather than attacking a single system in isolation. Cohesity’s research conducted on the sidelines of GITEX Global 2025 highlights how this challenge is playing out across the UAE. While 66 percent of organisations report full compliance with national data protection laws, one in three still struggle to keep up with evolving regulations. Nearly seven in ten organisations now review their AI governance practices every six months or less, showing that AI oversight is becoming a continuous operational requirement rather than an annual audit exercise. This shift reflects rising concern about shadow AI usage, volatile data flows and the need to ensure AI systems do not introduce new points of exposure. Despite strong confidence levels, 87 percent of organisations believe they can recover quickly from an incident, yet many still face difficulty validating the integrity of their data across multicloud environments and external service providers. The research shows that 62 percent of UAE organisations now monitor compliance directly across their third-party suppliers, signalling a sovereignty-first mindset where businesses take ownership of governing their wider ecosystem. The lesson is clear; the level of resilience capabilities is as strong as your weakest link. Whether that lies in a supplier’s cloud configuration, a partner’s data handling practices, or an internal team’s legacy system, one gap can undermine even the most sophisticated cyber strategies. As digital transformation reshapes the region’s digital ecosystems, attackers are increasingly targeting the connections between systems rather than single vulnerabilities. This is why organizations are beginning to treat AI governance as part of their core resilience strategy, since unmonitored AI models and unmanaged data flows can quickly become weak links in the wider ecosystem. • Data risk posture will become a board-level priority, driven by stricter regulatory expectations, AI-generated data flows and increased pressure to demonstrate clear oversight across cloud and third-party environments. • End-to-end data protection will become non-negotiable, with organisations expected to prove that critical datasets are recoverable across on premises, cloud and edge locations. • Verified recoverability will replace assumed recoverability, as organisations face growing scrutiny to demonstrate clean,
Gregg Petersen Regional Director for the Middle East, Cohesity sovereign and jurisdiction-aligned restoration during disruptions such as ransomware or wiper attacks. • AI governance will emerge as a critical pillar of cyber resilience, with organisations adopting continuous oversight of model behaviour, monitoring AI-driven data flows and enforcing strict guardrails to ensure AI systems do not introduce new exposure points across multicloud environments. As part of this shift, organizations will also need to ensure that AI models operate effectively across major languages rather than relying on English-first deployments. Without this level of internationalization, gaps can emerge in output quality, model accuracy and oversight, creating new governance blind spots that weaken overall resilience. • Sovereign AI adoption will accelerate, as organizations, cities, and nations seek to maintain control over how data is stored, processed, and governed within their borders. Increasingly, organizations and governments are recognizing the advantages of keeping data within their own corporate or geographic boundaries, using sovereign AI. While this strengthens privacy, compliance, and strategic autonomy, its long-term value will depend on how effectively it is balanced with innovation, interoperability, and cross-border collaboration. • Operational resilience will redefine cyber maturity, with organisations routinely testing applications, identity systems and recovery playbooks to build real-world readiness and reduce downtime. In 2026, cyber maturity won’t be about the strength of individual defences but the collective integrity of the digital ecosystem. The future belongs to those who treat resilience as a team sport. JANUARY 2026 / CXO DX
33
» COLUMN
POST-QUANTUM CRYPTOGRAPHY: THE STATUS QUO AND NEED FOR ACTION Bas Westerbaan, Principal Research Engineer, Cloudflare says regardless of when Q-Day occurs—2034 or 2050—most experts agree it will come too soon for organisations that delay preparation The Path to Q-Day: Hardware and Software Progress Two developments influence the arrival of Q-Day: advancements in quantum hardware and improvements in the algorithms that run on these machines.
Hardware Progress Every year brings new quantum processors boasting higher qubit counts. But qubits are fragile, and noise limits their reliability. Silicon-based quantum computers are fast and scalable, but extremely noisy—requiring millions of qubits with error correction to break RSA-2048. Ion-trap systems are quieter but harder to scale; even hundreds of thousands of qubits could threaten RSA2048.
Bas Westerbaan Principal Research Engineer, Cloudflare
Scalability remains a challenge, but Google’s Willow project— announced in late 2024—demonstrated the first scalable implementation of a logical qubit using surface code, a major milestone. Google continues to advance superconducting qubits, while Microsoft explores topological qubits, a theoretically much more stable but not yet proven architecture. Other emerging approaches include neutral atoms and ion traps. Still, software optimizations have accelerated the threat more dramatically than hardware.
Software Breakthroughs
T
he rapid progress in quantum computing is reshaping long-term security planning. While today’s quantum computers cannot yet break widely used cryptographic algorithms, their future potential creates an urgent need to transition to post-quantum cryptography (PQC). Data intercepted today could be decrypted later in a “harvest now, decrypt later” scenario once a powerful quantum computer becomes available—a moment often referred to as Q-Day.
34
CXO DX / JANUARY 2026
In 2025, Craig Gidney’s work showed that breaking RSA-2048 requires fewer than one million superconducting qubits—down from earlier estimates of 20 million—bringing Q-Day about seven years closer, assuming a Moore’s law of qubit counts doubling every one-and-half years. Further optimisations are expected, but RSA-2048 will likely require at least a quarter million superconductig qubits. Occasionally, new dramatic algorithmic claims surface. In 2024, a proposed quantum algorithm by Yilei Chen briefly caused concern for lattice-based cryptography before being shown incorrect.
» COLUMN
This episode highlighted how heavily today’s PQC designs rely on lattice-based schemes, and how few viable alternatives exist. Quantum key distribution, often presented as a solution, is not scalable enough for widespread deployment.
ers, and certificate authorities. We expect the first PQ certificates available in 2026, with broader adoption by 2027.
How Soon Will Q-Day Arrive?
By 2025, PQC entered mainstream deployment. NIST standardised ML-KEM (FIPS 203) for key exchange and ML-DSA/ SLH-DSA for signatures (FIPS 204/205). ML-KEM is now widely supported in TLS, browsers, and operating systems. ML-DSA support in certificates is progressing but not fully integrated.
While no one can predict the exact date, governments are not waiting. The U.S. NSA’s CNSA 2.0 guidelines set migration targets for 2030–2033, while the U.S. federal government aims for full adoption by 2035. Australia plans completion by 2030, and the UK and EU expect transitions between 2030 and 2035. Regardless of when Q-Day occurs—2034 or 2050—most experts agree it will come too soon for organisations that delay preparation.
Two Migration Priorities: Key Exchange and Signatures Transitioning to PQC involves two critical components: key agreement and digital signatures. Symmetric encryption (like AES-GCM) is already considered safe against quantum attacks. Grover’s algorithm does not require doubling key sizes, so AES-128 remains robust. Increasing to AES-256 is optional. The real vulnerability lies in traditional asymmetric cryptography—RSA and ECC—which quantum computers can break using Shor’s algorithm. Organisations must prioritise replacing these systems rather than strengthening symmetric encryption.
1. Post-Quantum Key Agreement Key agreement is urgent because it prevents harvest-now/decrypt-later attacks. Today’s TLS handshakes rely on X25519, which collapses under quantum attack. Post-quantum methods like ML-KEM can be integrated into existing systems with minimal disruption. Cloudflare already protects about half its traffic using hybridfully post-quantum key exchange methods, and all major browsers now support PQC by default.
2. Post-Quantum Signatures and Certificates Digital signatures authenticate identities online. RSA and ECDSA signatures will be forgeable by quantum computers, but replacing them is far more complex than updating key exchange. TLS handshakes use multiple signatures, certificate chains are long, and post-quantum signatures tend to be much larger. NIST has standardised ML-DSA and SLH-DSA for signatures, but wide adoption requires updates to certificate formats, brows-
Where PQC Stands Today
Meanwhile, Cloudflare, Google, and browser vendors have spent years testing hybrid approaches like X25519MLKEM768 to ensure compatibility, performance, and resilience during the transition. Despite early friction—largely due to middleboxes expecting classical packet sizes—over 50% of global internet traffic is now protected against quantum-era decryption attacks.
The Harder Part: PQ Signatures Signatures remain the biggest hurdle. ML-DSA-44 adds around 15 KB of extra data to each TLS handshake—too heavy for slow mobile networks. FN-DSA-512 reduces this overhead but introduces side-channel risks from floating-point operations. Experimental schemes like SQISign, MAYO, SNOVA, and UOV offer trade-offs between size, performance, and security, but none are ready for large-scale deployment. That is why we’re working with Chrome on Merkle Tree Certificates, a next generation of certificates, that brings post-quantum without performance degradation. For now, ML-DSA-44 is the most realistic starting point, even if not ideal.
What Organisations Should Do Now Companies should act on two priorities: 1. Adopt post-quantum key exchange immediately. Use hybrid modes like X25519 + ML-KEM-768 to prevent harvest-now/decrypt-later attacks. Tools such as Cloudflare Radar and Wireshark can verify support. 2. Prepare for PQ signatures. Identify high risk uses of cryptography,, modernise outdated systems, enable automated certificate management, and begin testing PQ-ready infrastructure. The global transition to PQC is an opportunity to modernise decades of legacy cryptography. Those who start early will be ready long before Q-Day arrives.
JANUARY 2026 / CXO DX
35
» TECHSHOW
AXIS Q3558-LVE DOME CAMERA Built on ARTPEC-9, this robust AI-powered camera with support for AV1 codec offers accelerated performance to run impressive analytics applications on the edge. Furthermore, AXIS Audio Analytics can detect critical sounds, adding an extra layer of security. AXIS Q3558-LVE offers outstanding image quality and forensic details in 8 MP resolution, even in harsh weather and environments. It features OptimizedIR, and an innovative IR-shielded dome prevents IR reflections from rain and snow ensuring clear, sharp images every time. Lightfinder 2.0 and Forensic WDR ensure true colors and great detail in near darkness or challenging light. Furthermore, electronic image stabilization keeps the image steady when the camera is subject to vibrations. Featuring a deep learning processing unit (DLPU), this AI-based camera runs advanced features and powerful analytics on the edge. It comes with AXIS Object Analytics preinstalled to detect, classify, track, and count humans, vehicles, and types of vehicles. Now combined with ARTPEC-9, this application offers enhanced performance with greater accuracy. With an acoustic sensor and support for AXIS Audio Analytics, you be notified whenever something relevant happens, even when there's no visual indication. For instance, it can detect screams, shouts, as well as changes in sound level. Additionally, AXIS Image Health Analytics comes preinstalled, so you’ll be notified if your image is blocked, degraded, under-exposed, or redirected. Made from high-grade aluminum, this robust, IK10-, IP66-, IP6K9K- and NEMA 4X-rated outdoor-ready camera is both vandal- and impact-resistant. It has an operating temperature range
from -50°C to 55 °C (-58 to 131°F). And a built-in intrusion switch can detect tampering. It can be powered with DC and PoE to ensure power redundancy. Highlights: • Outstanding image quality in 8 MP • Next-generation AI-powered analytics • R-shielded dome to prevent reflections • AXIS Audio Analytics preinstalled • Built-in cybersecurity with Axis Edge Vault
D-Link DAP-X3060W AX3000 D-Link DAP-X3060W AX3000 Wi-Fi 6 Wall-Plate Access Point is a compact in-room solution designed for hospitality, education, enterprise, and multi-dwelling environments. Its discreet wall-mounted form factor fits standard junction boxes, delivering high-speed connectivity directly to guest rooms, classrooms, offices, and individual living units while supporting both wireless and wired endpoints such as smart TVs, IP phones, and PCs through integrated PoE and multiple Gigabit LAN ports. Powered by Wi-Fi 6 with dual-band AX3000 throughput, OFDMA, and MU-MIMO, the DAP-X3060W ensures smoother streaming, lower latency, and consistent performance in high-density environments. Built with D-Link’s MIT-quality engineering and secure, intelligent design, it provides a scalable foundation for modern smart spaces. When paired with D-Link Nuclias Network Controller, organizations can simplify deployment and achieve centralized management across entire properties, fulfilling D-Link’s commitment to enabling intelligent connectivity for the next generation of digital environments.
Highlights: • Optimized for guest rooms and suites, the DAP-X3060W delivers seamless high-speed Wi-Fi and room-specific coverage without intrusive hardware. Multiple LAN ports support in-room devices, while VLAN segmentation and WPA3 security ensure guest privacy and hotel network protection.
36
CXO DX / JANUARY 2026
» TECHSHOW
DELL POWEREDGE XE7740 SERVER WITH INTEL GAUDI 3 PCIE ACCELERATORS Dell ihas ntroduced the PowerEdge XE7740 server, featuring Intel Gaudi 3 PCIe accelerators. With this, Dell is proud to be the first to market with an integrated server configuration featuring the new Intel Gaudi 3 PCIe AI accelerator. The PowerEdge XE7740 is designed to offer powerful AI acceleration, flexibility and performance. The 4U PowerEdge XE7740 delivers the ease of integration of the PowerEdge R-Series with the performance and scalability of PowerEdge XE-Series, advanced networking and powerful accelerator configurations to meet the growing needs of AI development. Whether fine-tuning AI models for specific business workflows or running high-performance inferencing, the XE7740 simplifies deployment, improves operations and sets new benchmarks for AI price vs. performance. Enterprise business and industries like financial services, healthcare, manufacturing, telecommunications and retail will have even more freedom to choose rightsized AI infrastructure. In addition to raw computing power, this server delivers flexible networking with up to a 1:1 accelerator to Network Interface Card (NIC) ratio through eight full-height PCIe slots and an integrated OCP networking module. With frictionless integration into existing infrastructures, the XE7740 overcomes the power-per-rack limitations many enterprises face, operating efficiently in ~10kW racks common in existing data centers.
In addition to raw computing power, this server delivers flexible networking with up to a 1:1 accelerator to Network Interface Card (NIC) ratio through eight full-height PCIe slots and an integrated OCP networking module.
Highlights: • The XE7740 accommodates up to eight double-wide or PCIe accelerators. • Configurations supporting up to 8 individual Gaudi 3 accelerators, the XE7740 optionally offers two groups of 4-way bridged accelerators. • 4-way Gaudi 3 PCIe accelerator bridging integrates 1,200 GBps combined throughput for accelerator-to-accelerator communication over 18x 200GbE interfaces using Remate Direct Memory Access (RDMA) over Converged Ethernet (RoCE v2). • Accelerator-to-accelerator bridging is crucial for larger-scale AI models and larger memory spaces, ensuring workflow scalability and flexibility.
• Ideal for classrooms, lecture halls, and dormitories, the compact wall-mount AP supports simultaneous connections for large numbers of student devices. PoE installation simplifies campus deployments, and centralized management improves IT oversight across buildings and campuses. • For offices, meeting rooms, and collaborative workspaces, the DAP-X3060W provides fast Wi-Fi 6 connectivity with consistent, room-by-room coverage. Its low-profile design reduces visual clutter, while Nuclias offers scalable, organization-wide network control. • In apartments and shared living spaces, the DAP-X3060W delivers stable, high-performance Wi-Fi with reduced interference between units. Secure tenant isolation via VLAN and WPA3 encryption ensures each resident enjoys private, reliable connectivity.
JANUARY 2026 / CXO DX
37
» TRENDS & STATS
52% OF GOVERNMENT CIOS OUTSIDE OF THE U.S. EXPECT IT BUDGETS TO INCREASE IN 2026 IT Investments to Rise Despite Overall Budget Pressures Fifty-two percent of government CIOs (not including the U.S.) expect their IT budgets to increase for AI and other key technologies in 2026, according to a survey by Gartner, Inc., a business and technology insights company. This is despite overall budget pressures, with governments recognizing their transformational potential for modernizing public services and achieving critical mission objectives. The 2026 Gartner CIO and Technology Executive Survey gathered data from 2,501 respondents from May 1 to June 30, 2025, including 284 government CIOs (not including the U.S). “Geopolitical shifts and economic volatility are forcing government CIOs to rapidly adjust their priorities for next year,” said Arthur Mickoleit, Director Analyst at Gartner. “They are being asked to demonstrate the mission impact of technology investments – including, but not limited to, cost savings and user experience.” The top four technologies government CIOs (not including the U.S.) plan to increase investments in next year are cybersecurity (85%), AI (80%), generative AI (80%) and cloud platforms (76%). AI Deployments to Accelerate According to the survey, 74% of government CIOs (not including the U.S.) have already deployed or plan to deploy AI within the next 12 months, with GenAI higher at 78%. Interest in AI agents is also rising, with 49% reporting current or planned deployment in the next 12 months (see Figure 1). Figure 1: State of AI Deployments in Government (not including the U.S.)
“Agentic AI is emerging as an enabler of government transformation, but CIOs must remain mindful of the hype that can distract from more mature technologies like machine learning and business process automation,” said Mickoleit. “This next wave of innovation will be essential for delivering on public sector priorities, especially as expectations are high following years of investments in digital government.” The survey reveals high expectations for both AI and other key technologies as government leaders focus on building a more productive workforce in 2026. More than half (51%) of government CIOs (not including the U.S.) will increase focus on boosting employee productivity next year, followed by launching new digital products and services (38%) and improving the overall citizen experience (37%). “CIOs should prioritize AI initiatives that rapidly improve internal efficiency and productivity,” said Mickoleit. “At the same time, governance practices must be updated to modernize procurement, manage limited resources and balance risks with opportunities in citizen-facing AI applications.” Reassessing Vendor Relationships Amid Global Uncertainty According to the survey, 55% of government CIOs (not including the U.S.) expect changes in how they engage with technology providers due to rising geopolitical tensions and digital sovereignty concerns. Location is now a defining factor in procurement decisions next to cost or scale, with 39% of government CIOs (not including the U.S.) planning to work closer with technology providers based in their own region. “Government CIOs are increasingly seeking to reduce dependence on global technology vendors to strengthen resilience,” said Mickoleit. “Many are now factoring geopolitical risk into vendor selection and long-term planning. Mapping risks and dependencies across public sector technology stacks will ensure they can mitigate and absorb future disruptions.”
Source: Gartner (November 2025)
38
CXO DX / JANUARY 2026
HOSTED BY
OFFICIAL GOVERNMENT CYBERSECURITY PARTNER
OFFICIALLY SUPPORTED BY
SCAN HERE
ENQUIRE FOR 2026!
#gisecglobal
gisec@dwtc.com
SPONSORS & PARTNERS
JANUARY 2026 / CXO DX
39
40
CXO DX / JANUARY 2026