



![]()




The enterprise technology landscape across the Middle East is entering a far more demanding phase of transformation. Not very long ago, much of the region’s digital transformation narrative revolved around cloud adoption, modernization initiatives, and the acceleration of digital services. Today, however, multiple transitions are unfolding simultaneously across the enterprise technology ecosystem.
The rapid rise of sovereign AI initiatives across the GCC is now reshaping not just software strategies but infrastructure priorities as well. Governments and enterprises are increasingly focusing on localized compute environments, enterprise-owned infrastructure, AI factories, GPU clusters, and data center expansion as they attempt to build longterm AI capabilities with greater control, governance, and resilience. AI itself is no longer being viewed merely as a layer of applications and models, but increasingly as an operational capability that demands entirely new foundations beneath it.
At the same time, enterprises are also confronting growing operational complexity across cybersecurity, governance, observability, and infrastructure management. SOC modernization, AI-assisted security operations, real-time threat visibility, and continuous governance are becoming increasingly important as attack surfaces continue expanding across hybrid environments, cloud ecosystems, third-party dependencies, and AI-driven systems. The rise of digital workers and agentic environments is adding yet another dimension to this evolution, where organizations are beginning to explore systems capable not only of assisting humans, but increasingly participating in operational workflows and decision-making itself.
Navigating these shifts will require a far more holistic approach than simple technology adoption alone.
Our cover story in this issue explores how the region’s growing AI ambitions are accelerating investments into enterprise infrastructure, storage, compute, and localized data center ecosystems. Alongside this, our feature on operational intelligence examines how organizations are attempting to move beyond static dashboards and siloed monitoring models toward more connected, contextual, and real-time operational environments. As enterprise ecosystems become increasingly autonomous, distributed, and interconnected, the ability to operationalize intelligence responsibly may well become one of the defining enterprise capabilities of the years ahead.
RAMAN NARAYAN
Co-Founder & Editor in Chief narayan@leapmediallc.com Mob: +971-55-7802403
Ali Raza Designer
R. Narayan Editor in Chief, CXO DX
SAUMYADEEP HALDER
Co-Founder & MD
saumyadeep@leapmediallc.com Mob: +971-54-4458401
MALLIKA REGO
Co-Founder & Director Client Solutions mallika@leapmediallc.com Mob: +971-50-2489676

14
As AI infrastructure demand accelerates across the Middle East, ASBIS is increasingly positioning itself around the region’s evolving ecosystem spanning data centers, GPUs, enterprise storage, and AI-ready compute environments
16
As enterprises across the Middle East continue modernizing infrastructure, the challenge is no longer visibility alone but transforming operational telemetry into actionable intelligence
Francesco Colavita, Global Vice President - Consulting at JAGGAER, explores why contracts must evolve from static documents into executable, data-driven assets
Gabriele Obino, VP Southern Europe & Middle East at Denodo, discusses why trusted, real-time, and well-governed data foundations are becoming critical as enterprises move toward largescale agentic AI adoption
Meriam ElOuazzani, VP, META at Censys, discusses how AI-driven threats and expanding attack surfaces are forcing organizations to rethink traditional SOC models
Vibhu Kapoor, Regional Vice President - Middle East, Africa & India at Epicor, explores why manufacturers must move beyond traditional pricing models and use ERP, real-time data, and AI-driven intelligence to protect margins
Tim Freestone, Chief Strategy Officer at Kiteworks, examines how a growing wave of AI security vulnerabilities is exposing deeper weaknesses around trust boundaries, access control, and process containment
Lori MacVittie, Distinguished Engineer and Chief Evangelist at F5, explores how the rise of agent skills as an emerging open standard is reshaping the security model for autonomous AI systems
Michael Cade, Global Field CTO at Veeam Software, explores why data sovereignty, visibility, and governance are becoming increasingly critical
Diego Arrabal, Vice President, Eastern Europe, Middle East and Africa at Check Point Software Technologies, explores how the rapid integration of AI across the UAE’s digital ecosystem is reshaping cybersecurity
As regional demand for low-latency, in-country AI compute accelerates, Submer positions itself as the end-to-end partner for AI datacenter delivery
Submer, a market leading AI infrastructure provider, announced the expansion of its technology portfolio and global service capabilities with the acquisition of Radian Arc Operations Pty Ltd earlier this year. This consolidates its position as a full-stack AI infrastructure provider and broadening its capacity to serve enterprises and telecom operators throughout the Middle East.
Khalid Aljamed, General Manager, Middle East, Turkey & Africa, Submer said, "We have spent a decade as market leaders in liquid cooling, and that foundation has allowed us to move into something much bigger, being fully accountable for AI infrastructure from the chip level all the way through to live operations. The Middle East is a region where the ambition for AI leadership is very real, and where operators need a partner that can deliver, not just advise. Operators and governments want sovereign AI infrastructure that works today, generates revenue, and scales tomorrow.
We are one of very few companies that can genuinely deliver across every layer of that stack.”
The company’s full-stack cloud offering brings together inferX, Submer Group’s NVIDIA Cloud Partner (NCP) AI cloud and edge company launched earlier this year, with Radian Arc’s edge GPU infrastructure platform. The result is a dual-plane infrastructure model, sovereign, telco-grade cloud services operating both at the core and at the network edge, giving operators the ability to run high-performance AI workloads closer to end users, with data remaining firmly within national borders.
Submer Group's expanded portfolio now spans the complete AI infrastructure stack. The company has access to over 5GW of land and power pipelines across the UK, USA, India, and the Middle East through established partner consortiums, providing
The network currently includes approximately 17,000 access points and 10,000 switching and routing devices.

HPE has announced that Red Sea Global (RSG), the developer behind regenerative tourism destinations The Red Sea and AMAALA, is using a self-driving networking designed by HPE as its foundational network architecture for its largescale expansion of its resorts. The new agile, future-ready network, featuring secure, AI-native switching and Wi-Fi, helps RSG scale efficiently while maintaining sustain-
ability, operational excellence, and premium digital engagement for visitors.
Aligned with Saudi Arabia’s Vision 2030, RSG’s current destinations expect to add $8.79 billion annually to Saudi Arabia’s economy and create 120,000 jobs when fully complete. To support this, RSG requires a secure, seamless, Wi-Fi-centric guest experience across a significantly expanded footprint. Its foundational network architecture, built on HPE Aruba Networking, enables intelligent, secure, always-on connectivity that supports smart destination management, real-time environmental monitoring, and highly personalized guest experiences.
“Choosing an AI-native self-driving network solution that meets our need for seamless connectivity while supporting our

the raw capacity to support next-generation AI deployments at scale. Its AI cloud business unit combines inferX with sovereign, telco-focused edge cloud capabilities and AI inference services. This is complemented by end-to-end design and build expertise for turnkey, modular datacenters, whether enterprise-scale or hyperscale-class.
expansion plans was a critical priority for us,” said Sultan Moraished, Group Head of Technology and Corporate Excellence, Red Sea Global. “By selecting HPE, we are not only addressing day-to-day connectivity needs for our guests but also enabling a foundational digital platform that supports our broader strategic vision of delivering exceptional guest experiences.”
The Wi-Fi first environment leverages HPE Aruba Networking Wi-Fi 6E, supported by an end-to-end enterprise network that spans from the data center core to the edge. The network currently includes approximately 17,000 access points and 10,000 switching and routing devices. RSG leverages HPE Aruba Central AIOps for insight, automation and assurance, alongside HPE Aruba Networking CX switching to deliver consistent, high-performance connectivity across multiple locations, supporting resort development across Saudi Arabia’s diverse landscape.
Additionally, HPE Aruba Networking EdgeConnect Enterprise appliances are deployed, complete with bandwidth, security and high availability licenses for guests. This SD-WAN solution simplifies network architecture, improves orchestration and enhances application performance.
Availability across EMEA gives customers choice and control over data, AI workloads, and critical digital infrastructure
Cisco, has launched its Sovereign Critical Infrastructure (SCI) portfolio for customers across Europe, the Middle East and Africa (EMEA). Cisco Sovereign Critical Infrastructure addresses the needs of organizations to innovate at pace while maintaining even greater control and autonomy over their data and digital infrastructure.
The portfolio spans Cisco’s core product lines including networking, security, compute, collaboration, network management, AI and Splunk. Customers can configure and operate it in their own air-gapped, on-premises physical environments.
SCI is designed to support customers at different stages of their digital sovereignty journey. Built around the principle that there is no one-size-fits-all approach, the portfolio gives organizations with a need for digital sovereignty the flexibility to
choose the model that best meets their needs, whether fully on-premises, airgapped environments for maximum control or hybrid approaches that combine sovereign infrastructure with cloud services. By addressing key customer priorities around data control, operational autonomy, and freedom from dependency, Cisco helps organizations strengthen resilience while maintaining choice and control over their digital infrastructure.
“In the UAE, we are seeing strong demand from organizations that want to accelerate innovation while maintaining tighter control over critical data, systems, and operations. This is especially important as AI, security, and infrastructure strategies become more closely connected. Cisco’s Sovereign Critical Infrastructure portfolio gives customers the ability to build secure, customer-controlled environments that support

resilience, compliance, and long-term digital growth. Backed by Cisco Customer Experience, we are helping organizations in the UAE create trusted infrastructure that is ready for both today’s operational needs and tomorrow’s AI opportunities,” said Abdelilah Nejjari, Managing Director for Gulf and Levant at Cisco.
The new AIoT offerings combine engineering, AI, automation, cybersecurity, and digital twin technologies to enable real-time, outcome-driven operations across manufacturing, energy, and smart city environments.
Omnix International, a leading technology solutions provider in the Middle East, has announced the launch of its Artificial Intelligence of Things (AIoT) offerings. This marks another significant milestone in Omnix’s strategy to address evolving industry needs by connecting engineering, infrastructure, cybersecurity, digital platforms, and AI into integrated business solutions.
These intelligent connected environments are designed to sense, analyze, and act in real time, enabling outcome-driven operations across sectors such as manufacturing, energy, and smart cities, where operational resilience, efficiency, and responsiveness are increasingly critical.
Walid Gomaa, CEO of Omnix International, said: “We are focused on building cross-domain offerings that combine engineering and digital capabilities into differentiated business value. Our approach brings together engineering, smart infrastructure, AI, automation, cybersecurity, and digital twin technologies into a single integrated framework. This enables orga-
nizations to connect and secure physical assets, operational data, and AI-driven decision-making in a way that delivers measurable business outcomes.”
The new offerings also bring together the complementary strengths of AIoT, Agentic AI, and Conversational AI. While AIoT provides the real-world signal layer through connected devices, sensors, telemetry, and operational data, Agentic AI adds decision logic and task orchestration. Conversational AI serves as the interaction layer, allowing operators, engineers, supervisors, and customers to engage with systems in natural language.
The GCC, particularly the UAE and Saudi Arabia, continues to play a leading role in accelerating the adoption of advanced technologies that support sustainability, efficiency, and real-time responsiveness. In this context, the launch of Omnix’s AIoT offerings is both timely and highly relevant.
“For us, AIoT is not a side initiative; it is a key enabling layer that links physical
Goma CEO, Omnix International

assets, operational data, and intelligent decision-making. We are addressing core customer challenges such as fragmented operational data, limited real-time visibility, and slow response to operational events. At the same time, our engagement models are flexible enough to support managed services, outcome-based, and platform-led requirements,” Gomaa added.
Delivered by Acronis TRU, the service enables MSPs to provide threat detection, rapid response, and cyber resilience
Acronis, a global leader in cyber protection, has announced the launch of Acronis MDR by Acronis TRU, a globally available 24/7/365 managed detection and response (MDR) service. Built specifically for managed service providers (MSPs) of any size, the highly accessible service provides threat detection, rapid incident response, and cyber resilience powered by the Acronis Threat Research Unit (TRU). With this service, MSPs can expand their security offerings and deliver scalable protection without the complexity or cost of operating an in-house security operations center.
As cyber threats grow in sophistication and frequency, many MSPs struggle to deliver advanced security services due to the cost, expertise, and infrastructure required. Acronis MDR by Acronis TRU addresses this challenge by delivering continuous monitoring, rapid threat containment, and expert incident response powered by the Acronis Threat Research Unit, helping MSPs
strengthen client security while reducing operational overhead.
Unlike traditional MDR services that rely on multiple tools for detection, remediation, and recovery, Acronis MDR by Acronis TRU provides an integrated, globally available solution optimized for MSPs of all sizes. The service combines endpoint detection and response with integrated proactive protection via patch management and built-in business continuity capabilities, enabling faster incident response, streamlined management, and improved cyber resilience.
“Acronis MDR by Acronis TRU was built to make advanced detection and response accessible globally to MSPs of any size,” said Gaidar Magdanurov, President at Acronis. “Unlike traditional MDR services, Acronis MDR combines proactive protection, integrated business continuity, and Acronis’ expertise so MSPs have the abil-

ity to deliver secure, high-quality MDR to their clients while minimizing complexity and costs.”
Acronis MDR by Acronis TRU enables MSPs to expand their service portfolio with a scalable, cost-efficient solution that integrates detection, response, and recovery in a single platform for end-to-end cyber resilience and business continuity.
The integrated solution enables organisations to meet regulatory requirements while delivering tangible financial benefits to UAE-based finance teams
CPX Holding, a leading provider of cutting-edge cyber and physical security solutions and services, and SpendConsole, a global leader in AI-powered finance automation, announced a strategic partnership to launch the UAE’s first sovereign, mandate-ready e-invoicing platform.
The joint solution enables the UAE’s public and private sector entities to meet the Ministry of Finance’s new e-invoicing regulations, which will enter into voluntary effect on 1 July 2026, before becoming mandatory in phases from 2027.
The UAE’s e-invoicing mandate also establishes a national foundation for real-time financial governance, standardised digital tax compliance and secure data exchange across public and private sectors. This shift gives organisations a unique opportunity to modernise their accounts payable operations, strengthen internal controls and adopt global best practices beyond basic compliance requirements.
The collaboration responds directly to the
national shift towards standardised digital invoicing, including incorporating structured XML formats to improve efficiency, reducing manual errors and strengthening tax compliance across B2B and B2G transactions.
Through this partnership, CPX and SpendConsole will provide an integrated solution that enables organisations to meet regulatory requirements while delivering tangible financial benefits to UAE-based finance teams. The platform combines SpendConsole’s AI-powered finance automation and e-invoicing capabilities with CPX’s cybersecurity assurance, compliance reporting, secure data hosting and continuous SOC monitoring, ensuring audit-ready processes and trusted digital exchanges.
Beyond regulatory compliance, the collaboration aims to support the UAE’s AI and Digital Economy Strategy by accelerating enterprise uptake of AI, strengthening national tax transparency and reducing fraud risk and VAT leakage.

“Secure, compliant and intelligent financial systems are essential to building confidence in the UAE’s digital economy and long-term national objectives. Through our collaboration with SpendConsole, we are delivering a cutting-edge solution that combines advanced cybersecurity with AI-driven finance automation. The partnership positions CPX as a trusted enabler of the Ministry of Finance’s e-invoicing mandate while extending our role beyond cybersecurity into enterprise finance transformation,” said Hadi Anwar, CEO of CPX.
New Alteryx AI Insights Agent delivers insights through analyst-defined AI ready datasets and business logic within governed workflows

Alteryx, an AI-ready data and analytics company, has announced the launch of the Alteryx AI Insights Agent, now available on Google Cloud Marketplace, bringing governed analytics directly into Gemini
Enterprise. As companies increasingly turn to AI to drive decisions, a critical gap has emerged between speed and trust. While generative AI is reshaping how work gets done, most approaches still fall short in enterprise environments where accuracy, governance, and control are essential. AI-generated responses are often inconsistent with business metrics, difficult to validate, and not aligned with how organisations actually operate. Nearly half of leaders cite high-quality, accessible, and well-governed data as the top factor for agentic AI to reach its full potential, underscoring the gap between AI capability and enterprise readiness.
“At the core of enterprise AI is trust,” said Ben Canning, Chief Product Officer at Alteryx. “When it comes to decisions like pricing, operations, or compliance, accuracy isn’t optional. AI doesn’t just need data — it needs to understand how the business actually works. That means applying
defined logic, rules, and context that the people closest to the work understand and continuously evolve. With the AI Insights Agent, we’re bringing that logic directly into Gemini Enterprise, so every answer is consistent, explainable, and ready to drive action.”
The Alteryx AI Insights Agent allows information workers to define governed datasets and business logic within Alteryx One that are executed in response to user queries in Gemini Enterprise. Instead of generating answers from raw or unstructured data, the agent leverages in-place analytics to run predefined workflows directly on data platforms such as BigQuery, ensuring outputs align with business metrics without the need for data movement or manual effort.
“Bringing AI Insights Agent to Google Cloud Marketplace will help customers quickly deploy, manage, and grow the agent on Google Cloud's trusted, global infrastructure," said Dai Vu, Managing Director, Marketplace & ISV GTM Programs at Google Cloud. “Alteryx can now securely scale and support customers on their digital transformation journeys.”
This will help secure AI Agents with integrated discovery, governance, and runtime protection
Check Point Software Technologies Ltd announced that it will serve as a launch partner with Google Cloud to integrate Check Point's AI Defense Plane with Google Cloud's Gemini Enterprise Agent Platform. The integration will combine centralized agent control with contextual intelligence and real-time behavioral protection to deliver comprehensive security for enterprises deploying AI agents at scale.
As enterprise AI moves beyond chat assistants to autonomous agents that invoke tools, query data, and execute workflows, traditional security controls are insufficient, and security is no longer just about who has access, but what AI is allowed to do. Organizations need guardrails at the point where AI risk becomes real: runtime, in production, across live agent interactions.
"The emerging architecture for agentic security requires three layers: a control plane for identity and connectivity, a gov-
ernance layer for policy enforcement, and a runtime intelligence layer for behavioral protection," said David Haber, VP of AI Security at Check Point Software Technologies. "Google Cloud's Enterprise Agent Platform provides the control plane. Check Point adds the other two. We govern which agents, tools, and connections are allowed, and we inspect every action at runtime to determine whether it should proceed because in agentic systems, access alone doesn’t guarantee the right outcome."
This integration will deliver three layers of agent security:
• Full Visibility into Agent Estate: automatically inventories all agents deployed across Google Cloud environments, including their components, tools, and Google Cloud Model Context Protocol (MCP) server connections.
• Enforce Controls Before Deployment: enables security teams to define and enforce policies: allow and deny lists for

MCP servers, tools, and skills; agent posture policies that flag or block risky configurations; and centralized policy management across the entire agent estate.
• Runtime Guardrails in Production: adds real-time, context-aware protection inline with Agent Gateway.
The multi-agent system provides real-time visibility, explainable AI decisions and outcomes focused insights across complex, multivendor environments
NTT DATA, a global leader in AI, digital business and technology services, announced the launch of NTT DATA Software Defined Infrastructure (SDI) Services Agent, a conversational agentic service experience for enterprise infrastructure. Embedded within NTT DATA’s SDI Services, this multi-agent system is redefining how enterprises operate, optimize and govern AI infrastructure at scale.
The SDI Services agent acts as an orchestrator selectively triggering the appropriate agents in the background. This multi-agent system continuously senses, reasons and acts across networking, hybrid data center, cybersecurity and digital workplace environments – delivering predictive intelligence, faster resolutions and measurable outcomes across availability, utilization and business value.
This marks a significant evolution of NTT DATA’s SDI Services. Acting as a digital
twin for critical IT operational roles, the SDI Services agent fundamentally transforms how enterprises govern infrastructure using AI agents. For the first time, enterprises can interact with their multivendor infrastructure environment through natural language prompts, gaining persona-based insights to operate infrastructure confidently into the AI Era.
“Middle East and Africa organizations are under pressure to scale digital infrastructure while controlling cost and risk,” said Hani Nofal, Executive, Head of Technology Solutions, NTT DATA Middle East and Africa. “The SDI Services Agent helps enterprises across MEA shift from reactive operations to outcomedriven infrastructure, improving efficiency, resilience and time to value as they invest in AIled growth.”
Usually Original Equipment Manufacturer (OEM) AI assistants are limited to single-vendor ecosystems, the NTT DATA SDI Services Agent delivers enter-
DXC OASIS introduces a new managed services operating model that combines human expertise with agentic AI
DXC Technology has announced DXC OASIS, an intelligent orchestration platform that introduces a new managed services operating model. Designed as a single, governed, and secure layer, DXC OASIS integrates seamlessly across an organization’s existing IT estate. It reimagines how managed services are delivered by combining human expertise with agentic AI, shifting from reactive support to real-time, intelligent operations across the entire technology environment and enabling greater confidence in mission-critical operations. Leveraging decades of DXC delivery expertise, validated through DXC’s Customer Zero approach and shaped through direct customer collaboration, DXC OASIS connects every system, signal, and technology decision, bringing together human judgment and agentic AI to run critical systems with greater speed, clarity, and control.
Enterprises today operate across complex
multivendor environments, yet often lack a unified view of performance, cost, risk, and operational health. Technology estates have been built over years, often decades, resulting in siloed data and fragmented workflows that limit visibility and make it harder to act with speed and confidence. As a result, executives and IT leaders are often forced to navigate multiple disconnected systems to piece together the data and insights they need, slowing response times and increasing operational risk.
DXC OASIS addresses this complexity by establishing a trusted, enterprise-wide view of technology operations, bringing together data, workflows, and systems into one intelligent operating model. This enables teams to align actions, decisions, and outcomes across the enterprise in real time, so every action is traceable, and every insight is explainable.
“DXC is defining a new category in man-

Hani Nofal
Executive, Head of Technology Solutions, MEA, NTT DATA
prisegrade intelligence across complex, multivendor infrastructure environments. The agent also incorporates sustainability insights, helping organizations understand and optimize the environmental impact of their infrastructure estates.
NTT DATA’s Global AI Report: A Playbook for AI Leaders found that AI leaders are investing more in rebuilding their core applications with embedded AI capabilities rather than limiting themselves to surface-level add-ons (34.5% of those surveyed).

Chris Drumgoole
President, Global Infrastructure Services, DXC Technology
aged services. We have decades of trust, experience, and delivering reliable outcomes for the world’s leading enterprises,” said Chris Drumgoole, President, Global Infrastructure Services, DXC Technology. “ With DXC OASIS, we’re moving to real-time, orchestrated agentic operations across the entire IT environment. Purpose-built for modern, AI-driven estates, it gives customers clear, continuous control over performance helping them deliver increased business value.”
As agentic AI rapidly becomes the backbone businesses run on, Cequence delivers the governance layer that identity alone cannot provide Cequence Security, has announced the general availability of Agent Personas in Cequence AI Gateway. Agent Personas give enterprises granular, infrastructure-level control over what AI agents are permitted to do — down to the specific tool call — closing the critical privilege gap that identity alone cannot address.
As organizations deploy AI agents to connect to enterprise applications via the Model Context Protocol (MCP), a dangerous assumption has taken hold: that authenticating who an agent is amounts to controlling what it can do. It does not. Agents inherit the privileges of their users and, unlike humans, have no judgment about when not to use available access. Agent Personas solves this by using a plain-English job description to define a scoped virtual MCP endpoint for each agent role. For example, a customer service AI agent gets CRM read-only access, not the ability to modify records. A coding
agent can read GitHub issues and create Jira tickets but cannot merge pull requests. A CI/CD automation agent gets access to specific pipeline tools and a single notification channel, and nothing else.
The release also introduces Agent Access Keys, a new composite credential type purpose-built for headless agents running in automated workflows. Each key binds agent identity, user identity, and persona-level privileges into a single attributable credential, giving security teams the forensic clarity to answer exactly who did what, when, and under which permissions.
Early deployments show how Agent Personas govern AI agent access in complex environments. Scoped virtual endpoints ensured each agent accessed only what it needed, eliminating lateral access risks without extra infrastructure.
“Enterprises have made massive invest-

Ameya Talwalkar CEO and Co-Founder, Cequence
ments in AI, and the race to put agents into production across customer experiences, employee workflows, and business operations is accelerating fast,” said Ameya Talwalkar, CEO and Co-Founder at Cequence. “However, security, governance, and scale requirements can’t be ignored. Cequence closes the gap that has been holding organizations back by automatically limiting agent tool access which lowers costs, enhances performance, and improves security.”
New and upcoming multitenancy offerings and service validation programs are designed to help service providers scale efficiently while modernizing customer environments
Nutanix, a leader in hybrid multicloud computing, announced new platform and program enhancements for Nutanix Elevate Service Provider Program partners, including the new multitenant cloud capabilities enabled by the Nutanix Service Provider Central program designed to help partners scale and differentiate their services.
Service Provider Central with the Nutanix Cloud Platform (NCP) solution aims to provide a clear path for recently disenfranchised VMware Cloud Service Provider partners to continue offering profitable services to their customers. It is a new product that will be available in the second half of 2026 and is designed to address the pressing market need for an enterprise-grade multitenant Infrastructure as a Service (Iaas) on NCP.
Service Provider Central will offer a single pane of glass through Nutanix Central enabling service providers to run multiple tenants with automated workflows
on shared Nutanix infrastructure without compromising control or compliance.
Individual tenants will get their own private cloud environment with access to the familiar Nutanix Prism solution. Tenants will be able to manage their own compute, storage and networking, identity, and authorization. Service providers will maintain centralized operational control and governance.
New program offerings include a new “Powered by Nutanix: Verified Solutions” where service providers delivering offerings aligned with Nutanix best practices and architectural standards can earn official verification from Nutanix, helping customers more easily identify trusted, high-quality services built using Nutanix software.
“Service providers are playing an increasingly critical role in helping organizations modernize and adopt flexible cloud operating models, particularly across the Mid-

Shaista Ahmed
Director, Channel & OEM Sales, Middle East & Africa, Nutanix
dle East and Africa. With our enhanced multitenant capabilities and partner programs, we are enabling providers to scale efficiently, deliver differentiated services, and support customers as they transition to hybrid multicloud environments with greater confidence and control,” said Shaista Ahmed, Director, Channel & OEM Sales, Middle East & Africa at Nutanix.
Customers will benefit from improved product availability, localized technical expertise, and stronger pre- and post-sales support, enabling faster deployment cycles
Axis Communications, a global leader in network video, audio, analytics, and access control technologies, announced a regional distribution agreement with 360 Security Systems, a leading security and communications solutions provider operating across the Middle East and Africa (MEA).
The partnership is designed to strengthen the availability, deployment, and longterm support of Axis’ intelligent security solutions across a region experiencing accelerated infrastructure development, digital transformation, and increasing demand for resilient systems. By combining Axis’ network-based technology portfolio with 360 Security’s Systems regional execution capabilities, the agreement aims to deliver greater value to partners, system integrators, consultants, and end customers operating in complex and high-growth environments.
Through this collaboration, Axis will leverage 360 Security’s Systems multi-country
footprint, established logistics infrastructure, and proven channel development model to enhance market coverage and consistency across key MEA markets, including [Afghanistan, UAE, Egypt, Qatar, Kuwait, Oman, Bahrain, Jordan, Iraq, Lebanon, Libya, Pakistan, Palestine, Sudan, Yemen]. Customers will benefit from improved product availability, localized technical expertise, and stronger pre- and post-sales support, enabling faster deployment cycles.
Working in close collaboration with system integrators, consultants, and technology vendors, 360 Security Systems plays a critical role in bridging strategy and execution, ensuring that complex security projects are deployed, and maintained to meet both technical and operational requirements.
“This partnership represents a strategic step forward in how we support customers and partners across the Middle East and Africa,” said Loubna Imenchal, Managing Di-

rector for the Middle East, Türkiye, Central Asia and Africa at Axis Communications. “The region continues to invest heavily in national infrastructure, smart cities, and digital transformation initiatives. To support this growth, customers need not only advanced technology, but also strong local execution, consistency across markets, and partners who understand regional operational realities. 360 Security brings the scale, technical capability, and channel maturity that align closely with Axis’ longterm vision for the region.”
Appoints Laxmi Nageswari as Chief AI Officer
Cloud Box Technologies, a leading systems integrator and IT services specialist in the Middle East, announced its AI-first strategy with the introduction of a focused three-pillar framework led by Laxmi Nageswari as the Chief AI Officer (CAIO). This highlights how the company has evolved from a traditional IT infrastructure provider into a full spectrum digital transformation partner including AI, automation and cybersecurity.
The new role of Chief AI Officer establishes that Cloud Box Technologies is incorporating AI into the core of its offerings. Laxmi will guide the strategy, innovation, partnerships and capability development where AI is an integrated layer in all its offerings and not just a standalone service.
The company’s AI strategy is anchored on three pillars. Firstly, it covers AI-based cybersecurity, data analytics, automation and cloud integrated intelligence, making sure that AI is included in all its services. Next
is the Algo-as-a-Service (AaaS) model, which helps to deploy scalable, reusable AI models, speeding up time-to-market with consistency and accessibility for customers. At the heart of this strategy and supporting the other pillars is its Centre of Excellence (CoE). This serves as the hub for governance, innovation, and developing talent by providing best practices, helping with research and making sure that AI is adopted responsibly.
Together, they reshape AI from individual initiatives into a combined capability that is available across the whole company. It improves scalability, speeds delivery and strengthens the company’s long-term competitive positioning. Designed as an integrated innovation ecosystem, the strategy connects hardware, applications, and talent to create a cohesive platform for AI adoption.
Ranjith Kaippada, Managing Director at Cloud Box Technologies, said, “The intro-

duction of the three-pillar framework, and the strategic move to appointing Laxmi Nageswari to lead it strengthens our ability to deliver scalable AI-driven solutions and aligns our vision with the UAE’s National Strategy for Artificial Intelligence 2031. This will have a significant impact on how Cloud Box Technologies transforms into an all-encompassing digital transformation partner and harness AI effectively.”
The initiative has improved customer and partner experiences through faster order processing, more responsive approvals, and greater operational transparency across the value chain.
Mai Dubai, a leading bottled water company, has successfully completed an enterprise-wide automation programme using the Kissflow low-code, no-code platform. In just two years since deployment, the company has digitalised and automated 96 critical operational processes, all developed in-house without vendor dependency. This has significantly reduced manual workloads, accelerated turnaround times, and improved overall business agility.
Adrian D’Cunha, Head of Information Technology at Mai Dubai said, “We have always been committed to building a digital-first organisation. While our ERP system remains central to our operations, many of our challenges exist around it, not within it. We recognised that a low-code, no-code platform would allow us to rapidly build and customise applications, integrate data across systems, and digitise workflows without disrupting our core SAP environment.”
Operating with a lean IT team, Mai Dubai moved at remarkable speed following implementation of Kissflow’s low-code, no-code platform in November 2024. Within months, the company began rapidly scaling automation, going on to build 96 processes spanning sales order creation, invoice approvals, discount approvals, and a wide range of workflows that previously relied on manual intervention or fragmented systems.
A standout example of this capability is Mai Dubai’s fleet management system. Rather than investing in a separate, off-the-shelf solution, the company designed and deployed a fully functional fleet management system using Kissflow’s workflow and application-building capabilities. This not only reduced costs and implementation timelines, but also ensured the system was tailored precisely to Mai Dubai’s complex and expansive operations, demonstrating the platform’s ability to replace traditional enterprise applications.
The impact has been substantial. By eliminating repetitive tasks and streamlining approvals, Mai Dubai has reduced process cycle times by up to 50%. This has not only improved internal efficiency but also enhanced experiences for customers and partners, enabling faster order processing, more responsive approvals, and greater operational transparency across the value chain.
Beyond automation, the platform has empowered business users to take ownership of innovation. Beyond large-scale systems such as fleet management, the platform has also enabled rapid innovation at the micro level. An example is the company’s merchandising system, which was conceptualised, built, and deployed in just 45 minutes. This demonstrates the speed and flexibility that low-code development can unlock.
“Kissflow bridged the gap between speed, efficiency, and governance for us. What started as a simple approval workflow evolved into a full-fledged application platform—deployed in

Adrian D’Cunha Head of Information Technology, Mai Dubai
weeks, scaled internally without third parties, and even extended to vendors. From building workflows in hours to launching a live merchandising module in 45 minutes, Kissflow has truly been a game changer,” D’Cunha said.
Prasanna Rajendra, Vice-President, EMEA at Kissflow added, “What stands out in Mai Dubai’s journey is not just the scale of automation, but the shift in how technology is consumed within the business. This is no longer solely about IT-led transformation — it’s about empowering operational teams to actively build, adapt, and optimize their own workflows, dramatically increasing the speed of execution. By creating a unified digital layer that connects people, processes, and data in real time, Mai Dubai has laid the foundation for a far more responsive and intelligent operating model. As adoption deepens, the value will compound with each new workflow and integration contributing to greater agility, insight, and long-term resilience.”
Today, Mai Dubai is leveraging the platform not just for automation, but as a foundation for data-driven decision-making. By consolidating workflows and integrating data from multiple systems, the company now benefits from real-time insights into its operations. This enhanced visibility is enabling more accurate planning and forecasting, improving resilience, and supporting more informed, proactive decision-making across the business.
As Mai Dubai continues its growth trajectory, its investment in low-code innovation, and its ability to build and scale business-critical systems in-house, positions it to remain agile, efficient, and responsive in an increasingly competitive market.
New pre-built Field Service Digital Workers for Planning, Dispatch and Knowledge Work enable service-focused businesses to rapidly mobilize agents out-the-box

IFS, a leading provider of Industrial AI software, announced strong and accelerating momentum for its agentic Digital Workers together with the launch of IFS Loops Agent Studio.
The power of Industrial AI is most pronounced when applied to industry-specific scenarios. Deploying Digital Workers to these scenarios is enabling organizations to drive efficiency across the business and deliver better products and services to customers.
Today’s milestone update sees IFS Loops now offer an Agent Studio that enables customers to configure, govern, refine, and expand Digital Workers for their business. Intuitively designed for non-technical, functional employees, IFS Loops Agent Studio requires no technical or coding knowledge.
IFS Loops Digital Workers arrive prebuilt with deep industry context, proven workflows, and enterprise-grade AI Trust controls -security, permissions, and governance guardrails defined out of the box. The powerful combination with Agent
Studio means organizations can focus on the business outcomes Digital Workers deliver, not the complexity of standing them up.
It is simple to set context, define a process, design actions, and test safely before deploying fully customized Digital Workers into production. The Agent Studio provides the ability to monitor operational outcomes, exceptions, and performance metrics, enforce governance guardrails, maintain auditability, and expand agentic capabilities incrementally as confidence grows.
Proven value of Industrial Digital Workers
Across multiple asset-intensive industries, the world’s most progressive industrial organizations are reporting measurable, real-world business outcomes from Digital Workers, including:
• 60% gain in operational efficiency and recovered 20 hours per week
• $3 million annual ROI and 90,000 hours returned to the workforce
Somya Kapoor, CEO, IFS Loops, said, "Building agents is easy – governing how they operate is the hard part. Digital Workers are not something you deploy once and forget. Like any workforce, they improve over time. Organizations start by building or modifying a Digital Worker, testing it in real workflows, refining the rules, guardrails, and decisions it makes. Then they monitor how it performs in production. That continuous cycle of change, test, and monitor is how Digital Workers become more capable and more trusted
over time. It's how enterprises move from experimenting with AI to operating with it every day and seeing real ROI within weeks."
Expanding the Digital Worker portfolio: New field service capabilities
Extending IFS’s differentiation in field service and building on the initial IFS Loops Digital Workers for supply chain, IFS is introducing a set of new Digital Workers designed specifically for field service. These additions help service organizations move from manual orchestration toward automated, exception-based supervision.
• Service Planning Assistant Digital Worker: Continuously evaluates service demand, technician availability, and operational constraints to support predictive scheduling and planning - helping organizations anticipate demand rather than simply react to it. Key impacts include improved scheduling efficiency, reduced manual planning effort, and faster response to service demand changes.
• Dispatcher Assistant Digital Worker: Monitors service queues, identifies scheduling conflicts, and recommends optimal dispatch decisions – escalating operational exceptions to supervisors only when human judgement is required. Key impacts include reduced dispatch coordination effort, faster service assignment, and improved technician utilization.
• Knowledge Manager Digital Worker: Provides field technicians with contextual operational knowledge by interpreting asset data, service history, and enterprise documentation in real time. Instead of searching across manuals, service records, and knowledge bases, technicians receive the most relevant guidance directly within their workflow – at the exact moment it is needed during a job.

As AI infrastructure demand accelerates across the Middle East, ASBIS is increasingly positioning itself around the region’s evolving ecosystem spanning data centers, GPUs, enterprise storage, and AI-ready compute environments
The AI boom is no longer just about algorithms and applications. Across the Middle East and Africa, the real transformation is happening deeper in the stack, inside data centers, enterprise storage environments, GPU clusters, and high-performance computing infrastructure.
Governments, hyperscalers, enterprises, and system integrators are now racing to build AI-ready infrastructure capable of supporting everything from sovereign AI initiatives to enterprise-scale workloads. This shift is fundamentally reshaping the regional technology distribution landscape as well.
For ASBIS Middle East, the evolution of the market has created an opportunity to move beyond traditional volume distribution into a far more strategic role centered around AI infrastructure enablement.
Hesham Tantawi, Vice President of ASBIS Middle East, says the nature of “volume” itself has changed dramatically over the past two years. What was once driven largely by traditional enterprise hardware is now increasingly linked to data center expansion, AI servers, storage infrastructure, and compute-intensive environments.
“The distribution landscape is changing significantly,” said Hesham. “While ASBIS has always been a volume-focused distributor, today the volume itself has shifted toward data center infrastructure, enterprise servers, AI systems, and large-scale computing environments.”
According to him, governments and enterprises are no longer simply consuming cloud services. Many are now actively investing in their own AI environments, private compute infrastructure, and AI-ready data centers.
“The demand today is centered around building and upgrading data centers, AI servers, and high-performance infrastructure,” Hesham explained. “The role of the distributor is evolving from simply moving products to enabling infrastructure at scale.”
One of the biggest shifts ASBIS is seeing is the emergence of ‘AI factories’, environments purpose-built for AI workloads and compute-intensive applications.
“Governments and enterprises are now actively building their own AI engines and environments internally,” he said.
That demand is driving strong growth across the entire infrastructure stack, including CPUs, GPUs, SSDs, enterprise storage, and high-performance server components.
ASBIS today works with a broad ecosystem of infrastructure vendors, including NVIDIA, AMD, Intel, Micron, Seagate, Toshiba, Supermicro, and others, positioning the company directly within the AI infrastructure supply chain.
“We are the CPU guys, we are the GPU guys, we are the SSD guys,” Hesham says while discussing how the company’s core strengths align with current market requirements.
The shift away from traditional OEM dependency
Hesham believes another major transition underway is the movement away from purely OEM-driven infrastructure models toward

Hesham Tantawi Vice President, ASBIS Middle East
more flexible, open, and customizable architectures.
Traditionally, enterprises across the region depended heavily on branded infrastructure from top vendors. But that model is gradually evolving.
“Two years ago, people were demanding servers from many original manufacturers. Today they are moving toward more open sources,” says Hesham.
This trend is particularly benefiting component-focused distributors such as ASBIS because organizations are increasingly sourcing CPUs, GPUs, SSDs, and storage components directly to build systems optimized for their own workloads.
The company says large data centers are increasingly assembling infrastructure internally and monetizing those environments by renting out computing power, GPU capacity, and infrastructure services.
“Large data centers are increasingly sourcing and assembling infrastructure themselves. They are building computing environments optimized for their own workloads and then monetizing those environments by reselling computing power, GPU capacity, and infrastructure services,” adds Hesham.
He highlights emerging models where investors fund the creation of specialized computing infrastructure that can later be consumed by sectors such as petroleum, energy, financial services, and research institutions without those organizations needing to build large-scale data centers themselves.
Within the region, ASBIS sees the UAE and Saudi Arabia as the primary growth engines for AI infrastructure demand.
“The UAE and Saudi Arabia are the primary focus markets today,” Hesham said, citing the scale of AI and data center investments underway in both countries.
At the same time, Africa has emerged as another major strategic growth market for the company.
ASBIS has already expanded its footprint through new offices in Ivory Coast and Ghana as it strengthens its West African operations, while East Africa is also under active consideration for future expansion. Iraq is another market being evaluated as part of the company’s broader regional strategy.
Perhaps one of the clearest indicators of the infrastructure boom can be seen in enterprise storage demand.
According to Hesham, the AI era has dramatically accelerated demand for enterprise-grade hard drives and SSDs, creating supply constraints across the market.
“Most of the hard drive manufacturers are effectively pre-sold until 2027,” he said. “We are facing a lot of allocation issues with them.”
The surge in hyperscale and cloud demand is creating major pressure on worldwide supply availability.
“The largest global cloud operators now consume a substantial
share of worldwide storage supply,” Hesham explains, adding that hyperscalers are absorbing a significant portion of global manufacturing output.
As a result, enterprise storage pricing continues to rise while distributors and regional markets compete for limited availability. At the same time, storage capacity expectations are also rapidly evolving.
“Today, we are talking about 32-terabyte hard drives. Within five or six months, we might talk about 48-terabyte drives,” says Hesam.
In such a constrained environment, forecasting and operational efficiency have become critical competitive differentiators.
ASBIS now places orders as much as a year in advance in order to secure vendor allocation and maintain supply continuity.
“Efficiency is one of the core focus areas for us. Timing of order processing, forecasting, inventory management, and supply chain coordination are all essential,” adds Hesham.
The company is also navigating geopolitical and logistics-related challenges that continue to impact shipping routes and delivery timelines across the region.
“Supply chain bottlenecks today are heavily linked to logistics and shipping disruptions,” says Hesham.
Despite the volatility, the company believes close vendor collaboration and long-term partnerships remain central to maintaining stability.
“Partnerships are absolutely central to the business,” he emphasizes.
ASBIS expects continued momentum around AI infrastructure, enterprise-owned data centers, surveillance systems, and localized compute environments across the Middle East and Africa.
Hesham adds, “We expect continued momentum around AI factories, enterprise-owned infrastructure, and localized data center investments.”
“The role of the distributor is evolving from simply moving products to enabling infrastructure at scale.”
As enterprises across the Middle East continue modernizing infrastructure, expanding cloud environments, and embracing increasingly autonomous operations, the challenge is no longer visibility alone but transforming operational telemetry into actionable intelligence
As enterprises across the Middle East continue accelerating digital transformation, the volume of operational data flowing across infrastructure, cloud environments, cybersecurity systems, applications, and operational technology environments has grown exponentially. Yet despite unprecedented visibility, many organizations are still struggling to convert telemetry into meaningful operational intelligence that improves resilience, governance, and decision-making.
Increasingly, CIOs and CISOs are discovering that the challenge is no longer a lack of data, but the absence of context, unified visibility, and governance models capable of connecting operational signals across fragmented environments. As hybrid infrastructure, AI-driven operations, cloud-native environments, and autonomous systems continue expanding, operational intelligence is rapidly evolving from an IT monitoring function into a strategic business capability.
Industry leaders say the traditional approaches to dashboards, static reporting, and siloed monitoring are no longer sufficient for modern enterprise operations.
Faisal Khan, Associate Director - Information Security & Compliance, IT Security and Compliance at Dubai World Trade Centre, believes many enterprises are still failing to fully utilize the operational visibility already available to them.
“Organizations are collecting more data than ever before which is generally termed as Data Hoarding, but many of us are still not doing enough to turn that raw visibility into genuine operational intelligence. Too often the information sits in silos or gets reviewed after the fact in reports that no one has time to act on,” says Faisal.
According to him, enterprises must shift from reactive data gathering toward proactive orchestration.
“This means deploying unified data layers that can correlate events across applications, networks, and endpoints in real time,” he explains. “Organizations need to stop asking what happened after an outage and start using contextual data pipelines to predict where the next bottleneck will occur.”
Anchal Choubey, AI - PMO and GRC Practitioner, agrees that the problem facing enterprises today is not the absence of data, but the inability to derive meaningful context from it.

Associate Director - Information Security & Compliance, IT Security and Compliance, Dubai World Trade Centre
“The problem today is not that there is no data,” says Anchal. “The problem is that teams have a lot of data but they do not have enough context to understand what it means.”
He points to fragmented visibility as one of the biggest operational challenges confronting enterprises.
“Most companies are still dealing with multiple systems, and they are using separate monitoring tools,” he says. “It is very common for IT and security leaders to look at their dashboards and see that everything looks fine. They are missing the fact that a big problem is already happening with their business.”
According to Anchal, many of the most dangerous operational blind spots are now emerging outside traditional monitoring models. He points to growing concerns around shadow IT and SaaS sprawl, where employees increasingly adopt tools outside IT visibility, along with supply chain exposure, identity overload, bad data, and alert fatigue across security operations.
“There is also the ‘Green Dashboard’ Trap,” says Anchal. “This is when the monitoring system says everything is fine. The actual
customer experience is not good.”
Luqman Kondeth, Director, Campus Technology Security Services at NYU, says operational blind spots increasingly emerge between converging technology domains rather than within individual systems themselves.
“The blind spots that matter sit in the seams between domains, not on the dashboards,” says Luqman. “Identity and entitlement sprawl, especially non-human and AI agent identities, is multiplying faster than most governance programs can track.”
He also warns that unmanaged SaaS environments, shadow AI, and third-party exposure are introducing new visibility challenges.
“Third and fourth party supply chain exposure, shadow AI, and unmanaged SaaS are quietly moving sensitive data through channels that never appear on a network diagram,” Luqman adds.
The growing complexity of enterprise operations is also forcing organizations to rethink traditional monitoring and reporting models.
“Traditional dashboards were made to report on what happened in the past,” says Anchal. “Modern companies need to be able to respond quickly to what is happening now.”
According to him, static reporting models fail to provide the real-time operational awareness modern enterprises require.
“A monthly report or a static tracker only tells you what went wrong this week,” he explains. “It does not help you understand what is going wrong now or what might go wrong next.”
Anchal believes organizations now require operational intelligence systems capable of linking infrastructure visibility directly to business impact.
“A dashboard that shows a server is working is not enough anymore,” he says. “The real value comes from a system that can tell you ‘This specific server problem is costing us $10,000 an hour in lost sales and is increasing our risk.’ If you have visibility but do not know what to do with it it is just noise.”
Faisal similarly argues that enterprises must avoid falling into the trap of collecting telemetry without understanding what matters operationally.
“One of the biggest mistakes organizations make is collecting everything without defining what truly matters to the business,” says Faisal. “The key is intelligent filtering and prioritization, using AI to reduce noise and highlight signals that align with business priorities rather than every possible metric.”
According to him, organizations must increasingly focus on relevance rather than volume.
“Ultimately it is about quality and relevance, not quantity, so the team spends time on insight instead of drowning in alerts,” Faisal adds.

As organizations become increasingly dependent on digital operations, operational intelligence is now becoming deeply intertwined with business resilience and continuity strategies.
“Operational intelligence is rapidly moving from a nice-to-have IT tool to a core driver of business resilience and continuity,” says Faisal. “High-performing organizations use operational intelligence to build digital sovereignty, ensuring that infrastructure can dynamically adapt to cyberattacks, cloud outages, or sudden traffic surges without interrupting the customer experience.”
Luqman believes the convergence of IT, cybersecurity, cloud, and operational technology is fundamentally reshaping how organizations think about operational visibility itself.
“Convergence is forcing a question most enterprises have avoided, which is who actually owns the single operational picture of the organization,” says Luqman.
He argues that the traditional separation between infrastructure, security, cloud, and operational technology teams is becoming increasingly unsustainable.
“A misconfigured cloud identity can degrade a building system, and a firmware update on a chiller can take down a data center floor,” Luqman explains. “Operational visibility is therefore becoming a shared governance function across the CIO, CISO, facilities, and chief risk officer rather than a byproduct of whichever team owns the biggest platform.”
Faisal also believes operational intelligence is fundamentally changing governance and risk management models.
“Instead of periodic audits and static controls, leaders can make governance real-time and proactive,” says Faisal. “This intelli-
Luqman Kondeth Director, Campus Technology Security Services, NYU

gence also strengthens resilience by revealing dependencies and potential failure points across the entire ecosystem.”
As operational environments become increasingly autonomous and AI-driven, enterprises are also grappling with how to balance automation with human oversight.
“The smartest companies are not trying to replace humans,” says Anchal. “They are trying to free humans from doing busywork.” According to him, automation should primarily focus on repetitive operational tasks.
“You want to use automation for tasks, such as basic infrastructure scaling first-line security triage, workflow routing and gathering compliance logs,” he explains.
However, he warns that humans must remain central to high-impact decisions.
“You need to keep humans involved in important decisions,” says Anchal. “Machines should not be making decisions about risk handling, crisis management, dealing with dilemmas or changing strategic priorities.”
Luqman echoes a similar view, arguing that organizations must be deliberate about defining where humans remain inside operational workflows.
“The leaders who get this right are deliberate about where the human belongs in the loop rather than treating automation as all or nothing,” says Luqman.
He believes routine operational activities should increasingly be automated aggressively.
“Routine, low consequence work such as patching, certificate
rotation, and standard remediation should be automated aggressively,” he explains. “Consequential actions such as isolating a host or revoking access work best as assisted automation, where the system proposes and the human approves with full evidence in view.”
Faisal says enterprises are increasingly learning to position automation as an operational partner rather than a replacement for human expertise.
“Automation handles the repetitive, high-volume tasks and initial triage, freeing skilled professionals to focus on complex judgment calls, strategy, and innovation,” says Faisal.
At the same time, he notes that cultural resistance remains a significant barrier.
“There is often a deeply ingrained cultural resistance to automation and open data sharing, driven by the fear of job displacement,” he adds.
Despite rapid investments in observability and operational intelligence platforms, organizations continue struggling with cultural and structural barriers to unified visibility.
“Honestly technology is usually not the problem,” says Anchal. “The problem is usually politics and culture.”
He points to turf wars, fragmented operating models, and data hoarding as persistent enterprise challenges.
“One thing I see a lot is companies spending a lot of money on observability platforms but they are not spending any money to fix their broken operating models,” Anchal explains. “You cannot just buy your way out of a culture that is not working together.”
Luqman similarly believes operational visibility failures are overwhelmingly organizational rather than technical.
“Unified visibility fails for organizational reasons far more often than technical ones,” says Luqman. “Teams treat tool ownership as identity and may resist consolidation.”
He also highlights the absence of shared operational language across enterprise functions.
“The absence of a shared operational language means availability and severity mean different things to different functions,” Luqman adds.
For enterprises across the region, the operational intelligence conversation is increasingly evolving beyond dashboards, monitoring, and observability tools into a broader discussion around resilience, governance, operational context, and business continuity. As infrastructure environments become more distributed, autonomous, and interconnected, organizations that successfully transform operational visibility into actionable intelligence may ultimately gain a significant advantage in resilience, agility, and decision-making.

Gabriele Obino, Vice President Southern Europe & Middle East at Denodo, discusses why trusted, real-time, and well-governed data foundations are becoming critical as enterprises move from AI experimentation toward large-scale agentic AI adoption across increasingly distributed and sovereign environments.
As AI moves from conversational interfaces to agentic autonomy, is the real trust gap less about the AI models themselves and more about confidence in the underlying data architecture?
Yes. As agentic AI begins to make decisions and trigger actions, trust depends less on the model alone and more on the data foundation beneath it.
An AI agent can only act reliably when it has access to accurate, current and well-governed data, supported by the right business context. If the data is fragmented, outdated or poorly managed, the output becomes harder to trust, no matter how advanced the model is.
The Trust Gap Report shows that 66% of organizations say AI data must be accessible in near real time to be considered trustworthy. This matters because agentic AI is operational, not just advisory. It is expected to support live decisions, workflows and actions. That requires real-time situational awareness and a trusted data architecture behind every decision.
As enterprises deploy AI agents across multiple departments, how can they ensure these systems understand the business context and meaning of data without being constrained by conflicting silos?
The main challenge is not a lack of data. It is a lack of shared meaning.
Different departments often use different systems, definitions and governance practices. This makes it difficult for AI agents to understand context or act consistently across the enterprise.
Around 63% of organizations say identifying and preparing the most relevant and trustworthy data remains a major obstacle to AI adoption. To address this, enterprises need a logical data management approach that unifies access to live data across distributed systems while preserving business meaning and governance.
A semantic layer also helps AI systems understand what data means in context, not just where it is stored. Reusable data products can then package trusted data, rules and definitions in a way that AI systems and business teams can use consistently across departments.
UAE enterprises are increasingly demanding faster data refresh cycles than the global average. How is this real-time mandate reshaping expectations around digital sovereignty and data readiness in the region?
The UAE’s AI ambitions are raising expectations around re-

Gabriele Obino VP Southern Europe & Middle East, Denodo
al-time access and digital sovereignty at the same time. As organizations move toward AI-driven operations, delayed data is no longer a technical inconvenience. It is becoming an operational risk. AI needs live data to be trustworthy.
Data readiness is no longer about copying and preparing it in centralized infrastructure. It now depends on whether organizations can securely access, govern and activate live operational data across cloud, on-premises and sovereign environments without having to copy it. Copied data is not live data.
For UAE enterprises, the priority is to innovate with AI while retaining visibility and control over sensitive information. This is shifting attention from where data is stored to how quickly,
securely and intelligently it can be accessed and used.
How does Denodo’s data virtualization strategy help address the latency challenge that prevents AI agents from acting on real-time or near-real-time information?
Traditional architectures often rely on batch movement, where data is extracted, copied, transformed and loaded into central repositories before it can be used. That approach may support historical reporting, but it struggles with AI systems that depend on live operational awareness.
Data virtualization creates a unified logical layer that allows organizations to access and integrate information in real time without physically consolidating the data first.
This is important for agentic AI because these systems need current information to make accurate decisions. The Trust Gap Report found that 66% of organizations believe AI data must be available in near real time to be trusted.
By reducing reliance on overnight processing and static copies, data virtualization lowers latency and gives AI systems a more accurate operational picture at the moment decisions are made.
With the UAE’s focus on national digital sovereignty, how can organizations balance borderless AI innovation with the need for localized, governed data? Can data virtualization act as a bridge between these priorities?
UAE organizations want to move quickly on AI while maintaining control over sovereignty, governance and compliance. Traditional architectures can make this difficult because they often require data to be copied or centralized across multiple systems and cloud environments.
Data virtualization offers a scalable path forward. It allows organizations to access and integrate distributed information in real time while sensitive data remains inside sovereign or regulated environments. It also allows governance policies to be applied centrally at the access layer rather than managed separately across every system. This creates stronger visibility, consistency and control.
For the UAE, this provides a practical way to scale AI innovation without weakening governance or compliance.
How does Denodo’s zero-copy virtualization approach help businesses maintain a single source of truth across hybrid and multi-cloud environments?
Maintaining a consistent view of data becomes harder when organizations operate across hybrid and multi-cloud environments with hundreds of systems.
Traditional integration methods often create multiple versions of the same information across different platforms. Over time, this can lead to inconsistencies, governance gaps and conflicting insights.
Denodo’s zero-copy virtualization approach creates a unified logical layer that connects data directly from source systems while preserving consistency across environments.
Instead of physically consolidating everything into one repository, the platform delivers information in real time while applying governance, security and business logic centrally at the point of access.
This helps business users, analysts and AI systems access governed information faster while maintaining a stronger single source of truth across the enterprise.
Looking specifically at the Middle East, what are the biggest cultural, organizational, or technical hurdles enterprises face as they move from AI pilots to full-scale agentic AI adoption? The biggest challenge in the Middle East is moving from experimentation to operational trust.
Many enterprises have completed pilots, but scaling agentic AI into live operations requires stronger governance, clearer accountability and reliable real-time data.
Culturally, there is still caution around allowing AI to act autonomously inside critical processes, especially when confidence in the underlying data is uneven.
Organizationally, data ownership is often fragmented across departments, making shared governance and business context difficult to establish.
Technically, enterprises are managing cloud platforms, legacy systems, sovereign data requirements and growing volumes of real-time information. Maintaining performance and visibility across these environments remains difficult.
Business leaders now expect AI to deliver clear outcomes, faster decisions and visible returns. The organizations that scale successfully will be those with trusted, governed and operationally mature data foundations.
By 2027, what will separate organizations that successfully scale agentic AI from those that remain stuck in experimentation?
By 2027, successful organizations will treat trusted data as a strategic operational asset, not just a technical resource.
The gap will not be defined by access to AI models alone. It will be defined by the ability to provide AI systems with trusted, context-aware and operationally ready data across the enterprise.
Leaders will build architectures that support real-time decision making, strong governance, semantic consistency and reusable data products across business functions.
They will also judge AI initiatives by operational impact, efficiency, responsiveness and business value, not experimentation alone.
Organizations that remain stuck will likely continue to struggle with fragmented systems, disconnected silos and limited confidence in AI-driven decisions. Ultimately, the leaders in agentic AI will be those with the most trusted and scalable data foundations underneath their AI strategies.
Meriam ElOuazzani, Vice President, Middle East, Turkey and Africa at Censys, discusses how AI-driven threats, expanding attack surfaces, and increasingly distributed infrastructure are forcing organizations to rethink traditional SOC models around real-time visibility, internet-wide intelligence, and proactive risk reduction.
Traditional SOCs are often overwhelmed by fragmented tools and alert fatigue. How does Censys reimagine the SOC model for the present and future?
The SOC model most organisations are running was designed for a threat landscape that no longer exists. Tools proliferated, alerts multiplied, and analysts became triage operators rather than investigators. That is not a staffing problem. That is an architectural one.
What has changed the equation is the nature of the workforce inside the SOC itself. Every AI agent, every automated workflow, every non-human identity spun up through a vendor came without a governance model attached. Most SOC leaders cannot enumerate the agents already active in their environment. You cannot supervise what you cannot see.
The SOC of the future is built on authoritative ground truth. AI-driven detection only works when the underlying data is accurate and current. What Censys brings to the SOC is exactly that outside-in view — the same picture an attacker builds before they move. When you combine that with continuous monitoring and enriched, real-time intelligence, you shift the SOC from reactive alert management to proactive risk reduction. That is not a minor operational improvement. That is a different model entirely.
Discuss your operations in the region?
The META region is at an inflection point. Governments and commercial organisations are moving beyond perimeter defence and demanding real-time visibility into their actual digital footprint. That shift is not aspirational anymore. It is operational, and the demand is accelerating faster than most vendors anticipated.
I joined Censys early this year as the company's first dedicated Vice President for META, and the mandate is clear: establish Censys as the default external attack surface intelligence layer across the region. We are building out the team, partnerships, and ecosystem infrastructure across government, enterprise, channels, MSSPs, and hyperscaler alliances.
The META market understands the urgency now in a way it did not five years ago. The UAE alone absorbed 166 nation-state cyber events according to Microsoft's 2025 Digital Defense Report, making it the fourth most targeted country globally. That pressure has accelerated maturity faster than most markets experience voluntarily.
We are already building partnerships focused on sovereign nations and critical infrastructure, the segments where the stakes are highest and where the gap between exposure and awareness

Meriam ElOuazzani Vice President META, Censys
is most consequential.
Elaborate on the opportunity, along with the challenges you see in the region's addressable market segments like the enterprise and the public sectors, especially with critical infrastructure sectors?
The region is not catching up to global cybersecurity maturity, But in several areas, it is setting the pace. The move from voluntary frameworks to mandatory posture requirements changed the boardroom conversation. Questions stopped being about audit readiness and started being about actual exposure.
Critical infrastructure is where the most consequential gap remains. Operational technology environments, such as power, water and industrial systems, were never designed with internet exposure in mind, yet they are increasingly connected, and that connectivity is outpacing the security controls around it. We identified nearly 400 internet-exposed Human-Machine Interfaces supporting water facilities in the US alone, many accessible without authentication. That problem is not unique to any one geography. It is a global pattern, and the META region is not immune.
The enterprise challenge is different but related. Organisations are investing seriously, but environments grow faster than visibility does. Acquisitions happen, cloud workloads spin up, and shadow assets accumulate. The attack surface is dynamic; most tools are not.
The public sector opportunity is significant precisely because the stakes are sovereign. Governments here understand that cybersecurity is infrastructure, not compliance. The harder conversation is execution — translating policy ambition into operational visibility at every layer, including the assets nobody has mapped yet.
As cyberattacks become faster and increasingly AI-driven, how important is real-time intelligence in reducing the gap between detection and response?
The gap between detection and response is where attacks succeed. And that gap is being exploited with increasing precision.
Attackers are not breaking in anymore. They are logging in. They acquire valid credentials, operate inside environments exactly as a legitimate employee would, and trigger no alerts because authentication appeared to work perfectly. Mandiant tracked North Korean IT worker operations with a median dwell time of 122 days. Nearly four months of legitimate-looking access tells you how long that gap can remain invisible.
AI has changed both sides of the equation. The UAE faces up to 150,000 cyberattacks daily. You cannot staff your way out of that volume. But AI-driven defence is only as good as the data behind it. Without continuously updated, internet-wide telemetry, you reach the wrong conclusions faster.
Real-time intelligence is not a feature. It is the precondition for everything else. The organisations closing the detection-response gap are the ones that start with authoritative ground truth. Everything else builds from there.
Why does external attack surface visibility remain such a persistent blind spot for enterprises despite years of cybersecurity investments?
Because most security investments were built to protect what organisations already knew about. The perimeter was defined, assets were inventoried and tools were deployed against that known surface. The problem is that the surface never stopped growing.
Environments expand faster than visibility does. What is distinct here is the attacker's starting point. They do not begin from your inventory. They start from the internet and find what your inventory missed: forgotten subdomains, legacy services left open from an acquisition, cloud workloads nobody formally approved.
There is also a structural blind spot that is widening. Every new AI agent introduced through a vendor expands the attack surface without appearing in any asset register. Most organisations cannot enumerate what is already operating in their environment.
External visibility is not one capability among many. Without it, every other investment is protecting an incomplete picture.
Censys positions itself around 'Internet-wide visibility.' How does this level of visibility change the way security teams approach threat hunting and adversary investigation?
Most threat hunting starts from the inside, such as a suspicious log, an endpoint alert, an anomaly in the SIEM. The problem with that starting point is that the attacker has already arrived.
Internet-wide visibility inverts that model. Censys continuously scans the entire IPv4 space, all 65,536 ports, and over 200 application-layer protocols, normalising that data into structured, queryable intelligence. Security teams can pivot across IPs, domains, certificates, and autonomous systems to map adversary infrastructure before it is weaponised against them.
The certificate intelligence dimension is particularly powerful for adversary investigation. By ingesting certificate transparency logs and observing TLS handshakes, defenders can identify unknown assets, track infrastructure relationships, and spot impersonating domains through certificate reuse patterns.
The shift this enables is from reactive investigation to proactive hunting. You are no longer waiting for the attacker to announce themselves. You are finding them first.
“The SOC of the future is built on authoritative ground truth. AI-driven detection only works when the underlying data is accurate and current. What Censys brings to the SOC is exactly that outside-in view — the same picture an attacker builds before they move.”
With AI increasingly entering SOC workflows, are organizations at risk of over-automating security operations without having the right contextual intelligence behind those systems? Yes. And the pattern of failure is consistent.
Organisations rush to deploy AI-driven workflows because the productivity case is compelling. They discovered after an incident that they had no access controls, no governance policy, and no incident playbook for AI specifically. The Replit incident is the parable I keep returning to, where an autonomous agent was given more agency than oversight and ended up deleting a production database during a code freeze, then produced confident, misleading status messages about it. The lesson is not that automation is unsafe. It is that confident output is not the same thing as correct output.
AI is only as good as the data it operates on. Without authoritative, internet-wide telemetry as the intelligence layer underneath, automated SOC workflows will make faster decisions with incomplete context. Speed without accuracy does not close the detection gap. It widens it.
How important is historical telemetry and change tracking in modern incident response, especially when organizations are trying to understand the timeline and scope of sophisticated attacks?
When a sophisticated attack surfaces, the first question is never "what happened?" It is "how long has this been happening?" The answer almost always extends further back than the organisation expects.
Historical telemetry is what turns an incident into an understandable timeline. Censys preserves over four years of historical snapshots of internet-connected infrastructure, which enables security teams to track the lifecycle of attacker infrastructure, identify when an asset first became exposed, and correlate adversary activity across time. That retrospective capability is not a secondary feature. It is often the difference between containing an incident and understanding it well enough to prevent recurrence.
Change tracking adds the operational dimension. Newly exposed services, certificate changes and configuration drifts are the signals that precede exploitation. Catching them in real time means the investigation starts before the breach, not after.
What are the biggest challenges security teams face today in maintaining visibility across increasingly distributed infrastructure?
Three challenges converge and compound each other.
The first is scale. Cloud environments, remote work, and multicloud deployments have expanded attack surfaces faster than any inventory process can track. Assets appear and disappear at a pace that static tools were never designed for.
The second is the shadow problem. Unknown domains, unmanaged APIs, subsidiary infrastructure and forgotten cloud workloads are not the result of carelessness. They are the natural byproduct of organisations moving fast. Attackers understand this better than most security teams do.
The third is the newest and least governed: AI-introduced infrastructure. Every agent, every automated workflow deployed by a vendor extends the perimeter without a corresponding update to the asset register. Most security teams cannot enumerate what is already operating against them.
Visibility is the precondition for addressing all three. You cannot manage exposure that you have not mapped.
As organizations move toward more integrated security architectures, how do you see the relationship evolving between threat intelligence, attack surface management, SOAR platforms, and AI-driven security operations?
The boundaries between these disciplines are dissolving, and that is the right direction.
For too long, attack surface management sat separately from threat intelligence, which sat separately from response workflows. The result was context lost at every handoff. A newly exposed asset flagged in one tool, unconnected to the threat intelligence that would have made it urgent, unconnected to the SOAR workflow that would have triggered remediation. The gap between knowing and acting remained wide.
What is emerging is a more integrated architecture where external visibility feeds directly into threat-informed prioritisation, which triggers automated response through SOAR platforms, all enriched by AI at each layer. Censys integrates natively with Splunk, Microsoft Sentinel, Palo Alto Cortex, Qualys, Tenable, and Wiz, precisely because intelligence that stays siloed does not reduce risk.
The organisations getting this right are treating visibility as the data layer that the entire architecture depends on.
“Every new AI agent introduced through a vendor expands the attack surface without appearing in any asset register. Most organisations cannot enumerate what is already operating in their environment.”
Tim Freestone, Chief Strategy Officer at Kiteworks, examines how a growing wave of AI security vulnerabilities is exposing deeper weaknesses around trust boundaries, access control, and process containment as GCC nations accelerate AI adoption across government, enterprise, and critical infrastructure environments.
GCC states are deploying AI faster than nearly any region on Earth. Saudi Arabia's National Strategy for Data and AI, the UAE's National AI Strategy 2031, and Dubai's smart city infrastructure make the GCC a global leader in AI-driven transformation. That velocity creates competitive advantage, yet makes the AI security failures disclosed globally over the past year directly relevant.
Between mid-2025 and April 2026, researchers disclosed six critical AI vulnerabilities. EchoLeak and Reprompt in Microsoft Copilot, ForcedLeak in Salesforce Agentforce, GeminiJack in Google Gemini Enterprise, GrafanaGhost in Grafana, and a supply chain attack on the OpenAI plugin ecosystem that went undetected for six months.
The industry has treated these as one problem, but they are three. And organizations subject to PDPL, SDAIA frameworks, and UAE data protection requirements need to address all of them.
Every vulnerability in this series starts the same way. External data enters the system through a legitimate channel and an AI component processes it without validation.
EchoLeak's payload was a crafted email. GeminiJack's was a poisoned Google Doc indexed by RAG. ForcedLeak's was text in a Web-to-Lead form field. GrafanaGhost's was URL query parameters stored in event logs. In each case, data from the outside world stored internally, past the perimeter was treated as trustworthy by the AI. Nobody applied input validation to AI-processed data the way they apply it to web-facing user input.
This is not a data access control problem. It is a zero-trust input validation failure. For organizations deploying AI across government services, financial platforms, and critical infrastructure in the GCC, the principle is straightforward: external data cannot be trusted because it has been stored internally. It must be validated before AI processes it.
Five vulnerabilities involve AI systems operating on behalf of a user with broad, implicit data access. Copilot accesses everything in OneDrive, SharePoint, and Teams. Gemini sweeps across all Workspace data. Agentforce queries the entire CRM. The OpenAI plugin attack used compromised credentials for six months. Each

Tim Freestone Chief Strategy Officer, Kiteworks
AI authenticated once and then accessed whatever it could reach.
Evaluating each individual data request against policy would have constrained the blast radius. This is the pattern where RBAC, attribute-based access control, credential isolation, and audit trails directly apply. PDPL's access control requirements, SDAIA's auditable governance expectations, and UAE Federal Decree-Law No. 45's data protection obligations all point toward per-operation enforcement as a baseline.
GrafanaGhost operated through trusted back-end enrichment processes with system-level privileges. The back-end process consumed untrusted input without validation and had functional scope it was never designed to use. Rendering dashboards, generating image tags, making outbound requests. Nobody constrained what the process could do.
The OpenAI plugin attack succeeded because agent credentials were accessible to compromised plugin code. Tokens were not stored outside the AI's accessible context. Six months of silent access because credential isolation did not exist.
Least privilege must apply to functional scope and to credential storage, not just to data access.
For input trust boundaries: treat every data source an AI processes — emails, documents, form submissions, event logs — as potentially adversarial. Validate before AI processing.
For data access scoping: require per-operation authentication and policy enforcement for every AI data request. Store credentials outside the AI's context. Produce audit trails satisfying PDPL and SDAIA requirements.
For process containment: scope back-end AI processes to only the functional capabilities they require. Broad data read access may be necessary. The ability to render content, generate outbound requests, or communicate externally is not.
Michael Cade, Global Field CTO at Veeam Software, explores why data sovereignty, visibility, and governance are becoming increasingly critical as organizations attempt to scale AI responsibly amid growing regulatory scrutiny and mounting concerns around data quality, transparency, and operational resilience.

Michael
Cade
Global Field CTO, Veeam Software
So far, AI adoption has outpaced regulatory frameworks, leaving organisations largely to make up their own rules. But this lack of clarity hasn’t slowed organisations down. In fact, McKinsey’s latest survey found that 88% of organisations already report using AI in at least one business function. Despite this, innovation has slowed, and it’s become clear that organisations have overlooked a key enabler of safe and secure AI - data sovereignty.
Simultaneously, regulation has begun to catch up, and much of it points to the same principles of data sovereignty and AI visibility. Take the EU AI Act, for example, which sets strict, risk-based rules on both AI development and deployment within the EU to improve AI visibility.
Rather than blindly charging ahead, organisations need to pause to develop transparent, traceable, and sovereign-by-design data architectures. Otherwise, they won’t just be unable to unlock the true potential of AI for their businesses; they’ll also fall behind on regulatory compliance.
As you might expect, both digital sovereignty and AI innovation boil down to data. It’s already well documented that AI needs a lot of data, and we’ve got plenty, with the IDC estimating that the global datasphere reached around 181 zettabytes annually in 2025. But, despite having plenty of data, Generative AI (genAI) pilots continue to fail widely. Some research suggests that as many as 95% of enterprise genAI pilots fail to reach production, or even demonstrate measurable ROI. The reason? Long-standing
data hygiene issues.
Thanks in no small part to AI, data growth has become exponential, but organisations have largely failed to keep up. This influx has far outpaced storage processes, and organisations have somewhat taken their eye off the ball, with ‘junk’ data being stored alongside the ‘useful’ data required for AI usage. And ultimately, AI systems inherit not just the bias but also the quality and structure of the data they are trained on. So, if the training sets are poorly structured and include ‘junk’ data, outputs, and usability suffer.
There’s also a significant knock-on effect with compliance and regulation. While regulatory bodies are yet to agree on a unified approach to AI regulation, it’s already becoming clear that visibility will be central to future requirements. In Europe alone, the EU AI Act and the NIS2 Directive are already signalling a broader push for stronger governance, transparency, and control over operational and training data. And without strong sovereignty, organisations will remain unable to map and understand their data landscape to adhere to existing and future requirements.
After the last few years of data growth, the sheer scale of the workloads most businesses now hold can seem daunting. Before organisations can improve their data hygiene, they first need to understand and classify their data. Not just for what it contains, but also according to how sensitive it is. A piece of data may be useful for a genAI pilot, but if it’s too sensitive, it cannot be used. This level of understanding not only avoids mistakenly giving genAI programmes sensitive data, but could also be key to creating genAI that delivers on its potential. Instead of training it on a pile of ‘useful’ data peppered with ‘junk’ data, organisations will be able to feed AI only the information it actually needs.
Once this is all in place and you know what you’re working with, organisations can begin to define the sovereignty requirements for each data bucket, including both regulatory and locality rules. For some, the knee-jerk reaction is to restrict usage to meet the strongest requirements of data localisation laws. Still, the EU’s GDPR, for example, doesn’t mandate localisation within a specific EU country, just to the European Economic Area (EEA), although it does place strict restrictions on the transfer of personal data outside the EEA – creating a ‘soft localisation’ effect in practice. There’s a lot of nuance within this, which is why many organisations are adopting hybrid or multi-cloud architectures to maintain flexibility over where workloads are processed and stored. With these, organisations can restrict data where needed to meet localisation requirements, while still maintaining data portability, which will be essential as regulations continue to change. This flexibility and transparency allow organisations not just to monitor where their data resides, but who can access it - essential
knowledge not just for compliance, but for security too.
Up until now, data sovereignty has been relegated to the bottom of the priority list, seen mostly as a compliance exercise. Organisations have ticked it off, but only as part of a longer list of regulatory requirements, rather than considering it as a vital part of their data strategy. But if fully understood and wielded correctly, aligned with the wider business strategy, it can do much more.
Not only can it feed into the data governance frameworks that underpin operations, but it can also help inform and establish AI governance. With clean, structured, and classified data, organisations can finally unlock the true potential of their genAI pilots.
So far, data sovereignty has been underestimated, but with genAI innovation stalling and regulation catching up, organisations can’t afford to do so any longer.
“Before organisations can improve their data hygiene, they first need to understand and classify their data. Not just for what it contains, but also according to how sensitive it is.”
Francesco Colavita, Global Vice President - Consulting at JAGGAER, explores why contracts must evolve from static documents into executable, data-driven assets that strengthen governance, resilience, and enterprise decision-making in an increasingly volatile business environment.
For all the talk of digital transformation, many organisations are still running one of their most critical business functions on email threads, shared drives and scanned PDFs. Contracts, the documents that define revenue, costs, obligations and risk, remain stubbornly analogue in an otherwise digital enterprise. For CEOs and business leaders, this is not an administrative inconvenience, it is a material business risk. In most organisations, contracts are fragmented across inboxes, local folders, legacy systems and filing cabinets. Commercial teams negotiate over email, legal teams track versions manually, finance often sees agreements only after they are signed, and executives are left with little real-time visibility into what the business has actually committed to.
This fragmentation has the potential to create blind spots that can cripple organisations precisely when they need clarity most. Just recently, rising tensions between the US and Iran caused flights from major regional aviation hubs to be cancelled. While the disruption was quickly reversed, it prompted many business leaders to question the true resilience of their supply chains. When such disruptions hit, executives need immediate answers to very practical questions: Which suppliers are exposed? What termination or force majeure rights do we have? Which contracts auto-renew next quarter if no action is taken? How will governance and cost fragmentation be affected?
For many organisations, those answers are locked inside static documents that were never designed to support rapid decision-making. The result is slow reactions, missed opportunities to mitigate risk, and unnecessary financial leakage.
Ironically, many companies believe they have already “digitised” contracts. They have PDFs, document management systems, and sometimes even searchable archives. But digitisation alone does not make contracts digital assets.
A digital copy of a contract is still, at heart, an analogue artefact. It is read by humans, interpreted manually, and acted on inconsistently. It does not guide workflows, enforce policy, or automati-

Francesco Colavita
Global Vice President - Consulting, JAGGAER
cally trigger approvals, alerts, or financial controls. In this sense, it is not far removed from the stacks of physically printed contract copies that once filled filing cabinets.
This is why contracts have become the analogue bottleneck in the digital enterprise. While finance operates on real-time data and supply chains are optimised through analytics, contractual commitments remain static and opaque. That disconnect is increas-
ingly untenable in a region defined by rapid growth, complex and fragile supply chains, and heightened regulatory scrutiny.
Reframing contracts: from documents to executable rules
To move forward, organisations must first strip contracts back to their essence. At their core, contracts are not documents, they are a set of rules and dynamic criteria.
Rules governing pricing, obligations, penalties, renewal terms, service levels, jurisdictions, and approvals. For decades, rulesbased execution has been the foundation of computing power. When contracts are treated as code rather than text, their value changes fundamentally.
Contracts-as-code does not require futuristic thinking or blind faith in AI. It starts with a simpler shift in mindset: contracts should be structured, machine-readable, and executable. Digital records should not merely store agreements; they should actively govern how the business operates.
Seen this way, contract lifecycle management becomes less about document storage and more about operational intelligence. The contract stops being an endpoint and becomes a living asset that guides workflows, enforces policy, and informs strategic decisions.
When contracts are structured and governed as executable logic, several outcomes follow. First, visibility improves dramatically. Leaders gain a single, authoritative view of all contractual commitments across suppliers, customers, and partners. Questions about exposure, renewals, or obligations can be answered in minutes rather than weeks.
Second, risk management becomes proactive rather than reactive. Contracts can be monitored continuously against SLAs, compliance deadlines, execution, spend, traceability and regulatory requirements. Automated alerts replace surprises, allowing decisions to be made before issues escalate.
Third, contracts become a source of data-driven insight. Instead of relying on instinct, organisations can analyse negotiation trends, supplier concentration, renewal pipelines, and clause risk patterns. This supports better sourcing decisions, stronger negotiations, and more predictable financial outcomes.
Contracts like code are also open to a digital collaboration involving dynamic internal and external stakeholders, including suppliers, to guarantee a full end to end digitalisation.
A cornerstone of contracts-as-code is the concept of policy-as-code. In practical terms, this means that contracting rules
no longer live in manuals. They are encoded directly into the contract lifecycle itself.
Standard templates and clause libraries become codified policy. Clauses are classified by risk level, jurisdiction, and mandatory status. Conditional logic ensures the right language is used based on contract value, supplier risk, region, or ESG requirements. Consistency is enforced by design, not by memory.
Dynamic Approval workflows also become executable policy. Instead of relying on people to remember thresholds, rules are automated: if a contract exceeds a defined value, it routes to finance; if non-standard terms are introduced, legal review is triggered automatically. Every exception is deliberate and traceable.
The result is a single version of the truth which is essential for governance, auditability, and executive confidence.
Critically, contracts-as-code only delivers its full value when contract lifecycle management is not treated as a standalone system.
Integrated with finance and ERP platforms and with the Strategic and transactional procurement, CLM turns contracts into financial controls. Payment schedules, accruals, and obligations flow automatically into the general ledger. Discrepancies between contracted and invoiced amounts are flagged early. Finance shifts from downstream reporting to upstream control, improving cash flow forecasting and reducing financial leakage.
Integrated with CRM platforms, CLM connects promises to performance. Customer-specific terms inform sales and customer success teams. Renewal dates drive proactive engagement. Revenue is protected and expanded because commitments are visible and actionable.
When implemented correctly, these integrations transform CLM into the organisation’s central nervous system for commitments.
For organisations in the Middle East, this journey does not begin with technology for technology’s sake. It begins with recognising contracts as a strategic risk and value lever.
A modern CLM platform provides the foundation. It centralises contracts, structures data, enforces policy, and enables integration across procurement, finance, and sales. Vendor-neutral in concept, the goal is not another software module, but a new operating model for governance and supplier management.
In a region where geopolitical shifts, regulatory change, and supply chain volatility are constants rather than exceptions, this shift is no longer optional. Contracts can no longer remain analogue archives. Instead, they must become smart, executable assets that protect the business and enable confident growth.
Vibhu Kapoor, Regional Vice President - Middle East, Africa & India at Epicor, explores why manufacturers must move beyond traditional pricing models and use ERP, real-time data, and AI-driven intelligence to protect margins and stay competitive in a volatile market environment.

TVibhu Kapoor Regional VP - MEA & India,
Epicor
he economic outlook for the Middle East is still exceptionally strong, positioning the region as one of the most dynamic growth markets globally. Oxford Economics expects GCC GDP growth to reach 4.4% in 2026, up from 4% in 2025. At the same time, real household consumption across the GCC is projected to grow by 3.4% annually over the next five years, nearly double the rate forecast for advanced economies. For manufacturers serving sectors such as retail, FMCG, construction and automotive, this combination of economic mo-
mentum and rising consumer confidence represents a significant opportunity to scale.
Yet strong market momentum does not guarantee easy wins. Global supply chains remain fragile, energy prices continue to fluctuate, and geopolitical uncertainty still influences the cost and availability of raw materials. Even in growth markets, these factors create feedback loops that quickly ripple through manufacturing operations, impacting production costs, delivery timelines and ultimately pricing. As a result, customers are becoming more price conscious, competition is intensifying, and margins are under constant pressure. In this environment, the ability to price accurately and adjust pricing dynamically is no longer optional, it is central to sustaining growth.
The risks of getting pricing wrong are well understood. Research from SPARXiQ shows that most distributors charge customers either too much or too little. Overpricing damages loyalty and limits repeat business, while underpricing may help close deals but quietly erodes profitability and leaves value unrealised.
However, while the risks of sub-optimal pricing are widely recognised, the factors that lead to it are often far less visible. Revenue can appear healthy even as margins shrink. In other cases, margins look protected on paper, yet sales teams struggle to compete in the market. Left unaddressed, these disconnects undermine both financial performance and confidence across the organisation.
Many manufacturers continue to rely on pricing methods that are increasingly out of step with today’s market dynamics. Spreadsheets, historical benchmarks and cost-plus formulas remain common, despite their inability to reflect real-time changes in costs or demand. These approaches are slow, manual and prone to error, particularly in environments where energy prices, transport costs and supplier terms can shift rapidly.
There is also a structural challenge within organisations. Sales teams are under constant pressure to discount in order to secure deals, while production and operations teams absorb the impact of rising input costs and supply chain disruptions. When pricing decisions are made in silos, they become reactive compromises rather than strategic choices. The outcome is often pricing that supports short-term objectives but weakens long-term performance.
In an ideal scenario, pricing is informed by real-time data and a shared understanding across the business. Sales, finance, operations and supply chain teams work from the same information, aligned around common objectives. Pricing decisions reflect upto-the-moment costs, inventory levels and demand patterns, rather than assumptions or outdated models.
For employees, this creates clarity and confidence in day-to-day decision-making. Sales teams can quote prices knowing they are competitive and profitable. Finance leaders gain clear visibility into margin performance. Operations teams understand how production decisions influence pricing flexibility. At the heart of this model is a single, trusted source of truth that connects decisions across the organisation.
The solution is one many manufacturers already have in hand
Most manufacturers already have the foundation for this approach in place, even if they have not yet applied it to pricing. ERP systems are typically used to manage warehousing, inventory, order processing and supply chains, but they also contain the data required to support more intelligent pricing decisions.
By extending ERP into pricing, manufacturers can directly link prices to inventory positions, costs and forecasts. Slow-moving products can be priced more strategically to stimulate demand, while high-demand items can support stronger margins without alienating customers. When supplier costs change, pricing can be adjusted automatically to protect profitability. Forecasting capabilities also allow pricing strategies to be planned in advance, rather than formed reactively once margins are already under pressure.
This shift is not theoretical. One example can be seen in Qatar’s ceramics sector, where Uniceramic, the country’s leading local manufacturer moved away from estimate-based costing that relied on broadly dividing energy and raw material costs across production. By defining clear production and cost standards and capturing actual material usage, energy consumption and labour time for every production run, the business gained precise visibility into the true cost of each product. This transparency enabled it to protect margins, price more competitively and deliver fair value to customers, all while maintaining strong financial discipline.
next acceleration with AI and cloud ERP
The evolution of pricing is set to accelerate further as AI becomes embedded directly into ERP systems. Teams will increasingly be
able to interact with ERP platforms conversationally, exploring customer behaviour, supply trends and demand forecasts without relying on complex reports. Pricing decisions can become more predictive, scenario-driven and strategic, rather than reactive.
Cloud-based ERP is the foundation for this shift. It enables faster innovation, easier integration of AI capabilities and continuous improvement without the constraints of legacy infrastructure. For manufacturers considering their next move, transitioning ERP to the cloud is a practical way to future-proof pricing and decision-making.
As growth accelerates across the Middle East, manufacturers must become more deliberate in how they approach pricing. The good news is that many already have the systems needed to do this, but their potential remains underutilised. By treating pricing as a strategic discipline, enabled by ERP and strengthened by AI, manufacturers can protect margins, remain competitive and convert regional growth into sustainable value.
“When pricing decisions are made in silos, they become reactive compromises rather than strategic choices. The outcome is often pricing that supports short-term objectives but weakens long-term performance.”
Lori MacVittie, Distinguished Engineer and Chief Evangelist at F5, explores how the rise of agent skills as an emerging open standard is reshaping the security model for autonomous AI systems and why new enforcement layers such as “tool firewalls” may become critical for governing agentic AI environments.
As AI agents mature from copilots into autonomous actors, the industry is converging on a shared abstraction: agent skills.
Agent skills formalize what an agent knows how to do. They package instructions, expected behaviors, and declared tool usage into portable artifacts that can be shared, versioned, and reused across agents and platforms. Conceptually, they serve the same role plugins once did for IDEs or extensions for browsers.
What gives this model real weight is that it is no longer experimental or proprietary. Anthropic has published an open Agent Skills standard, positioning skills as a portable, interoperable layer rather than a framework-specific construct. Much like MCP standardized how agents talk to tools, Agent Skills are standardizing how agents acquire capability.
That matters. Open standards have gravity. They attract ecosystems, tooling, registries, and eventually enterprise adoption. When vendors align on a common abstraction, it stops being a curiosity and starts being infrastructure. The launch in December 2025 included partner skills from a variety of vendors (Atlassian, Figma, Canva, Stripe, Notion, and Zapier) demonstrating the standard already has momentum.
Which means the security implications are no longer hypothetical.
Agent skills are intentionally lightweight. They are designed to be human-readable, easy to author, and simple to distribute. Most implementations rely on Markdown for behavior and YAML for metadata, because frictionless sharing is the goal.
From a developer productivity standpoint, that’s a win.
From a security standpoint, it creates a familiar but dangerous pattern: executable intent delivered as content.
Skills are loaded at runtime. They operate inside the agent’s reasoning loop. They can influence planning, tool selection, and execution order. They are often fetched dynamically and composed transitively. In other words, they behave less like configuration files and more like supply-chain inputs.

Lori MacVittie Distinguished Engineer and Chief Evangelist, F5
Crucially, skills do not enforce anything. They declare what an agent would like to do. They do not constrain what the agent can actually do.
That distinction is everything.
Once a skill is active, the traditional “shift left” controls developers rely on become largely irrelevant. There is no pull request for an agent’s internal plan. There is no human code review before a tool call fires. There is no pause between reasoning and execution.
Development, for agents, happens at runtime.
The enforcement gap skills don’t fill
It’s tempting to treat agent skills as a security surface. After all, they list required tools and expected behavior. It feels like a natural place to insert guardrails.
But skills live in the wrong place in the stack.
They sit inside the agent. They are interpreted by the same model that is optimizing for completion and progress. Asking a skill to enforce security is equivalent to asking the agent to restrain itself.
That has never worked reliably, and it never will.
More importantly, skills have no authority. They cannot revoke access, throttle execution, inspect side effects, or prevent data exfiltration. At best, they provide hints. At worst, they provide a false sense of control.
Security cannot live at the level of intent description. It has to live at the level of capability execution. In more familiar terms, this is access control and identity management applied to autonomous systems. Our customers recognize this as a significant challenge related to agentic AI.

Identity and access control tops list of expected challenges for agentic AI in F5's State of Application Strategy survey.
Agents don’t cause harm by thinking incorrectly. They cause harm when thought turns into action at the tool boundary.
Every meaningful agent action from calling an API to writing code, from deploying infrastructure to querying a database or sending data to another system, crosses a tool interface. That interface is where autonomy meets reality. It is also the last place an agent cannot bypass if the system is designed correctly.
This is why a “tool firewall” emerges as the best control plane for agent security.
A tool firewall mediates every tool invocation. It sits between agents and the systems they touch, enforcing policy before execution rather than auditing after damage is done. Unlike prompt-level controls or skill metadata, it operates outside the agent’s reasoning loop and is therefore not subject to model compliance.
This is the “MCP security” meets “AI guardrails” layer. MCP defines how agents talk to tools. The tool firewall decides whether they’re allowed to and under what constraints. If tools are what
allow agents to learn “new tricks,” then the tool firewall is the control that prevents those tricks from burning down the house. This is not a new idea conceptually. It is the same pattern that underpins API gateways, service meshes, and zero trust architectures. What’s new is the actor on the other side of the interface. In practice, a tool firewall functions as a broker. Agents never hold direct credentials to external systems. They request actions. The firewall decides whether those actions are allowed, under what conditions, and with what constraints.
A tool firewall evaluates identity context (which agent, which skill, which environment), inspects parameters and payloads, enforces policy-as-code, and issues short-lived, least-privilege credentials only when appropriate. It observes outcomes, records provenance, and provides a verifiable audit trail for autonomous behavior.
This turns skills into what they should be: requests for capability, not grants of authority.
What’s left is for the market to decide what the form of a tool firewall will take. But its emergence as part of the security toolbox for agent architectures is inevitable.
Diego Arrabal, Vice President, Eastern Europe, Middle East and Africa at Check Point Software Technologies, explores how the rapid integration of AI across the UAE’s digital ecosystem is reshaping cybersecurity from a traditional protection model into a broader challenge centered around trust, control, resilience, and governance.
Artificial intelligence is no longer an extension of digital transformation. It is quietly redefining the conditions under which organisations operate, how decisions are made, how risk is assessed and how trust is maintained.
That shift is already visible. What makes this moment different is not only the speed of adoption, but the depth of integration. AI is no longer a layer applied to optimise efficiency. It is becoming embedded into the core of digital systems, influencing workflows, shaping outcomes and, in some cases, operating with a degree of autonomy.
This evolution is fundamentally changing the role of cybersecurity, often in ways that are only beginning to be fully understood. In the UAE, that shift is playing out at scale. National and sector-level strategies are increasingly designed with AI at their centre, not as an afterthought. The ambition to position the Dubai International Financial Centre as a global hub for AI-driven financial services reflects a broader direction, one that brings together infrastructure, regulation, talent and governance under a single objective: building an AI-native ecosystem.
This matters for cybersecurity because the nature of what needs to be protected is changing.
For decades, security strategies have focused on safeguarding systems, networks and data. Those priorities remain critical, but they are no longer sufficient on their own. As AI becomes embedded into decision-making processes, the question is no longer just whether systems are secure, but whether their outputs can be trusted.
That distinction is subtle, yet significant.
An AI model that produces inaccurate or manipulated outcomes can introduce risk without triggering traditional security alerts. A system behaving exactly as designed can still lead to unintended consequences if the data it relies on is compromised. In this environment, cybersecurity extends beyond protection. It becomes a question of control, integrity and reliability.
At the same time, AI is accelerating both sides of the equation.

Diego Arraba VP, Eastern Europe, MEA, Check Point Software Technologies
On one hand, it is strengthening defence. Machine learning models can analyse vast volumes of data in real time, identify patterns that would otherwise go unnoticed and reduce response times from hours to seconds. In complex, distributed environments, these capabilities are no longer optional; they are becoming essential.
On the other hand, AI is lowering the barrier to entry for attackers. Threat actors are already using AI to automate reconnaissance, generate convincing phishing campaigns and develop malicious code at speed. What once required specialised expertise can now be executed with far less effort. The result is not only more attacks, but faster ones, compressing the window between breach and impact.
This compression is forcing a rethink of traditional security models.
Approaches that rely heavily on detection and response assume there is time to act. In AI-driven environments, that assumption does not always hold. When systems operate in real time, reacting after the fact becomes less effective. Security needs to move closer to the point of action, with a stronger emphasis on preventing risks before they materialise rather than responding once they have already taken hold.
In practice, this means detection alone is no longer sufficient. By the time an issue is identified, the impact may already be in motion, making recovery more complex and costly.
Addressing this requires resilience to be built into how systems function from the outset.
It also calls for visibility across increasingly complex and distributed environments, spanning cloud platforms, on-premise infrastructure, SaaS applications and edge systems. Organisations need a clearer understanding of how data flows between these environments, how AI models interact with that data and where vulnerabilities may emerge. Most importantly, it requires defined boundaries around how systems are allowed to behave.
Securing AI requires addressing the full lifecycle, from how employees use AI tools and copilots in daily workflows, to how customer-facing AI applications and autonomous agents are protected at runtime, to the GPU infrastructure, training pipelines and inference APIs that power these systems. Each layer introduces distinct risks that traditional security architectures were never designed to address.
Without those controls, scale itself becomes a risk multiplier.
There is also a human dimension that cannot be overlooked. As AI tools become embedded into everyday workflows, employees are interacting with multiple platforms that process and generate sensitive information, often without full visibility into how that data is used or stored. Governance, in this context, is not a constraint on productivity or innovation. It is what allows organ-
isations to scale AI adoption while maintaining control over how information is accessed and shared.
The UAE’s approach suggests a clear understanding that innovation and control must develop in parallel. The focus is not only on accelerating AI adoption, but on building the frameworks that allow it to be deployed responsibly.
That balance will become increasingly important.
AI will continue to expand what organisations are capable of achieving. The real challenge is ensuring that these capabilities can be delivered consistently, securely and at scale, not as isolated point solutions, but as part of an integrated approach that works across hybrid environments, prevents threats before damage occurs and secures AI transformation while using AI to strengthen defence.
The organisations that recognise this early will not only be better protected. They will be better positioned to lead in an economy where intelligence is embedded into everything.
“When systems operate in real time, reacting after the fact becomes less effective. Security needs to move closer to the point of action, with a stronger emphasis on preventing risks before they materialise rather than responding once they have already taken hold.”
D-Link announced the release of Nuclias Unity, its brand-new cloud network management platform built to deliver efficient, centralized control for modern enterprise networks. Designed to support organizations from SMBs to large multi-site enterprises, the platform enables IT teams to manage both wired and wireless infrastructure through a single unified cloud interface—streamlining operations, minimizing on-site IT dependency, and accelerating cloud adoption without the cost and complexity traditionally associated with licensed cloud solutions. Nuclias Unity currently supports centralized cloud management for D-Link’s full range of business switches and enterprise-grade access points, with future support planned for business routers and IP surveillance cameras—further extending the platform’s role as a unified management foundation for evolving business networks.

time, and enabling scalable, future-ready network operations from single locations to large, geographically distributed enterprises.
Highlights:
Nuclias Unity simplifies the management of complex remote networks through real-time visibility, cloud-based configuration, proactive monitoring, and centralized governance. With capabilities such as topology visualization, remote provisioning, automated alerts, role-based access control, and integrated lifecycle management, the platform helps organizations maintain consistent performance, security, and operational efficiency across all sites—reducing misconfigurations, shortening troubleshooting
• Unifies visibility, deployment, monitoring, security, and governance into a single cloud platform
• Nuclias Unity currently supports centralized cloud management for D-Link’s full range of business switches and enterprise-grade access points
• Nuclias Unity simplifies complexity, strengthens operational control, and enables sustainable growth, without the traditional cost and rigidity of conventional cloud-based management.
ASUS has announced the all-new ASUS Chromebook CM32 Detachable, the perfect portable companion for study, work and play, with a versatile 2-in-1 design that allows it to transform seamlessly from a laptop to a tablet. It features a bright and vibrant touchscreen, an Arm®-based processor, a magnetic stylus with wireless charging, front and world-facing cameras, up to 13-hour battery life, fast Wi-Fi 7 connectivity, and outstanding military-strength durability.
ASUS Chromebook CM32 Detachable offers superb versatility with a range of practical accessories. The detachable keyboard allows smooth transition between tablet and laptop modes, making it ideal for learning or productivity. An optional magnetic stand covered with a strong, stain-resistant leatherette material can be
set at almost any angle. There's also an optional magnetic USI 2.0 stylus that charges wirelessly.
Ideal for remote learning or long business days, the ASUS Chromebook CM32 Detachable is engineered with an ample battery that delivers up to 13 hours of use on a single charge. Also, the lightweight design means it’s easy to take it anywhere. The device has been tested to industry-leading US MIL-STD 810H standards, ensuring it’s ready to deliver portable productivity anywhere.
Highlights:
• Versatile mobility: Seamless tablet-to-laptop transitions and
Toshiba Electronics Europe GmbH (Toshiba) has announced the M12 Series of 3.5-inch nearline hard disk drives (HDDs) for hyperscale and cloud service providers operating large-scale data centers. The new series uses Shingled Magnetic Recording (SMR) technology to deliver storage capacities ranging from 30 to 34 TB. Sample shipments have begun and Toshiba also plans to begin sample shipments of M12 drives that use Conventional Magnetic Recording (CMR) to deliver capacities of up to 28 TB in the third quarter of 2026.
The requirement from data centers, the repositories for most of the world’s digital data, is for higher-capacity, better performing HDDs to support more efficient system configurations. The M12 Series is designed to address this demand by significantly increasing storage capacity in the standard 3.5-inch nearline HDD form factor.
M12 Series drives leverage Toshiba’s proprietary design and analysis technologies cultivated through the development of slim and compact products. They sur-

pass previous generations (CMR MG11 and SMR MA11 Series) by incorporating an additional magnetic disk, bringing the total to 11 disks. Additionally, the recording media used in the M12 Series replaces the standard aluminum substrate with glass, which offers greater durability and enables a thinner design. Their enclosures are helium-filled, and the drives combine Toshiba’s proprietary Flux Control Microwave-Assisted Magnetic Recording (FC-MAMR™) technology with SMR, achieving storage capacities of 30 to 34 TB.
• The M12 Series HDDs adopt a host-managed SMR architecture, in which the host system manages data placement and rewriting within the drive. This approach enables more efficient data handling and reduces perfor-
wide range of optional accessories make it ideal for retail, healthcare or education sectors
• Outstanding durability and reliability: Military-strength design for everyday resilience, with stain-resistant case option or protective impact shield
• Daily productivity: Powerful Arm®-based MediaTek™ Kompanio 540 processor, up to 8GB LPDDR5X 6400MT/s memory, and up to 128GB storage
• Upgraded visuals: 2.5K 600-nits touchscreen with 120Hz refresh rate, TÜV Rheinland-certified eye care, Gorilla® Glass 3, and anti-fingerprint coating
mance degradation in server and storage system environments.
• The new SMR HDDs reach a maximum data transfer rate of 282 MiB/s[, an improvement of approximately 8%, while power consumption per terabyte (W/TB) is approximately 18 % lower than that of the previous generation of products.
• Designed for continuous 24/7 operation, the M12 Series supports an annual workload rating of 550 TB and offers an MTTF/MTBFof 2.5 million hours, an annualised failure rate (AFR) of 0.35 %.

Gartner says Enterprise GenAI Applications Will Face Rising Security Incidents as Adoption Accelerates

By 2028, 25% of all enterprise generative AI (GenAI) applications will experience at least five minor security incidents per year, up from 9% in 2025, according to Gartner, Inc., a business and technology insights company.
As organizations continue to build and integrate agentic AI applications using technologies such as Model Context Protocol (MCP), new attack vectors and immature security practices will significantly elevate risk exposure.
“MCP was built for interoperability, ease of use and flexibility first, so security mistakes can manifest without continuous oversight for agentic AI,” said Aaron Lord, Sr. Director Analyst at Gartner. “Because of this, the rate of minor security incidents within GenAI applications is set to grow at an increased rate. We will eventually see 15% of all enterprise GenAI applications experience at least one major security incident per year by 2029, up from 3% in 2025.”
As enthusiasm for frameworks like MCP grows, software engineering leaders must be prepared for the security realities that follow, ranging from data exposure incidents to vulnerabilities lurking in widely used third-party components. Protecting against these risks requires establishing rigorous security review processes, prioritizing low-risk use cases, mitigating known threat-patterns, and empowering domain experts to define guardrails that keep agentic AI both powerful and safe.
MCP’s design optimizes interoperability and developer speed,
not security enforcement by default, which means missteps can surface through ordinary usage. This can happen especially where agents can access sensitive data, ingest untrusted content, or communicate externally in the same flow. Software engineering leaders should treat any use case that combines those three factors as a “no-go zone” due to heightened exfiltration risk.
“Software engineering leaders should collaborate with data, security, and infrastructure teams to create a formal security review for MCP use cases to prioritize low-risk patterns and explicitly exclude high-risk combinations,” said Lord. “They should reinforce this with strong authentication and authorization practices tailored specifically for AI agents, not inherited from human user roles, to keep permissions tightly scoped. Applying well-known threat-pattern mitigations, such as guarding against content-injection and tightening oversight of third-party MCP components, will help close the most common gaps before they can be exploited.”
Successful, proactive mitigations for MCP security requires knowledge of antipatterns that can lead to vulnerabilities. Software engineering leaders will need to mitigate MCP vulnerabilities focused on known threat-patterns, such as content injection attacks, supply chain threats, and disclosure of sensitive data or escalation of privileges when AI tries to be helpful but makes a mistake.
“Software engineering leaders will need to establish domain-oriented ownership for MCP servers to drive domain-driven guardrails,” said Lord. “Growing complexity from agentic AI will eventually lead to complications managing access to data and maintaining compliance.”
To address this at scale, Gartner recommends that software engineering leaders collaborate with domain experts and work backward to ensure secure-by-default interactions for agentic AI. It will be critical for domain experts to predefine their guardrails before allowing MCP clients to access their data and resources. These domains should be the owners of MCP servers and define the guardrails for agentic AI usage.


