SAFER SITES
How AI is transforming construction safety
CLOUD CONFIDENCE
Building safer, smarter spaces
HUMAN FACTOR
Building trust in the AI era

$25 MILLION
![]()
How AI is transforming construction safety
Building safer, smarter spaces
Building trust in the AI era

$25 MILLION
IDEMIA Public Security explores the growing threat of deepfake fraud
As the META region innovates, the "Mythos" threat landscape is completely rewriting cybersecurity. Adversaries now weaponize frontier LLMs to execute autonomous attacks, slashing the vulnerability exploit window from nine months to just nine hours.
Human-paced patching cannot survive these machine-speed threats.
Contain AI-driven attacks with microsegmentation
• Shrink the blast radius immediately
• Ringfence critical assets
• Contain malicious sessions Akamai Technologies, Arenco Tower Al Safouh 2 - Unit No. 1704, Level 117Dubai, United Arab Emirates akamai.com


EDITORIAL
Publisher
Barry Bebbington +44 1708 229354 barry@pubint.co.uk
Editor Cora Lydon +44 7834 244613 cora.lydon@securitymiddleeastonline.com
ADVERTISING
Worldwide
Mike Dingle +44 1752 267330 mike@securitymiddleeastonline.com
Ryan Bickerton +44 1752 265802 ryan@securitymiddleeastonline.com
Gareth Driscoll +44 1752 260603 gareth@securitymiddleeastonline.com
Rahul Vara +44 1752 604352 rahul@securitymiddleeastonline.com
Will Russell +44 7800 513300 will@securitymiddleeastonline.com
Marketing Manager
Mark Doyle +44 7517 452283 mark@securitymiddleeastonline.com


As we move into the second half of the year, the security sector is entering an increasingly busy period, with industry professionals preparing for a number of key events and developments. In November, the focus will turn to Saudi Arabia as both Intersec Saudi Arabia and the Security Middle East Conference (more details on page 14) bring together leaders from across the region and beyond to share knowledge, explore innovation and address the evolving challenges facing the industry.
PUBLISHED BY
Publications International Ltd +44 1708 229354 166 Front Lane, Upminster, Essex, RM14 1LN, UK
This publication may not be reproduced or transmitted in any form in whole or in part without the written consent of the publishers.
©Publications International Ltd. 2026
For subscriptions and advertising enquires, or for further information on the magazine visit our website at: securitymiddleeastmagazine.com
This issue reflects many of the themes that will shape those conversations, from technology-driven transformation to the continued importance of human-centred security strategies.
Our cover story this issue examines the growing challenge of deepfake technology and its implications for financial institutions. Rodolphe Hugel, IDEMIA Public Security, explores why identity has become one of banking’s most vulnerable points — and how the strongest defence may already exist within the branch environment itself, take a look on page 12.
Following the global spotlight on the FIFA World Cup 2026, we take a closer look at how the Saudi Pro League has enhanced its approach to safety and security, with measures developed by ESM Operations Ltd to support safer, more resilient matchday environments (page 22).
Elsewhere, Gary Ng of viAct considers how computer vision is transforming worksite safety, moving beyond traditional compliance models towards more proactive approaches that support real-time decision-making and improved operational control (page 16). And on page 30 John Rodriguez explores how artificial intelligence is reshaping security operations, while highlighting that the ability to build trust through genuine human connection remains one of the sector’s greatest strengths.
As security professionals continue to navigate an environment shaped by emerging technologies, evolving threats and increasing expectations, one message remains clear: effective security depends on the ability to combine innovation with expertise, collaboration and practical implementation.
Cora Lydon Editor cora.lydon@securitymiddleeastonline.com
ISSUE 149 JULY 2026
03 Up front
Foreword from the Editor
06 Market Monitor
A roundup of the latest security products and solutions
09 News Monitor
The latest regional and international security news
12 Cover story: IDEMIA Public Safety
Deepfakes have turned identity into banking’s softest target. The strongest defence may already exist inside the branch, according to IDEMIA Public Security
14 Security Middle East Conference 2026
Saudi Arabia’s mega-event future is redefining security excellence – and Security Middle East Conference is helping shape the next generation of industry leaders
16 The intelligent site
Gary Ng, CEO and Co-Founder of viAct, considers how Computer Vision is moving worksite safety from compliance to command

24 From alerts to understanding Identity is the new perimeter. Most breaches do not start with a hack. They start with access that already exists, and no one is tracking it, says Karl McGowan, Co-Founder of FrontierZero
27 Cloud control
Louise Bou Rached, Director, Middle East, Turkey, and Africa at Milestone Systems, looks at how building safer, smarter spaces starts with secure cloud infrastructure
35 Building resilient data centres
Firas Jadalla, Regional Director – META, Genetec, explores why physical security is more critical than ever
30 Security professionals can smile, AI can’t smile
John Rodriguez, Empathic Security Cultures, argues that while AI is transforming security operations, the ability to build trust through genuine human connection remains the profession’s greatest competitive advantage

40 Intelligence in action
Why threat intelligence and threat hunting must converge in the AI era by Azeem Aleem, Executive Director, Cyber Resilience Services at CPX
22 Case study: Saudi Pro League
ESM Operations has been instrumental in building a safer matchday experience across the Saudi Pro League, we find out more
48 SSPN: From compliance to confidence
Why audit readiness matters in 2026 and a practical mid-year checklist for security leaders seeking operational excellence, from the Security & Safety Professionals Network (SSPN)

49 Interview: Crisis and disaster management
Meshal Aljohani, CPP, PSP, PCI, Security Operations Specialist, chats with Dr Ayman Barnawi, Head of Crisis and Disaster Management
50 Diary
Diary dates for forthcoming security exhibitions, conferences and events
20 March Networks




Karl McGowan
Co-Founder, FrontierZero
Karl McGowan helped found the the GCC’s first SaaS Security Posture Management platform and is the winner of the Rising Star in Cybersecurity 2025 from UAE CyberSecurity Council.
Louise Bou Rached
Director, Middle East, Turkey, and Africa, Milestone Systems
Having spent a decade in technology sales, Louise exercises her passion for technology and people across emerging and developed markets in the Middle East and Africa.
Azeem Aleem
Executive Director, Cyber Resilience Services
Azeem is specialised in cyber defence technologies, security operations design and implementation, threat intelligence, incident response and behavioural analytics.








Dubai Police has unveiled the second generation of its ‘Ghiath’ smart patrol vehicles, developed in partnership with Al-Futtaim, the exclusive distributor of BYD vehicles in the UAE, as part of efforts to advance smart, sustainable policing capabilities.
The new patrol vehicles are based on the plug-in hybrid DENZA B8 platform and are designed to support Dubai Police operations through the integration of advanced security technologies, artificial intelligence capabilities and improved mobility solutions.
The launch, held on 8 July 2026, coincided with the signing of a Memorandum of Understanding between Dubai Police and Al-Futtaim to support the development of the next generation of
Ghiath patrols. The agreement was signed by Major General Saif Muhair Al Mazrouei on behalf of Dubai Police and Yousuf AlRaeesi, Director of Government Affairs at Al-Futtaim.
Lieutenant General Abdulla Khalifa Al Marri, Commander-in-Chief of Dubai Police, said the partnership reflects the organisation’s commitment to using innovation and technology to enhance public safety while developing a more efficient and sustainable security transport ecosystem.
The Ghiath project is one of Dubai Police’s flagship smart vehicle initiatives, incorporating advanced systems and AI technologies to support policing activities and improve operational capabilities. alfuttaim.com


Security technology manufacturer Paxton has launched Solo, a new cloud-hosted access control system designed to use smartphones as both the security system and access credential.
The company says Solo represents a new approach to access control by removing the need for on-site servers, networks or centralised PCs. Instead, the system is managed through the Paxton Solo app, with users able to access sites using their phone’s built-in biometric features.
Solo combines the simplicity of standalone systems with the flexibility of networked access control. The system has also undergone independent cybersecurity testing, achieving IASME Level 1 and Level 2 certification, as well as UL IoT Cybersecurity Diamond certification. paxton-access.com
Hanwha Vision has launched its second-generation X Series AI Compact Cameras, combining advanced artificial intelligence capabilities with a discreet design aimed at supporting modern security applications.
Powered by the Wisenet 9 SoC and Dual NPU technology, the new cameras provide enhanced image processing and accurate object analytics while maintaining a compact form suited to challenging installation environments.
The cameras feature Dynamic Privacy Masking, enabling real-time protection of sensitive information by automatically masking people, faces, vehicles and licence plates.
Designed for both indoor and outdoor use, the cameras offer integrated infrared technology with up to 25m illumination, alongside IP66 and IK10 ratings for durability. Available in 2MP, 5MP and 8MP models, the range provides installers with flexible options for a variety of security requirements. HanwhaVision.eu

The UAE Cyber Security Council and Commvault have launched an Innovation Center of Excellence in Abu Dhabi to strengthen national preparedness against evolving cyber threats.
Unveiled during Commvault’s SHIFT Dubai roadshow, the centre will provide a hub for cyber resilience research, innovation and hands-on security demonstrations, including simulated environments for testing response and recovery from cyberattacks.
The facility will support government entities, critical infrastructure operators, universities and technology partners, while helping develop future cybersecurity talent through industry-focused training and certification.
The initiative includes plans for a regional Commvault Readiverse
environment, enabling organisations to practise recovery scenarios and strengthen resilience against increasingly sophisticated attacks.
“Cyber resilience is a national imperative, and it requires more than the ability to defend; it requires the capacity to recover. This Center of Excellence with Commvault directly advances that capacity, bringing enterprise-grade recovery simulation and structured talent certification to the UAE’s government entities and critical infrastructure operators. It is a concrete step in building a digitally sovereign nation, prepared for the threats of today and ready for those of tomorrow,” said H.E. Dr. Mohamed Al Kuwaiti, Head of Cybersecurity for the UAE Government. csc.gov.ae
The rapid adoption of artificial intelligence across organisations in the UAE and Saudi Arabia is creating new cybersecurity challenges, with research highlighting concerns that governance frameworks are struggling to keep pace with the deployment of autonomous AI tools.
A study by KnowBe4 found that AI agents are already taking actions within organisational workflows across the region, while a proportion of businesses are using AI applications without formal oversight or security controls. The findings highlight the growing challenge of managing ‘shadow AI’ as employees adopt new tools outside approved processes.
According to the research:
• 84% of cybersecurity leaders surveyed said AI agents are already operating within workplace workflows.
• 24% reported unapproved or ungoverned AI use within their organisations.
• 52% say that a deepfake scam could deceive them at work.
• Over 54% agreed that routine employee mistakes had the greatest impact on cybersecurity over the past year.
• But, 76% of security leaders said they felt “very well prepared” for emerging AI-driven threats.
Cybersecurity company Group-IB has released its Top 10 Masked Actors for 2026 report, drawn from its High-Tech Crime Trend Report 2026, highlighting the threat groups and cybercriminal ecosystems it says are having the greatest impact on the global cyber landscape.
Based on more than 1,550 frontline investigations and underground threat monitoring, the report identifies a growing shift towards supply chain attacks, with threat actors increasingly targeting trusted infrastructure and
third-party ecosystems rather than individual organisations.
The ranking highlights a range of evolving threats.
1. Scattered Spider
2. Lazarus
3. MuddyWater
4. Tycoon 2FA
5. GoldFactory 6. TX-NFC
7. Shadow Silk
8. Bloody Wolf
9. Teste PHP
10. DarkBlinders
The growing commercialisation of cybercrime tools, including phishingas-a-service platforms, is lowering the barrier for less experienced attackers to launch sophisticated campaigns.
The company warned that organisations must adopt a more intelligence-led approach, focusing on understanding adversary behaviour and anticipating future attack methods.
group-ib.com


Most cybersecurity conversations stop at the network. Firewalls, user access, encrypted connections – all essential, but they only cover part of the journey your data takes. What about everything that happens after: through the processors, the cables, all the way to the screen itself?
Barco built a continuous chain of trust that protects content from source to every individual LED pixel. No gaps between vendors, no weak links at the handoffs, no assumptions about what’s “probably fine.” Just one accountable chain, secured at every step, from Barco CTRL to the Infinipix image processor to the display itself.
Curious how far security should really go? Read the full article and see what source-to-pixel protection looks like in practice.

Security professionals are increasingly being called upon to support not only physical safety and operational resilience, but also the psychological wellbeing of employees as organisations navigate geopolitical uncertainty, constant connectivity and evolving workplace pressures.
To support this need, International SOS has launched a new Psychological Support Service, offering short, scalable workshops designed to help employees build resilience during challenging periods. The sessions cover areas including crisis coping strategies, managing the 24/7 news cycle, balancing work and home pressures, fatigue management and maintaining focus during prolonged uncertainty.
Available globally, the 30-minute sessions are designed to complement existing wellbeing and risk management programmes, providing organisations with an accessible way to strengthen employee support and resilience.
For security leaders, the initiative highlights the growing role of workforce wellbeing as a key component of effective security strategies and organisational preparedness. internationalsos.com
The International Security Management Association (ISMA) has appointed Marcelo Rodriguez as President of its Board of Directors, effective 1 July, as the organisation focuses on supporting the evolving role of the Chief Security Officer.
Rodriguez, VP & Global Head of Security, Safety and Travel at Assurant, brings more than 30 years of experience across law enforcement, corporate security and enterprise resilience.
He said security leaders are increasingly expected to act as strategic business partners, managing complex risks spanning geopolitical, cyber, physical and supply chain environments. The appointment follows the completion of ISMA’s first IGNITE programme cohort, designed to support the development of future security leaders. isma.com
The UAE is continuing to expand AI and biometric technologies across its airports, enabling more passengers to travel without repeatedly presenting passports or boarding passes. By integrating facial recognition and digital identity systems, authorities aim to speed up passenger processing, enhance border security and improve the overall travel experience as airport traffic continues to grow.
Kuwait has launched a US$100 million Emergency Response Fund to support crisis response, recovery and rehabilitation efforts. The initiative, established by the Kuwait Fund for Arab Economic Development, aims to improve national preparedness and enable faster mobilisation of resources during emergencies.
Oman has been ranked among the world’s safest countries (2nd place), highlighting its strong public security, low crime levels and effective law enforcement. The country’s high safety ranking reflects continued investment in security measures, stability and public order, reinforcing Oman’s reputation as a secure destination for residents and visitors.
Hikvision has announced that its DeepinView network camera series (iDS-2CD7x) has achieved EUCC (European Cybersecurity Scheme on Common Criteria) certification, becoming the first CCTV camera product category to receive the accreditation, according to the company.
The certification was issued by TrustCB B.V. following independent evaluation by Bureau Veritas Cybersecurity Europe against Common Criteria standards. The cameras achieved the EUCC ‘Substantial’ assurance level, validating security controls including authentication, access management, secure communications and vulnerability handling.
Hikvision said the certification demonstrates its Security-by-Design approach, with cybersecurity integrated throughout the product lifecycle. hikvision.com
•
•
•
•



NETWAY SPECTRUM
Hardened PoE Switches & Fiber Media Converters
Deploy IP devices at remote locations with or without local power
Supports up to 90W per port
Rapid battery charging provides extended power backup
115/230VAC or 277VAC input
• Manage and reset devices remotely with LINQ™ Network Power Management
• Lifetime warranty

altronix.com
© 2026 Altronix Corporation.




Deepfakes have turned identity into banking’s softest target. The strongest defence may already exist inside the branch. By Rodolphe Hugel, Head of Smart Connect at Smart Biometrics, IDEMIA Public Security
In early 2024, a finance worker at the engineering firm Arup joined what looked like a routine video call with the company’s Chief Financial Officer and several colleagues. The faces were familiar and the request was straightforward. Over the following days the employee arranged transfers of roughly $25 million. None of the people on the call were real. Every
face and voice had been produced by artificial intelligence.
The Arup fraud drew attention for its size, but the method behind it has become routine. Banks across the Middle East and elsewhere now face a steady, smaller-scale version of the same threat. The tools they rely on to confirm who is on the other end of a transaction were not
designed for a world in which a believable human face can be created on demand. Identity, rather than the network or the database, has become the most exposed part of a modern bank.
Consider how differently a bank handles the same customer in two settings. Walk into a branch to move a large sum and a teller compares the

identification with the face, registers that a real person is present, and verifies it on camera with colleagues within earshot.
Carry out the same transaction in the bank’s app and, until recently, the whole process came down to a password and a code sent by text. For 20 years the industry treated a digital transaction as deserving a lower standard of proof than one conducted in person. That assumption has become the gap through which fraud now travels.
The technique has shifted in a way many banks have not registered. Early deepfake attacks presented a fabricated image to a device’s camera, and software was trained to detect them. Newer attacks bypass the camera altogether, injecting
“Authorities
have started requiring banks to move away from text-message codes towards stronger methods”
a synthetic video stream directly into the application so that no genuine image is ever captured. The useful question is no longer only whether a face matches the one on record. It is also whether the face on the screen belongs to a living person who is actually present.
attacks don’t fool the camera – they bypass it
Most fraud succeeds not by overpowering a bank’s strongest control but by slipping between two controls that do not communicate. Account recovery is the familiar example. A bank can run advanced biometric login and still hand an account to a caller who fails that login, reaches a help desk, and is cleared on a date of birth and a utility bill. The login was never the vulnerability. The procedure beside it was.
A similar blind spot divides a bank’s physical and digital defences, which in most institutions are managed by separate teams that seldom share information. If an employee’s badge records them entering headquarters at nine in the morning, and their credentials approve a large overseas transfer a few minutes later, neither system sees anything wrong on its own. Placed side by side, the two records describe something impossible. Comparing signals across the physical and digital worlds catches fraud that either system would miss alone, and few banks have begun to do it.
None of this amounts to a case for simply buying more biometric technology; banks understand its value already. The harder task is distinguishing a system that genuinely withstands a manufactured attack from one that only claims to. As someone whose company
builds these systems, I would urge buyers to trust no vendor’s assurances, including ours. Independent laboratories now test identity software against live impersonation and injection attacks and publish measured results. A supplier unable to point to that kind of outside verification is requesting faith rather than offering evidence.
Regulators have reached the same view. Authorities in the United Arab Emirates and Saudi Arabia have started requiring banks to move away from text-message codes towards stronger methods, for their own staff as much as for customers.
Underneath the technology sits a very old question, the one a teller answers every time someone steps up to the counter: is this person who they say they are? Banks could once take the answer for granted. They no longer can. The institutions that come through the next few years intact will be the ones that decided their app deserved the same scrutiny as their front desk, and built the two to work as one. The alternative is a banking system full of customers and staff who, like the employee at Arup, are sure they are in good company when in fact they are entirely alone.
Rodolphe Hugel is Head of Smart Connect at Smart Biometrics, IDEMIA Public Security, which has spent decades building the biometric and identity systems used by governments and financial institutions around the world. The company works with banks across the Middle East on the questions raised here.
idemia.com

Saudi Arabia’s mega-event future is redefining security excellence –and the Security Middle East Conference is helping shape the next generation of industry leaders
The world is watching Saudi Arabia. Over the next decade, the Kingdom will host some of the largest and most complex international events ever staged in the region. The Asian Winter Games in 2029. Expo 2030 in Riyadh. The FIFA World Cup in 2034. Alongside these landmark events sits an ambitious pipeline of giga-projects, tourism destinations, smart cities and critical infrastructure developments that are transforming the Kingdom at an unprecedented pace.
While much attention is rightly focused on economic growth, tourism and infrastructure investment, another equally important conversation is taking place behind the scenes. How do nations safely welcome millions of visitors, athletes, dignitaries and VIP delegations while protecting critical assets, maintaining public confidence and ensuring uninterrupted operations?
The answer lies in world-class security, resilience and risk management capabilities.
Major international events present unique challenges for security leaders, government agencies, venue operators and critical infrastructure providers. Stadiums, exhibition centres, hotels, transport hubs and entertainment venues must not only provide a seamless visitor experience but also maintain robust physical security, cyber resilience and emergency preparedness under intense global scrutiny.
From crowd management and access control to threat intelligence, command and control systems, cybersecurity and critical infrastructure protection, successful events require integrated security strategies that can adapt to an increasingly complex risk environment.
As Saudi Arabia’s global profile continues to rise, so too does the expectation that its security standards will meet – and increasingly exceed –international best practice.
Building a global benchmark Riyadh offers a compelling example of this evolution.
Over recent years, the Saudi capital has emerged as one of the fastest-growing centres for security, safety and resilience in the Middle East. New developments are incorporating advanced technologies, smart infrastructure, integrated command centres and data-driven security strategies from the earliest stages of planning and design.
The city is also becoming a focal point for professional collaboration and knowledge exchange. International exhibitions and conferences dedicated to
security and resilience have experienced significant growth, reflecting both the scale of development underway and the increasing recognition that security is a fundamental enabler of economic growth and social development.
The success of events such as Intersec Saudi Arabia demonstrates the growing appetite for professional learning, innovation and industry engagement. Attendance has increased year-on-year, attracting security directors, government officials, consultants, technology providers, systems integrators and risk management specialists from across the region and beyond.
This growth is not simply a reflection of market opportunity. It signals a broader shift in mindset. Organisations increasingly recognise that effective security is no longer solely about protection; it is about enabling growth, supporting business continuity and safeguarding national reputation.
For security professionals, Riyadh is rapidly becoming a destination where important conversations about the future of the profession are taking place.
One of the defining characteristics of successful international events is the ability to learn from previous host nations.
The challenges faced by organisers of major sporting events, world expos and global summits are rarely unique. Protective security, crowd management, intelligence sharing, cybersecurity, VIP protection, crisis management and business continuity planning are issues that have been encountered and refined across multiple continents.
The opportunity lies in sharing these lessons.
As Saudi Arabia prepares for a decade of international events, there is significant value in bringing together experts from around the world to discuss emerging threats, technological innovation and best practice approaches that can help shape future preparedness.
In an increasingly interconnected world, professional networks can be just as valuable as technology.
“At the Security Middle East Conference, held in Riyadh on 29 November, attendees will have the opportunity to engage with international experts,”
Alongside technological advancement, another trend is reshaping professional development across the security sector: The rise of micro-credentials.
Security professionals today operate in an environment characterised by rapid technological change. Artificial intelligence, cybersecurity, digital investigations, proactive security and resilience planning all require continual learning and adaptation.
Micro-credentials, digital certificates and digital badges provide a modern mechanism for recognising specialist knowledge and professional development. Increasingly, they are being used to demonstrate competence, support career progression and strengthen professional credibility.
Importantly, these credentials are becoming valuable additions to professional portfolios, LinkedIn profiles and continuing professional development records, providing visible evidence of an individual’s commitment to lifelong learning.
The security challenges of tomorrow will require leaders who understand not only traditional security principles but also emerging technologies, cyber-physical threats, intelligence-led operations and organisational resilience.
Professional events provide a valuable platform to support this development journey.
At the Security Middle East Conference, held in Riyadh on 29 November, attendees will have the opportunity to engage with international experts, explore emerging trends and gain valuable insights into
the issues shaping the future of security and resilience. In partnership with the University of South Florida, participants will also receive digital certificates recognising the professional learning and knowledge gained through attendance.
While the certificate itself represents an important achievement, the broader value lies in the investment professionals make in their own development and future capability.
Saudi Arabia’s journey towards hosting some of the world’s most significant international events presents an extraordinary opportunity for the security profession.
The scale of ambition demands worldclass standards. It requires innovation, collaboration and a commitment to continual learning.
As Riyadh continues to strengthen its position as a regional hub for security, safety and resilience, the conversations taking place today will help shape the preparedness, operational excellence and leadership required for tomorrow.
For professionals seeking to remain at the forefront of these developments, there has never been a more important time to engage, learn and contribute to the future of security and resilience in the region.
We hope to see you at the Security Middle East Conference in Riyadh on 29 November.



Gary Ng, CEO and Co-Founder of viAct, considers how Computer Vision is moving worksite safety from compliance to command
With an unprecedented construction boom taking place throughout the Middle East, there has never been such rapid progression towards mega-infrastructure development, and Saudi Vision 2030 is an example of this growth that has created continual expansion across both the urban and industrial landscapes of the UAE. Many of the newly constructed buildings are considered to be among the most advanced buildings ever built in all respects, including prefabrication, logistics, BIM (Building Information Modelling) and drone surveying technology.
Unfortunately, the safety methods used today to manage injury prevention on construction sites in the Middle East have not changed very much since they were first introduced. Even today, they usually rely on people watching over each other, conducting periodic safety audits, and reacting to incidents after they occur. Therefore, with trillions of dollars being spent on projects for the future in the Middle East, these traditional methods of managing construction worker safety leave a huge gap in the effectiveness of managing incidents on site. However, it is clear that computer vision has started to change the current ways of construction worker safety management, and its implications reach well beyond the safety function.
All EHS professionals are aware with the compliance framework: Establish standards, train workers, inspect activities and document results. This is a good model indeed and has been used for many decades. However, the issue with it is that it was designed for a different scale of operations than the current conditions. On a mega-site with thousands of workers in multiple work zones, no
inspection regime can provide continuous visibility. For instance, a toolbox talk at 7 AM does not prevent a PPE noncompliance by a worker at 2 PM when the temperature is 45 degrees. Similarly, a manual permit-to-work does not provide real-time information about an unauthorised entry into the operating radius of a crane.
The data reflects this. The current global mortality rate within the construction industry is about 6.1 per 100,000 workers. This is nearly double the all-industry average. Across the GCC, despite regulatory reforms, incident rates in the region have historically lagged behind more mature safety markets. The existing compliance model produces documentation, but it rarely produces prevention.
The transformation that computer vision enables is not a mere small adjustment. It is a change in how recording is done, from observations after-the-fact to instead include information that describes the conditions that precede an incident.
Think about a worker approaching a restricted area near active lifting operations. The traditional method of recording would be a camera recording the worker entering this area. But a well-built scenario-based AI will notify the supervisor of the worker’s approach and create a response plan (site-wide response) before they enter the area. The difference isn’t just the camera; it is the way the video feed is processed through the AI system.
A wide array of site risk scenarios exhibits this same reasoning: Fatigue postures for lone workers, PPE noncompliance before entering a high voltage area, proximity violations between individuals and mobile equipment, and

environmental stress indicators that show the potential for a heat-related injury. In all of these scenarios, the AI-powered safety system does not react after-the-fact to instances of injury. The system reads the conditions that created an injury, and ‘intervenes’ in the interval of time between the two points, that is, the point at which the event started and the point at which one can react to it.
Operationally, this is what ‘predictive safety’ is. It is not simply a marketing position; it represents a change in the informational architecture used to manage sites. The goal was never to create a smarter camera to provide the site leadership with a different way to manage their assets and people. The true goal was to provide them the information needed to make ‘real-time’ decisions concerning the potential for a future accident. This is the only ‘safety’ that actually works.
Deploying computer vision across a megaproject site in the Gulf is an operational layer that serves multiple risk functions simultaneously. For example, at any point during a given shift, that same computer vision system can be used to track vehicle movement patterns to prevent blindspot collisions near active excavation zones; detect improper scaffolding assembly before a crew begins working at height; monitor material stacking to flag structural instability risks in
storage areas; and identify unauthorised personnel approaching site perimeters during off-hours.
The value of deploying computer vision is not about the individual functions but rather relating that information into a single, unified command picture that executive leadership on-site can act on in real-time.
This is where the transition from monitoring to command becomes tangible. A safety officer who manages a dashboard that reflects live risk conditions for the entirety of 500 acressites has a fundamentally different capability than an individual who only receives incident reports. Decisions concerning shift rotation, zone access and equipment scheduling can be made based on live intelligence instead of historical trends. Safety is no longer separated from site operations, but rather directly impacts the day-to-day operational flow of the site.
The results of one such implementation shows this trend to be true. A major construction project in Saudi Arabia, integrated IoT-enabled smart wearables and AI video analytics to help manage heat stress of workforce working under extreme desert conditions, dispersed over an extensive geographical area. The system allowed continuous physiological monitoring rather than periodic wellness checks, so risks could be identified before workers showed any symptoms. This allowed supervisors to
intervene immediately and led to a 63% reduction of on-site medical emergencies. Further, the data collected facilitated operational planning and risk reporting for management.
The Middle East is currently experiencing a unique opportunity with all the developmental activities happening at the same time as the political will behind Vision 2030. Further, many national strategies are being implemented across the GCC. Any infrastructure decisions made today will create the operational standards for decades to come going forwards. Embedding predictive AI oversight into the current infrastructure now, instead of retrofitting it later, is both cost-effective and oriented towards longterm strategic goals.
C-Suite leaders should no longer wonder ‘Will AI enhance safety?’, as the current deployment of AI has already answered the question. What they should instead wonder is: ‘How will they utilise their safety data?’ Will they be treating safety data as an operational asset, or will they simply continue to manage it as a compliance obligation. The sites that successfully answer this question will benefit from reduced incidents and, most likely, gain a measurable competitive advantage compared to sites that do not.
viact.ai


Sinden, Regional Director,
VIVOTEK,
looks at the new priorities for video intelligence
Across the Middle East, one theme is coming to dominate the video surveillance conversation: video is becoming a core part of national infrastructure, enterprise security and operational decision-making.
Banks, retailers, hospitality groups, transport operators and public safety organisations are managing larger and more complex video environments. Many are responsible for hundreds or thousands of sites, distributed teams, mixed camera estates and growing volumes of data.
At the same time, expectations are changing. Organisations need video systems that are secure, flexible, centrally managed and able to turn information into action.
This is where the market is moving: towards trusted video infrastructure that supports data sovereignty, cybersecurity, hybrid cloud and multi-site intelligence at scale.
Data sovereignty is now a priority Video data is sensitive. It can reveal how people move, how sites operate, where risks exist and how incidents unfold. For any organisation managing critical or government-adjacent operations, that data must be handled with care.
Customers across the region are asking where video is stored, who can access it and how it is protected, making data sovereignty a defining part of video strategy.
The answer is not always a full move to the cloud. In many cases, the best model is hybrid. Critical video can stay close to the site on a robust NVR, while cloud services support central management, long-term storage, analytics, dashboards and remote access.
This gives organisations the flexibility to keep control of sensitive data and support local requirements, while still benefiting from cloud-based intelligence where it makes sense, and organisations moving workloads to the cloud are seeing storage costs drop by up to 80%.
For large multi-site operations this flexibility is essential. A bank branch, ATM, hotel, depot or public safety location
may each have different bandwidth, storage, retention and operational needs. A modern video platform must support those differences without adding complexity.
must be built in Cybersecurity is now central to every video conversation. Cameras, recorders, software, mobile apps and cloud services are all connected. If any part is not designed and maintained properly, it can create risk.
That is why organisations are looking more closely at supply chain trust, device security, software updates, access controls and long-term lifecycle management. They want video infrastructure that is secure by design, not secured as an afterthought.
This is one area where the March Networks and VIVOTEK merger creates practical value. Together, the companies bring a more connected ecosystem across cameras, recorders, video management, analytics, cloud services and central management – a stronger foundation for trusted, end-toend video deployments.
Many of the region’s most important video deployments are not single buildings –they are networks spanning branches, stores, depots, field sites and remote assets across dozens, hundreds or thousands of locations.
Public safety and infrastructure projects can involve thousands of locations and very large camera counts.
At that scale, the challenge is not simply recording video. It is keeping every site visible, healthy, secure and easy to manage.
A distributed NVR platform gives each location reliable local recording and built-in intelligence. Central management gives teams full-estate oversight. Health monitoring identifies issues quickly, remote configuration reduces site visits, and investigation tools help teams find the right video faster.
March Networks has a long history in large, distributed deployments, including thousands of remote ATM locations in Saudi Arabia managed over the past 15 years. These projects have proven the value of rugged hardware, reliable local recording and centralised software for managing many sites at scale.
The same approach is now relevant far beyond banking. Infrastructure, traffic, public safety, smart city and transport environments all need video systems that can scale across many locations without becoming difficult to operate. Giga-projects such as NEOM, the Red Sea Project and Diriyah Gate, together with the build-up to the 2034 FIFA World Cup in Saudi Arabia, will demand exactly this kind of enterprisegrade video infrastructure, deployable across hundreds or thousands of sites and trusted by the world’s largest banks, retailers and transport agencies.

The next step is making video more useful. Traditional surveillance helps teams review what happened. Modern video intelligence helps them understand what matters and act on it faster.
In hospitality and QSR environments, this can support guest flow, queue management, loss prevention, fraud investigations and operational reporting. In banking, it can help teams review ATM activity, access events, suspicious behaviour and compliance-related incidents. In infrastructure and public safety, it can support incident response, site visibility, restricted-area monitoring and faster evidence retrieval.
March Networks’ AI-enabled tools support these workflows: AI Smart Search and Attribute Search help users find and validate relevant moments faster, while Searchlight Cloud dashboards and reports turn video and operational data into clearer insights. Customers report reducing investigation time by up to 90%.
The goal: reduce the time it takes to find evidence, understand incidents and make informed decisions.
The Middle East is investing in some of the world’s most ambitious projects – in banking, hospitality, transport, smart cities and public infrastructure. The organisations leading those projects need video technology that serves more than the security team: it must support operations, compliance, customer experience and business performance, all from a single connected platform.
This is the value March Networks and VIVOTEK are working to deliver together: a complete video ecosystem for organisations that need secure, sovereign and scalable intelligence across many locations.
The future of video surveillance in the region will not be defined by who can capture the most footage. It will be defined by who can protect that footage, manage it efficiently and turn it into intelligence that helps operations run better and decisions get made faster.
For more information, visit marchnetworks.com.
ESM Operations has been instrumental in building a safer matchday experience across the
As the Saudi Pro League continues its rapid rise as one of the world’s fastestgrowing football competitions, and the Kingdom strengthens its position as a major destination for international sport, ensuring safe, consistent and professionally managed matchday environments has become an increasingly important strategic priority.
With rising attendances, expanding infrastructure and growing international attention, the league recognised the need to benchmark operational performance across its venues and establish a clear framework for long-term public safety excellence. To support this ambition, the Saudi Pro League partnered with global event public safety consultancy ESM Operations to undertake a comprehensive review of public safety and operational standards across league stadiums, creating a roadmap for greater consistency and continuous operational improvement.
The Saudi Pro League’s accelerated growth has created significant opportunity, while also increasing operational complexity.
As clubs continue to evolve their matchday offering, differences in stadium infrastructure, venue capacity and operational procedures can create inconsistencies in public safety delivery. For a competition growing in scale and international visibility, these variations present a challenge.
The SPL required a clear understanding of how each stadium was performing against recognised international standards, while also identifying opportunities to create a more unified operational approach across the league.
Mohammed AlAqeel, Director of Fan Experience at Saudi Pro League, commented: “As the league continues

Operating across three international hubs, ESM Operations supports clients across all phases of an event, from early planning and design through to live operations and post-event review across the events, sports and entertainment sectors, delivering consistent standards of public safety across diverse and complex environments.
esmoperations.com

to evolve, our collaboration with ESM Operations marks an important step in strengthening safety, improving operational consistency and enhancing the overall matchday experience across all venues. By establishing league-wide standards and supporting our clubs in achieving them, we are building a stronger operational foundation that aligns with international best practice and supports Saudi Arabia’s wider ambitions as it prepares to host major global sporting events in the years ahead.”
The challenge was not simply to identify operational gaps, but to establish a strategic framework capable of supporting continuous improvement across all clubs while ensuring future scalability as the league continues to grow.
To address these challenges, ESM Operations delivered Phase One of a league-wide operational review programme covering 16 Saudi Pro League stadiums, with two venues excluded due to ongoing construction and capacityrelated considerations.
The assessment focused on public safety and crowd management across the full spectator journey, with evaluations covering key operational areas including arrival, last mile, ingress and egress, stadium operations, internal circulation, pitch protection and egress and dispersal.
A consistent scoring methodology was applied across all venues to ensure fairness and transparency. Detailed reports were produced for each stadium, assessing performance across 11 categories and multiple subcategories, benchmarked against international best practice and ESM’s extensive operational expertise.
Results were presented using a clear traffic light-style framework, categorising
performance as poor, medium, good or very good. This enabled direct comparison across venues and provided league stakeholders with a clear, evidence-based understanding of operational strengths and development priorities.
David Dymitrow, Head of Public Safety and Crowd Management at ESM Operations, said: “This first phase provided a clear and structured understanding of current operations across the league. By applying a consistent methodology rooted in international standards, we’ve been able to identify both strengths and opportunities for improvement.
“As the Saudi Pro League continues to develop and evolve its matchday environment, there is an increasing focus on delivering safe, secure and professionally managed event operations. We are proud to support the league on this journey and look forward to building on these strong foundations in the next phases of the project.”
The project has provided the Saudi Pro League with a robust leaguewide benchmark for public safety and operational performance, giving stakeholders a clear view of how venues are performing and enabling more informed decision-making around future planning and investment.
The review has identified examples of existing best practice while delivering targeted recommendations to strengthen public safety and operational consistency across the competition, creating a clear framework for ongoing assessment and long-term strategic development.
Significantly, the review has established the foundation for Phase Two of the programme. Building on these insights, the next steps will focus on
The Saudi Pro League is Saudi Arabia’s premier professional football competition and one of the fastest-growing leagues in global sport. As part of the Kingdom’s wider sporting transformation, the league has undergone significant expansion in recent years, attracting international players, increasing fan engagement, and investing heavily in stadium infrastructure and matchday experience. As its profile continues to rise on the world stage, maintaining consistent operational excellence, public safety standards and high-quality spectator experiences across all venues has become a central priority for the league’s long-term development.
supporting the development of a unified public safety and crowd management platform across all Saudi Pro League clubs. This will involve establishing consistent operational principles, strengthening collaboration with clubs and stakeholders, and aligning practices with recognised international standards and guidance to support safer and more effective event operations across the league.
This approach is intended to create greater consistency in planning, delivery and oversight across matchday operations, while also supporting long-term capability development and continuous improvement throughout the league environment.
As Saudi Arabia continues to strengthen its position as a global destination for elite sport, this proactive investment ensures the Saudi Pro League is building the operational resilience required to deliver world-class matchday experiences for years to come.


Identity is the new perimeter. Most breaches do not start with a hack. They start with access that already exists, and no one is tracking it, says Karl McGowan, Co-Founder of FrontierZero
A colleague of mine who advises large enterprises on security shared a story recently that I have not been able to stop thinking about.
A senior executive at a major organisation had a problem. An important client needed VPN access to collaborate on a project. It was urgent. Going through
IT would take weeks, and this was a relationship he could not afford to slow down.
So he solved it himself. Bought a router on his personal card, configured the VPN, gave the client access, and got back to what he considered his actual job. He did not go through onboarding.
Did not log it with IT. Did not set a secure password. As far as the security team was concerned, that connection did not exist. It did exist, though. For months. Quietly. And when attackers eventually found it, they did not need to break anything. They just walked through a door that nobody knew was open.
The thing that stays with me is not the mistake. It is the motivation. That executive was not being reckless. He was being helpful. He had a business problem, found a solution, and security was simply not part of the equation in that moment. That dynamic did not disappear when we moved to the cloud. It accelerated. Today the equivalent is an SaaS integration approved over email to close a deal faster. A vendor given broad access because onboarding felt like friction. A shadow AI tool quietly connected to the company CRM by someone who wanted to work smarter.
The device changed. The blind spot did not.
The illusion of being covered
When organisations talk about cloud visibility, they usually mean they have logging turned on. Events are captured. Alerts are firing. Someone is watching the dashboard.
But here is the question worth sitting with: if something were going wrong inside your SaaS environment right now, would you know? Not eventually. Not after a vendor notified you. Right now.
Most security leaders, if they are honest, are not sure. And that uncertainty is the real visibility gap. Not missing data, but missing confidence.
I spoke with a security operations lead in Dubai whose team was processing over 2,000 alerts per day. Not because their environment was unusually hostile. Because their tooling was generating noise faster than humans could clear it. When I asked how many alerts he believed were genuinely significant, he paused before answering.
“Maybe five. But we don’t always know which five.”
That is alert fatigue in its most honest form. And it is not a staffing problem. It is a context problem.
The question detection tools are asking wrongly
Most security detection logic asks: does this event match a known bad pattern? If yes, alert. If no, pass. Simple. Scalable. And increasingly inadequate.
In a modern SaaS environment, the most dangerous activity often does not look dangerous. A user logging in. An integration pulling records. A contractor
“Map every external connection into your environment”
downloading files. Valid credentials. Approved access. No rules triggered. And yet something is very wrong. If identity is the perimeter, then unmonitored identity is an open door. The better question is not “does this match a rule?” It is “does this make sense for this user, at this time, accessing this data, in this sequence?” The difference between legitimate and malicious is often not what happened, but whether it is consistent with everything that came before.
Think about how a fraud analyst at a bank thinks. Not just whether a transaction exceeds a threshold, but whether it fits the pattern of this specific customer. When a transaction appears in a city they have never visited, at 3am, for an amount they have never spent, it stands out, not because it broke a rule but because it broke a pattern.
Cloud security is applying the same logic. Building a pattern of life baseline means establishing how each user, application and third-party connection normally behaves. Volume, timing, data accessed, systems touched. Not a static snapshot but a living model that updates continuously.
When something deviates, it surfaces. The contractor accessing files three days after their project ended. The integration that only ever touched contact records suddenly querying financial data. Neither of those would trigger a rule. Both of them are worth investigating.
As the baseline matures, the noise drops. The analyst’s queue shrinks, and everything in it earned its place there.
access you approved but stopped watching
Onboarding processes have improved. Vendor assessments, access reviews, least-privilege policies. But these are point-in-time controls. They tell you access was appropriate when granted. They tell you nothing about what happens six months later.
Think about how many integrations, vendors and contractors have access to your environment right now. Now think about the last time you reviewed not just whether that access exists, but what those entities have actually been doing with it.
In most organisations, that question does not have a clear answer. And that gap is exactly where some of the most damaging breaches of recent years originated.
Moving from access management to access intelligence starts with something deceptively simple: map every external connection into your environment. Not what exists on paper, but what is actively being used, touching what data, and whether that pattern has shifted. You cannot monitor what you have not mapped.
The organisations getting this right share one thing in common. They invested in understanding normal before trying to detect abnormal.
In practice, that means resisting the urge to add more detection rules when coverage feels thin, and instead asking: do we have enough context to know whether what we are seeing is genuinely suspicious?
Start with highest-risk access. Thirdparty integrations with broad permissions. Contractors whose access outlasts their engagement. Applications onboarded quickly and never reviewed. Establish what normal looks like for each, then build detection sensitive to deviations from that baseline.
The good news is this is a solvable problem. But solving it starts with being honest about what visibility actually requires.
Not more data. More understanding of the data you already have. And a clear map of every door that is open into your environment.
Because most breaches do not start with a hack. They start with access that already exists, and no one is tracking it. frontierzero.io



Louise Bou Rached, Director, Middle East, Turkey, and Africa at Milestone Systems, looks at how building safer, smarter spaces starts with secure cloud infrastructure
Security at a crowded airport terminal, stadium entrance or city transport hub fails when a camera goes offline, a credential is misused, a queue builds up near an exit, or a control room receives too many alerts and too little context. In
those moments, cloud security becomes part of how safely people move through physical spaces.
The bigger change is that cloud and hybrid architectures are moving deeper into real-time security operations. A modern video system is no longer only there to record what happened. With AI-assisted analytics, sensor integrations and workflow automation, it can help operators understand what is happening now and where attention is needed next.
The situation at a shopping mall before a major event, an airport during peak travel, or a metro station after a service disruption can change virtually every minute. People do not move through these environments in neat patterns, and here is where AI-integrated video management systems play a vital role.
Video intelligence can help operators spot congestion, identify blocked paths, understand dwell time and respond before a manageable crowd becomes a risk. But that only works if the cloud layer behind the system is secure, available and governed.
The weak point is often the user identity
Identity is the foundation for controlling who can access cloud resources, from where and under what conditions. For video management systems, it defines which users can view live feeds, export

footage, change retention settings, adjust analytics settings or connect to third-party applications.
In high-traffic venues, those privileges are important, especially when a control room may need rapid access during a safety incident. But that does not mean every user should have the same access every day. Role-based permissions, multi-factor authentication, conditional access, and regular access reviews are what keep useful systems from becoming dangerous ones.
The security infrastructure in many organisations has grown in layers over time, with legacy cameras, new analytics, cloud dashboards, access systems, mobile apps, storage platforms and integrations often added by different teams at different moments. Each layer
may work on its own, but the total picture can become foggy.
Risk often hides in configuration, such as exposed storage, excessive access, incomplete logs or integrations that move data beyond intended boundaries. As cloud environments become more distributed, organisations need identityled access, continuous verification and consistent security policies rather than relying on traditional perimeter controls.
Recurring risks such as data breaches, weak access controls, insecure interfaces and system misconfigurations continue to underscore the need for stronger cloud governance. The UAE’s National Cloud Security Policy aligns with this requirement by setting out clear security standards, governance responsibilities and risk management expectations. Cloud adoption for business leaders should advance in step with governance and security to ensure sustainable growth and resilience.
“Video intelligence can help operators spot congestion, identify blocked paths, understand dwell time and respond before a manageable crowd becomes a risk”

For physical security teams, that means knowing where video data is stored, who can access it, how long it is retained, how it is protected and how activity is audited. It also means testing integrations. A cloud-connected video platform becomes more valuable as it integrates with more systems, but each connection requires a security model.
Crowd intelligence needs a resilient architecture
Crowd and flow management puts a different kind of pressure on cloud security. Unauthorised access is only one part of the risk. In these environments, operators also need to trust that alerts, dashboards and shared footage remain accurate as people move through the space.
This is particularly relevant in regulated sectors such as aviation, where security authorities require strict control over access, retention and auditability of surveillance data.
If analytics flag a developing bottleneck at an entrance, operators need to trust the alert. If a dashboard shows crowd density across a venue, they need to know the data is up to date. If an incident requires sharing footage with another team, the workflow must be secure yet not so slow as to be useless. In a fast-moving incident, resilience keeps the system from becoming another point of failure.
This is where hybrid architecture often makes sense. Some processing may happen at the edge, close to the camera, where speed and continuity are essential. Other functions may sit in the cloud, where scale, storage, analytics and remote collaboration can be managed more efficiently. The aim is not to force everything into a single environment, but to align architecture with operational risk.
Best practice is rarely glamorous. It usually comes down to encryption, segmentation, monitoring, audit trails, access control, patching, failover testing and rehearsed incident workflows.
Responsible AI depends on secure cloud foundations
AI adds another layer to this discussion. As video systems become more intelligent, they rely on trusted data pipelines, secure processing and strong privacy controls. If the cloud environment is weak, AI does not magically make it stronger. It simply gives bad architecture more influence.
Responsible AI in video security needs clear boundaries. Teams need to know what data is being used, how it is protected and who is accountable when the system is uncertain. That discipline is not a drag on innovation. It is how new systems survive real scrutiny from regulators, customers and the public.
There is also a growing importance of privacy in video AI. Tools can help organisations use video data more responsibly by protecting identities. This connects AI, privacy and practical deployment rather than treating them as separate conversations.
In busy public spaces, that is an important distinction to keep in mind. Many use cases do not require knowing who a person is. They simply require understanding movement, density, direction, dwell time and risk. The more organisations can separate operational insight from unnecessary personal identification, the easier it becomes to build trust.
The real benefit is operational trust
The strongest cloud-based security systems are not stronger simply because
they are cloud-based. Their strength comes from identity controls, governance, resilience, privacy and a clear operational purpose.
In many UAE and GCC environments, data residency and sovereign control requirements further reinforce the need for hybrid architectures with clearly governed data flows.
That is the practical mindset CTOs and security leaders need. Cloud can make security systems more flexible, scalable and useful across complex environments. It can help organisations connect video to analytics, workflows and AI-assisted decision-making. It can support better crowd and flow management in the places where people gather, move, wait and sometimes panic.
But the cloud is not a shortcut around discipline. It raises the standard. Organisations need to know what they are connecting, why they are connecting it, who controls it and how it behaves under pressure.
Cloud-based security should not mean moving every system off-site and hoping for the best. Serious security leaders need hybrid, governed and auditable environments that provide operators with better information without sacrificing control.
When cloud security is done properly, the benefit is not simply stronger protection against cyber threats. It gives operators something more practical: systems that remain available, data that is handled responsibly and sufficient visibility to act when movement through a space begins to change.
milestonesys.com


John Rodriguez, Founder, Empathic Security Cultures, argues that while artificial intelligence is transforming security operations, the ability to build trust through genuine human connection remains the profession’s greatest competitive advantage
This article is a culmination of 44 years of frontline security management experience from a Propriety Security Officer to Manager with General Motors, then senior corporate security positions with Levi Strauss & Co., Kimberly-Clark, Cardinal Health and CSO with TempleInland in Austin, TX. I emphasise the word frontline because there is no other way for site leaders to know, like and trust you – three foundational components to the Art of Human Connection and your journey to building a security culture that business leaders and employees understand and embrace. Regardless of your position in your security department constant human connection should be an innate desire – from a friendly smile and good morning passing in the hallway or parking lot, to delivering executive level briefings to time-constrained business leaders, to incident/crisis management communications or workforce security training events.
A company’s overall culture – and ultimately its profitability – can be strengthened by embracing a security culture philosophy. Employees are either the weakest or the strongest link in the success of any security programme. The deciding factor is often the human aspect of business: what influences employees to be engaged with their work and colleagues each day, and how much discretionary effort, care, productivity, teamwork and innovation they choose to contribute.
Artificial Intelligence is also reshaping how security departments protect employees at work, while travelling on business and even at home. The most innovative security professionals are extending that value beyond traditional security functions by partnering with departments such as

“Employees are either the weakest or the strongest link in the success of any security programme”
facilities management to help monitor fire detection and suppression systems, as well as wider smart building technologies. Security leaders who remain solely in their ‘security lane’, rather than looking for opportunities to support other business functions, risk missing valuable opportunities to contribute to the organisation’s broader objectives. After all, the business mantra is simple: you are either making money or saving money.
Affordable modern-age security technology has existed for over 75 years now – technology that was developed and applied was leveraged by Security Departments at facilities and it met their needs at that time. Security technology in general has evolved constantly over those years up to the current domain of artificial intelligence. Just one example is how security video cameras evolved in 1950 with the Vidicon tube camera systems, then three decades later, solid-state CCD (Charge-Coupled Device) chip cameras arrived, followed by CMOS (Complementary Metal-OxideSemiconductor) sensor technology. In the last decade, embedded software then AI software made security
departments exponentially more efficient and effective.
AI products are benefiting almost every aspect of physical security, supply chain security, travel risk management and area event monitoring, but not direct human connection and that means positively influencing a leader’s or employee’s feelings (emotion) and cognitive understanding in the moment. An AIgenerated person can imitate human emotion, but people quickly recognise the difference. Automated voices and virtual faces rarely create genuine trust or empathy. A security professional’s greatest advantage still begins with a smile, a greeting and a positive first impression.
The first few seconds of any interaction can define how security professionals are perceived. A professional smile, a courteous greeting and genuine eye contact may seem like small gestures, but they are often the foundation of trust. Whether meeting a visitor for the first time or greeting a colleague at the start of the day, these moments demonstrate a uniquely human quality that technology can’t replace, and remain central to effective security.

A security professional who says, “I’m going to get business leaders to trust me and support our security programme” is often approaching it with the wrong mindset. Business leaders and employees need to know you and like you first. Only then can you begin the journey of earning their respect (they value you) and, ultimately, their trust. Trust is theirs to give, not yours to claim, and it is built gradually through one interaction after another.
A security culture is achieved when employees:
• Feel safe and secure;
• Protect each other;
• Give you information to protect them and the business;
• Have leaders and employees that trust you.
Security culture is often misunderstood. Two common definitions illustrate why:
“The security department instills security culture in all employees’ DNA”
This is a top-down enforcement mindset. It views culture as something forced onto people from the outside, rather than cultivated from within each employee’s understanding that by supporting the security programme, “I will be helping to keep me and my co-workers safe”. Furthermore, claiming security is in the DNA is corporate buzzword-speak that pretenses a lack of true employee buy-in.
“We train the employees to protect the company and it’s part of the company culture”
This is compliance-driven and transactional. Training is an event (a checkbox); culture is a continuous pattern of behaviour. When people feel protected by the site culture, protecting co-workers
and the business becomes a natural byproduct.
Business leaders and the workforce determine if a security culture is established. It has taken me over four decades of studying human interaction focused on the art of human connection, psychology and neuroscience to define a security culture.
The level of success in developing a security culture depends on the overall company culture and how employees are treated by leadership and each other. Are employees treated with respect and dignity consistently from day one? Is there a sense of fairness and accountability?
Many security professionals focus on building relationships with the C-suite, and gaining executive support is critical. However, it is just as important to engage with site and operational leaders. Each site leader is the CEO of their own operation, responsible for business performance and shaping the local culture.
When a security issue, incident or investment decision arises, the C-suite will value your expertise, and will likely place significant weight on the views of trusted peers. Building strong relationships at every level of the organisation is therefore essential to influencing decisions and achieving lasting security outcomes.
More on human connection: what are your personality traits or character attributes? What has worked well in establishing human connections with leaders and the workforce? What would you like to develop to do even better? These eight-character attributes have been my foundation in the human connection journey in my Security Culture Professional’s Attributes ModelTM –fairness, innovation, tenacity, respect, credibility, vulnerability as well as being perceptive and engaging. And each of these eight have multiple deeper critical aspects.
Science (Process)
The science side includes all the core services we provide, for example:
• Policies/procedures
• Security technology (video, access, intrusion, artificial intelligence)
• Intelligence
• Risk mitigation and crisis management
• Investigations
• Staffing
• Workplace violence prevention and response
• Travel risk management
• Insider threat programmes
• Supply chain security
• Assessment/auditing
• Training/awareness
• Executive protection
• Intellectual property rights
All these specialties are complex and challenging and require significant time to learn and develop solid expertise and the final achievement of wisdom (making and learning from my mistakes and those of others along the way). Seasoned front-line practitioners that have accumulated many corporate scars know they are precious achievements to be proud of.
The art of human connection (People) I believe this part is in general the harder of the two because it deals with humans. This security culture journey is nonlinear, perpetual, difficult, discouraging and frustrating. Yet, exhilarating and invigorating when achieved – and the eight-character attributes can help you succeed. When you combine those with self-care for your physical, mental, emotional and spiritual health, you will better understand the ebb and flow of successful human connections.
empathicsecuritycultures.com

CENSUS applies an offensive security mindset — a deep understanding of how systems are breached — to build cybersecurity/defensive features that produce resilient, real-world outcomes.
We collaborate with Fortune 500 companies and leading international organisations, specialising in critical sectors such as defence, automotive, healthcare, banking, maritime and telecommunications.
CENSUS DNA

Hacking acumen
Scientific superiority
CENSUS mission and vision
Safeguarding the digital landscape, our focus is on securing critical domains on a global scale. Providing expert cybersecurity engineering, solutions, consulting and development fuelled by both outstanding research and deep experience.
CENSUS offering
Cybersecurity engineering Cybersecurity engineering Tiger team
Ethos & professionalism
To be universally identified as a unique cybersecurity powerhouse in an emerging cyberworld.
CENSUS’ offering has a unique edge. Our DNA allows us to comprehend in depth the actions, processes and technical details of exploitation. Through research that advances the stateof-the-art and our experience, CENSUS gains unique insights into new attack vectors and techniques. This cybersecurity intelligence shapes our offering, essentially shielding our collaborators from future threats.
Our solutions have been designed with the following objectives in focus:
1 To empower our partners achieving end-to-end cybersecurity, from inception to post-deployment.
2 To provide cutting-edge cybersecurity engineering implementation for niche problems.
3 To enable vendors to offer cyber-resilient products and services
4 To identify new cybersecurity risks in technologies and organisation processes.
5 To provide exploitation and zero day vulnerabilities intelligence
CENSUS has helped major corporations around the world to achieve cybersecurity resilience and provide hackproof products with the cybersecure promise. It has audited the design and implementation of multiple security-critical devices. Many of its findings have made it into public advisories, covering both system-level components (e.g. Microchip SDKs, Linux kernel, Android multimedia framework, Microsoft Windows networking stack) and popular applications (e.g. WhatsApp Messenger, Oracle WebCenter). Furthermore, each year CENSUS experts present groundbreaking research at industry-leading conferences, such as Black Hat, DEF CON, INFILTRATE, OffensiveCon, TROOPERS, OWASP AppSec.
For more information about CENSUS and its services scan here


93% of organizations that moved to a unified platform saw a decrease in compatibility issues across their security system. This is why our Security Center platform excels. It delivers a cohesive operating picture through modules that were built as one system. So, whether you’re securing an airport, a parking structure, a multi-site enterprise, public transit, or an entire city, you can access all the information you need in one place. This is unification.


Firas Jadalla, Regional Director – META, Genetec, explores why physical security is more critical than ever
As the backbone of the digital economy, data centres are under constant pressure to deliver uninterrupted service, meet complex compliance obligations, and stay ahead of a rapidly evolving threat landscape. While cyber threats often take centre stage, physical security remains equally critical. Unauthorised access, sabotage, insider threats and even geopolitical unrest can jeopardise uptime, violate compliance mandates and put sensitive customer data at risk.
As data centres scale, diversify and adapt to new challenges, their approach to physical security must keep pace. This means rethinking outdated strategies and embracing more resilient, unified security architectures.
Today’s data centre operators are increasingly moving their facilities from dense urban cores to more stable rural environments. This trend is driven by the quest for affordable land and power and the need to reduce exposure to grid instability and other localised risks. However, more remote locations pose different security considerations.
Perimeter security, once reliant on passive barriers and manual oversight, is being transformed by technologies such as biometric access control, AI-powered analytics, drones and intelligent fencing. Operators are embracing systems that can automatically detect and classify threats, distinguish between authorised and unauthorised activity, and trigger real-time alerts. These upgrades improve accountability, response coordination and risk mitigation.
Along with the shift to rural areas, there’s a renewed emphasis on hardened infrastructure; facilities are investing in redundant power systems, private energy sources and high-availability networking to ensure continuous operations. These measures are essential, but they must be supported by equally resilient security postures.
The challenge intensifies as data centres grow in both scale and distribution.
• Edge data centres, typically small and remote, have no staff on-site and must rely on automation, remote management and real-time diagnostics to remain secure. Physical access must
be tightly controlled through remote credentialling, while sensor networks must deliver accurate environmental data to detect unauthorised entry, tampering or environmental anomalies.
• Hyperscale facilities manage sprawling campuses where thousands of people and devices move through daily. The complexity of these environments requires a different approach.
Maintaining consistent security across multiple buildings and zones is no small task, especially with the constant churn of contractors, technicians and deliveries. Every access point is a potential vulnerability.
What unites both edge and hyperscale scenarios is the need for a physical security solution that can scale with the operation. A unified security platform that consolidates video surveillance, access control, intrusion detection, analytics and intercom systems enables this strategy.
Important new capabilities in physical security include video analytics and artificial intelligence tools. Data centre operators benefit from automated

analysis of live video feeds to help their employees detect physical security risks such as tailgating, loitering or unauthorised object placement. With these capabilities, it is possible to alert operators to potential threats before an incident occurs, empowering them to address these risks proactively. And, because the systems can also track and respond to multiple incidents at once, security teams benefit from a decrease in false alarms and excess noise.
Analytics can also help with predictive maintenance. By analysing sensor data from HVAC units, power supplies or even vibrations in racks, analytics can warn operators about potential failures before they cause disruption.
Beyond security and uptime, compliance is a growing driver of physical security modernisation. Data centres are responsible for enforcing strict access control, maintaining detailed audit trails and protecting the privacy of individuals captured on video management systems. Standards like ISO/IEC 27001, SOC 2, GDPR and HIPAA all impose
“Today, teams must work collaboratively to automate device management”
specific physical access and monitoring obligations. Non-compliance can mean lost business, regulatory fines or damage to clients’ trust.
Meeting these standards requires systems that do more than just control access; they must document, contextualise and report on it. A unified physical security platform can automatically link access control events with video evidence, generate detailed audit reports on demand and even redact faces to protect individuals’ identities in compliance with privacy laws. It can also enable fast retrieval and secure sharing of video evidence when required — a vital capability for streamlining compliance audits and supporting incident investigations.
For multi-tenant facilities, detailed access records are essential for demonstrating compliance and accountability.
Physical security must also support operational efficiency. In a business where uptime is everything, security measures that delay technicians or block workflows can create friction and frustration. The goal is not to slow down access, but to control it intelligently.
Modern physical security platforms offer integrated communications, enabling security teams to verify visitor identity through intercom systems linked to video streams before granting access. This small but powerful capability enhances both security and operational efficiency, particularly at unguarded entry points or during after-hours operations.
To be truly effective, physical security cannot rely on a single point of detection. Yet many data centres still operate with disconnected, legacy systems — a model
that slows response and complicates compliance. It means creating and managing tiered access zones, from the outer perimeter to server cabinets, and enforcing and tracking strict partitioning between customer environments. Colocation data centres, in particular, must take great care to ensure that no tenant can access another’s equipment, even inadvertently.
Of course, the physical security system, including the software and related hardware/IoT devices (cameras, readers, sensors), is itself part of a broader attack surface. As such, all connected devices must be hardened against cyber threats. This means ensuring that all components run on up-to-date firmware, default passwords are replaced, and the software platform can support network requirements to secure traffic via encryption.
In the past, these responsibilities were split between IT and physical security teams, but increasingly, they’re centralised into unified physical and cybersecurity programmes. Today, teams must work collaboratively using these programmes to automate device management, updates and credential rotation with a shared goal of reducing risk and maintaining compliance.
Data centres today face mounting complexity: Rising customer expectations, stricter regulations and an increasingly sophisticated threat landscape. By investing in unified, scalable and intelligent physical security systems, operators can not only mitigate risk but also enhance efficiency, improve compliance and secure their operations for the future.
As the industry evolves, the data centres that thrive will treat physical security not just as a cost, but as a fundamental part of their operational and business strategy.






Fifteen years after reshaping the access control market with Architect, STid is preparing its return
For nearly 15 years, Vincent Dupart, CEO of the STid Group, has carried a clear conviction: In a world where threats constantly evolve, security can no longer remain static. It must become intelligent, scalable and sovereign.
Under his leadership, STid has established itself as one of Europe’s leading secure access control companies, driven by a strong ambition: Not to follow market standards, but to redefine them.
And with Architect II, set to launch later this year, the French company is preparing to open a new chapter in secure access control.
STid was born to break standards. How did it all begin?
The story began in 1996 in a small garage near Paris.
At the time, RFID was still considered an emerging technology. But STid already believed it would radically transform security and identification. The company was created with one simple ambition: To go beyond existing standards.
Very quickly, STid chose a different path from the rest of the industry.
While many companies focused on closed, proprietary systems, STid embraced openness, interoperability and modularity. A vision considered disruptive at the time – but now essential for organisations seeking stronger cybersecurity and technological sovereignty.
This decision was never just technological.
It was already a different way of thinking about security.
Fifteen years after Architect, why does STid still stay ahead?
Because STid has always anticipated market transformations before anyone else.
Over the past 30 years, the original garage has grown into an international group with offices across Europe, the United Kingdom, the United States, Mexico and Dubai. Today, more than 50% of STid’s revenue is generated internationally.
But STid’s real strength lies elsewhere. Fifteen years ago, the company launched Architect, the world’s first modular access control reader range. It became a global benchmark and earned more than 20 international awards.

The idea was simple: A reader should never be a fixed device.
It should evolve alongside new uses, new security requirements and new business needs.
That same vision continues to guide STid today through technologies such as SSCP and the European SPAC alliance, bringing together nearly 100 major industry players around a shared vision of open and sovereign security.
In an industry still largely shaped by non-European standards, STid is defending another path:
• more open;
• more sustainable;
• more sovereign.
Why is access control becoming a strategic issue?
Because companies are no longer simply securing doors.
They now need to protect critical infrastructure, sensitive data and digital identities in hybrid environments where cyber threats evolve constantly.
For STid, access control can no longer be viewed as a simple piece of hardware. It must become a truly scalable security platform.
That is the vision shared by Vincent Dupart and the STid teams: Enabling organisations to adapt their security level over time through intelligent readers capable of evolving via software updates, hardware and software modularity, and personalised user experiences.
In this model, the reader becomes an intelligent connected platform at the core of a company’s security strategy – and a new service generator.
Because threats are evolving faster than ever – and so are regulations.
For the past three years, STid’s R&D, product, design and cybersecurity teams have been working on a new generation of readers, designed to meet the challenges of the next 15 years.
Architect II will not be a simple upgrade.
It will be a new generation. A generation designed to push the boundaries of access control – not only in terms of security, but across the entire user experience. It preserves and strengthens the DNA that made Architect successful: a unique modularity allowing the reader to evolve with changing needs, use cases and security levels – without replacing the existing infrastructure. This

ability to evolve is becoming a compliance issue in its own right.
Around the world, regulators are raising their requirements on the cybersecurity of connected products –and Europe is leading the way with the Cyber Resilience Act (CRA), a framework already inspiring similar initiatives in other regions. Wherever they operate, organisations will increasingly be accountable for every connected device they deploy – including access control readers. Security-by-design, vulnerability management and updatability over the entire product lifecycle will no longer be best practices: they will become obligations. Architect II was designed with this new reality in mind. A reader that can evolve through its lifecycle is a reader that can stay compliant – wherever the regulation goes next.
The full picture will be revealed at launch – and one thing is already certain: this new generation is shaping up to become a new market benchmark. Behind this project are dedicated men and women united around a common ambition: building the next European reference in secure access control.
Why are inclusivity and sustainability becoming strategic priorities?
Because truly effective security must first be fluid, intuitive and accessible to everyone.
Working alongside associations supporting visually impaired and blind users, STid teams have spent the past three years designing the simplest and smoothest identification methods possible — with one clear objective: allow everyone to identify themselves simply, quickly and securely.
Sustainability was also integrated from the very beginning. The new generation consumes only the energy it truly needs, and its modularity extends product lifespans and reduces the carbon footprint of installations.
Because tomorrow’s security must be high-performing, responsible and designed for everyone.
In one sentence, what is STid’s ambition?
To build the next European benchmark for secure access control.
With Architect II, STid is not simply launching a new product range.
The company is expressing a vision: Open, intelligent and sovereign security capable of evolving alongside threats rather than reacting to them.
Fifteen years after Architect, STid is not coming back to follow the market.
STid is coming back to redefine its standards. stid-security.com

“AI is rewriting the security playbook, but the real disruption isn’t where people are looking.”


Why threat intelligence and threat hunting must converge in the AI era by Azeem Aleem, Executive Director,
Cyber Resilience Services at CPX
In an era dominated by artificial intelligence (AI), threat intelligence is becoming easier to produce but significantly harder to differentiate.
Automated systems can now effortlessly draft threat reports, enrich indicators and cluster complex campaigns in a matter of seconds. Yet, despite this unprecedented abundance of data, security operations still struggle to translate raw information into a distinct operational advantage.
The bottleneck we face today is not a scarcity of intelligence; it is the inability of static intelligence alone to deliver a competitive edge. For years, threat intelligence has been described as “actionable”. In practice, however, most organisations are left waiting. Security teams watch threat reports accumulate and indicators expire, while agile adversaries continuously outpace traditional intelligence cycles.
In modern cyber defence, however, the defining victory belongs to those who operationalise intelligence with speed and precision. Today, this advantage no longer belongs to those with the most intelligence, rather, it goes to those who can put it to work.
A big part of the problem lies in how most organisations still treat threat intelligence as a standalone capability.
Threat intelligence teams produce insights. Threat hunting teams investigate activity. Incident response teams step in during a breach. Detection teams build controls. Each of these roles is incredibly important, but they often operate separately.
Attackers do not see those boundaries. They interact with one environment, test it, learn from it and adjust. Every failed attempt teaches them something, and every success makes their next attempt easier.
That is where things start to break down. Defenders often operate in parts, while attackers behave as one unified system. For businesses, this creates a fundamental imbalance. The attacker learns as a system, while the defender often responds as a collection of functions. That imbalance is becoming increasingly difficult to sustain. AI is speeding things up on both sides, but without changing how teams work together, technology mostly makes
organisations quicker to react, rather than better at staying ahead.
Frans Johansson’s idea of the Medici Effect helps explain why this matters. His argument was simple: real breakthroughs happen when different disciplines come together, not when they stay in their own lanes. The Renaissance did not happen because people worked in isolation. It happened because ideas crossed boundaries.
Cybersecurity is now running into the same challenge. Individually, each security discipline creates value. But when they are brought together into a shared ecosystem, they create something far more powerful: Adaptive Intelligence. At their intersection, intelligence becomes testable, hunting becomes strategic and response becomes a continuous learning mechanism. This is where defensive advantage truly emerges, directly linking security agility to measurable business resilience.
Each function in security sees a different part of the picture. Threat intelligence focuses on the adversary. Threat hunting
looks at how those threats might actually show up internally. Incident response handles what really happens during an attack. Detection engineering focuses on what can be picked up consistently across systems.
On their own, these perspectives are useful. But when they come together, they reinforce each other. Intelligence gets tested on the ground, assumptions get challenged and insights get refined. Security stops being theoretical and starts becoming practical.
For instance, you can see this clearly in a ransomware scenario. Intelligence might point to a specific pattern, like credential theft followed by lateral movement across systems. On its own, that is just insight. When a hunting team looks into it, it becomes an active enquiry: are we seeing anything like this in our environment? If they find something, incident response can confirm exactly how the attack played out, showing how access was gained, what was touched, and how the attacker stayed hidden.
Those real-world learnings then feed directly back to detection engineers, who build custom alerts to spot similar behaviour going forward. At that point, threat data is no longer just information. It becomes a permanent part of how the organisation protects itself.
AI can automate the data, but security teams must still drive the decisions
AI is making it much faster to generate intelligence. Tasks that used to take time, like enrichment, correlation

“Organisations that continue to optimise security functions in silos will struggle to keep up.”
or summarisation, are now largely automated. While that is a good thing, it also shifts where the real value sits. If everyone can produce intelligence quickly, then the intelligence itself stops being the differentiator. What becomes harder, and far more valuable, is knowing what to do with it.
AI can surface patterns and insights, but it does not replace human judgment. It does not understand the unique context of a specific business environment, and it cannot always tell the difference between something that truly matters and something that just looks interesting. That crucial distinction only becomes clear when intelligence is tested against what is actually happening on the ground.
intelligence isn’t the answer, better integration is For security leaders, this shift changes everything. The challenge isn’t acquiring more intelligence, but ensuring that intelligence actually drives decisions and actions. That means connecting teams more closely, building continuous feedback loops, and learning from live incidents instead of just documenting them after the fact.
Organisations that continue to optimise security functions in silos will struggle to keep up. Those that actively connect them will adapt faster, turning everyday operational reality into a shared learning loop of continuous improvement and operational continuity.
AI is rewriting the security playbook, but the real disruption isn’t where people are looking.
In cybersecurity, the advantage always goes to the side that learns faster. While AI is making intelligence more available than ever, raw availability is no longer the bottleneck. The real challenge lies in turning that intelligence into environmentspecific, operational defence. The future is not about who accumulates more data; it is about how seamlessly that intelligence is fused, tested and improved in real time. For security leaders, the real benchmark is whether their intelligence is agile enough to survive, adapt and dominate in operational reality, ultimately securing the business against an unpredictable future.
cpx.net


16 - 18 November 2026
Riyadh Front Be part of

500+ Exhibitors from 40 different countries
2 Conferences
25,000+ Trade visitors
110+ Speakers
40,250 sqm Exhibition space
5 Key product sectors


www.intersec-ksa.com
intersec-saudiarabia@ksa.messefrankfurt.com


For the modern operative, diplomat or ultra-high-net-worth individual, standard encryption is no longer enough. We have spent the last decade obsessed with software security — end-to-end encryption and zerotrust architectures. At Braniff Enterprises, we recognise that while these technologies safeguard the content of your communications, they fail to protect the most critical asset of all: Context.
Your adversaries — whether foreign intelligence services, advanced persistent threats (APTs) or corporate espionage rings — no longer need to break your encryption to neutralise your operations. They simply need to track your Pattern of Life (POL). And the beacon broadcasting that pattern is the one variable you thought you couldn’t change: your International Mobile Equipment Identity (IMEI).
The metadata trap
Every mobile device has a unique fingerprint. The IMEI is a 15-digit serial number hardcoded into the deviceʼs cellular modem. Traditional OPSEC (Operational Security) suggests that simply swapping SIM cards protects your identity.
This is a fatal misconception.
When an operative inserts a new SIM into a phone with a static IMEI, the cellular network — and any hostile International Mobile Subscriber Identity (IMSI) catcher or ‘Stingray’ in the vicinity — instantly links the new number to the old, tracked device. You have not become a new person; you have simply attached a new alias to the same targeted hardware.
Regulatory compliance & sales restriction disclaimer
Braniff solution: Dynamic hardware identity
True anonymity requires the ability to sever the digital tether between the user and the hardware. This is where Braniffʼs proprietary randomised IMEI rotation shifts the paradigm from defense to stealth.
Our latest secure architecture introduces Braniff Hyper-Cycling™ Technology. This feature allows the device to generate a cryptographically valid, randomised IMEI upon every reboot or at user-defined critical intervals. By spoofing the hardware identifier at the baseband level, the device presents itself to the network as a completely new, factoryfresh unit every time it connects.
Strategic advantages for high-value assets
1. Countering Pattern of Life (POL) analysis
Intelligence agencies build targets based on repetition. They map where a device sleeps, where it works and who it meets. By rotating the IMEI, Braniff technology shatters the continuity of data. The network sees a thousand different devices passing through a location once, rather than one device returning a thousand times. The pattern dissolves into noise.
2. Defeating IMSI catchers
Hostile entities deploy IMSI catchers in sensitive zones (embassies, conflict zones, financial districts) to harvest identifiers. A static phone is a sitting duck. A Braniff device with IMEI rotation
is a ghost — appearing and disappearing from the RF spectrum before an actionable profile can be built.
3. The ‘Burner’ without the waste
Historically, deep cover required physical ‘burner’ phones that were used once and destroyed. This is logistically heavy and a security risk if discarded improperly. With Braniffʼs IMEI spoofing capability, a single enterprise-grade device becomes an infinite supply of virtual burner phones. One piece of hardware, unlimited digital identities.
The new standard of privacy
In the high-stakes world of intelligence and enterprise security, a static identity is a vulnerability you cannot afford. To remain static is to be targeted. To rotate is to survive. Braniff Enterprises doesn’t just protect your data. We protect your existence.
your operations
Static defence is obsolete. Contact Braniff Enterprises today for a confidential briefing and demonstration of our dynamic hardware identity solutions. Seeking qualified customers and distributors with existing government contracts. Contact us for a demo with our Subject Matter Experts at sme@braniffenterprisesllc.com
Use with Authority: The capabilities described herein, specifically IMEI modification/spoofing, are powerful tools designed for sovereign, military, intelligence and authorised enterprise applications.
Restricted Sales: Braniff Enterprises restricts the sale of devices featuring Hyper-Cycling™ Technology strictly to vetted and authorised purchasers, including government agencies, military organisations and qualified corporate entities.
Legal Compliance: The use of IMEI changing technology may be regulated or prohibited in certain jurisdictions for general consumer use. It is the sole responsibility of the purchasing organisation to ensure that the deployment and use of Braniff devices comply with all applicable local, national and international laws and regulations relevant to their area of operation. Braniff Enterprises assumes no liability for the misuse of this technology contrary to local law.
Why audit readiness matters in 2026 and a practical mid-year checklist for security leaders seeking operational excellence, from the Security & Safety Professionals Network (SSPN)
As we move past the middle of 2026, corporate security leaders, hospitality managers and consultants across the region face a familiar challenge. The countdown to annual reviews, operational assessments and peak season demands has officially begun. In a demanding regulatory environment such as Dubai, compliance is never a static target. It is a continuous commitment to excellence. For the SSPN the message for this season is clear. Operational readiness should not be viewed as a stressful hurdle. When managed correctly, audit readiness becomes a powerful competitive advantage.
Through its ongoing engagement with the Security Industry Regulatory Agency (SIRA) and industry stakeholders, SSPN promotes a shared vision of proactive protection and continuous improvement. True security resilience means identifying gaps before an official inspection, internal review or operational challenge occurs. Based on industry observations and evolving regulatory expectations, this mid-year checklist highlights key areas that security leaders should review to strengthen both compliance and operational performance.
Advanced security technology is only as effective as the maintenance and oversight that support it. Teams should verify that surveillance systems, access control platforms and alarm monitoring infrastructure continue to meet operational requirements and current standards. Particular attention should be given to camera coverage, recording functionality and continuous power backup systems. A common point
of failure during high-demand periods is an unexpected loss of power. Testing uninterrupted power supplies under realistic operating conditions helps ensure that critical systems remain functional when they are needed most. Data retention protocols should also be reviewed to ensure surveillance information remains secure and protected against unauthorised access.
Equipment alone cannot secure an environment. Effective security relies on trained professionals who can make sound decisions under pressure. Managers should review training records, verify that certifications remain current, and ensure refresher programmes are being conducted as planned. Through its collaboration with the International Foundation for Protection Officers (IFPO), SSPN supports access to internationally recognised certifications and professional development opportunities for security professionals. This is an ideal time for organisations to invest in staff development and ensure supervisors remain familiar with evolving procedures, including emergency response protocols, drone awareness and evacuation planning. Risk assessments should also form part of every mid-year review. Threats, vulnerabilities and operational requirements can change rapidly. Existing assessments should be revisited to confirm that mitigation measures remain relevant and aligned with current conditions. A risk assessment should be treated as a living document that supports decision-making throughout the year, rather than a document reviewed only during inspections.
In a fast-moving operational environment, clear and verified communication supports public confidence and effective decision-making. Security teams should review incident logs to ensure records remain accurate, timely and supported by appropriate evidence. Well-maintained documentation strengthens investigations, assists with audit preparation and demonstrates accountability. Organisations should also ensure that employees rely on verified communication channels during emergencies and regional alerts. Preventing the spread of unverified information helps maintain calm, coordinated and professional responses when it matters most.
Perhaps most importantly, leaders should assess whether policies and procedures are being followed in practice. Compliance on paper does not always translate into performance on the ground. The strongest security programmes are those where documented procedures are consistently reflected in daily operations. Regular inspections, supervisor engagement and operational reviews help ensure standards are consistently applied across all levels of an organisation.
As the second half of 2026 unfolds, the difference between standard security and exceptional security often comes down to preparation. By focusing on technical reliability, staff competence, effective risk management and clear communication, organisations do more than avoid regulatory issues. They build trust, strengthen resilience and enhance their professional reputation. sspn-sira.com

Can you tell us about your journey in this field?
It began with a foundation in allied health services, but it was during my early clinical exposure that I recognised a critical gap in emergency preparedness and resilience within healthcare. This realisation, paired with a passion for strategic problemsolving, drove me to pursue advanced training and certifications — a PhD in Risk Management, Masters in Strategic Studies, High Diploma in Crisis & Disaster Management and a portfolio of global credentials including CEM, CBCP, PECB and ISO 31000 etc. I’ve worked across Saudi Arabia, leading emergency preparedness initiatives, training over 1,000 professionals, and advising national-level healthcare bodies. My commitment has always been to bridge clinical realities with robust risk and crisis governance to safeguard lives and operations.
Why is crisis and disaster management a critical enabler of patient safety, operational continuity and public trust within healthcare facilities?
In healthcare, crisis management isn’t an auxiliary function — it’s a core enabler of trust and safety. During emergencies, from pandemics to infrastructure failures, hospitals must continue delivering critical care. Without a structured disaster preparedness strategy, patient outcomes suffer, staff are vulnerable and reputational trust erodes. My work establishing an in-house Crisis Management Department and Emergency Operations Plan at a major Saudi hospital ensured operational resilience, with protocols embedded at every level to protect patients, staff and infrastructure. Effective crisis management secures continuity, minimises harm and preserves public confidence when it’s needed most.
How has the role of healthcare crisis personnel evolved in response to increasingly complex threats?
The role has shifted from reactive to proactive, from siloed to strategic. Healthcare crisis personnel now engage in governance, regulatory alignment and inter-agency coordination. The COVID-19 pandemic exposed the necessity for real-time decision-making, supply chain foresight and behavioural health support – all areas I’ve worked to embed in organisational planning. Today’s professionals must manage not only biological threats but also cybersecurity incidents, mass casualty events and climate-driven disasters. My role as a lead trainer for several entities reflects this evolution – training the next generation to think systemically and act decisively.
What makes a modern healthcare security command essential for effective crisis management and coordinated response?
Modern command centres are the brain of crisis response — integrating intelligence, coordination and execution. I led the development of such a centre, designed to function not just during crises but as a strategic tool for readiness. These centres enable synchronised action across clinical leadership, logistics, communications and external responders. They house real-time data feeds, facilitate situational awareness, and provide a structured chain of command. Without this centralised capability, response efforts risk fragmentation and delay — two critical failures in any emergency.
How do emergency command centres support realtime decision-making and collaboration between security teams, clinical leadership and

emergency responders?
Command centres function as nerve centres, enabling unified command and control. In my experience, through drills involving chemical spills, floods and workplace violence scenarios, the command centre provided a realtime platform for integrating threat intelligence, clinical priorities and logistical coordination. Tools such as Incident Action Plans (IAPs) and scenario dashboards ensure that decisions are based on validated data and aligned with strategic priorities. By embedding clinical, security and external agency liaisons within the centre, we achieve rapid consensus and execution, reducing confusion and improving outcomes.
What capabilities, technologies or strategic investments will be most important to strengthen healthcare crisis resilience and future effectiveness?
Future-ready command centres must integrate predictive analytics, AI-enabled triage tools, interoperable communication platforms and environmental monitoring systems. Investments in cloud-based continuity solutions, cybersecurity infrastructure and multi-hazard simulation technologies will be critical. Strategically, embedding crisis governance into organisational culture — continuous training, accreditation alignment and executive-level crisis committees — is equally vital. Having spearheaded these efforts, I see the next frontier as the fusion of digital intelligence with human expertise to create agile, adaptive and anticipatory healthcare systems.
Meshal Aljohani is the Security Group Supervisor at Saudi Aramco, has 15 years experience and holds the prestigious ASIS Triple Crown (CPP, PSP, PCI).
9–12 September
SECUTECH VIETNAM 2026
Friendship Cultural Palace, Hanoi, Vietnam
secutechvietnam.tw. messefrankfurt.com
10–12 September
AEDEX + AIRPORT EXPO
Yashobhoomi, IICC, Dwarka, New Delhi, India
aedexandairportexpo.com
21–23 September GISEC GLOBAL
Dubai Exhibition Centre, Expo City, Dubai
gisec.ae
24 September
CISO MIDDLE EAST SUMMIT 2026
Dubai, UAE
exeglobe.com/ciso-middle-east-summit-dubai-2/
19–20 October OFSEC
Oman Convention & Exhibition Centre, Muscat, Oman
ofsecevent.com
16–18 November INTERSEC SAUDI ARABIA
Riyadh Front Exhibition & Conference Center, KSA
intersec-ksa.ae. messefrankfurt.com
18–19 November
SECUTECH THAILAND 2026
Queen Sirikit National Convention Center, Bangkok
secutechthailand.tw. messefrankfurt.com
19 November
CISO MIDDLE EAST SUMMIT 2026
Crowne Plaza Riyadh Palace, KSA
exeglobe.com/ciso-middleeast-summit-2026-saudi/
29 November
SECURITY MIDDLE EAST CONFERENCE
Voco Hotel, Riyadh, Saudi Arabia
securitymiddleeastconference.com
30 November
FIRE MIDDLE EAST CONFERENCE
Voco Hotel, Riyadh, Saudi Arabia
firemiddleeastconference.com
21–23 December
GENERATION IOT EXPO RICEC, Saudi Arabia
30 November THE SECURITY & FIRE AWARDS FOR EXCELLENCE
JW Marriott Grosvenor House, London, UK
securityandfireawards.com
12–14 January
INTERSEC GLOBAL
Dubai World Trade Centre, UAE
intersecglobal.ae. messefrankfurt.com/dubai/ en.html
Please check the event websites for the most up-to-date details as dates can change all the time.


The future of security isn't artificial. It's trusted.
For 25 years, we've helped security professionals see further, respond faster, and protect what matters most. Today, AI Video Analytics and Generative AI are transforming how threats are detected, investigated, and understood. But in security, technology alone is never enough. Real security requires trusted innovation. It requires proven reliability. It requires human expertise guiding every critical decision.
That's why we continue to combine intelligent technology with human judgment, helping organizations make faster, more informed decisions and delivering solutions they can trust for the future.

