Skip to main content

Magazin September 2026

Page 1

TRUST TECHNOLOGY TRANSFORMATION

SUCCESS THROUGH FOCUS HESHAM TANTAWI VICE PRESIDENT ASBIS MIDDLE EAST


EDITOR’S NOTE

02

Dear Readers,

T

echnology has always been about change. But over the past year, the pace of that change has been unlike anything we have seen before.

From the rapid adoption of AI and the growing focus on cybersecurity to the evolution of cloud, infrastructure, and digital transformation, organizations across the GCC are not just adopting new technologies—they are rethinking how they operate, innovate, and create value. At the heart of this transformation is one important factor: trust. Trust in technology. Trust in partnerships. Trust in the leaders who are making critical decisions that shape the future of their organizations. This edition of TechPulse Magazine is built around this very thought — Trust. Technology. Transformation. Throughout the year, we have had the opportunity to connect with incredible technology leaders, innovators, and industry experts across the region. Every conversation highlighted one common message: technology alone is not enough. The right vision, strong leadership, and trusted partnerships are what truly drive meaningful transformation. In this special edition, we bring you highlights from the TechPulse CISO 50 Connect & Awards, celebrating the cybersecurity leaders who are working behind the scenes to protect businesses and enable innovation. We also take you through the key moments and insights from GISEC Global, along with exclusive perspectives from industry leaders and our featured cover story with ASBIS. This issue is a celebration of the people behind the technology—the decision-makers, innovators, partners, and communities that continue to shape the GCC's digital journey. As TechPulse completes its first successful year, I would like to personally thank our readers, contributors, partners, and

the entire technology community for your incredible support, encouragement, and trust. This journey has been made special by every conversation we have had, every leader we have featured, every story we have shared, and every partnership we have built along the way. Each interaction has helped us create a stronger platform that connects, informs, and celebrates the technology ecosystem across the region. Thank you for being an important part of the TechPulse journey. We look forward to continuing this journey together with many more stories, conversations, and milestones ahead.

Dolly Lakhani

Management Dolly Lakhani

CEO & Chief Editor Email - editor@techpulsemea.com Mobile - 050 674 1731

Developer Team Pooja Panjwani

Co-founder & Managing Editor Email - pooja@techpulsemea.com Mobile - 052 564 8788

Business & Media Relations: editor@techpulsemea.com pooja@techpulsemea.com

www.techpulsemea.com

Nabeel Khan

PR & Social Channel Manager

Faisal Farooq Head Developer

Publisher Techpulse Media LLC

Sharjah Media City Free Zone United Arab Emirates.

SEP 2026


12 05

18 16

13 15

17

10

19

20

COVER STORY

05

ASBIS - Focus that Builds. Partnerships that Grow.

OPINION

12

EEMEA - AI-Enabled Growth Needs Stronger Cyber Resilience

15

FORTINET - Who Owns Time? The Board’s Question Nobody Can

13

CENSYS - Attackers don't need a breach when the Front Door is Already Open

17

SOPHOS - As AI Scales, Why Cybersecurity Risk Can No Longer Rest With CISOs Alone


21

23

30

32

10

ThreatLens

Manoharan Mudaliar Founder and CEO

ThreatLens identifies the data, checks policy, chooses a trusted AI destination, and allows, redacts, routes, or blocks the request.

16

Genesis

Khalifa Al Shehhi Founder

AI is reshaping cybersecurity. True resilience requires governance, visibility, accountability, and continuous third-party risk monitoring.

25

18

DEWA

Samh Khalid

Lead AI Architect

Governed AI makes compliance easier and curbs shadow AI. True innovation comes from making experimentation safe and accessible.

19

Dubai Ambulance

Asma Muallemi

Digital Leader / CISO

26

35

CONTENT INTERVIEW

24

34

Preparing for AI means preparing people to work differently, with a focus on secure innovation.

20

26

Preparing for AI means preparing people to work differently, with a focus on secure innovation.

The bigger challenge is preparing people to work differently. Governance should not become a barrier to innovation.

Sudhir Kumaran Director of IT

21

NMC Healthcare

Nidhi Chaudhary

Information Security Compliance Officer

Al Ghurair Group

Mario Foster Group CIO

30

FVC

K. S. Parag MD

AI transformation is about people and trust, with governance enabling innovation—not blocking it.

Traditional security remains vital, while threat intelligence helps organizations understand who may be targeting them.

23

32

Ajman Municipality

Hend Al Shamsi

Director of Smart Services Development Department and Digital Transformation & AI Head

AI is a leadership priority, guided by clear governance, measurable KPIs, and balanced risk.

24

GPSSA

Khurram Sabir

Chief Internal Auditor and Chief Risk Officer

AI automates tasks, not accountability. Good governance enables innovation, while future leadership means adapting intelligently to change.

25

Environment Agency of Abu Dhabi

Dr. Ghazi Sultan

Head of Organization Development

AI readiness starts with people and work design, with governance enabling innovation.

FINESSE

Eljo J P

Chief Business Officer & Director

Finesse takes an AI-first approach, making AI the foundation of its cybersecurity operations.

34

Alcon – Cyber Security

Navinchandar Naidu CEO

Cybersecurity isn’t about company size—it’s about what you protect. SMEs can face greater impact from ransomware, breaches, or disruption.

35

VisionTech

Aliasgar Dohadwala CEO & Founder

Cybersecurity is a fundamental cost of doing business, protecting digital assets, data, and reputation.


05

COVER STORY

FOCUS THAT BUILDS. PARTNERSHIPS THAT GROW.

In a technology landscape defined by constant change, growth is not always about moving faster. Sometimes, it is about knowing exactly where to focus. For Hesham Tantawi, that focus is at the heart of ASBIS's approach to distribution. From understanding local markets and building trusted vendor relationships to supporting the infrastructure behind the region's growing AI ecosystem, his perspective is clear: sustainable growth comes from doing the right things well.

Hesham Tantawi Vice President ASBIS Middle East

In this exclusive conversation with TechPulse Media, Hesham shares his perspective on what makes ASBIS different, why genuine partnerships matter, how AI is influencing the distribution landscape, and what vendors need to bring to the table when entering and developing new markets.


INTERVIEW

Q1. Can you define one word for ASBIS? For ASBIS focus that's really the heart of who we are. ASBIS is, at its core, a focus distributor and that's not just a description, it's our philosophy. In fact, it's built right into our slogan: "Success through Focus." Everything we do, every decision we make, comes back to that one idea staying focused on what truly matters and letting that focus drive our success.

every level, growth simply doesn't happen the way it should. This is, in my view, the single most important factor to succeeding in business in every local market we operate in building relationships that go beyond transactions and working together as one ecosystem toward the same goal.

Q2. What differentiates ASBIS from other value-added distributors operating in the region? I would say, is the balance we strike. On one hand, ASBIS is very much a multinational distributor. We carry all the hallmarks of one. That means the compliance standards, governance, the structures and processes that modern, world-class businesses require. Nothing is left to chance. But on the other hand, this is just as important as we never lose sight of the local market. In every country we operate, we make it a priority to localize ourselves, to understand the culture, the customers, and the way business is actually done on the ground. So, it's really that combination, the discipline and credibility of a global player, paired with the agility and closeness of a local one. That's what makes ASBIS different. Q3: ASBIS has evolved significantly across the Middle East. What are the key strategic priorities driving your growth? The key thing driving our growth, really, is genuine partnership, a true alliance between vendors, and our partners on the ground. That triangle of trust is essential. Without real collaboration at

www.techpulsemea.com

|

ASBIS

06

Look, trust, compliance, and security sit above everything else. That's non-negotiable for us. So, whenever we adopt new AI technologies in our day-to-day work, it's never adoption for adoption's sake, it's grounded in compliance, built on trust, and shaped in partnership with our people, all working together to move the business forward. For us, AI is a tool to take the business to its next stage, not something we use just because it's the trend of the moment. There has to be a purpose behind it.

Inside Hesham Tantawi's vision for a more connected and capable technology distribution landscape.” Q4: How do you foster innovation and adaptability within your organization? ASBIS is a very dynamic company that's really at the core of who we are. We are constantly adapting to what's new, whether that's artificial intelligence (AI), evolving processes, or the systems we rely on every day. In fact, we're developing and refining our systems continuously, not as a one-time effort but as an ongoing commitment. Our approach is simple, we learn, we implement, and we do it. There's no room for standing still innovation for us isn't a buzzword, it's a daily practice. Q5: As you said about adoption and implementation, how do you balance innovation responsible for AI adoption and accelerate how businesses can ensure they remain innovative while maintaining trust, compliance and security?

Q6: How important are collaborations between vendors, distributors, and partners in accelerating digital transformation? This is the recipe of success, plain, and simple. It starts with a vendor who genuinely wants to develop markets, not just sell into them. Then it needs a distributor who is professional, who has the roots on the ground, and who understands the mapping of each and every market segment because that's what allows a vendor's business to actually grow. When those pieces come together, the vendor's ambition and the distributor's local expertise that's the recipe of success. There's really no shortcut around it. Q7: What emerging trends do you believe will have the greatest impact on IT distribution landscape in 2026 and beyond?

SEP 2026


07

INTERVIEW

|

ASBIS

Honestly, there's a lot of challenges facing distributors in 2026 and beyond. Supply shortages are real, and that means you need a distributor with the capacity to guarantee and ensure the supply chain. We are dealing with challenges on shipping routes, and challenges around the availability of goods from vendors. So what's needed now is a distributor who can forecast two, three years ahead to guarantee supply to the partners they serve. Q8: As ASBIS has partnered with industry leaders, how do you see AI infrastructure evolving across the Middle East? You mean on the overall business side? AI is really growing in the Middle East. We are seeing giants building their own data farms, data servers, AI servers, and data centers right here in the region. And around these partners, we're developing a lot of services to support them, and honestly, this is what's going to drive the business growth in the coming years. Q9: How important is hybrid storage architecture supporting the AI data intensive application? Look, most people today think data centers and AI applications are only about GPUs. But storage is just as important. Without it, data farms simply won't work. That's the part people overlook. This is exactly why we're seeing such a big demand for storage of products from data centers right now. Q10: Will AI reduce the importance of traditional infrastructure, or will it make a robust infrastructure more critical than ever? To be precise, it gives the current infrastructure the tools to grow,

SEP 2026

and that's how I see it. But I don't think AI will do the sales itself not yet. AI will guide us to sell better, guide us to build better partnerships, guide us with the data and the tools we need to grow the business. But at the end of the day, it needs the existing infrastructure and the people behind it, to understand how to actually use AI well to grow their business. One doesn't replace the other. Q11: Your portfolio includes many of the world's leading technology brand. What criteria do you see or use when deciding onboarding a new vendor who is completely new in the market? At ASBIS, we study the vendor relationship closely before anything else. We only bring on vendors where we know we can genuinely add value to them. I won't onboard a vendor if I don't believe we can make a real difference for them. That's important to us because, as a distributor, we see ourselves as market openers. We do the right screening of the markets, we identify the real needs on the ground, and then we bring in vendors who can actually fulfill those needs. It has to work both ways. Q12: Going forward, since cybersecurity is being implemented more and more in the UAE, how do you think ASBIS would be a fit for a new cybersecurity vendor or how can a new vendor become a good addition to your portfolio?

we create sales. Through this approach, we came across a lot of projects in cybersecurity, storage, and computing, and we build those up together with our vendor’s reach. So, it’s a cycle where the vendor, the distributor, and the end user work together to identify the needs and shape the projects we implement. That’s how the cycle completes itself. Q13: What makes a vendor stand out when approaching a value-added distributor like ASBIS? As a professional distributor, ASBIS always comes back to focus, that word again. We focus with each vendor individually to develop their own business. Sometimes vendors come to us and say, "Wait, ASBIS is distributing this brand and that brand, and they're competitors of ours." But ASBIS is different. Let me give you an example: we distribute two of the biggest names in a certain technology space, brands that are direct competitors of each other. You don't really see that combination elsewhere in the market, two rivals under one roof. And yet, uniquely, we're the biggest distributor for both of them. Why? Because we focus on developing the technology and the partnership of each vendor separately, on their own terms. That's the difference.

I'll tell you. First of all, as I said at the beginning, our motto is “Success through Focus.” We focus on a lot of different segments of the market, and one of them is VAD. In that space, we are not just serving system integrators, we are actually linking the needs of the market with the system integrators, and that's how

www.techpulsemea.com


INTERVIEW

|

THREATLENS

10

credentials, explain why. That transparency changes the relationship between security and the user. Governance stops feeling like an invisible restriction and starts becoming something employees can actually understand. Our view at ThreatLens is that probably 99 percent of legitimate enterprise AI usage should be enabled safely. Blocking should be the exception, not the operating model. Q3. What role does data governance play in enterprise AI security? For me, AI governance is fundamentally a data governance problem. People spend a lot of time debating which model is safer, but the more useful question is: what data are we giving that model and how much do we trust the destination receiving it?

Manoharan Mudaliar Founder and CEO, ThreatLens Q1. AI adoption is accelerating across enterprises. What is the biggest governance risk CISOs should be thinking about today? The biggest risk is that AI adoption is already happening faster than governance. Employees are using ChatGPT, Copilot, Claude and dozens of other AI tools because they genuinely make people more productive. The mistake is thinking you can solve that by blocking everything. We tried that approach with cloud, SaaS and personal devices. People always find another route. The real question for a CISO is much simpler: what company data is going into AI, where is it going, and under what rules? If someone pastes customer information, financial data, source code or credentials into an AI tool, the organization needs to make a decision before that data leaves its control. Is this destination trusted? Should sensitive values be redacted? Should the request be routed to an enterprise-managed model? Or is this one of the few cases that genuinely needs to be blocked? That's how I think AI governance has to evolve. Not another policy document telling employees what they shouldn't

www.techpulsemea.com

do, but controls embedded directly into how they use AI. Q2. How should organizations approach shadow AI without slowing down employees who want to use these tools? I don't think the answer to shadow AI is banning AI. Most employees aren't trying to bypass security. They're trying to finish their work faster. If the approved enterprise experience is slower or less useful than the public tools, people will eventually work around it. So the organization has to give employees a governed front door to AI. Let them ask questions, analyse documents, research information and use different AI capabilities, but put the governance layer underneath it. Classify what they're sending, understand the sensitivity of the data, check which AI destination is appropriate, and automatically apply the company policy. And importantly, show the employee what happened. If their request was routed to an enterprise model because it contained customer data, tell them. If some values were redacted, tell them. If something was blocked because it contained

Customer information has a different risk profile from public marketing content. Source code and credentials are different again. Financial information, HR data, legal documents and board strategy all require different treatment. That's why a simple approvedversus-unapproved model list isn't enough. The organization needs policies based on both the content and the destination. Maybe public information can go to a public frontier model. Customer data might require an enterprisemanaged model. Credentials should never leave at all. Other sensitive information might be usable once identifying values are removed. And this governance has to work consistently whether somebody types the information into a prompt, uploads a document, retrieves something from SharePoint or uses an AI agent. The policy should follow the data. That's the architecture we're building around ThreatLens. Classify first, apply the organization's trust policy, then allow, redact, route or block. Q4. AI governance and assurance are climbing the board agenda in the GCC. What should organizations put in place before deploying AI at scale? Visibility first. A lot of organizations are discussing AI policies while they still don't know how much AI is already being used internally. Employees are using public AI tools, business units

SEP 2026


11

INTERVIEW

|

THREATLENS

are buying AI-enabled SaaS platforms, developers are connecting APIs and Microsoft Copilot is appearing across enterprise workflows. You can't govern what you can't see. Once you have visibility, the next step is policy enforcement. Decide which categories of company data can go to which AI destinations, what trust level is required, what should be redacted and what genuinely needs to be blocked. I also recommend starting in monitor mode instead of switching on aggressive enforcement from day one. Observe how people are actually using AI, establish the baseline, identify the real risks and then enforce with evidence. Otherwise you risk creating controls that generate false positives and drive employees back towards shadow AI.

determine where that request is allowed to go.

We want every employee to have a single governed way to use AI.

That model is especially important in the GCC because organizations care deeply about data sovereignty, regulatory accountability and where sensitive information is processed. Another important principle is that “cloud” shouldn't automatically mean unsafe and “local” shouldn't automatically mean safe. An organization's Azure OpenAI or AWS Bedrock environment under its own enterprise controls may be a perfectly appropriate destination for sensitive workloads.

They ask the question or attach the document. ThreatLens understands what kind of information is involved, checks the company's policy, determines which AI destination is trusted enough and then allows, redacts, routes or blocks the request.

We also hold ourselves to the same standard. We run AI agents in production inside our own SOC investigation platform, so we govern AI the way we would want our own AI governed.

The final piece is assurance. Boards, auditors and regulators are increasingly going to ask, “Show me how AI is being governed.” A PowerPoint policy isn't enough. Organizations need evidence showing what happened, what data was involved, which policy was applied, where the request went and what decision was made. That's where governance becomes assurance, and it's the gap we built ThreatLens AI Assurance to close: a continuous, auditable record of what is inside every AI system, what data it touches and how policy was applied. Boards don't need another policy document. They need evidence. Q5. How can CISOs balance AI innovation with security, privacy and regulatory requirements? I think we need to stop treating innovation and governance as opposing forces. The business wants AI because it improves productivity. Security wants control because sensitive information can't simply leave the organization without oversight. Both sides are right. The solution is architecture. Give employees access to AI, but make the governance decision automatically in the workflow. They shouldn't need to understand whether a particular model is Public Frontier, Enterprise-Managed, CustomerManaged or Private. They should just describe what they're trying to achieve. The governance platform should

SEP 2026

The part I'm particularly passionate about is that the user sees the governance decision before the AI answer starts. If information was redacted, you see it. If a request was handled differently because it contained sensitive customer data, you see it, and you see why.

ThreatLens understands what kind of information is involved, checks the company's policy, determines which AI destination is trusted enough and then allows, redacts, routes or blocks the request. Governance should be based on the organization's level of trust in the destination, not simply where a server happens to sit. If you get that right, security stops being the department that prevents AI adoption and becomes the function that makes AI adoption possible. Q6. What is your vision for ThreatLens, and where do you see the company making the biggest impact in the global cybersecurity ecosystem? Our vision is for ThreatLens to become the enterprise control plane for AI adoption.

And behind that experience is the assurance layer. Every classification, policy decision, destination and administrative change creates an auditable record. Over time, I think that record becomes extremely valuable. CISOs will be able to show the board not just that they have an AI policy, but exactly how AI was used across the organization and how that policy was enforced. That's the gap we're focused on closing with ThreatLens: helping enterprises accelerate AI adoption without giving up control of their data.

Today, organizations are being forced to choose between allowing employees to use AI without enough visibility or restricting AI so heavily that people find unofficial alternatives. I don't think either approach works.

www.techpulsemea.com


OPINION

|

EEMEA

12

AI-Enabled Growth Needs Stronger Cyber Resilience By Diego Arrabal, Vice President, EEMEA, Check Point Software Technologies

A

rtificial intelligence is reshaping cybersecurity in ways that extend far beyond betterwritten phishing emails. The broader shift is that AI is transforming the speed, scale and accessibility of cyber operations. Cybercriminals are using AI across multiple stages of the attack lifecycle, from reconnaissance and social engineering to malware development and automated intrusion workflows. Rather than simply increasing the volume of attacks, AI is lowering barriers to entry, allowing less-skilled actors to execute increasingly sophisticated campaigns while enabling advanced threat groups to operate faster and at greater scale. Check Point's 2026 Cyber Security Report found that organisations faced an average of 1,968 cyberattacks per week in 2025, a 70% increase since 2023. Its AI Security Report 2026 further highlights how AI-driven capabilities are becoming embedded across the attack lifecycle rather than remaining experimental. For organisations investing heavily in AI, cloud services, digital government, smart cities and next-generation digital infrastructure, cybersecurity is becoming a fundamental business requirement. As digital ecosystems expand, maintaining trust, resilience and operational continuity becomes increasingly important. One of the most significant changes is in social engineering. AI-generated messages are now more convincing, personalised and context-aware, making traditional warning signs such as poor grammar or generic language far less effective. The risk also extends beyond email to browsers, collaboration platforms, SaaS applications, messaging tools and voice channels. Deepfakes add another layer of risk. AI-generated audio and video make impersonation attempts increasingly realistic, raising concerns around executive fraud, account recovery scams and the manipulation of employees during time-sensitive business situations. Familiar voices or convincing video interactions should no longer be accepted at face value when money, access privileges or sensitive information are involved. AI is also accelerating malware development and helping threat actors improve the efficiency of

www.techpulsemea.com

their operations. At the same time, attackers are increasingly targeting credentials linked to cloud and AI platforms, creating new opportunities for data exposure, fraud and unauthorised access. While attackers are leveraging AI to improve efficiency, defenders are applying the same technology to strengthen detection, investigation and response capabilities. AI can analyse large volumes of security data across networks, endpoints, cloud environments and user activity, helping security teams identify risks earlier, prioritise threats and respond more effectively. As technology environments become more interconnected, organisations need security approaches that continuously assess risk, identify weaknesses and reduce exposure before vulnerabilities can be exploited. For organisations accelerating AI adoption, strong governance is essential. Leaders need visibility into which AI tools are being used, what information is being shared and whether sensitive data may be exposed through unmanaged usage. Attempting to block AI altogether is unlikely to succeed and may encourage shadow AI. A more effective approach is to establish clear policies, oversight and security controls that enable innovation while managing risk. Identity protection also requires renewed attention. Multi-factor authentication, least-privilege access, privileged access management and independent transaction verification are becoming increasingly important in a world where impersonation attempts are more credible than ever. The digital workspace should be viewed as a single connected environment. Email, browsers, SaaS applications, collaboration platforms and business services are all part of the same security ecosystem. Protecting one area while leaving another exposed creates opportunities for attackers. AI applications themselves must also be assessed and secured before deployment. Organisations need to understand how these systems access data, interact with business applications and make decisions. Risks such as prompt injection, data

leakage and unsafe automated actions require appropriate safeguards and oversight. This is particularly relevant across sectors including government, energy, financial services, healthcare, education, transport, telecommunications and critical infrastructure, especially in rapidly digitising economies such as the UAE and Saudi Arabia. As digital economies become increasingly dependent on connected technologies, trust, resilience and availability become strategic requirements rather than purely technical concerns. Cybersecurity is also emerging as an important enabler of sustainable digital transformation by helping organisations reduce disruption, improve operational efficiency and manage increasingly complex technology environments.

How AI is transforming cybersecurity and redefining the future of digital resilience. AI is reshaping the cybersecurity conversation because it is closely tied to broader economic and digital transformation agendas. Cybersecurity is no longer simply about protecting IT systems. It is about protecting the trust layer that underpins digital services, connected infrastructure and innovation. Organisations that succeed will not be those that avoid AI, but those that embed security and cyber resilience into every stage of its adoption. In the AI era, resilience is no longer just a technical requirement—it is a business imperative.

SEP 2026


13

OPINION

|

CENSYS

Attackers Don't Need a Breach When the Front Door Is Already Open

By Meriam ElOuazzani, Censys Vice President for the Middle East, Turkey and Africa

A

sk most security teams what worries them about Critical National Infrastructure, and they'll describe a dramatic scenario. A coordinated nation-state intrusion. A headline-grabbing breach. What rarely comes up is the forgotten test server still running, the dashboard nobody remembered to lock down, the industrial protocol that was supposed to stay local and somehow didn't. These unremarkable oversights are quietly becoming the biggest risk to energy grids, water systems and transportation networks, and they're exactly what External Attack Surface Management (EASM) was built to catch.

environment is spun up for a temporary project and kept alive. An industrial communications protocol, such as Modbus or BACnet is made accessible via TCP/IP without any form of authentication on the assumption by the engineer that it would never be accessed except locally. A web-based operational control panel meant solely for internal access is accidentally made available externally due to improper access control configuration. These don’t seem immediately threatening on their own — but to an attacker, they’re priceless. They provide footholds, context, and the kind of environmental knowledge that makes a targeted intrusion possible.

What EASM Actually Does At its core, EASM is about continuous visibility; the ongoing discovery, classification, and monitoring of every Internet-facing asset an organisation owns, whether it officially knows about it or not. Every sector has blind spots, but in CNI, those blind spots carry a particular weight. A misconfigured VPN portal in a bank is a problem. The same oversight on a system connected to a power grid is something else entirely. The UAE is aware of this pressure. The State of the UAE Cybersecurity Report 2025, released jointly by the UAE Cyber Security Council and CPX, found that over 223,800 assets within the UAE are potentially exposed to cyberattacks, up from 155,000 in 2024, with half of those critical vulnerabilities left unaddressed for more than five years. The attack surface isn't just large. It's expanding. The Assets Nobody is Watching The challenge for CNI operators isn't usually a failure of intent. Most organisations build their environments with security in mind. The problem is complexity, be it decentralised operations, third-party vendors, legacy systems, or shadow: it creates corners of the network that fall outside routine visibility. A staging

SEP 2026

integrations, remote access requirements, and the gradual convergence of OT and IT networks have introduced pathways that simply didn't exist when the model was designed. An exposed jump host at Level 3 can become a route into an industrial DMZ. A remote-access VPN into Level 2 with inadequate access restrictions can hand an attacker more visibility into HMIs than anyone intended. Cloud-connected services can inadvertently bridge security layers that were designed to be separate. The point isn't that the Purdue Model is wrong — it's that EASM is what makes it honest. Without visibility into what's exposed, the model is an aspiration rather than a guarantee.

Exploring the hidden entry points attackers can exploit in critical infrastructure—and how EASM helps organisations uncover and secure them before they become a serious threat. Why EASM Still Matters Behind Firewalls The Purdue Model has long been the foundational framework for securing industrial control systems (ICS) — a hierarchical structure that places sensors and physical controllers at the bottom (Levels 0 and 1), humanmachine interfaces (HMIs) and control systems in the middle (Level 2), and IT and enterprise networks at the top (Levels 3 through 5). The assumption baked into this model is that the lower levels are protected by the layers above them. That assumption is increasingly difficult to sustain. Modern operational environments don't respect the model's clean boundaries. Cloud

The HMI Problem HMIs sit at one of the most sensitive intersections in any ICS environment. They're the point where a human operator exerts direct influence over a physical process, like turbine speeds, valve positions, grid settings. And they are, increasingly, web accessible. Many run on operating systems that have long since passed their end-of-life dates. Many connect to cloud-based monitoring or analytics platforms. And in more cases than anyone would like to admit, they end up directly exposed to the Internet with default credentials or, worse, no authentication at all. Even when HMIs aren't directly exposed, they can be indirectly at risk. Breach a service at Level 3 or 4, and the path to Level 2 —

www.techpulsemea.com


OPINION

to the interfaces that control physical infrastructure — can be shorter than it looks on a network diagram. Building an EASM Programme That Works Addressing these risks requires moving from reactive to continuous. A modern EASM strategy for CNI environments starts with comprehensive asset discovery — not just the known, officially deployed infrastructure, but the subsidiaries, acquired entities, contractors, and legacy systems that accumulate over time and rarely appear on the approved asset register. Once assets are discovered, they need to be understood in context. Where do they sit in the Purdue model hierarchy? If this exposure were exploited, what would the blast radius look like? Discovery without that contextual layer is just a list. From there, the focus shifts to the protocols and services that matter most in ICS environments: detecting exposed Modbus or DNP3 traffic, flagging open RDP or VNC access, and identifying HMIs that are reachable from outside. On top of that, attack path assessment, which is a method to stress test the hypothesis that your perimeter defences are functioning as expected, bridges the gap between organisational assumptions about security and the reality of what is truly accessible. Finally, there is integration – using EASM insights in SOC operations, vulnerability management, and ICS risk frameworks to ensure that information leads to action, rather than just being collected on paper.

|

CENSYS

14

nation-states, and hacktivist groups are already assessing the weaknesses in these systems, including those mentioned above, and taking advantage of them. EASM doesn't eliminate that risk, but it changes the terms of engagement. It gives defenders the ability to see their environment the way an attacker sees it — completely, continuously, and from the outside in. In a threat landscape where what you don't know is exactly what gets exploited, that visibility isn't a feature. It's the foundation.

The cyber threat actors seeking to exploit vulnerabilities in CNI systems across the Middle East and beyond aren't waiting around for the right time to strike. Cybercrime syndicates,

www.techpulsemea.com

SEP 2026


15

OPINION

|

FORTINET

Who Owns Time? The Board’s Question Nobody Can By Ricardo Ferreira, EMEA Field CISO at Fortinet

A

sk a board to list its critical organisational inputs, and the answer is quick: capital, energy, connectivity, data. Still, one that is never mentioned is time. This is not about time management, but time as a foundational signal within a microsecond precise broadcast, unauthenticated from satellites above Earth, on which every trade, every network handover, and the grid silently depend on. Telecom networks synchronise every 5G tower to within a microsecond, and power grids rely on the phase measurement unit that does not work when the clock drifts. Logistically, ports operations all assume that time arrives quietly and correctly from space. Once again, it’s not a satellite problem; it’s an unmeasured input problem. Take into consideration the aviation safety data, it shows GPS spoofing incidents surging 500% year on year with analysts now tracking over 700 jamming and spoofing events every single day. Similarly, the reports coming from the Middle East and the Baltic states still fresh in memory, most of it is driven by nation states linked activities. The reality is that it reaches far beyond aviation into every sector that runs on satellite delivered time. The Cost of an Unowned Clock Three separate invoices are getting drafted, the first comes from the regulator. Accountability for operational resilience is moving up the org chart. Under NIS2, management bodies carry personal responsibility for cyber-risk oversight. The proposed EU Space Act requires threat-led penetration testing before launch and every three years thereafter. The direction is consistent across jurisdictions: Resilience must be evidenced. Insurers and underwriters are already pricing this exposure before most boards are measuring it. The space cyber insurance market is growing at over 17% annually, and

SEP 2026

operators with documented and demonstrable controls already command premium reductions of 15–30%. The logic is spreading to any sector dependent on satellite timing and communications. And finally, there is the audit problem, which on the systems keep running, but the records that uphold integrity quietly lose their standing. Trade sequencing becomes disputable, logs lose evidential value, and forensic timelines collapse. Own it, Measure it, Prove it Who is the executive responsible for owning time in your organisation? The CIO runs the networks. The CISO runs cyber risk. The COO runs operations. Time, all members of the board depend on, but nobody owns it, no budget line is associated with it, and normally there are no KPIs or SLAs. There is a lesson to this: Systemic risks remain unmanaged unless someone is made accountable. The next four points help get a grasp on the risk: 1.

Inventorise: Map what breaks if time drifts by 50 microseconds, 5 milliseconds, or 5 minutes

2.

Assign ownership: An executive, a defined tolerance, a time integrity SLA, similarly to any other critical input

3.

Instrumentise: Use sensors and analytics to feed the security operations capabilities already existing in the organisation

4.

Test: Simulate interference and holdover before an adversary, a regulator, or an underwriter

The necessary metrics will vary by organisation, but the following ones could provide a good starting ground: • • •

Timing integrity SLA adherence Holdover margin (hours of trustworthy autonomous time) Mean time to detect interference

You Can't Secure What You Don't Measure At Fortinet, our continuous collaboration with critical infrastructure operators across every sector keeps returning to the same lesson: You cannot secure what you do not measure. And today, almost nobody is measuring time. So, who owns it in your organisation?

An expert perspective on the hidden risks of satellitedelivered time and why organisations must measure, secure, and take ownership of time integrity. www.techpulsemea.com


INTERVIEW

|

GENESIS

16

Q4. You have worked across digital transformation, operational leadership and cybersecurity. What led you to focus on third-party risk management, and why is this area becoming increasingly important for organizations today? I saw that many organizations were strengthening internal security but still had limited visibility in vendors and suppliers. Businesses now rely on third parties for systems, data and critical operations, yet assessments are often slow, manual and difficult to scale. We created Genesis Platform to modernize that process by combining AI-powered assessments, automated validation and continuous monitoring, so organizations can make faster and better-informed decisions about the companies they trust. Q5. From your experience in the UAE market, where do you see the biggest gaps in how organizations approach third-party cyber risk?

Khalifa Al Shehhi

Founder of Genesis Platform Q1. AI is transforming cybersecurity, but it is also introducing new risks. What is the biggest AI-related risks you believe CISOs, and business leaders should be preparing for? AI is becoming a powerful tool for both defenders and attackers. The biggest concern is speed: attackers can use AI to scale phishing, social engineering and vulnerability discovery. There is also a challenge to trust. If AI relies on weak, incomplete or manipulated data, it can produce poor decisions. At Genesis Platform, we believe AI should support people, not replace accountability. Organizations need strong governance, clear oversight and continuous visibility when using AI in cybersecurity. Q2. The GCC is rapidly digitizing critical infrastructure and enterprise operations. What unique cybersecurity challenges does this create for the region? Rapid digitization creates more connections between organizations, cloud providers, technology vendors and critical suppliers. This expands the attack surface and means that a weakness in one third party can affect the wider business ecosystem. The region must also address sectorspecific regulation, data sovereignty and the security needs of government, finance, energy and critical infrastructure. Genesis Platform helps organizations manage this complexity through

www.techpulsemea.com

localized risk assessments, continuous monitoring and clearer vendor visibility. Q3. Looking ahead to the next three to five years, what will distinguish organizations that are truly resilient from those that are simply compliant? Compliance shows that an organization has met a requirement at a point in time. Resilience means understanding how risk is changing and being ready to respond. Truly resilient organizations will continuously monitor their vendors, priorities the risks that matter most and act quickly when a supplier's security posture changes. They will use automation and real-time insights to support decisions instead of relying only on annual reviews and spreadsheets.

The biggest gap is continuous visibility. Many organizations assess a vendor during onboarding, then do not see how that vendor's security posture changes over time. Another gap is the continued use of spreadsheets, long questionnaires and manual reviews. This makes the process inconsistent and difficult to scale. Genesis addresses these gaps through automated assessments, attack-surface monitoring, risk scoring and clear reporting for security and business leaders. Q6. Where do traditional GRC tools fall short in managing third-party risk, and why do organizations need a dedicated TPRM approach? I believe GRC provides a broader framework, but it does not fulfil third-party risk management on its own. TPRM brings together supplier questionnaires, breach intelligence and outside-in security assessments to build a more complete, current picture of supplier risk. That helps organisations understand the potential business impact and act before it becomes a disruption.

AI is transforming cybersecurity, but resilience depends on more than technology—it requires governance, visibility and accountability.” Genesis Platform highlights why continuous third-party risk monitoring is becoming essential in an increasingly connected GCC ecosystem. SEP 2026


17

OPINION

|

SOPHOS

As AI Scales, Why Cybersecurity Risk Can No Longer Rest With CISOs Alone

A

By Harish Chib, Vice President Emerging Markets, Middle East & Africa, Sophos

cross the Middle East, artificial intelligence is moving from experimentation to execution at remarkable speed. From conversational assistants and document automation to predictive analytics and business copilots, AI is now being embedded into daily workflows across government, financial services, healthcare, retail, energy, and other critical sectors. For regional business leaders, the question is no longer whether AI will be adopted. It is whether organizations can adopt it securely, responsibly, and at the pace the market now demands. This urgency is particularly evident in the Middle East, where national digital transformation agendas and enterprise innovation priorities are accelerating AI adoption faster than many organizations can build the governance structures around it. According to Deloitte's Digital Consumer Trends 2025 report, 58% of consumers in the UAE and Saudi Arabia have already used generative AI tools, significantly higher than adoption levels seen across many European markets. That momentum is now entering the enterprise, transforming usage patterns, decision-making processes, and the way sensitive data moves across organizations. As a result, it is becoming increasingly unrealistic to expect CISOs to carry AI-related risk alone. A shift in risk that is redefining the CISO’s role Historically, the role of the Chief Information Security Officer was to protect infrastructure, access, and sensitive data. Their remit was clearly defined around preventing cyberattacks and controlling technical risk. But with the rise of generative AI, the issue is changing in scale. Artificial intelligence does not simply create a new cyber risk. It changes how people work, accelerates data flows, and in some cases even transforms decision-making mechanisms within companies. This shift is also disrupting a major pillar of modern cybersecurity: digital identity. Today, identity has become the primary attack surface for organizations. User accounts, cloud access, APIs, automated assistants, and AI agents are multiplying the number of potential entry points. In many companies, security teams are already struggling to keep pace with

SEP 2026

the creation and management of privileges. This trend is being amplified further by the rapid emergence of non-human identities. The pace of AI deployment is creating a governance challenge for organizations across the region. Deloitte reports that more than 80% of Middle Eastern organizations feel significant pressure to adopt AI, while 69% plan to increase investment in AI initiatives. However, many leaders acknowledge that governance, skills, and operational readiness have not matured at the same speed as adoption. AI agents, bots, and automated systems are gaining access to sensitive resources at a pace that security teams can no longer always control effectively. This proliferation of technical identities is creating a new imbalance between the speed of adoption and organizations’ actual ability to govern these uses. The CISO is therefore becoming far more than a technical expert. They are now expected to act as a coordinator of digital trust, capable of assessing AI-related risks, preventing data leaks, supervising internal usage, and contributing to regulatory compliance, particularly under new European requirements. AI governance must become collective The main paradox is that companies still often treat AI as a purely technological or cyber issue, when in reality it is first and foremost a broad organizational transformation. AI governance concerns business units just as much as legal teams, human resources, compliance, IT, and executive leadership. The issues at stake include data confidentiality, intellectual property, accountability for automated decisions, as well as ethics and corporate reputation.

AI tools without internal approval and sometimes with sensitive data, driven by the immediate pursuit of productivity gains. These behaviors are rarely malicious, but they reveal a growing gap between the speed at which technologies are adopted and the maturity of organizations in framing and governing them. Banning AI tools would be unrealistic. Companies that choose a purely restrictive approach would risk pushing usage outside any official framework. The challenge is therefore no longer to block, but to organize. That means putting clear policies in place, raising employee awareness, classifying the data that can be used, and above all sharing responsibility for governance across all business functions.

AI is redefining the CISO’s role, making collective governance and digital trust essential for secure and responsible adoption. The challenge is particularly significant in the Gulf, where governments are investing heavily in becoming global AI leaders. The UAE continues to rank among the world's most advanced AI adoption markets, while Saudi Arabia's Vision 2030 agenda is accelerating AI deployment across public and private sectors. As AI becomes embedded into critical business processes, the question for organizations is no longer whether they will use AI, but whether they can govern it effectively and responsibly.

In this context, the CISO can no longer be seen as the sole line of defense against AI-related risk. No security leader can, on their own, define acceptable use, arbitrate the organizational impacts of automation, or carry the full weight of the regulatory obligations now emerging. This lack of clear governance is already encouraging the emergence of a phenomenon comparable to shadow IT, now commonly referred to as “shadow AI.” Employees are using

www.techpulsemea.com


INTERVIEW

|

DEWA

18

Q3. Technology alone cannot create innovation. How can organizations encourage a culture where employees embrace change, experiment, and contribute to continuous improvement? Culture is not built through posters or innovation days; it comes from practical actions. First, lower the cost of experimentation by providing accessible sandboxes with clear boundaries, enabling teams to test ideas quickly. Second, make it safe to fail small by defining contained, reversible experiments that do not require extensive approval, while maintaining governance for larger risks. Third, close the feedback loop by responding to employee ideas, even when the answer is no. Finally, leaders must lead by example. If leaders expect teams to adopt AI, they must use it themselves. Visible leadership behaviour builds credibility and drives adoption far more effectively than campaigns. Q4. The role of leaders is evolving rapidly. What qualities and capabilities do you believe future leaders need to navigate constant technological and business change?

Samh Khalid Lead AI Architect

Q1. With AI changing the workplace, how should organizations prepare their workforce for the next era of digital transformation? Accept one reality: your people are already using AI, whether you approved it or not. The first priority is providing a governed, approved environment to prevent shadow AI and data risks. Second, focus on role-based skills, not generic awareness. Engineers, procurement teams, and other functions need different AI capabilities. Third, measure adoption and impact—who uses AI, how, and whether outcomes improve. Finally, address the human side honestly. Instead of saying “AI won’t replace you,” explain what parts of each role will change, what becomes more valuable, and what support employees will receive to adapt and succeed. Q2. Trust has become a key factor in digital transformation. How can organizations build stronger governance frameworks while continuing to innovate? Governance and innovation are not opposites; when designed well, governance can accelerate innovation. First, governance must be embedded within the delivery pipeline, not added at the end. Automated controls such as code scanning, secrets detection, policy as code, and

www.techpulsemea.com

AI safeguards provide immediate feedback without creating unnecessary delays. Second, make the compliant path the fastest path. Pre-approved environments, patterns, and AI tools encourage teams to adopt governance naturally. This is especially important in critical national infrastructure, where uncontrolled experimentation carries significant risk. Manual governance cannot scale effectively. Automated guardrails enable organizations to maintain strong security and compliance while allowing teams to innovate quickly, safely, and confidently.

Four leadership capabilities matter most. First, leaders need enough technical depth to ask the right questions and distinguish genuine capabilities from impressive demos. Second, they must be comfortable making decisions without complete information, understanding which decisions are reversible and acting quickly when needed. Third, leaders must translate effectively between technical teams and the board, connecting technology initiatives to clear business value. Finally, and most importantly, they need outcome discipline—the willingness to stop initiatives that are not delivering results. Organisations often excel at launching pilots but struggle to end unsuccessful ones. Strong leaders focus on measurable outcomes, turning transformation from scattered experiments into sustained business impact.

SOUNDBITE “Governed AI is the cure for shadow AI. If you don't give people an approved tool, they'll find an unapproved one.” SOUNDBITE “Governance should be a paved road, not a checkpoint. Make the compliant path the fastest path and adoption takes care of itself.”SOUNDBITE “You don't build an innovation culture with slogans. You build it by lowering the cost of trying something.”SOUNDBITE “Future leaders don't need to write the code. They need enough depth to tell a real capability from a good demo.” SEP 2026


19

INTERVIEW

|

DUBAI AMBULANCE

Q3. Technology alone cannot create innovation. How can organizations encourage a culture where employees embrace change, experiment, and contribute to continuous improvement? Innovation starts with people. Technology provides the tools, but employees need the confidence and opportunity to challenge existing ways of working. Leaders should create an environment where ideas are welcomed, experimentation is encouraged within appropriate boundaries, and lessons are valued even when outcomes are not as expected. Innovation should also extend beyond technology teams; employees closest to operations often identify the most valuable opportunities for improvement. When people feel heard, empowered, and recognized for contributing ideas, innovation becomes part of the organizational culture rather than a standalone initiative.

Asma Muallemi CISO

Q1. With AI changing the workplace, how should organizations prepare their workforce for the next era of digital transformation? Preparing for the AI era is not simply about introducing new technology; it is about preparing people to work differently. Organizations should invest in continuous learning, particularly in AI literacy, cybersecurity, data skills, and critical thinking. Employees should understand how AI can augment their capabilities while remaining aware of risks related to security, privacy, and responsible use. Equally important is creating an environment where people feel confident adapting to change. The organizations that succeed will be those that combine technological advancement with a skilled, adaptable, and security-conscious workforce.

from the beginning, not added later. As technologies such as AI and cloud evolve, governance must also become more dynamic, with clear accountability, strong data governance, and continuous risk monitoring. The objective should be secure innovation: enabling organizations to move quickly and adopt emerging technologies while maintaining the trust of employees, stakeholders, partners, and the communities they serve.

Q4. The role of leaders is evolving rapidly. What qualities and capabilities do you believe future leaders need to navigate constant technological and business change? Future leaders need strategic vision, technological awareness, adaptability, and strong human leadership. They do not need to be experts in every emerging technology, but they must understand its potential, risks, and business value. Curiosity and continuous learning will be essential as technology evolves faster than traditional planning cycles. At the same time, communication, empathy, integrity, and accountability will become even more important as AI and automation reshape the workplace. Ultimately, successful leaders will be those who can balance innovation with responsibility, speed with resilience, and technological advancement with the needs of people.

Q2. Trust has become a key factor in digital transformation. How can organizations build stronger governance frameworks while continuing to innovate? Trust is fundamental to digital transformation. Strong governance should enable innovation rather than slow it down by creating clear boundaries within which teams can innovate confidently. Cybersecurity, privacy, risk management, and compliance should be embedded

SEP 2026

Preparing for the AI era is not simply about introducing new technology; it is about preparing people to work differently. The objective should be secure innovation

www.techpulsemea.com


INTERVIEW

|

SUDHIR KUMARAN

20

becomes safer, faster and easier to scale. Q3. Technology alone cannot create innovation. How can organizations encourage a culture where employees embrace change, experiment, and contribute to continuous improvement? Technology alone does not transform an organization; people do. Employees embrace change when they understand the operational problem being solved and see how technology improves their work, safety or customer service. Involve warehouse, transport, cargo, customer-service and security teams early to identify manual handoffs, delays and process gaps. Use small pilots, measurable outcomes and rapid feedback rather than large “big-bang” implementations. Create digital champions within each business area to support colleagues and connect operational feedback with IT teams. Leaders must model curiosity, accountability and openness to learning. Continuous improvement becomes real when employees feel safe to say, “There is a better way—let us test it”

Sudhir Kumaran Director of IT

Q1. With AI changing the workplace, how should organizations prepare their workforce for the next era of digital transformation? AI should augment people, not simply automate jobs. In logistics, supply chain and aviation, organizations should start with role-based AI literacy: what AI can do, where human judgement remains essential and how data must be handled responsibly. Focus first on practical use cases such as exception management, demand forecasting, document processing, customer communication and predictive maintenance. Involve frontline employees early because they understand operational realities and exceptions better than any algorithm. Finally, invest in continuous reskilling, clear governance and change management. AI succeeds when employees see it as a trusted assistant that improves safety, service quality and productivity—not as a replacement for experience. Q2. Trust has become a key factor in digital transformation. How can organizations build stronger governance frameworks while continuing to innovate? Trust is essential because logistics and aviation depend on secure, reliable and interconnected operations. Governance should enable innovation, not delay it. The

www.techpulsemea.com

best approach is risk-based: allow low-risk pilots to move quickly within defined guardrails, while applying deeper security, privacy, resilience and compliance checks to highimpact solutions involving customer data, government interfaces or AI decision-making. Core controls include data ownership, secure-by-design architecture, vendor due diligence, integration standards, audit trails and tested business-continuity plans. ISO 27001, ISO 22301, ITIL and COBIT provide useful structure. When governance is built into design from the start, innovation

Q4. The role of leaders is evolving rapidly. What qualities and capabilities do you believe future leaders need to navigate constant technological and business change? Future leaders need technological awareness, business judgement, resilience and humanity. They do not need to be experts in every new technology, but they must understand AI, cyber risk, cloud, data and automation well enough to link investment decisions to business outcomes. In 24x7 logistics and aviation environments, they must remain calm during disruption, communicate clearly and make responsible decisions under pressure. Ethical judgement is equally important: leaders must protect privacy, manage AI bias and retain human oversight in critical decisions. Most importantly, they must develop people—building capable teams, mentoring future leaders and creating a culture of trust, learning and innovation.

AI should augment people, not simply automate jobs. Trust is essential because logistics and aviation depend on secure, reliable and interconnected operations.

SEP 2026


21

INTERVIEW

|

NMC HEALTHCARE

peer learning, job-tool experimentation, and AI-driven tool training.

Nidhi Chaudhary

Information Security Compliance Officer

Q1. With AI changing the workplace, how should organizations prepare their workforce for the next era of digital transformation?

executives retain final decision-making authority. •

Organizations must consider AI-driven workforce changes more holistically than equipment adoption. This approach stimulates know-how development and effective collaboration with AI to perform jobs. In advance of AI-powered transformations, organizations are expected to: •

Develop AI literacy: Encourage employees to build AI skills, safety awareness, and critical thinking, and to interpret AI recommendations, while

SEP 2026

•

Change the perception of job automation skills: Consider jobs’ tasks and the implications of automation, augmentation, or human requirements. Instead of considering which AI job automation will have on the workforce, organizations should concentrate on identifying tasks and skills whose importance will increase. Include learning as a job requirement: Knowledge and skill development should include ongoing, job-related short-form training, such as simulations

•

Emphasize human skills: Invest in strengthening emotional, cognitive, methodical, and ethical skills to remain adaptable. Strive to develop the strongest workforce, which is a holistic combination of expert skill and AI capability.

•

Restructure processes: Use AI technology to restructure work processes instead of incorporating new software.

•

Create an experimentation culture: Design governing rules for safe AI use to let teams find new viable AI frameworks and applications. Provide domains and methods to define reusable AI tools and develop new approaches with clearly defined data-access governance and security boundaries, with human review.

•

Lead with transparency: Be frank about workplace changes and developments. Employee job security is top of mind for everyone. Leaders should emphasize the transparency of the change and uncertainty and what the company will do to support the workforce.

Q2. Trust has become a key factor in digital transformation. How can organizations build stronger governance frameworks while continuing to innovate? Organizations should consider how trust and innovation connect with governance as an enabler rather than a blocker: •

Implement clear guardrails: Set guardrails for privacy, security, AI ethics, appropriate data use, and accountability.

•

Implement risk-based governance: Apply stronger controls to higher-impact technologies while allowing lower-impact technologies to be used experimentally.

•

Foster transparency: Document how AI and digital systems make decisions and provide oversight. Educate users on how to provide oversight.

•

Employee empowerment: Train

www.techpulsemea.com


INTERVIEW

•

•

teams on responsible technology use and give them ways to raise concerns.

•

Psychological safety is present when it’s ok to question existing assumptions and practices.

Piloting: Use regulated environments first to evaluate innovation plus its possible impacts. Measure the possible impacts and adjust the initiative as needed.

•

Investing in learning is a company’s best investment. New skills are always a company’s biggest competitive advantage.

Evolving governance: View each governance policy framework as a temporary control to be adapted.

Q3. Technology alone cannot create innovation. How can organizations encourage a culture where employees embrace change, experiment, and contribute to continuous improvement? To develop an innovation culture, organizations can perform the following: •

Employees must be given the freedom to think outside the box, which often leads to bad ideas. Treat each idea as a foundation for a new learning experience.

•

Initiative should be recognized. Everyone improves at least one step in identifying a problem, proposing a solution, and implementing it.

•

Leverage teams. Autonomy helps people make decisions and aims to act on new ideas.

Q4. The role of leaders is evolving rapidly. What qualities and capabilities do you believe future leaders need to navigate constant technological and business change? Future leaders will need to draw on a mix of technical, strategic, and interpersonal skills to manage the ongoing flux of the contemporary business world. •

Flexibility: Leaders will need to be comfortable with the unknown and able to shift their plans as technology and markets change.

•

Technology: Business leaders will not need to be technology experts; they just need to know what technologies are available and how they may affect the business.

•

Strategic: Leaders will need to align tech investments with corporate targets rather than adopt tech blindly.

•

Development of New Skills: Trust-building, effective communication of change, and employee development will become increasingly important.

|

NMC HEALTHCARE

22

•

Innovation: Leaders must build a culture of employee-proposed ideas through an experimental framework and an acceptance of reasonable risk.

•

Systems: AI and data systems shape the value of leaders’ ethical judgment.

•

Resilient: Leaders must stay focused and make decisions quickly during uncertainty.

•

Demonstration: Leaders must embrace new systems of change and encourage employee experimentation.

Organizations must consider AI-driven workforce changes more holistically than equipment adoption. Organizations should consider how trust and innovation connect with governance as an enabler rather than a blocker

www.techpulsemea.com

SEP 2026


23

INTERVIEW

|

AJMAN MUNICIPALITY

Q3. Technology alone cannot create innovation. How can organizations encourage a culture where employees embrace change, experiment, and contribute to continuous improvement?

Hend Al Shamsi

Director of Smart Services Development Department and Digital Transformation & Ai Head Q1. With AI changing the workplace, how should organizations prepare their workforce for the next era of digital transformation? AI creates value when people know how to use it effectively. In our organization, AI is treated as a leadership priority, focused on five strategic business outcomes with clear governance and measurable KPIs. We embed AI learning into daily work, combining AI literacy with critical thinking, judgment, and problemsolving. We also assess how AI is reshaping roles and skills, creating targeted reskilling, career development, and apprenticeship pathways. Most importantly, we are redesigning processes, roles, decision rights, and governance to enable effective human-AI collaboration. This approach moves beyond technology adoption toward meaningful, sustainable digital transformation and business value. Q2. Trust has become a key factor in digital transformation. How can organizations build stronger governance frameworks while continuing to innovate? Trust is the foundation of digital transformation. In our organization, AI governance is embedded into operations, balancing speed, risk, and accountability. We use agile governance, enabling teams closest

SEP 2026

to each use case to make timely decisions as risks evolve. Trust is built by design through automated monitoring, data protection, prompt and output logging, and policy controls. Governance is integrated across design, development, deployment, and usage, with risk, legal, compliance, and procurement aligned under one framework. Most importantly, governance is opportunity-focused, helping teams manage risks while accelerating valuable AI initiatives. This approach enables innovation with confidence and accountability.

Technology is an enabler, but real innovation comes from people feeling empowered to use it effectively. In our organization, culture is as important as technology. Leaders actively use and experiment with AI tools, demonstrating that learning from failure is encouraged. We create structured opportunities through innovation sprints and pilot programs, enabling employees to test ideas with clear, lightweight funding. Success is measured not only by outcomes but also by validated learning, reducing fear of experimentation. Finally, decision-making is decentralized, giving teams ownership of AI initiatives. This combination of leadership, experimentation, learning, and empowerment drives stronger adoption, innovation, and continuous improvement. Q4. The role of leaders is evolving rapidly. What qualities and capabilities do you believe future leaders need to navigate constant technological and business change? AI-driven transformation requires a new leadership mindset. Leaders must be comfortable with ambiguity, making sound decisions without complete information while recognizing when challenges require organizational change. They need functional AI literacy to understand capabilities, limitations, risks, and opportunities without being technical experts. Leadership increasingly depends on influence, collaboration, and cross-functional alignment rather than hierarchy. Leaders must also personally champion responsible and ethical AI use. Equally important is balancing today’s operational priorities with investments for the future. Ultimately, future leaders should move beyond command-andcontrol management and become coaches who guide, empower, support, and enable their teams to adapt, innovate, and succeed.

In our organization, AI is treated as a leadership priority, focused on five strategic business outcomes with clear governance and measurable KPIs.In our organization, AI governance is embedded into operations, balancing speed, risk, and accountability.

www.techpulsemea.com


INTERVIEW

|

GPSSA

24

Q3. Technology alone cannot create innovation. How can organizations encourage a culture where employees embrace change, experiment, and contribute to continuous improvement? Technology does not create innovation; culture does. Leaders must create an environment where people can experiment, learn from failure and innovate responsibly within clear boundaries for risk, data, security and regulation. AI should not be treated solely as an IT responsibility. The BAT Framework—Business, Assurance and Technology—must work as equal partners. Business defines value and strategy, Assurance manages risk, controls and compliance, while Technology enables design and implementation. AI ownership must therefore extend across the organization, supported by strong leadership and a culture that embeds people, processes and technology. Audit and Risk should enable improvement, identify opportunities and encourage learning alongside accountability.

Khurram Sabir

Chief Internal Auditor and Chief Risk Officer Q1. With AI changing the workplace, how should organizations prepare their workforce for the next era of digital transformation? AI transformation should not be viewed simply as a technology implementation. From an audit and risk perspective, it is fundamentally about people, processes and decision-making. Organizations need AI literacy, redesigned processes and stronger human capabilities such as judgement, critical thinking, creativity and decision-making. Accountability must remain with people who understand, challenge and own AI-supported outcomes. AI should not replace human expertise but multiply it, transferring routine tasks to intelligent systems while freeing employees to focus on complex, higher-value work. Ultimately, the goal is to create an organization where people and AI work together to make better, faster and more responsible decisions. Q2. Trust has become a key factor in digital transformation. How can organizations build stronger governance frameworks while continuing to innovate? Governance and innovation should not be viewed as opposing forces. Good governance enables innovation by creating clear boundaries for safe experimentation. From an audit and risk perspective, governance should

www.techpulsemea.com

be proportionate, with stronger controls for AI affecting customers, employees or financial outcomes. Clear principles around data, privacy, cybersecurity, model risk, compliance and accountability allow businesses to innovate confidently. Governance must also include continuous monitoring and assurance to confirm controls work effectively, rather than simply relying on policies. As technology evolves rapidly, governance must evolve with it. AI is like a smart, fast intern: highly capable but requiring validation, oversight and checks before its outputs can be trusted.

Q4. The role of leaders is evolving rapidly. What qualities and capabilities do you believe future leaders need to navigate constant technological and business change? Future leaders must be comfortable with uncertainty and able to make decisions without having all the answers. Five capabilities are particularly important: strategic curiosity, to understand how technology and business trends create opportunities and risks; judgement, to distinguish valuable insights from information overload; adaptability, to challenge assumptions and change direction when evidence changes; trust-building, to communicate change clearly and support employees; and risk awareness, without becoming risk-averse. From an Audit and Risk perspective, leadership is not about avoiding risk, but understanding it, keeping it within appetite and building resilience. Ultimately, effective leaders ask better questions, learn continuously and adapt confidently.

“AI may automate activities, but it doesn’t automate accountability.” “Good governance should not stop innovation. It should be a guardrail that enables innovation with confidence.” “The culture I want encourages people to challenge the way we’ve always done things, while understanding the risks.” “Future leadership is not about predicting perfectly. It’s about building an organization that can respond intelligently to change.” SEP 2026


25

INTERVIEW

|

ENVIRONMENT AGENCY OF ABU DHABI

Q3. How can organizations create a culture where employees embrace change and continuous improvement?

Dr. Ghazi Sultan

Head of Organization Development Q1. How should organizations prepare their workforce for the next era of digital transformation? Artificial intelligence is reshaping how work is designed, decisions are made, and value is created. Organizations should prepare their workforce by focusing on people and work design, not technology alone. This requires building practical AI literacy, critical thinking, data interpretation, systems thinking, and ethical judgment, while redesigning roles so routine activities are automated and employees can focus on higher-value work. Managers also need the capability to lead teams where people increasingly work alongside AI. From my experience supporting organizational restructuring, HR system transformation, and process redesign, the key lesson is that technology, workforce capability, leadership engagement, and change management must move together. When employees understand why change is happening, how their roles will evolve, and how they will be supported, digital transformation is far more likely to deliver sustainable value. Q2. How can organizations strengthen governance while continuing to innovate? Governance and innovation should reinforce each other rather than compete. Strong governance provides the trust, clarity, and decision

SEP 2026

discipline that allow organizations to innovate responsibly and at speed. In AI-enabled environments, this means clear accountability for decisions, appropriate human oversight, strong data privacy and cybersecurity controls, and transparency in how technology is used. Governance must also be proportionate to risk rather than becoming bureaucratic. In my experience, standardized policies, well-defined delegation of authority, RACI frameworks, executive governance forums, and clear process ownership have strengthened accountability while enabling faster and more consistent decision-making. As advanced technologies become embedded in core processes, these foundations are essential to clarify where automation can support decisions and where human judgment and accountability must remain firmly in place.

Employees are far more likely to embrace change when they are meaningfully involved in shaping it rather than having it imposed on them. Organizations should foster psychological safety, encourage constructive challenge and experimentation, and give employees practical channels to influence how change is implemented. During major restructuring and transformation initiatives I have supported, change champions, workshops, focus groups, and structured feedback mechanisms were used to build ownership and reduce resistance. Shifting project documentation and collaboration to digital platforms also enabled faster iteration, greater transparency, and alignment with sustainability goals. Continuous improvement becomes embedded in culture when employees see that their feedback leads to visible action, leaders remain consistent and present, and incremental improvements are recognized instead of focusing only on large transformation programmes. Q4. What capabilities will future leaders need to navigate constant change? Future leaders will need learning agility at least as much as technical expertise. They must be digitally fluent enough to understand AI, analytics, and emerging technologies, but their true value will lie in distinctly human capabilities such as judgment, empathy, communication, coaching, ethical reasoning, and systems thinking. They also need to create clarity while operating in environments that are themselves continuously changing. My experience leading organizational restructuring, workforce planning, competency framework development, enterprise system implementation, and HR digitalization has reinforced that transformation is fundamentally a leadership challenge. Leaders do not need to have all the answers, but they must ask the right questions, make responsible decisions with incomplete information, build trust, empower others, and normalize continuous learning. These capabilities will ultimately determine organizational resilience and relevance in an era of constant change.

Organizations should prepare their workforce by focusing on people and work design, not technology alone. Governance and innovation should reinforce each other rather than compete. www.techpulsemea.com


INTERVIEW

|

AL GHURAIR GROUP

26

current way of doing things. Leaders need to create an environment where employees can suggest ideas, test them, and occasionally fail without being blamed. Small pilots are often more effective than large transformation programmes because they allow teams to prove value quickly. Recognition is also important. When people see colleagues being recognised for improving a process or solving a problem, innovation becomes part of the culture rather than a management slogan. Q4. The role of leaders is evolving rapidly. What qualities and capabilities do you believe future leaders need to navigate constant technological and business change?

Mario Foster Group CIO

Q1. With AI changing the workplace, how should organizations prepare their workforce for the next era of digital transformation? Organisations should avoid treating AI as simply another technology rollout. The bigger challenge is preparing people to work differently. That means investing in practical upskilling, giving employees access to the right tools, and helping them understand where AI can genuinely improve their work. Not everyone needs to become an AI expert, but everyone should understand how to use it responsibly and productively. I also believe organisations should focus on redesigning roles, not just automating tasks. The real opportunity is to let AI handle repetitive work while people spend more time on judgement, creativity, problem-solving, and decision-making.

bureaucratic. If employees know what data they can use, which tools are approved, and who owns the final decision, innovation becomes safer and faster. Trust comes from transparency, clear ownership, and consistent controls.

Future leaders will need curiosity, adaptability, strong judgement, and the ability to make decisions with incomplete information. Technical knowledge helps, but leadership is increasingly about connecting technology to business outcomes and bringing people along with the change. I also believe humility is becoming more important. No leader can know everything in today’s environment. The strongest leaders will be those who listen to specialists, challenge assumptions, make decisions quickly, and are comfortable changing direction when the facts change.

Q3. Technology alone cannot create innovation. How can organizations encourage a culture where employees embrace change, experiment, and contribute to continuous improvement? Innovation works best when people feel comfortable challenging the

Q2. Trust has become a key factor in digital transformation. How can organizations build stronger governance frameworks while continuing to innovate? Governance should not become a barrier to innovation. The right approach is to define clear boundaries around data, security, privacy, and accountability, while still giving teams room to experiment. I prefer governance that is practical and risk-based rather than overly

www.techpulsemea.com

The bigger challenge is preparing people to work differently. Governance should not become a barrier to innovation. SEP 2026


INTERVIEW

|

FVC

30

digital transformation, cloud adoption and AI initiatives, which naturally increases the attack surface. At the same time, regulatory requirements and the need to protect critical infrastructure are pushing organizations to take a more proactive approach to cybersecurity. Q4. How important is threat intelligence today compared to traditional security controls? Traditional security controls remain extremely important, but threat intelligence has become essential for understanding what is happening beyond the organization's perimeter. Organizations need to know not only whether they are being attacked, but who may be targeting them, what vulnerabilities are being exploited, what assets are exposed, and what threats are emerging in their industry or region. Threat intelligence allows security teams to move from a reactive approach to a more proactive, intelligence-led security strategy. We see it working alongside traditional controls not replacing them.

K. S. Parag MD, FVC.

Q1. What key cybersecurity solutions and innovations is FVC showcasing at GISEC 2026, and how do these address the most pressing security challenges facing organizations in the Middle East today? At GISEC 2026, FVC is showcasing a comprehensive cybersecurity portfolio covering identity and privileged access management, threat intelligence, attack surface and vulnerability management, AI-powered security, security analytics, cloud security and cyber resilience. Our focus is not simply on adding more security tools, but on helping organizations build a layered, proactive security strategy. With the rapid adoption of cloud, AI and hybrid environments across the Middle East, organizations need greater visibility, stronger identity controls and the ability to detect and respond to threats before they become major incidents. Our technology partners enable us to address these challenges across the entire security lifecycle. Q2. How is FVC helping partners build cybersecurity expertise and services capabilities? Our partners are at the heart of our cybersecurity strategy. We are investing heavily in partner enablement, technical training, workshops, certifications, solution demonstrations and joint go-to-

www.techpulsemea.com

market initiatives. We want our partners to move beyond simply reselling products and become trusted cybersecurity advisors. FVC supports them with technical expertise, pre-sales assistance, solution design, marketing programs and access to our technology vendors. This enables partners to build their own cybersecurity services capabilities and create sustainable business opportunities. Q3. Which sectors in the UAE and GCC are currently driving the highest demand for cybersecurity investments? We are seeing strong cybersecurity demand across government, banking and financial services, energy and utilities, healthcare, telecommunications, and large enterprises. The UAE and wider GCC are accelerating

Q5. FVC has evolved from a collaboration-focused distributor into a major cybersecurity player. What were the key strategic decisions behind this transformation? The transformation was driven by a clear decision to treat cybersecurity as a strategic business priority rather than simply another technology category. We invested in building a dedicated cybersecurity team, developing technical competency, strengthening our vendor portfolio and, most importantly, building a strong partner ecosystem across the region. We carefully selected technology partners that address real market challenges—from identity and access security to threat intelligence, AI, vulnerability management and security operations. Our philosophy has been simple: bring the right technology, the right expertise and the right partners together. Today, FVC is positioned not just as a distributor, but as a cybersecurity value-added distributor and ecosystem enabler, helping vendors and partners take innovative security solutions to market across the Middle East and Africa.

Traditional security controls remain extremely important, but threat intelligence has become essential for understanding what is happening beyond the organization's perimeter. Organizations need to know not only whether they are being attacked, but who may be targeting them, SEP 2026


INTERVIEW

|

FINESSE

32

security framework that balances innovation with protection. Our AI/Gen AI Governance framework establishes clear policies and guardrails for responsible AI adoption while ensuring compliance with rapidly evolving regulatory requirements. At the technical level, our cutting-edge Gen AI Broker/LLM Gateway creates a secure intermediary layer between enterprise systems and generative AI bot platforms. This sophisticated solution implements real-time content filtering, prompt injection protection, and bidirectional data sanitization to prevent sensitive information leakage while allowing organizations to leverage AI's transformative capabilities.

Eljo J P

Chief Business Officer & Director, Finesse Q1. What is Cyberhub 24*7 and how does it fit into Finesse's overall digital transformation strategy? Cyberhub 24x7 serves as the cybersecurity backbone of Finesse, providing businesses with comprehensive, round-the-clock protection against modern cyber threats. Its Cognitive Security Operations Centers (CSOC), situated in Dubai and Bangalore, deliver 24/7 monitoring, real-time threat detection, and rapid incident response to safeguard businesses navigating AI & digital transformation. This dedicated cybersecurity pillar integrates seamlessly into Finesse's three-pronged strategy of Advising, Enabling, and Securing. While Finesse's other pillars focus on strategic advisory (1CXO) and implementation of digital solutions, Cyberhub ensures digital innovations remain secure from inception to execution leaving clients to focus on their business . This integration demonstrates Finesse's commitment to embedding security as a foundational priority. Q2. How does Cyberhub 24*7, the cybersecurity pillar of Finesse, leverage AI to protect businesses from evolving cyber threats? Finesse has envisioned cybersecurity with an AI-first philosophy that goes beyond supplementary applications to make artificial intelligence the

www.techpulsemea.com

foundational element of our security operations. Our Cognitive Security Operations Center (CSOC) employs advanced AI analytics that continuously process volumes of security data to identify subtle patterns and behavior anomalies human analysts might miss. Our machine learning models enable predictive security capabilities, forecasting trends in user behavior, identifying potential vulnerabilities and addressing them before attackers can exploit them. When incidents do occur, our AI-driven automated response systems dramatically compress reaction times from hours to minutes, neutralizing threats with minimal human intervention. This transformative approach allows organizations to maintain operational continuity even when facing sophisticated, multi-vector attacks. Customized threat modelling hunt for GEO/sector-specific attack vectors with relevant Threat Intelligence. Q3. How does Finesse address the security challenges of generative AI while helping clients leverage its benefits? Finesse recognizes the dual potential of generative AI—its transformative power and inherent risks. Finesse offers a comprehensive Gen AI

The system maintains comprehensive audit trails of all AI interactions & “Gen AI brokerage”, providing the transparency and accountability essential for both security and compliance purposes. Additionally, our specialized AI security assessment services evaluate data handling practices, model security, and AI-specific attack vectors to identify vulnerabilities before they can be exploited. By addressing these security challenges proactively, Finesse enables organizations to safely harness generative AI's power while protecting their most sensitive information from emerging AI-specific threats. Q4. How does Finesse ensure comprehensive security in cloud environments? Finesse delivers multi-layered cloud protection through an integrated suite of technologies. Our Cloud Access Security Broker (CASB) provides visibility and control over cloud applications, while Cloud Security Posture Management (CSPM) continuously evaluates configurations against security best practices. For advanced protection, our Cloud Native Application Protection Platform (CNAPP) secures the entire application lifecycle from development through deployment. These solutions work in concert to automate vulnerability responses, enforce security policies, and ensure compliance across hybrid and multi-cloud environments. The system leverages AI to prioritize alerts based on risk impact, eliminating alert fatigue and ensuring security teams focus on genuinely critical issues. Additionally, our secure access solutions enable protected remote

SEP 2026


33

INTERVIEW

|

FINESSE

work without compromising security integrity. Q5. What are the most common pain points or challenges your customers face in implementing and maintaining effective cybersecurity measures? Today's organizations contend with a perfect storm of cybersecurity challenges. The dramatic shortage of qualified security professionals creates expertise gaps that leave many organizations vulnerable, particularly as attack volumes have surged by over 50% since covid. Security teams face overwhelming alert volumes, leading to critical alert fatigue where genuine threats are missed among thousands of daily notifications. This challenge is compounded by integration issues between disparate security solutions that create dangerous visibility gaps. Regulatory compliance adds another layer of complexity as frameworks like GDPR, HIPAA, and industry-specific requirements continuously evolve. Perhaps most challenging is achieving the delicate balance between robust security and business agility—implementing protection without creating productivity barriers. Emerging technologies, particularly AI and generative systems, introduce entirely new risk categories that traditional security approaches aren't designed to address, requiring innovative protection strategies. Q6. What strategic approaches should organizations adopt to strengthen their security posture? Organizations seeking to enhance their security posture should implement a multi-layered strategy that begins with AI-powered threat detection and response capabilities. These systems analyze vast data volumes in real-time, identifying suspicious patterns and predicting potential threats before they materialize into breaches. Zero Trust principles should be implemented across the enterprises, incorporating microsegmentation, privileged access management, and adaptive authentication to minimize the attack surface and prevent lateral movement by attackers who breach perimeter defenses. Comprehensive data governance frameworks are essential for managing risks and ensuring compliance with evolving regulatory requirements. Regular security assessments, including vulnerability

SEP 2026

scanning and penetration testing, help identify and address weaknesses before they can be exploited. Employee education remains critical, with regular security awareness training creating a human firewall against social engineering and phishing attacks. By combining these approaches with proactive threat hunting and continuous monitoring, organizations can develop a security posture that is both robust and adaptable to emerging threats. Q7. Can you brief your AI-based solutions and services “under Cyberhub”. Finesse's Cyberhub offers a suite of AI-powered cybersecurity solutions designed for modern threat landscapes. Our comprehensive suite integrates cutting-edge artificial intelligence to provide unparalleled protection for enterprises facing increasingly sophisticated cyber threats. Core AI-Driven Operations • Cognitive Security Operations Center (CSOC): Our 24/7 operations centers in Dubai and Bangalore leverage advanced AI analytics and machine learning algorithms to continuously monitor your entire digital ecosystem—from endpoints to networks and cloud environments. This AI-driven approach enables real-time anomaly detection, identification of unusual activity patterns, and proactive threat neutralization before damage occurs. • Automated Incident Response: Our AI systems transform traditional incident response by automating critical security workflows. This dramatically reduces response times from hours to mere minutes, minimizing human intervention and ensuring business continuity even during active threats. The system continuously learns from each incident, improving future response capabilities. Specialized AI Security • Generative AI Security: As organizations adopt generative AI technologies, Finesse provides a comprehensive Gen AI Governance Framework ensuring responsible implementation and compliance. Our

innovative Gen AI Broker/LLM Gateway serves as a secure intermediary between users and AI systems, delivering advanced content filtering, protection against prompt injection attacks, and automatic data sanitization. • AI-Enhanced Zero Trust: We've elevated traditional Zero Trust architecture with AI capabilities, implementing dynamic micro segmentation algorithms and sophisticated behavioral analytics for Privileged Identity & Access Management (PIM/PAM). Our AI systems contextually enhance multi-factor authentication, continuously adapting security protocols based on user behavior patterns and risk assessments. Cloud, Identity & Data Protection • AI-Enhanced Cloud Security: Our multi-layered protection approach integrates CASB, CSPM, and CNAPP solutions powered by AI and machine learning to monitor cloud usage patterns, automatically identify misconfigurations, orchestrate vulnerability responses, and maintain continuous compliance with regulatory requirements. • AI-Powered Digital Identity & Brand Protection: Our AI systems vigilantly patrol the entire internet landscape—including dark web and deep web environments—to detect unauthorized brand usage, corporate impersonation attempts, and compromised credential exposures before they can be exploited. • AI-Driven Data Protection & Privacy: We offer sophisticated AI-powered Data Vault and Data Masking solutions to protect sensitive information. Our context-aware AI-based Data Leakage Protection (DLP) system analyzes data usage patterns to prevent exfiltration attempts and unauthorized access. Assessment Services • AI/Cyber Security Assessment: Finesse provides comprehensive evaluations of your organization's AI roadmap / implementation and cybersecurity posture, identifying vulnerabilities specific to AI systems and delivering strategic recommendations tailored to your unique security requirements.

Finesse has envisioned cybersecurity with an AIfirst philosophy that goes beyond supplementary applications to make artificial intelligence the foundational element of our security operations. www.techpulsemea.com


INTERVIEW

|

ALCON – CYBER SECURITY

34

For me, the biggest concern is the gap between AI adoption and security maturity. Q3. Small and mid-sized businesses often think cybersecurity is only for large enterprises. What would you say to change their mind? I would tell them that cybersecurity is not about the size of your company; it’s about the value of what you are protecting. In fact, smaller businesses can be more attractive targets because attackers often expect weaker security. A single ransomware attack, data breach or business disruption can have a much bigger impact on an SME. The good news is that they don't need an enteprisesized security budget. They need the right security controls, prioritised around their actual risks. Q4. Alcon covers a lot of ground GRC, VAPT, SIEM, SOC, cloud security, data privacy. For a business just starting to think about cybersecurity, where should they actually begin? When a new client comes on board, how does Service Framework actually help them settle in faster and know exactly what to expect from Alcon?

Navinchandar Naidu CEO, Alcon – Cyber Security

Q1. You've worked at du, Jio, and TATA Communications before starting Alcon what made you leave that stability to start your own company, and is there a lesson from those big-company days that still shapes how you run things now? Honestly, I had a very good journey working with companies like du, Jio and TATA Communications, and I learned a lot from each of them. The stability was definitely there, but after spending many years in the industry, I reached a point where I wanted to move from simply being part of an organization to actually building one. What motivated me to start Alcon was the opportunity to take my experience, relationships and understanding of the cybersecurity and telecom industry and create something where I could make decisions quickly, build the right team and directly see the impact of our work. Starting a company is obviously very different from working in a large organization. In a big company, you have established processes, resources and a strong brand behind you. As an entrepreneur, you have to build all of that yourself from customers and people to credibility and processes. One of the biggest lessons I carried from my corporate years is the importance of discipline and execution. Large organizations taught me that good ideas are not enough; you need processes, accountability, customer focus and consistent execution to deliver results. At Alcon, I try to combine that corporate discipline with the agility of a smaller organization. We can move faster, make

www.techpulsemea.com

I would say, don't start by buying security tools. Start by understanding your risk. decisions closer to the customer and adapt quickly, but without compromising on professionalism and quality. So, I don't really see it as leaving stability. I see it as moving from building businesses for other organizations to taking the risk and responsibility of building something of my own. Q2. Cyber threats change so fast. How do you personally keep up, and what's one recent trend that's genuinely worrying you? I try to stay current through industry discussions, threat intelligence, security research, and regular conversations with CISOs and technology leaders. The trend that genuinely concerns me is AI-powered cyberattacks. Attackers can now automate reconnaissance, social engineering and phishing at a much larger scale, while many organisations are adopting AI faster than they are securing it.

First, identify what is critical to your business, where the vulnerabilities are, and what regulatory requirements apply. From there, build the right foundation, typically GRC, vulnerability assessment and basic security monitoring and then mature into areas like SOC, SIEM, cloud security and data privacy as the business grows. The key is to prioritise security based on risk, not technology. Q5. Your mission talks about "innovative solutions" for each client. In a world full of standard security tools, what makes your approach actually different? I don't believe innovation means creating another security tool. It means solving the client's actual problem in the most effective way. Most security tools are available to everyone. What makes Alcon different is how we combine the right technologies, people and processes around the client's specific risk, business and regulatory environment. We don't start with, “What tool should we sell?” We start with, “What problem are we trying to solve?” That customer-first approach allows us to build solutions that are practical, scalable and actually deliver business value.

cybersecurity is not about the size of your company; it’s about the value of what you are protecting. In fact, smaller businesses can be more attractive targets because attackers often expect weaker security. A single ransomware attack, data breach or business disruption can have a much bigger impact on an SME. SEP 2026


35

INTERVIEW

|

VISIONTECH

respond decisively and continue operating when the unexpected happens. Even after more than two decades in technology, that responsibility remains a strong motivation. If the work we do can prevent a security incident from becoming a business crisis, then we are creating tangible value, and that continues to drive me. Q3. What are the biggest cybersecurity worries you hear from businesses, do you think local businesses take cybersecurity seriously enough, or is it still seen as "extra cost" rather than a must-have?

Aliasgar Dohadwala

CEO & Founder, Visiontech Systems International LLC Q1. VisionTech has been around since 2003, what first made you decide cybersecurity needed to become a core part of the business rather than just an add-on, and how has that side of things changed since then?

alongside detection and response, compliance, backup and disaster recovery. The objective is not simply to prevent an attack, but to ensure the organization can detect, respond, recover and continue operating when an incident occurs.

When we founded Visiontech in 2003, the priority for most organizations was building reliable IT infrastructure and connectivity. As businesses became increasingly digital, however, it became clear that technology could not be separated from the risks that came with it.

Perhaps the biggest shift is at the leadership level. Cybersecurity is no longer purely an IT responsibility; it is a business risk, continuity and resilience priority. That is the perspective we bring to every customer engagement at Visiontech.

That realization shaped our approach early on. Cybersecurity could not be an additional layer applied after the infrastructure was built; it had to be embedded into the technology foundation itself. What has changed significantly since then is the scale and complexity of the risk. Data has moved beyond the traditional perimeter, cloud and hybrid environments have expanded the attack surface, and threats have become more sophisticated and persistent. As a result, our role has evolved from deploying individual security solutions to helping organizations build comprehensive cyber resilience. Today, we look at security across the entire environment—identity, endpoints, networks, cloud and data,

SEP 2026

Q2. Cybersecurity can feel like a never-ending race against attackers what keeps you motivated to stay in this fight, even after all these years What continues to motivate me is the responsibility that comes with cybersecurity. At its core, we are protecting businesses, their people, their operations and the trust they have built over many years. The threat landscape will continue to evolve, just as technology will. For me, that constant change is what makes cybersecurity both challenging and meaningful. It requires us to continuously anticipate risk, strengthen our capabilities and help customers stay prepared for what comes next. I do not see cybersecurity as a race with a finish line. The objective is to build organizations that are resilient enough to withstand disruption,

The concerns we hear most frequently are ransomware, data loss, phishing, identity compromise and, increasingly, AI-enabled threats. But beyond the threat itself, there is a more fundamental concern: if an incident occurs, how quickly can the business detect it, contain it, recover and continue operating? Across the region, the mindset has changed considerably. Cybersecurity is increasingly a board and leadership priority, rather than solely an IT responsibility. At the same time, there are still businesses, particularly growing businesses, that tend to evaluate security primarily through the lens of cost, often until an i ncident exposes the true financial and operational impact of being underprepared. I believe cybersecurity should be viewed as a fundamental cost of operating in a digital economy. Organizations invest in protecting physical assets, maintaining business continuity and managing financial risk; digital assets, data and reputation require the same level of attention. Ultimately, the conversation needs to shift from “What will cybersecurity cost us?” to “What is the potential cost to the business if we are not prepared?” That shift in perspective is critical because the impact of a cyber incident today extends well beyond IT. It can affect operations, revenue, regulatory exposure, customer confidence and reputation. Q4. How do you find a new client's biggest weak spots, and make sure the security solution actually fits their business instead of being one-size-fits-all? We always start by understanding the business before recommending the technology. No two organizations have the same risk profile; it is shaped by their industry, operating model,

www.techpulsemea.com


INTERVIEW

infrastructure, data, regulatory obligations and how their people access and use technology. Our first step is to assess the existing environment across areas such as identity, endpoints, networks, cloud, applications, data protection and recovery readiness. But identifying vulnerabilities is only part of the exercise. More importantly, we determine which gaps represent the greatest potential impact to the business. From there, it becomes a matter of prioritization. Cybersecurity is not about deploying every available solution or adding more tools to the environment. It is about addressing the most significant risks first, strengthening existing investments where possible, and building a security roadmap that can evolve as the organization grows and its risk profile changes. At Visiontech, our approach is simple: effective cybersecurity is not measured by how much technology you deploy, but by how effectively you reduce business risk. The right technology, applied to the right risks, is what ultimately creates resilience. Q5. With so many businesses moving to the cloud, has that made things easier or harder to secure? Cloud has made businesses more agile and scalable, but it has also changed the security model significantly. I would not necessarily say it has made security harder; rather, it has made security more distributed and responsibility more shared. Cloud platforms provide highly sophisticated security capabilities, but moving workloads and data to the cloud does not automatically make an organization secure. Businesses remain responsible for how they manage identities, access, configurations, applications and data, and many security incidents are ultimately linked to gaps in these areas. The other major shift is the disappearance of the traditional security perimeter. Employees, applications and data now operate across multiple devices, locations and environments. In many ways, identity and data have become the new perimeter, which makes strong access controls, continuous visibility and effective data protection increasingly important. The answer is not to slow cloud adoption, but to ensure security is built into the cloud strategy from the

www.techpulsemea.com

outset. When security and cloud transformation move together, organizations can gain the speed and flexibility of cloud while maintaining the control, visibility and resilience the business requires. Q6. Is there a project or client story that really shows what makes VisionTech's approach to security different from other providers in the region? There have been several, but the engagements that stand out are often those where a customer comes to us asking for a specific security solution, and our assessment reveals that their most significant risk actually lies elsewhere. In one such engagement, rather than immediately recommending the product requested, our team assessed the customer’s broader security posture. We identified gaps across multiple layers of the environment, prioritized them according to business impact, and developed a roadmap that addressed the immediate risks while creating a longer-term path to stronger resilience. That reflects an important part of our philosophy at Visiontech: we do not start with the product; we start with the risk. Our objective is not simply to deploy more technology, but to solve the underlying security challenge. In some cases, that means introducing new capabilities. In others, it means strengthening, integrating or optimizing investments the customer already has. Equally important, our responsibility does not end with implementation. Through managed security services, continuous monitoring, periodic assessments and ongoing advisory, we remain engaged as the customer’s business, technology environment and threat landscape evolve. For me, that combination of consulting expertise, technology capability and

|

VISIONTECH

36

long-term accountability is what differentiates our approach. We are not simply implementing security solutions; we are helping customers build and sustain cyber resilience. Q7. What's one thing VisionTech is working on right now that you're excited about? One area I am particularly excited about is how we are evolving our cybersecurity capabilities beyond protection towards complete cyber resilience. The reality is that no organization can assume every threat will be prevented. The real measure of resilience is how well a business can anticipate risk, detect and contain threats, protect critical data, recover quickly and continue operating with minimal disruption. We are bringing these capabilities together through managed security, MDR and XDR, AI-driven threat detection, continuous assessments, data protection and disaster recovery. At the same time, technology alone cannot create resilience. People remain a critical part of the security equation, particularly as phishing, social engineering and AI-enabled attacks become more sophisticated. That is why we are also strengthening our security awareness and training capabilities, helping organizations build a security-conscious culture alongside their technology investments. Another exciting dimension is taking these capabilities into emerging and high-growth markets, including Africa, where digital transformation is accelerating and organizations have an opportunity to build security and resilience into their infrastructure from the outset. What excites me most is that we are not simply expanding a portfolio of security solutions. We are building a more integrated approach around technology, people and processes, one that helps our customers not only defend against cyber threats, but remain resilient when disruption occurs.

I believe cybersecurity should be viewed as a fundamental cost of operating in a digital economy. Organizations invest in protecting physical assets, maintaining business continuity and managing financial risk; digital assets, data and reputation require the same level of attention SEP 2026


C O NNE C T & AWAR DS 20 26 Securing Tomorrow. Recognizing Today's Cyber Leaders. 23 R D SEP TEMB ER 2026 | SH ANG R I- LA DUBAI

Celebrating 50 Exceptional Cybersecurity LEADERS An exclusive, invitation-only gathering of Cybersecurity & Technology Leaders from across the Middle East

Key Highlights • • • • • •

Top 50 CISO Recognition Cybersecurity Leadership AI & Cyber Resilience Strategic Industry Networking Executive Panel Discussions Awards & Gala Dinner

RECOGNISING EXCELLENCE IN CYBERSECURITY LEADERSHIP Recognizing outstanding leaders driving digital transformation, strengthening cyber resilience, and protecting organizations from evolving cyber threats.

CISOs

CIOs

CTOs

Security Experts

Government Leaders

Technology Executives

SPONSORS

techpulsemea.com/cisos-50/


MEETING ROOM SOLUTIONS From traditional conferencing rooms to more open spaces, easily video-enable spaces of all shapes and sizes for better hybrid collaboration.

LEARN MORE


Turn static files into dynamic content formats.

Create a flipbook
Magazin September 2026 by techpulsemea.com - Issuu