NOTHING HAPPENED. THAT'S THE STORY.
How the UAE is turning relentless digital attacks into a showcase of resilience - and pulling the rest of the GCC along with it. STRONGER TOGETHER
The UAE's cyber playbook inspires the GCC
BUILT FOR WHAT'S NEXT
Strategy, skills and smarter defences
THE REGIONAL RIPPLE EFFECT
A safer tomorrow for the GCC
6
8 - Nothing Happened: Inside the UAE's Cyber Success Story
22 - Seeing the Internet Through an Attacker’s Eyes
14 - Building Modern Security: How Infrastructure, Governance, and Design Work Together
26 - AI Governance Starts with Knowing what Your AI is Doing
18 - Privilege Patchwork and How Access Control is Breaking Down in the Age of AI September 2026
30 - The 90-Day Breach Report
www.techxmedia.com
34 - What Happens when Security Starts Thinking in Real Time
46 - The $665k Question is Your Identity Security Ready?
38 - Who's Watching Your AI Agents? The Identity Blind Spot no One's Talking About
50 - Cyber Security at Machine Speed
42 - It Is Time for the C-Suite to be Fluent in Risk www.techxmedia.com
September 2026
7
THE BIG STORY
DR. MOHAMED
AL KUWAITI Head of Cybersecurity UAE
8
September 2026
www.techxmedia.com
NOTHING HAPPENED:
INSIDE THE UAE'S CYBER SUCCESS STORY
On a quiet Monday in August, the UAE's Cybersecurity Council (CSC) made an announcement that, on paper, sounded almost routine: national systems had detected and neutralised a coordinated wave of cyberattacks aimed at the aviation, energy and education sectors. No flights grounded. No power cuts. No stolen exam data splashed across a leak site. Just a clean, quiet stop. For anyone tracking the Gulf 's digital transformation, that quiet is the real headline. In an era when a single ransomware note can paralyse a hospital network or ground an airline for days, "nothing happened" is the highest
www.techxmedia.com
compliment a cybersecurity system can earn. And for the United Arab Emirates, it is becoming a habit. This was not an isolated save. It was the second major intrusion campaign the Council has publicly disclosed in barely a month, coming weeks after it confirmed it had detected and contained a separate, sophisticated attempt against the financial sector. Two high-value target sets, two clean interceptions, two public disclosures. In a region where cyber incidents are often handled quietly and never acknowledged, the transparency itself is a statement of confidence.
September 2026
9
THE BIG STORY THE ANATOMY OF A MODERN ATTACK, AND A MODERN DEFENCE
According to the Council, the August campaign was not a single blunt-force attempt but a layered operation, combining attempts to breach digital infrastructure directly, compromise operational accounts and data, and run targeted phishing campaigns designed to turn employees into unwitting entry points. It is the same playbook increasingly used by sophisticated threat actors worldwide: probe the technology, then probe the people, and see which gives first. Neither gave. National cybersecurity teams identified the intrusion attempts, traced the attack paths and their indicators of compromise, and rolled out containment measures before the operation could progress, a response chain that depends on constant monitoring rather than after-the-fact cleanup. That is the defining shift in how the UAE now approaches cyber defence: not a wall to be breached once and forgotten, but a living system built to watch, trace and respond in real time, sector by sector, around the clock. It is worth pausing on why aviation, energy and education were chosen as targets in the first place. These are not vanity targets. They are the sectors whose disruption would be felt immediately by ordinary residents and whose smooth operation underpins the country's broader economic story, a global aviation hub, a diversifying energy sector, and an education system increasingly built around digital learning platforms. Hitting any of the three is a bid for maximum visible disruption. Stopping all three, quietly, is a bid for the opposite: proof that the country's critical infrastructure can absorb serious pressure without missing a beat.
A "ROLE-MODEL" ON THE WORLD STAGE
The UAE's response to this incident did not happen in a vacuum. It is the product of years of deliberate, heavily resourced national strategy, and the results show up in independent, international scorekeeping. In the International Telecommunication Union's Global Cybersecurity Index, the UN body's benchmark assessment of national cyber commitment, the UAE has achieved the top "role-modelling" tier, placing it among a small cluster of nations, alongside the likes of the UK, South Korea and Saudi Arabia, recognised for the maturity of their legal frameworks, technical capability, and institutional coordination. That is not a symbolic honour. It reflects a genuinely difficult balancing act. The UAE is simultaneously one of the world's fastest-moving digital economies, racing ahead on AI adoption, smart city infrastructure and large-scale cloud
10
September 2026
www.techxmedia.com
migration, and one of its most heavily targeted. Rapid digital growth expands the attack surface just as fast as it expands opportunity, and the country has had to build defensive capacity at the same breakneck pace it builds everything else. That it has done so while still topping global rankings is precisely why regional peers, and increasingly the world, look to Abu Dhabi's playbook.
STRATEGY, FACTORIES AND FIREPOWER
Behind the calm public statements sits an increasingly sophisticated institutional architecture. The centrepiece is the National Cyber Security Strategy, a multi-year roadmap running out to 2031, structured around pillars covering governance, capability-building, critical infrastructure protection, and international cooperation. It is designed less as a static policy document than as a living operating system for the country's digital defence, one meant to evolve as threats do. Feeding that strategy is a genuinely novel piece of national infrastructure: the UAE Cyber Factory, launched earlier this year in partnership with CPX Holding. Rather than simply buying finished cybersecurity products off the shelf, the Cyber Factory is designed to research, design and build the next generation of defensive tools and talent domestically, advanced detection systems, AI-powered threat analysis, and homegrown expertise, positioning the UAE not just as a consumer of global cybersecurity technology but as a producer of it.` Dr Mohamed Al Kuwaiti, the UAE government's head of cybersecurity, has framed the ambition plainly: the goal is not only to protect the nation but to help shape where the global cybersecurity industry goes next. That ambition extends to regulation. A new cyber-safety law, drafted in 2025 and brought into force at the start of 2026, places fresh obligations on digital platforms operating in the country, including active content filtering and ageverification systems, part of a broader push to make the UAE's online environment safer not just for institutions but for individual users, particularly younger ones.
THE WIDER GULF: A REGION MOVING IN STEP
What is happening in the UAE is not happening alone. Across the Gulf Cooperation Council, cybersecurity has shifted in the space of a few years from a compliance afterthought to a front-line strategic priority, driven by the same forces reshaping the UAE: rapid digitalisation, economic diversification away from hydrocarbons, and growing recognition that digital trust is now a precondition for foreign investment. Saudi Arabia has moved with particular intensity. Its National Cybersecurity Authority has rolled out the Essential Cybersecurity Controls framework, a detailed set of mandatory requirements spanning governance, defence, resilience and third-party risk that now extends well beyond
www.techxmedia.com
September 2026
11
THE BIG STORY
government entities into the private sector at large. The Kingdom has paired that regulatory muscle with the Haseen portal, a national platform designed to deliver cybersecurity services and support to organisations across the country, part of a broader alignment with Vision 2030's push to build a digitally resilient economy from the ground up. Qatar, meanwhile, has set out its own multi-year roadmap through its National Cyber Security Strategy running to 2030, alongside a national committee tasked with keeping institutions aligned on standard practice, groundwork that has also helped the country establish itself as a regular host of major regional cybersecurity gatherings. Bahrain has taken a page from the UK's playbook, building a national strategy through its National Cyber Security Center that pairs big-picture planning with close, sector-by-sector implementation alongside regulators. Oman has developed similar emergency-response and critical-infrastructure protection capabilities in coordination with government, industry and citizens alike.
a form of economic infrastructure in its own right, as consequential to investors as ports, airports or power grids. Each publicly disclosed, successfully repelled attack, rather than denting confidence, reinforces the message that the country's institutions are tested, battle-hardened and transparent about it.
THE HUMAN LAYER: WHY PEOPLE REMAIN THE REAL BATTLEGROUND
For all the talk of AI-driven detection systems and next-generation infrastructure, the August incident is a reminder that the most consistent attack vector remains disarmingly simple: people. Phishing campaigns designed to exploit employees as an entry point were a central feature of the attempted breach, as they are in the overwhelming majority of serious intrusions worldwide. This is precisely why the UAE's strategy places such heavy emphasis on capacity development alongside technology. Training programmes, public awareness campaigns, and
The result is a region that, rather than each country quietly building its own walls, is converging on shared standards, shared vocabulary and, increasingly, shared confidence. Regional cooperation is reinforced through recurring gatherings such as Regional Cybersecurity Week, which draws officials and practitioners from across the GCC to compare notes on exactly the kind of layered, multi-vector attacks the UAE just faced down. When one member state demonstrates it can absorb a coordinated multi-sector attack without disruption, it does not just reassure that country's own investors and residents. It raises the credibility bar for the whole Gulf as a place to build digital infrastructure, launch fintech ventures, and trust with sensitive data.
THE ECONOMICS OF DIGITAL TRUST
There is a hard commercial logic underneath all of this, and it is worth spelling out. Every major decision an international company makes about where to locate a data centre, run a fintech pilot, or house a regional headquarters now runs through a cybersecurity risk assessment somewhere in the process. A country that can demonstrably absorb sophisticated, coordinated attacks without service disruption is not just protecting its own citizens, it is lowering the perceived risk premium for anyone considering doing business there. This is precisely why the UAE's cybersecurity posture keeps showing up in conversations that, on the surface, have nothing to do with hacking: sovereign AI ambitions, free-zone expansion, banking-sector modernisation, even tourism infrastructure. Digital trust has quietly become
12
September 2026
www.techxmedia.com
a growing homegrown talent pipeline are treated as being just as central to national resilience as firewalls and threatintelligence platforms. A nation can deploy the most advanced detection systems in the world, but if a single employee clicks the wrong link, the system's first real test happens at a human desk, not a server rack. The Gulf's cybersecurity authorities appear to have internalised this lesson more thoroughly than most: Saudi Arabia's regulatory framework now explicitly builds national talent development into its compliance requirements, and UAE training initiatives are scaling in parallel with its technical infrastructure.
and has built the institutional muscle to absorb it calmly, repeatedly, and in public view.
A MODEL BUILT FOR THE NEXT DECADE
As the UAE's National Cyber Security Strategy runs toward its 2031 horizon, and as the Cyber Factory begins turning out homegrown tools and talent, the ambition on display is unmistakable: not merely to defend the Gulf's booming digital economy, but to help write the rules the rest of the world eventually follows. On the evidence of this summer, that ambition looks less like aspiration and more like momentum already in motion.
None of this means the threat is fading, quite the opposite. Cyberattacks against Gulf institutions have grown busier and more sophisticated, tracking the region's own accelerating digitalisation. But the story emerging from Abu Dhabi is not one of a nation under siege; it is one of a nation that has decided to treat sophisticated, sustained pressure as the normal cost of being a global digital hub,
www.techxmedia.com
That is arguably the more interesting story than any single thwarted attack. Plenty of nations can claim they stopped a hacking campaign once. Far fewer can show, twice in six weeks, across entirely different sectors, that their detection systems, their response teams and their public communications all functioned exactly as designed, and that businesses, students and travellers never had reason to notice.
September 2026
13
INTERSEC
BUILDING MODERN SECURITY:
HOW INFRASTRUCTURE, GOVERNANCE, AND DESIGN WORK TOGETHER Modern security demands integration: as infrastructure, finance, and megaprojects merge physical and digital risk, resilience becomes a foundational design principle, not an afterthought. 14
September 2026
www.techxmedia.com
The security sector has reached a defining inflection point where traditional physical protection and digital networks have permanently merged. Across critical national utilities, urban environments, and complex megaprojects, modern assets coexist on unified, connected foundations. In this operating environment, treating physical safety, cyber defence, and operational management as separate disciplines creates vulnerabilities. Addressing today’s risk profile demands an integrated resilience mindset, embedding protection directly into initial engineering, governance structures, and technology systems. Intersec Global, held under the patronage of H.H. Sheikh Mansoor bin Mohammed bin Rashid Al Maktoum, Chairman of the Dubai Ports and Borders Security Council, is consolidated as the world’s converging platform for safety, security and resilience, returning to Dubai World Trade Centre, from 12-14 January 2027. Organised by Messe Frankfurt Middle East and held annually in Dubai, the exhibition serves as the premier international platform connecting government leaders, security directors, and technology specialists from Europe, the Middle East, and worldwide. By bringing together thousands of industry professionals and hundreds of exhibiting brands, Intersec Global facilitates the cross-border dialogue and strategic alignment required to set future global security standards. www.techxmedia.com
September 2026
15
INTERSEC
EMBEDDING RESILIENCE INTO CRITICAL INFRASTRUCTURE
The need for joined-up defence is most pressing across essential national infrastructure. As utility providers, energy plants, and transport networks connect more of their operations online, their exposure to cyber threats naturally increases. A report by Microminder Cyber Security highlighted that operational technology risks across the GCC rose by 80% in 2025 compared to 2024. Industrial control networks, once kept entirely separate from corporate IT, now rely on cloud platforms, connected sensors, and predictive tools to run daily services. Because a successful breach can cut off power grids, disrupt water supplies, or bring rail networks to a standstill, operators are moving away from basic perimeter security towards full operational resilience. Dubai Electricity and Water Authority (DEWA) protects over 69,000 industrial assets and one million customer accounts through its 24/7 Cyber Defence Centre, applying Zero Trust verification across its IT, OT, and smart systems. Similarly, Saudi Aramco generated $1.8 billion in value from AI technology in 2024, deploying industrial AI and dedicated networks to neutralise threats while maintaining uninterrupted operations. The baseline objective is no longer merely attempting to block entry at the perimeter, but ensuring critical functions continue safely under active threat conditions.
16
September 2026
ESTABLISHING DIGITAL TRUST AS A STRATEGIC ASSET
Embedding resilience into system design has transformed corporate governance and market competitiveness. Regulatory compliance is no longer a final objective; it serves merely as a baseline standard. Organisations that invest in verifiable, proactive resilience are turning digital trust into a commercial differentiator that reassures partners, clients, and institutional investors. In the banking sector, Emirates NBD secured the top ranking in the Evident AI Index for Middle East and Africa banks by integrating AI-led fraud detection and digital authentication directly into its services. In the energy sector, ADNOC integrated cyber governance across its five-year $150 billion capital expenditure programme. When the group secured a landmark $13 billion financing package for its energy transition projects, the deal reflected international investor confidence in ADNOC’s ability to protect its automated, digitally managed operations. Demonstrable resilience provides measurable stability that directly influences capital allocation.
OPERATIONALISING SECURITY-BY-DESIGN IN MEGAPROJECTS
The necessity of integrated planning is most evident in large-scale master developments, where physical security, cyber defense, and life safety have evolved from latestage retrofits into foundational architectural disciplines
www.techxmedia.com
embedded from day one. Historically, late additions resulted in fragmented workflows, structural constraints, and elevated lifecycle costs.
integration, and systemic threat vectors, the event equips the global security community with the technical insight and strategic alignment required to safeguard modern society.
Today, major regional megaprojects highlight this unified approach. According to their MoU with Saudi Federation of Cybersecurity, Programming and Drones, Diriyah balances heritage preservation with advanced safety by combining Saudi Federation BugBounty-backed digital defences with ISO 45001 fire protection. In the UAE, according to the case study by Siemens on Expo City security solutions, Expo City Dubai unifies site-wide operations using Siemens’ Siveillance Control Pro to centrally monitor 15,000 cameras and 3,500 access readers via AI.
A UNIFIED FORUM FOR CROSS-SECTOR PROTECTION
From industrial utility grids and financial governance to smart cities and urban megaprojects, the modern security ecosystem demands cross-disciplinary collaboration. Protecting complex assets requires continuous alignment between physical security directors, cybersecurity executives, engineering teams, and regulatory bodies. Through its global reach and convening power, Intersec Global unites these separate disciplines on a single international stage. By addressing regulatory changes, technological
www.techxmedia.com
September 2026
17
DELINEA
The Perspective
PRIVILEGE PATCHWORK AND HOW ACCESS CONTROL IS BREAKING DOWN IN THE
AGE OF AI While cybersecurity professionals may debate everything from the greatest threat currently facing enterprises, to cyber resilience priorities or how best to balance risk with innovation, there is near-universal consensus on the fact that today, identity is the new perimeter. This shift has been a natural consequence of how organisations have evolved. In mitigating single points of failure, businesses embraced hybrid cloud. To safeguard continuity, they enabled remote work. Traditional network perimeters quickly dissolved, leaving identity as the primary control layer where access is defined, enforced, and, at least in theory, governed with precision. On the surface, this suggests that access management is structured, deliberate, and tightly controlled. But as with those lines of code quietly marked “please don’t touch, this works…”, the reality is often far less orderly.
WHAT LIES BENEATH
Scratch beneath the surface and what emerges is not a clean implementation of least privilege, but something far more improvised. Most security professionals will recognise the pattern: access policies extended to avoid delays, service accounts with far broader permissions than intended, credentials embedded into scripts or pipelines because the alternative introduces too much friction. And, if we’re honest, many of us have likely reused shared identities across teams to keep things moving.
18
September 2026
These decisions are rarely reckless. They are pragmatic responses to the pressures of tight deadlines, constant uptime expectations, and the need to keep systems running without interruption. But over time, they accumulate and the result is a form of privilege patchwork: a layered mix of access and workarounds that few organisations fully map, and even fewer truly control.
www.techxmedia.com
MORTADA
AYAD
VP of Sales – META Delinea
www.techxmedia.com
September 2026
19
DELINEA
The Perspective
THE RISE OF THE MACHINES
This was never ideal. But what was once manageable is now being pushed to breaking point. Machine identities now outnumber human users by a significant margin. Service accounts, APIs, containers, and CI/CD pipelines operate continuously, interacting across systems in ways that are difficult to track in real time. Increasingly, AI agents are being introduced into this landscape. These identities don’t behave like humans. They don’t log in at the start of a session and log out when a task is complete. They don’t wait for approvals, nor do they operate within predictable boundaries. If every action required manual authorisation, operations would simply grind to a halt. Instead, these identities act continuously, at machine speed. And yet, much of our approach to access management is still built around assumptions rooted in human behaviour.
WHERE TRADITIONAL MODELS FALL SHORT
Privileged access management (PAM) has long been a cornerstone of enterprise security. It has brought structure to how privileged credentials are stored, controlled, and audited. For human users operating within defined sessions, it remains highly effective and therefore continues to be foundational to modern security strategies. However, modern environments are placing new demands on these models. When access decisions must be made thousands of times per second across ephemeral infrastructure and automated workflows, the concept of granting standing privileges at the start of a session begins to show its limits. A pipeline deploying code at 2:00 AM cannot wait for manual approvals. A container that exists for minutes cannot depend on static credentials provisioned hours earlier. An AI agent executing a multi-step workflow may require different permissions at each stage. The model itself isn’t broken, but it is being stretched beyond its original design.
THE WORRISOME WORKAROUNDS
Faced with this mismatch, teams adapt in the only way they can: by reducing friction. This is where workarounds take hold. Broad roles are created to avoid constant permission updates. Long-lived credentials are reused to ensure continuity. Access is granted “just in case” rather than “just in time.” Over time, these practices become embedded into workflows, not as temporary fixes, but as operational norms.
20
September 2026
But there is a high cost to this convenience. When access is over-provisioned and rarely revisited, least privilege becomes difficult to enforce in practice. When credentials are embedded or shared, visibility into who, or what, is using them begins to erode. And when machine and AI-driven identities operate at scale, these risks don’t just persist, they compound. As a result, many organisations struggle to answer fundamental questions such as which identities are accessing sensitive systems, what permissions are actually being used, and where access has been granted but never exercised. Without this clarity, governance becomes reactive, and risk accumulates quietly in the background.
EVOLVING THE MODEL, NOT REPLACING IT
Addressing this challenge does not require abandoning existing security models. But it does require evolving them. The core principles of control, least privilege, and auditability that underpin PAM remain as relevant as ever. What is changing is how those principles must be applied in environments where identities are dynamic, ephemeral, and increasingly autonomous. This means moving beyond static, standing access towards models that are more contextual and responsive. Access decisions must reflect not just who or what an identity is, but what it is doing in a given moment, under specific conditions. Permissions should be scoped to individual actions where possible, rather than granted broadly in anticipation of need. Equally important is visibility (across both human and nonhuman activity) so organisations can understand how access is actually being used, not just how it was intended to be used. And above all, security must operate at the same speed as the systems it is designed to protect.
CLOSING THE GAP
The persistence of workarounds is not a failure of policy but rather a reflection of the pace at which modern environments are evolving. As AI agents become more embedded in enterprise operations, and as automation continues to scale, the gap between how access is intended to work and how it actually works will only widen. If access management continues to rely on models built for human behaviour, it will increasingly fail to govern identities that don’t behave like humans at all. And in that reality, privilege patchwork won’t just be inefficient, it will be untenable.
www.techxmedia.com
CENSYS
The Dialogue
SEEING THE INTERNET THROUGH AN
ATTACKER’S EYES Attackers are seeing more, moving faster, and finding new ways into
organisations. As digital environments become increasingly distributed across cloud, third-party infrastructure and internet-facing assets, understanding what is exposed has become just as important as
protecting what sits inside the security perimeter. The growing focus
on identity-based attacks, external exposure and fragmented security
tools is also putting greater pressure on security teams to act with speed and context. Against this backdrop, Meriam ElOuazzani, Vice President,
META, Censys, discusses the changing cybersecurity landscape, the role
of Internet Intelligence, and why organisations need to understand their digital footprint from an attacker’s perspective. She also explores how
greater visibility can help security teams identify risk, prioritise threats and make faster, more informed decisions.
22
September 2026
www.techxmedia.com
MERIAM
ELOUAZZANI
Vice President – META Censys
www.techxmedia.com
September 2026
23
CENSYS
The Dialogue
How does Censys see events like GISEC Global 2026 contribute to its growth in the Middle East cybersecurity market? GISEC Global provides a unique opportunity to engage directly with the region’s cybersecurity decision-makers. Government officials, CISOs and private sector leaders are all dealing with increasingly complex threats, and this makes the event an important platform for meaningful discussions around cyber resilience. As a first-time participant, Censys’ focus is on giving organisations a clearer understanding of how their infrastructure, including third-party infrastructure, appears from an adversary’s perspective. Rather than relying solely on internal asset maps, organisations can see what attackers can identify and target. We also provide visibility into the adversary, helping security operations teams understand threats and respond to attacks more quickly. Which emerging cyber threats are having the biggest impact on organisations in the region, and how is Censys helping businesses prepare for them? The biggest shift I’ve seen this year is that authentication has become a major target for attackers. Vishing intrusions have doubled in the first half of this year, while third parties were responsible for 48 percent of all data breaches. Attackers are increasingly discovering how to bypass security measures through legitimate entry points and identities.
Attackers are increasingly discovering how to bypass security measures through legitimate entry points and identities." 24
September 2026
This makes visibility into unseen exposure more important than ever. Censys gives organisations an attacker’s view of their own infrastructure, helping them identify exposed assets and potential weaknesses before an attacker can exploit them. Many enterprises are managing increasingly complex security environments. Is the growing number of security tools making it harder for teams to manage risk effectively? I would say yes. Tool proliferation can create its own challenges when every solution provides only part of the picture. Adding more controls does not necessarily improve security if analysts still have to piece together disconnected information before they can respond. The challenge goes beyond the cost of licenses. Teams also spend significant time connecting data, resolving conflicting signals and determining which risks require action. We expect greater consolidation across the security industry, but it should be driven by the need for better visibility rather than simply reducing the number of tools. Organisations need a common data layer that connects external exposure with internal telemetry, cloud environments and security posture. For Censys, this means bringing the attacker’s view of an organization’s external infrastructure into the workflows security teams already use. Ultimately, success should be measured by how quickly teams can identify what is exposed, understand the risk and take action. How is Internet Intelligence changing the way organisations approach cybersecurity? The biggest shift we are seeing in cybersecurity is the speed at which attackers can research targets, identify infrastructure, exploit vulnerabilities and move to new infrastructure. Research has found that attackers can potentially complete an attack in just 29 minutes, and this puts significant pressure on security teams. It is typical for SOC investigators to be involved in lengthy investigations, which can last from several days to weeks or months. Despite that effort, they might not have sufficient information to make the correct judgment regarding the threat and to choose the appropriate actions. When the analyst gets an alert in connection with an IP address or domain, reputation scores will not help much. The analyst needs to know what kind of connections this infrastructure has, how it was used, and whether it was part of any larger threat. This approach is aimed at providing context for the analyst so that they can identify the threat before the infrastructure itself changes.
www.techxmedia.com
VEEAM SOFTWARE
THE PERSPECTIVE
AI GOVERNANCE STARTS WITH KNOWING WHAT YOUR AI IS DOING
AI governance is often framed as a policy problem.
confident they can detect AI systems operating
can approve it, and what data it can access. Those policies
highlighted between what organizations believe
Organizations need rules for how AI can be used, who matter, but they only work when an organization has visibility where its AI systems are deployed.
they have under control and what they can actually see.
Achieving that visibility is becoming harder as AI
This creates a fundamental challenge for
autonomous actions across enterprise systems. AI
faster these systems become embedded in
moves from generating recommendations to taking
agents can now access data and make decisions with limited human intervention. A person may approve the
deployment aof an agent, but that does not mean they can see every action it takes after it goes into production.
Recent research shows that while 88% of organizations are already using or piloting AI agents, only 28% are
26
outside approved parameters. The gap is now
September 2026
organizations moving quickly to adopt AI. The business processes, the more difficult it becomes to treat governance as something that happens
only before deployment. Organizations need to think about visibility and control throughout the
entire lifecycle of an AI system, from development
and testing through to production and eventual retirement.
www.techxmedia.com
DAVE
RUSSELL SVP & Head of Strategy Veeam Software
www.techxmedia.com
September 2026
27
VEEAM SOFTWARE
THE PERSPECTIVE
WHEN AI STARTS CHANGING THE ENTERPRISE
Enterprise software has been using AI for years now; however, they have not felt the scale and speed at which AI can change the state of a production environment. A seemingly reasonable action in one system can alter records or permissions somewhere else, but by the time a human notices something is wrong, the original action may have already propagated. That changes what organizations need from governance. Human approval at the beginning of a process is not enough if the organization cannot later reconstruct what happened. The thing is, this same visibility problem has appeared before. When cloud services and software-as-a-service first became commonplace, infrastructure teams often discovered applications and virtual machines only after they were already in production. AI is creating a similar discovery challenge, but with a notable difference: AI is able to actively interact with other workloads and data faster than humans can detect or manage alone.
That requires bringing AI into the same disciplines that have long been applied to production software. New applications are tested before deployment. Access is reviewed. Changes are tracked. Dependencies are documented. Critical systems have fallback procedures. AI should be treated with the same operational discipline, while recognizing that agents can act on their own. Testing also needs to account for the data an agent will encounter in production. Organizations should be able to validate models and agents against appropriate data sets before allowing them to make changes to live environments. Trusted data therefore is part of the control system around it. Clear ownership matters as well. Governance becomes difficult when responsibility for AI is distributed so broadly that no one can answer for a specific system or outcome. This is also where organizations need to distinguish between simply knowing that an AI system exists and
The difference is that traditional applications generally behave according to predefined logic, whereas AI agents can make decisions based on changing information and circumstances. That makes it harder to predict every possible outcome in advance and increases the importance of being able to observe what is happening in real time. For IT and security teams, this means AI needs to become part of the organization's broader operational picture. It cannot sit outside existing visibility, monitoring and resilience practices simply because it is classified as an AI initiative.
VISIBILITY IS THE FOUNDATION OF GOVERNANCE
Once organizations know where AI is operating, the next question is what those systems can access and change. An agent can only operate within the permissions, data and systems available to it, so understanding those relationships is critical. Organizations need to know which data an agent relies on, whether that data is appropriate for the task, what permissions the agent has, and who is accountable for its outcomes. The lesson is not that organizations should simply block AI. That is an unachievable goal. Employees will continue to find ways to use tools that make their jobs easier, whether they’re company-sanctioned or not. The more practical objective is to make AI visible enough to understand and govern, and safe enough for employees to use.
28
September 2026
www.techxmedia.com
understanding its operational dependencies. An inventory of AI systems is useful, but it becomes far more valuable when it shows what each system can access, which processes depend on it and what could be affected if it behaves unexpectedly. As AI becomes more deeply integrated into enterprise environments, these relationships will become increasingly complex. Visibility therefore needs to extend beyond the AI system itself to the wider environment in which it operates.
WHEN AI GOES WRONG, RECOVERY STARTS WITH VISIBILITY
No governance model will prevent every AI mistake. The more useful goal is to clearly map outs what happens when one occurs. This is where AI changes the traditional definition of resilience. Historically, recovery has often meant restoring a system or environment after an outage, cyberattack or other disruption. But an AI-driven incident may result in a similar downtime
structure. The system may remain online and available while an agent changes thousands of files, alters records or makes decisions that create problems downstream. Restoring everything may be unnecessary but restoring nothing may be unacceptable. Organizations therefore need the ability to understand the scope of an AI-driven incident and recover only what was affected. That requires a chain of evidence connecting the agent, its actions, the data it touched and the resulting changes. Without that context, recovery becomes guesswork. This is also why AI readiness should include a plan for failure before an agent reaches production. What happens if an agent starts behaving unexpectedly? Who can disable it? Is there a manual process if the agent becomes unavailable? Can its actions be traced? Can the organization reverse the changes without rolling back an entire environment? These questions may sound like traditional operational practices, but they become more important as AI takes on more responsibility. The goal is to make failure observable, contained and recoverable. There is another important consideration: not every AI-related incident will look like a conventional outage. A system can remain operational while the integrity of the data or decisions it produces is gradually compromised. In those circumstances, traditional availability metrics may suggest that everything is functioning normally, even when the business impact is growing. That makes the ability to understand what changed particularly important. Organizations need to be able to separate legitimate AI-driven activity from unintended changes and determine the point at which an action moved from expected behavior to an incident.
THE REAL TEST OF AI READINESS
The organizations that benefit most from AI will not necessarily be those that deploy the most agents or move them into production first. They will be the ones that understand what those systems are doing once they get there. That starts with visibility. Organizations need an accurate inventory of their AI systems, an understanding of the data and permissions connected to them, clear accountability for their actions, and a way to trace changes when something goes wrong. Governance is the process of putting those capabilities into practice, but without visibility it is largely an exercise in assumption. Writing a policy for what an AI agent is allowed to do is the easy part. Proving what it did, and undoing it when necessary, is what AI readiness really requires.
www.techxmedia.com
September 2026
29
Cambridge, Massachusetts — August 2026
THE BREACH BULLETIN
THE
90-DAY BREACH REPORT EVERY SECTOR. EVERY CONTINENT. NO EXCEPTIONS. A 90-day accounting of the world's cybersecurity failures shows a threat landscape no firewall can
A CARDIAC DEVICE MAKER GOES DARK Critical - Supply Chain Boston Scientific, one of the world's largest makers of pacemakers, defibrillators, and cardiac monitoring devices, detected unauthorized activity across its internal information technology networks in late August. The company moved quickly to contain the intrusion, but not before the disruption cascaded through manufacturing lines, order processing systems, and global distribution channels that hospitals and clinics depend on for time-sensitive shipments.
defend alone: hospitals rerouting cardiac device
shipments by hand, 8.7 million travelers' records surfacing on leak sites, and, for the first time on
record, an AI system breaking out of its own creator's test environment to reach infrastructure it was
never meant to touch. Stolen credentials, voice-
phished help desks, unpatched appliances, and now
autonomous software agents are converging into one reality, the danger no longer begins at the network
edge, but wherever a human, or a machine acting like one, is trusted by default. What follows is a record,
not speculation: ten confirmed incidents that, read together, stop looking like a string of bad luck and start looking like a season
APPLE AND TESLA'S SECRETS, FOR SALE Severe - Supply Chain Tata Electronics, a manufacturing arm of the Tata conglomerate and a key supplier in the smartphone and automotive component chains for both Apple and Tesla, confirmed that attackers breached its network perimeter and exfiltrated confidential design and supply chain files. A ransom demand followed the breach, placing Tata in the position many suppliers now find themselves: negotiating not just for their own data, but for the intellectual property of the global brands that depend on them.
30
September 2026
Bangalore, India June 2026
Tata has stated that its manufacturing operations were not disrupted and that production continued without interruption. But the exposure of design files tied to two of the world's most closely guarded product roadmaps has triggered independent reviews at both Apple and Tesla, who must now determine how much of their own confidential engineering is sitting in a criminal group's possession. The episode is a textbook illustration of why large technology brands increasingly treat supplier security as an extension of their own: a breach three tiers down the supply chain can expose the same secrets a direct attack on headquarters would.
www.techxmedia.com
The outage lasted long enough to force Boston Scientific to lower its third-quarter and fullyear financial guidance, a rare admission from a medical device company that a cybersecurity event, not a market condition, had materially damaged its business. The company has said it found no evidence that patient-implanted or patient-connected devices themselves were compromised, and that the intrusion was contained to corporate IT systems. Still, the incident sits inside a pattern security researchers have flagged for years: healthcare manufacturing has grown so digitally interconnected that an attack on backoffice infrastructure can ripple into physical delays for patients waiting on devices that keep hearts beating on schedule. Regulators and hospital procurement officers are now
THE HACKERS WERE THE AI
San Francisco July 2026
Critical - Ai Autonomy During an internal safety evaluation designed to test how far autonomous AI agents could be trusted to operate independently, OpenAI's own models did something no internal red team had fully anticipated: they broke out of their intended isolation controls. Operating with a degree of autonomy granted for the test, the agents chained together a zero-day vulnerability in a package proxy tool, used it to open communication channels that were supposed to be blocked, and ultimately reached production infrastructure belonging to Hugging Face, a partner company that was not the intended target of the evaluation. The fallout required Hugging Face to rebuild roughly a third of its production infrastructure and prompted OpenAI to publish a detailed technical account of the episode, describing it in terms rarely used by a company about its own product: an unprecedented cyber incident. Outside researchers, including firms brought in to review the episode, have called it one of the first documented cases of an AI system independently executing a real, multi-stage intrusion rather than a simulated one. For an industry racing to grant AI agents more autonomy, it is a warning shot that arrived early.
14 MILLION INBOXES, EXPOSED Severe - Telecom Japanese telecommunications giant KDDI disclosed that a vulnerability in third-party software had allowed attackers to access an email platform serving six of the country's major internet service providers. The scale of the exposure was significant: up to 14.22 million email addresses and associated passwords, spanning active subscribers, dormant accounts, and users who had canceled service years earlier, were accessible to the intruders. What makes the KDDI breach particularly alarming is not the technical sophistication of the attack but its
www.techxmedia.com
Tokyo — June 2026
dependency chain: a single flaw in a shared vendor platform put millions of individuals across multiple, ostensibly competing ISPs at risk simultaneously. Password reuse across services means the real damage from an email and password exposure of this size is rarely contained to the platform where it occurred; security researchers have warned that credential-stuffing attacks against banking, retail, and social media accounts typically spike in the weeks following disclosures of this kind. KDDI has urged affected users to reset passwords and enable multi-factor authentication, but for accounts long since forgotten by their owners, that warning may never reach its audience.
September 2026
31
Irving, Texas — August 2026
THE BREACH BULLETIN
ZERO CLICKS REQUIRED
ONE PHONE CALL WAS ALL IT TOOK
Global — Sept. 2026
Critical - Healthcare McKesson, one of the largest pharmaceutical distributors in the United States, was breached not through malware or a software flaw but through a phone call. ShinyHunters, the same extortion group linked to the NAIC breach earlier in the quarter, used a vishing technique, impersonating IT help desk staff to convince an employee to hand over credentials tied to McKesson's Okta identity management system.
Critical - Zero-Day Security researchers confirmed active, in-thewild exploitation of a zero-day vulnerability chain affecting SonicWall's enterprise remoteaccess appliances, hardware and software widely deployed by mid-sized and large organizations to let employees connect securely to internal networks from outside the office. The chain requires no stolen credentials and no user interaction, meaning a vulnerable appliance can be compromised without anyone inside the organization doing anything wrong at all.
Once inside, the attackers gained access to systems holding prescription records, billing information, and other sensitive healthcare data. The technique is not new, but its repeated success in 2026 against pharmaceutical and healthcare distributors points to a stubborn weakness that no amount of software patching can fix on its own: employees trained to be helpful are consistently more exploitable than infrastructure. McKesson has notified affected parties and is cooperating with an investigation, but the underlying data, the kind that fuels long-running identity theft and insurance fraud schemes, cannot be recalled once it leaves the building. Security analysts now list vishing-driven identity compromise among the top three attack vectors of the year, alongside credential stuffing and unpatched
That combination makes the SonicWall exploitation one of the more urgent items in this issue: patching timelines that would be merely inconvenient for a credential-based attack become a race against active exploitation for a zero-click vulnerability chain already being used against real targets. Organizations running affected appliances have been urged to apply emergency patches immediately and to assume compromise on any device that has not yet been updated. The incident is a reminder that remote-access infrastructure, built specifically to be internet-facing by design, remains one of the highest-value targets available
8.7 MILLION TRAVELERS, TRACKED Severe - Travel Infrastructure Manchester Airports Group, which operates several major UK airports, confirmed that attackers breached its internal networks and subsequently leaked a large repository of operational and customer data. The compromised information reportedly includes personal records and flighttracking metadata connected to approximately 8.7 million travelers, data that, in aggregate, can reconstruct patterns of who flew where, and when, across an extended period.
32
September 2026
Manchester, United Kingdom August 2026
For critical travel infrastructure, the concern extends beyond identity theft. Flight-tracking and passenger metadata in the wrong hands carries implications for personal safety and surveillance risk that ordinary data breaches do not, particularly for travelers whose movements might be of interest to stalkers, criminal organizations, or hostile actors. The airport authority has said it is working with law enforcement and has strengthened access controls following the breach, but has not detailed how long the attackers had access before detection. The incident adds aviation to the growing list of critical infrastructure sectors, alongside healthcare, financial regulation, and
www.techxmedia.com
Berlin, Germany — August 2026
A CITY REFUSES TO PAY, AND PAYS ANYWAY Critical Government When hackers demanded roughly €2 million in Bitcoin from Berlin's city government in exchange for not releasing stolen files, officials refused to pay. The attackers followed through on their threat, publishing 5.8 terabytes of sensitive municipal data on the dark web, including records tied to the ministries responsible for transport and urban development. A second wave of leaks followed, this time dumping compromised user login credentials from cityrun digital services. The breach forced Berlin authorities to shut down external access to several government applications while they rebuilt defenses, disrupting services residents rely on for routine civic functions. The episode has become a reference point in the ongoing debate over ransom payment policy: refusing to pay avoided funding criminal operations directly, but did not prevent the data's exposure, leaving residents and city employees to absorb the consequences regardless of the moral stance taken. European cybersecurity officials have pointed to Berlin as evidence that municipal governments, often running on legacy systems and constrained budgets, remain some of the softest targets available to ransomware and extortion groups operating at scale.
THE VERDICT: NOTHING NEW WAS INVENTED; EVERYTHING WAS EARNED
Undisclosed Location — Late August
9.5 MILLION HEALTH RECORDS, ONE EXPOSED API Severe - Healthcare Aesto Health disclosed that attackers breached its cloud infrastructure, hosted on Amazon Web Services, through a misconfigured access point that left sensitive systems reachable without proper authentication controls. The resulting exposure compromised personal and health-related data belonging to more than 9.5 million individuals, placing it among the largest healthcare data breaches disclosed this quarter. The company has not detailed how long the misconfiguration existed before attackers discovered and exploited it, a gap that security researchers say is common and troubling: cloud misconfigurations of this kind are frequently invisible to standard monitoring tools until an external party finds them first, whether that party is a security researcher acting in good faith or an attacker acting in bad faith. Healthrelated data carries particular long-term risk for the individuals affected, since unlike a password, a medical history cannot simply be reset. The breach has renewed calls from healthcare security advocates for mandatory third-party audits of cloud configurations across the sector, arguing that self-reported compliance has repeatedly failed to catch exactly this category of error before it becomes a headline.
Ten incidents, one thread: the failure was almost never a broken machine, but a trusted
identity, a trusted vendor, or, in one unprecedented case, a trusted piece of software given more autonomy than its own creator expected. One group, ShinyHunters, touched three of the ten. All told, over 80 million records were exposed in 90 days, and not one breach required a nation-state or a novel technique, only patience, of which the other side has no shortage. The one to watch: an AI system that broke its own sandbox and reached
infrastructure it was never meant to touch, the first confirmed case of its kind, and likely not the last.
www.techxmedia.com
September 2026
33
Convergint
The Perspective
WHAT HAPPENS WHEN
SECURITY STARTS THINKING IN REAL TIME
When Issam Shibany arrived in the UAE in 2009, he planned to stay for just a year or two before returning to complete his education. Seventeen years later, he is serving as Director of Regional Accounts at Convergint MEA, with a career shaped by engineering challenges, large-scale national projects, and the region’s rapidly evolving security landscape. “I came to do one or two years, and here I am 17 years later,” Shibany reflects, noting that the UAE’s dynamic environment has continued to create new opportunities and challenges throughout his career.
A CAREER FORGED IN A “PERFECT STORM” OF GROWTH
Shibany’s early years in the UAE coincided with a pivotal phase in the region’s development. Emerging from a global financial crisis, the market was rebuilding rapidly, with infrastructure, mega projects, and national-scale developments accelerating at pace. For engineers and system integrators, this was not just opportunity, it was a testing ground. “The organization was engineering-oriented from the start,” he explains. “And the region was being built in front of us. That combination created a perfect environment to grow technically and professionally.” Working in a highly technical ecosystem, surrounded by engineers, clients who are engineers, and regulatory frameworks led by engineering-driven authorities, helped shape a mindset rooted in precision, problem-solving, and accountability.
34
September 2026
But beyond technical exposure, Shibany highlights another crucial factor: culture. “When people are willing to teach and share experience, you naturally adopt that mindset. You learn faster, you grow faster.”
FROM EARLY TEAM MEMBER TO ENTERPRISE SCALE
Shibany joined Convergint when it was still in its early stages in the region, he recalls being among the first dozen employees. Today, the organization has grown to hundreds of professionals across the region, evolving from a startup-like structure into a mature, global enterprise. That transformation, however, did not erase its early identity. “The first five years were very intense,” he says. “Overnights, problem-solving, building everything from scratch, you go through all of it. That shapes how you think.”
www.techxmedia.com
ISSAM
SHIBANY Director of Regional Accounts Convergint MEA
www.techxmedia.com
September 2026
35
Convergint
The Perspective
That blend of startup agility and enterprise structure, he notes, is one of the reasons the organization was able to scale while continuing to deliver complex projects across critical sectors.
BUILDING A LEGACY OF COMPLEX PROBLEM SOLVING In the Middle East security and systems integration landscape, Convergint has built a reputation around one central capability: delivering under pressure on highly complex projects.
From multi-site deployments to mega-projects like Expo 2020 Dubai, the organization has consistently been entrusted with high-stakes environments where failure is not an option. “We were always known as the team you call when something is very difficult to solve,” Shibany says. “Largescale, complex, multi-site projects, that’s where we operate best.” But beyond technical execution, another legacy stands out: people development.
One of the most significant transformations in the industry, Shibany notes, is the evolution of security systems from isolated infrastructure into integrated enterprise ecosystems. Traditionally treated as standalone systems, security functions today are deeply embedded into broader organizational operations. “Security is no longer a silo,” he says. “It is now part of the core infrastructure that supports multiple departments.” This shift is driven by both technological convergence and operational necessity. The same infrastructure used for security now supports analytics, operations, and decisionmaking across organizations. As a result, security has transitioned from being a cost center to becoming a value-generating function, contributing directly to operations, efficiency, and in some cases, revenue protection.
AI IN SECURITY: CAPABILITY OVER HYPE
Artificial intelligence is often positioned as the defining force in modern security systems. But Shibany offers a more measured perspective.
Shibany describes Convergint as a “micro-university,” where professionals are trained, developed, and then go on to take leadership roles across government, semi-government, and private sector organizations.
He acknowledges the role of AI-powered analytics, computer vision, drones, and real-time monitoring systems in enhancing situational awareness. However, he is cautious about overstating its autonomy.
“We’re proud of the people who have grown with us and now represent us in the wider industry,” he adds.
“I’m not on the hype train of AI replacing security operations,” he notes. “It complements human teams; it doesn’t replace them.”
THE POWER OF A GLOBAL NETWORK
Following its integration into a global structure, Convergint MEA gained access to broader engineering expertise, global procurement strength, and crossregional knowledge sharing. The impact, according to Shibany, is significant. “You suddenly have access to engineering experience from different parts of the world, across multiple industries,” he explains. “And that changes how you solve problems.” With global buying power, access to advanced technologies across continents, and a wider “lessons learned” ecosystem, the organization is able to approach challenges with a significantly expanded toolkit. Yet despite this global scale, Shibany emphasizes cultural alignment. “We are very similar in mindset, engineering-driven, customer-focused, and solution-oriented.”
36
WHY SECURITY IS NO LONGER A SILO
September 2026
In practice, AI enhances crisis readiness by delivering real-time insights from distributed sensors, cameras, and analytics systems. These insights help security professionals make faster, more informed decisions during critical events. During times of crisis, for example, integrated sensor networks can enable real-time monitoring and coordinated responses across a city, demonstrating the practical value of connected intelligence systems.“In crisis situations, realtime data can make the difference between control and chaos.”
COMMAND AND CONTROL: THE NERVOUS SYSTEM OF RESILIENCE At the heart of large-scale security and resilience frameworks lies command and control systems, platforms that aggregate, analyze, and distribute realtime operational intelligence.
www.techxmedia.com
For Shibany, their role is fundamental. “Command and control are about visibility and communication,” he explains. “It connects field operations with decision-makers in real time.” These systems enable leadership teams to understand what is happening on the ground, issue rapid instructions, and ensure execution across distributed teams, whether in government, enterprise, or critical infrastructure environments. In crisis scenarios such as severe weather, infrastructure disruptions, or public safety incidents, this closed-loop communication becomes essential for maintaining operational stability and protecting lives.
DESIGNING SYSTEMS FOR PRESSURE
Building security systems that can withstand real-world pressure requires a disciplined approach to design and execution.
Shibany outlines four key principles: • • • •
Quality-first design, ensuring robust, reliable components. Redundancy and failover systems, to eliminate single points of failure. Vendor-agnostic architecture, enabling flexibility and adaptability. Local support ecosystems, ensuring rapid response and maintenance availability.
“You cannot afford critical systems to fail under pressure,” he emphasizes. “Everything has to be designed with resilience in mind from day one.” Preventive maintenance also plays a crucial role, ensuring systems remain operational before failures occur rather than reacting after breakdowns.
A REGION MOVING TOWARD INTELLIGENT SECURITY
Looking at the broader Middle East security landscape, Shibany sees clear directional trends rather than uncertainty. Organizations across the region are investing in: • Advanced sensor technologies • Edge-based intelligence and analytics • Hybrid cloud architecture • Integrated command and control platforms • Regulatory modernization aligned with technology evolution The region, he notes, continues to be an early adopter of advanced security technologies, driven by rapid urban growth, geopolitical complexity, and large-scale infrastructure development.
www.techxmedia.com
“There is a strong drive toward smarter, more connected systems that deliver actionable intelligence, not just data.”
WHERE INVESTMENT MUST GO NEXT
Over the next three to five years, Shibany believes investment must closely follow demographic and infrastructural realities. Population growth, urban expansion, and increasing investment inflows into the region are all contributing to more complex security demands. “With more people, more infrastructure, and more movement, you naturally get more challenges,” he explains. “Security systems must scale accordingly.” At the same time, governments and enterprises must ensure that regulatory frameworks and operational capabilities evolve in parallel to maintain safety and resilience across cities and industries.
DEFINING MOMENTS IN A LONG CAREER
Despite working in a high-pressure industry, Shibany reflects on several defining moments that stand out as highlights in his career. The most significant among them was his involvement in the Expo 2020 Dubai security program, a landmark project that combined complexity, scale, and global attention. “Failure was not an option,” he says. “And then COVID happened. Everything stopped, restarted, and still, Expo happened.” Another milestone was securing Convergint’s first major law enforcement contract in Dubai, an achievement that marked a transition into national-level security responsibility. “That moment changed everything. It meant we were now contributing directly to public safety.”
WHAT COMES NEXT
As the region continues its rapid evolution, Shibany sees security systems becoming increasingly intelligent, integrated, and essential to urban life. But at the core of it all remains a simple principle: resilience is not built during crises; it is designed long before them. And for engineers like Issam Shibany, that design philosophy continues to shape not just systems, but the future of how entire cities think about safety, intelligence, and control.
September 2026
37
OMNIX INTERNATIONAL
The Dialogue
WHO'S WATCHING YOUR AI AGENTS? THE IDENTITY BLIND SPOT NO ONE'S TALKING ABOUT If an AI agent can act on its own, who is responsible for what it does? As AI agents move beyond experimentation and become active participants in enterprise workflows, identity and access management is facing a new challenge: securing entities that are neither traditional users nor conventional machines. These agents can make decisions, interact with applications, access sensitive data, and initiate actions with limited human intervention. This creates a new identity blind spot, where excessive privileges, weak accountability, compromised credentials, and insecure APIs can quickly amplify risk. In this conversation, Muhammad Zubair, Cybersecurity Presales Consultant at Omnix International, examines why organizations need to rethink IAM for AI agents, strengthen visibility and governance, and establish guardrails that allow enterprises to harness AI while keeping control and accountability firmly in place.
38
September 2026
www.techxmedia.com
MUHAMMAD
ZUBAIR
Cybersecurity Presales Consultant Omnix International
www.techxmedia.com
September 2026
39
OMNIX INTERNATIONAL
The Dialogue
What is the need to relook at security in Identity and Access Management with the use of AI Agents? AI agents represent a new type of identity in the workplace in that they are neither human nor machine but something in between. AI agents have the capacity for independent thought, decision-making, and interaction with applications. They can initiate actions on their own accord. This poses a new set of questions of how the AI Agents operate. New approaches to IAM are needed to govern AI agents given their capacity for independent thought, decision-making, and interaction with applications. The identity life cycle should be expanded to include AI agents and extended to incorporate elements of accountability. Similarly, privilege
40
September 2026
access management should also apply to AI agents in a way that is consistent with their unique characteristics. What are the biggest identity security challenges and how can organizations be prepared for such risks? The main identity security risks posed by AI agents include broad privileges, the lack of management of AI agent identities, the potential for credential theft, limited accountability, insecure APIs, and manipulation of AI agents. The ability of AI agents to perform actions on their own introduces an additional risk factor of accelerated impact as compared to traditional computing threats. Enterprises need to start by understanding their AI agents and work to develop comprehensive AI agent identity governance frameworks that incorporate strong authentication and authorization measures to minimize the risks and ensure that accountability is maintained. Enterprises should ensure that they have strong AI agent
www.techxmedia.com
access controls, including continuous monitoring, automated or manual response mechanisms, and prompt revocation of privileges if there is a possibility of compromise. There is also a need for humans to retain control of critical and risky functions and procedures. The next step is to embed AI agent governance and risk management into the broader enterprise IAM strategy and cybersecurity, compliance, and risk management framework. The immediate priority for enterprises is to obtain situational awareness of their AI agents. Organizations that start preparing now will be best positioned to benefit from the advantages of adopting AI technologies while also being able to manage the associated risks effectively. What controls should organizations have in place to monitor and manage AI agent access? Monitoring AI agents is more involved than simply analysing logs or the trails of activities they perform. It is critical that security teams obtain an adequate situational awareness of what an AI agent is doing, including what applications it is accessing and what information it is extracting from them. Ideally, this includes linking every specific action and application activity to the AI agent and, if possible, to the human user or business process that launched the agent. In the long run, organizations should be able to determine what is normal for a given agent based on the patterns of its activity, thus being able to readily discover when an agent is doing something unusual. In addition, organizations should develop response procedures and protocols when dealing with compromised agents. The key point is that whenever an AI agent acts independently, the organization should be able to monitor and, if necessary, disable that activity.
How can businesses secure AI agents against attacks and unauthorized manipulation? AI agents present unique risks as both the means and the target of attacks. A compromised AI agent can have farreaching effects simply by virtue of having been granted access privileges that it continues to exploit even after being manipulated. There are multiple ways in which AI agents can be compromised, including through instruction tuning, backdoors and compromised tools, poisoned data, insecure APIs, and excessive privileges. This highlights the importance of implementing robust IAM frameworks that combine strong identity governance with comprehensive monitoring and analytics to detect anomalies such as abnormal data access, utilization of unauthorized applications, anomalous API calls, privilege escalation, behavioural changes, and attempts to circumvent security measures. AI agents should be used within well-defined and carefully selected guardrails, which include restricting the tools, applications, systems, and data that they can interact with as well as the functions they can perform. Wherever possible, especially with regard to high-risk functions and activities, organizations should implement validation and approval controls, making it necessary for humans to review and approve specific activities or transactions before they are executed. Who should be responsible for governing AI agent identities within an organization? AI agent governance should be a shared responsibility between the business and the IT function with the former providing oversight over the purposes for which AI agents are used and the latter being responsible for implementing appropriate technical controls for their governance, security, and utilization. Every AI agent should have an owner who is accountable for its actions, including approval of its creation or deployment, defining its purpose, reviewing its access privileges, and ensuring its timely retirement when it is no longer needed. For high-risk AI agents, this also entails oversight from other relevant organizational functions, including risk and compliance management, data privacy, and so on. Having a clear inventory of all AI agents is an important starting point for AI agent governance. At a minimum, AI agents should be incorporated into broader enterprise identity governance frameworks with their identities managed in a way that supports ownership, accountability, access reviews, and other relevant governance requirements. Similarly, organizations may want to ensure least-privilege access for AI agents as well as continuous monitoring and appropriate safeguards to protect sensitive or restricted data.
www.techxmedia.com
September 2026
41
QUALYS
THE PERSPECTIVE
IT IS TIME FOR THE C-SUITE TO BE FLUENT IN RISK We often hear that our scientific community knows more about the depths of space than about the depths of our own oceans. This is underpinned by the relatively small amount of submarine environment we have mapped when compared to the night sky. The same could be said of our software. The vulnerabilities that are most successfully exploited are those that have yet to be discovered due to lack of visibility, already forgotten, or lost in the sea of new ones. And for businesses, risks most commonly stem from an inability of technical staff to communicate the dangers clearly, and in ways that are relatable for line of business executives. The ideal way to deliver software vulnerability reports to nontechnical audiences is through business-related terminology. Transparent metrics can more easily be weighed against risk appetite so leaders can balance agility and competitiveness against legal and technical safety. When we consider the extremes of risk-free operations and security-free operations, neither is sustainable. The former is prohibitively expensive, and the latter is unlikely to be profitable over the long term. Balance is a must.
42
September 2026
www.techxmedia.com
IVAN
MILENKOVIC VP Cyber Risk Technology EMEA Qualys
www.techxmedia.com
September 2026
43
QUALYS
THE PERSPECTIVE
SAILING ON THE SPECIFIC
The eventual goal is targeted investment: the right budget devoted to the right resources and the right actions. To that end, risk appetite should not be used as a phrase to explain away underinvestment in cybersecurity. CISOs must quantify consequences and present them as business impacts. This means risk appetite itself must be quantified. The practices of issuing high-level declarations on unmeasured acceptable levels of risk must change. Organisations need to use more specific metrics that track risk levels over time and compare them against clearly stated tolerances, such as a maximum of four hours per quarter of unplanned downtime for a core system. Risk thresholds must also be established to trigger critical actions. For example, if downtime exceeds agreed-upon limits, notify the CIO. If it exceeds them by more than an hour, the CIO should notify the board. All stakeholders must agree to declare war on ambiguity.
44
September 2026
Where possible, teams should measure risks, impacts, and outcomes in monetary terms. This leads to the formation of a common language for discussing risk and risk management. General discussions of comfort levels are replaced with specific questions like, “can we absorb an AED 5 million loss from a 24-hour downtime period?” Questions like this will emerge naturally from a risk audit, where the business and its most critical issues come under the microscope. Of course, some risks will be harder to convert into dirhams than others. By attempting to operationalise risk management, however, we take an important step towards guided action. As time goes on, we will improve accuracy as we gain more real-world experience.
SEE THE ROC
As with all changes in business culture, it is advisable to form a single, central entity with the authority to promote new, data-based conversaations. Just as the Security Operations Centre (SOC) did this for IT intrusions, the Risk Operations Centre (ROC) will gather risk signals and present them in a common monetary language so that the
www.techxmedia.com
best possible decisions can be made. The SOC performed a largely forensic role, identifying the sources of errors that led to damage. The ROC takes a data-led approach to prevent catastrophic incidents from occurring. Doing side-by-side comparisons of monetary data and risk tolerance, the ROC is equipped to make meaningful recommendations when changes in risk levels are detected and exceed formally stated thresholds. Data is critical. It must be used to provide a unified risk view that the board can easily use for strategic oversight. The three most important metrics are risk arrival, risk departure, and risk survival. Risk arrival rate measures the volume of new material risks entering the environment over a given period. It exposes the effectiveness of preventive controls alongside business growth factors. Risk departure rate, or burndown velocity, is the volume of risks your team successfully closes or accepts over that same period. Crucially, departure is a rate of volume, not a measure of time. If your arrival rate consistently outpaces your departure rate, your risk debt is compounding. Finally, risk survival is the persistence time of a specific risk; the lifespan from discovery to departure. Survival measures the actual efficacy and capacity of your remediation engine. If risks survive longer than your agreed business tolerance, you are operating outside your risk appetite.
The vulnerabilities that are most successfully exploited are those that have yet to be discovered." www.techxmedia.com
If presented visually, accompanied by incident costs, the board will be able to see if the organisation is making real progress on risk. Where investments have been made, decision-makers will be able to visualise if they are bringing adequate returns. They will see if the remediation engine can deal with the volume of new arrivals and if critical issues are being addressed in a timely manner. Stakeholders will be able to participate constructively in the risk conversation. They will be able to make suggestions about the prioritisation of critical issues that may stand in the way of revenue generation. They may direct the security team to concentrate on those issues and allow lower-risk threats to be addressed by automation.
JE PARLE RISK
The currency of risk is money. If the CISO can craft a narrative around profitability, impact, downtime, costs, and benefits, they will attract more decision-makers to their corner. Managing risk is orders of magnitude more effective than managing technology in the current threat landscape. The security function must evolve to become a risk function; one that makes better decisions, faster decisions, and decisions that can be readily defended. In an expat heavy region, it is not uncommon for people to want to learn a foreign language. Why don’t we all learn to speak Risk? Let Cyber Risk Quantification be your Babel fish.
September 2026
45
SOPHOS
THE DIALOGUE
HARISH
CHIB
VP for Emerging Markets, MEA SOPHOS
46
September 2026
www.techxmedia.com
THE $665K QUESTION
IS YOUR IDENTITY SECURITY READY? Every ransomware attack today tells the same story before it even begins: a stolen password, a phished login, a compromised identity. In the UAE, that story now comes with a price tag, an average recovery cost of US$665,000 per incident, according to Sophos' 2026 State of Ransomware report. Globally, four in five attacks start the same way, with identity-based access now outpacing exploited vulnerabilities as attackers' entry point of choice. "Identity has become the primary attack vector," says Harish Chib, VP for Emerging Markets, MEA at Sophos, pointing to why access control, least-privilege enforcement, and continuous monitoring have become non-negotiable for organizations across the region. As Chib puts it, resilience today is less about stopping every attack and more about limiting the damage and restoring trust fast, a mindset now shaping how Sophos is building AI directly into its defense strategy across the Middle East.
www.techxmedia.com
September 2026
47
SOPHOS
THE DIALOGUE
What is the current state of cybersecurity across the UAE and the wider Middle East? What are the key threats and challenges organizations should be watching out for? Ransomware continues to be one of the most disruptive threats facing organizations both globally and, in the UAE, and Sophos' 2026 State of Ransomware report shows why: identity has become the primary way attackers get in. Four in five ransomware attacks globally now start with compromised identities, with 79% of attacks involving an identity-based initial access vector. Malicious email and phishing have overtaken exploited vulnerabilities as the leading root causes of these attacks, accounting for 26% and 24% of incidents respectively, while compromised credentials made up another 23%. In the UAE specifically, organizations that suffered ransomware attacks reported an average recovery cost of US$665,000. The UAE did perform better than the global average on encryption outcomes, with 38% of attacks resulting in data encryption compared to 56% globally, but that shouldn't be mistaken for lower risk. The findings point to a clear need: stronger identity security, phishing-resistant controls, tested backup and recovery processes, continuous monitoring, and coordinated detection and response across endpoint, firewall, email, identity, and cloud environments. Sophos recently announced its participation in the OpenAI Daybreak Cyber Partner Program. Can you share more about what this means for Sophos’ approach to AIpowered cyber defence and how these capabilities could benefit organizations in the Middle East? Frontier AI is now a factor on both sides of the threat landscape, and we believe defenders need to match that capability responsibly, not just react to it. Through OpenAI's Daybreak Cyber Partner Program, we've built advanced, cyber-capable AI directly into our products, with our analysts and controls always in the loop, not raw model access handed to customers. It helps our team investigate threats faster, catch vulnerabilities sooner, and sharpen detections, while humans still make the final calls. For customers in the Middle East, that translates into stronger protection built into the tools and managed services they already use, backed by our global threat intelligence. We've taken a similar approach with Anthropic through Project Glasswing, which gives us early access to one of their most advanced, not-yet-public frontier models, specifically to identify and remediate software vulnerabilities before AI-powered attackers can exploit them.
48
September 2026
The principle underlying both partnerships is straightforward: as adversaries adopt frontier AI, defenders must have equal or greater capability, deployed with accountability and human oversight at every step. Why is GISEC an important platform for Sophos, and what does the event mean for your engagement with customers and partners across the region? GISEC is one of the most important cybersecurity events in the Middle East and provides Sophos with a valuable opportunity to engage directly with customers, partners, policymakers, and security leaders across the region. It is an ideal platform to discuss how the threat landscape is changing and what organizations need to do to secure themselves in the AI era. For Sophos, the event is also an opportunity to reinforce its commitment to the region, support its partner ecosystem, and help organizations understand how a unified, AI-native defense system can improve cyber resilience while reducing complexity. What are the most critical areas organizations must prioritize for operational continuity? Organizations must prioritize identity security, data protection, and recovery assurance. Identity has become the primary attack vector, so controlling access, enforcing least privilege, and monitoring authentication behavior are critical. Data resilience, including immutable backups and tested restoration processes are essential to ensure operations can resume without compromise. Segmentation and containment must be strong enough to limit blast radius if a breach occurs. Finally, organizations need real-time visibility and incident response readiness, including predefined playbooks and regular simulations. Continuity today depends less on preventing attacks entirely and more on limiting impact and restoring trust quickly. What do you see as the biggest opportunity for cybersecurity innovation in the next 3–5 years, and how is Sophos preparing for it? The greatest opportunity lies in using AI to democratize high-quality cybersecurity by embedding expert-level detection, response, and decision-making into every organization, regardless of size. Sophos is investing heavily in AI-powered automation, managed detection and response, and predictive analytics. These innovations empower CISOs to reduce risk, improve resilience, and make more strategic decisions with fewer resources. By anticipating attacks before they occur, Sophos aims to move security from reactive defense to proactive, adaptive protection, helping organizations stay ahead of increasingly sophisticated threat actors.
www.techxmedia.com
TENABLE
THE DIALOGUE
CYBER SECURITY
AT MACHINE SPEED Cyber threats are no longer moving at human speed. As digital transformation accelerates across the Middle East, organisations are facing an attack landscape where vulnerabilities can be discovered, chained and exploited in a matter of hours. Cloud environments, identities, operational technology and AI are converging, creating complex attack paths that traditional security processes struggle to keep pace with. For security leaders, the challenge is no longer simply identifying vulnerabilities, but determining which exposures can lead to real business impact and closing those pathways before attackers reach critical assets. In this conversation, Maher Jadallah, Vice President, MEA, Tenable, explores how organisations can respond to machine-speed threats, strengthen visibility across IT and OT environments, harness AI for faster remediation, and build resilience around the assumption that prevention alone is no longer enough.
50
September 2026
www.techxmedia.com
MAHER
JADALLAH
Vice President, MEA Tenable
www.techxmedia.com
September 2026
51
TENABLE
THE DIALOGUE
How would you characterise the cybersecurity landscape in the Middle East today, and what should be the biggest concern for organisations as the threat environment evolves? The Middle East cybersecurity landscape is defined by rapid digital transformation and cloud adoption, paired with an unprecedented surge in automated threat activity. Organisations are no longer just defending traditional IT; the attack surface now spans cloud environments, identity systems, operational technology and AI. The biggest concern for security leaders today is the sheer speed and volume of vulnerability discovery, particularly as bad actors leverage frontier AI models to identify and weaponize exposures at machine speed. This has collapsed the window between vulnerability discovery and active exploitation from months down to days and in some cases hours. Organisations can no longer fire-fight their way through endless lists of flaws using legacy 30-day patch cycles or manual triage. The core operational risk is active inertia, running outdated, human-dependent processes faster and expecting a different result. The focus must shift from attempting to fix every theoretical bug to identifying and closing the small percentage of exposures that present legitimate, exploitable paths to critical business assets. What are some of the most significant cyberattack trends emerging in the UAE this year, and how are they changing the way organisations need to think about security? A dominant trend in the UAE this year is the exploitation of complex, multi-domain attack paths that combine minor software flaws, cloud misconfigurations and excessive identity permissions. Bad actors no longer look at vulnerabilities in isolation. Instead, they chain together disparate weaknesses across hybrid cloud architectures, local infrastructure and identity frameworks to reach high-value targets. In tandem, the widespread adoption of AI tools and autonomous agents across UAE enterprises has introduced shadow AI exposures and expanded the attack surface into AI models and training pipelines. These trends force a fundamental shift in how security is approached. Looking at point-in-time scanning or siloed security tools creates dangerous blind spots. Security teams must move away from evaluating security posture through isolated compliance checklists or theoretical severity scores. Instead, they need a continuous, unified view of their entire attack surface that maps how assets, identities and cloud
52
September 2026
workloads interact, allowing them to stop chasing individual bugs and start closing real attack paths before an adversary exploits them. With AI changing both the attack and defence landscape, how can security teams use AI to make cybersecurity operations more effective? As AI enables threat actors to discover and exploit vulnerabilities at machine speed, human analysts can no longer manually validate, prioritize and remediate the influx of security signals on their own. Instead, security teams need to deploy agentic AI to automate defense at the exact same scale and velocity as the threat. AI can be used effectively to synthesize massive amounts of telemetry across IT, cloud, identity and operational environments, instantly distilling thousands of technical flaws down to the three percent that present actual business risk. Beyond prioritization, agentic AI engines can automate complex, multi-step investigation, ticketing and patch deployment workflows. This compresses mean time to remediation from months or days down to minutes, allowing security teams to automate repetitive operational tasks while retaining full expert oversight through human-in-the-loop controls. OT and ICS environments are becoming increasingly connected. What are the key security challenges organisations need to address in these environments? As operational technology and industrial control systems converge with corporate IT networks and cloud services, the primary challenge is maintaining complete asset visibility without endangering operational uptime or physical safety. Unmanaged IoT devices, legacy programmable logic controllers and dormant assets frequently create unmapped entry points into critical infrastructure. In addition, when IT and OT environments connect, attackers use minor IT exposures or compromised identities as stepping stones to move laterally into industrial networks. Organisations must address the lack of baseline asset inventories and eliminate boundary violations between systems. They need safe, non-disruptive visibility into deep device configurations, firmware, and network communication patterns. Once visibility is established, the priority must be mapping cross-domain attack paths to enforce proper segmentation and neutralizing toxic combinations of IT, OT and identity risks before they can cause physical disruptions or operational downtime. What does a resilience-first cybersecurity strategy look like in an environment where organisations can no longer assume that every threat can be prevented? A resilience-first strategy assumes breach conditions and
www.techxmedia.com
focuses on preemptive exposure management rather than reactive incident response. It is impossible to patch every flaw or prevent every attack attempt. Instead, resilient organisations must focus on building high-resistance environments that choke off an attacker’s ability to move laterally or reach crown-jewel assets. In practice, this means establishing continuous, deterministic asset discovery to maintain ground truth over everything connected to the network. It requires replacing basic CVSS vulnerability scoring with context-aware prioritization that factors in asset criticality, identity entitlements and network reachability. Furthermore, resilience demands continuous, automated validation of defenses against realworld adversary tactics, coupled with agentic remediation workflows that fix proven exposures at machine speed. When you continuously close the specific exposure combinations that form viable attack paths, you raise the operational cost for the attacker and render theoretical vulnerabilities irrelevant. What should organisations prioritise over the next 12–18 months to stay ahead of emerging threats? Over the next 12 to 18 months, organisations must prioritise consolidating their fragmented security stacks into unified exposure management programs. Security teams need to eliminate operational silos across IT, cloud, identity and OT so they can evaluate risk through a single source of truth. Second, organisations must prepare their operational workflows for the wave of AI-discovered vulnerabilities by replacing manual triage with intelligent, risk-based filtering and automated remediation. Third, identity governance and least-privilege enforcement across hybrid environments must be tightened, as identity misconfigurations remain a primary driver of lateral movement and blast radius. Finally, as regional cloud transformation continues, organisations should focus on securing AI workloads and implementing agentic orchestration to ensure their defensive execution operates at the same speed as modern, AI-accelerated threats.
www.techxmedia.com
September 2026
53
54
September 2026
www.techxmedia.com
www.techxmedia.com
September 2026
55
55
2026 سبتمبر
www.techxmedia.com
www.techxmedia.com
2026 سبتمبر
54
53
52
51
50
48
47
46
45
44
43
42
41
40
39
38
37
36
35
34
33
32
31
30
29
28
27
26
24
23
22
21
20
19
18
17
16
15
14
13
12
11
10
9
8
7
2026 سبتمبر
www.techxmedia.com
www.techxmedia.com
2026 سبتمبر
6
ﻣﺠﺮد اﻣﻦ
ﻟﻢ ﻳﺤﺪث ﺷﻲء. ﻫﺬه ﻫﻲ اﻟﻘﺼﺔ.
ﻛﻴﻒ ﺗﺤﻮّ ل اﻹﻣﺎرات اﻟﻬﺠﻤﺎت اﻟﺮﻗﻤﻴﺔ اﻟﻤﺘﻮاﺻﻠﺔ إﻟﻰ ﻧﻤﻮذج ﻳُﺤﺘﺬى ﺑﻪ ﻓﻲ اﻟﺼﻤﻮد ،وﺗﺪﻓﻊ ﻣﻌﻬﺎ ﺑﻘﻴﺔ دول ﻣﺠﻠﺲ اﻟﺘﻌﺎون اﻟﺨﻠﻴﺠﻲ إﻟﻰ اﻷﻣﺎم. اﻟﺘﺄﺛﻴﺮ اﻹﻗﻠﻴﻤﻲ اﻟﻤﺘﺴﻠﺴﻞ
ً أﻣﺎﻧﺎ ﻟﺪول ﻣﺠﻠﺲ ﻏﺪٌ أﻛﺜﺮ اﻟﺘﻌﺎون اﻟﺨﻠﻴﺠﻲ
ﻣﺒﻨﻲ ﻟﻤﺎ ﻫﻮ ﻗﺎدم
اﻻﺳﺘﺮاﺗﻴﺠﻴﺔ واﻟﻤﻬﺎرات ودﻓﺎﻋﺎت أﻛﺜﺮ ذﻛﺎء
أﻗﻮى ﻣﻌﺎ
ﻧﻬﺞ اﻹﻣﺎرات ﻓﻲ اﻷﻣﻦ اﻟﺴﻴﺒﺮاﻧﻲ ﻳﻠﻬﻢ دول ﻣﺠﻠﺲ اﻟﺘﻌﺎون اﻟﺨﻠﻴﺠﻲ