Back to all food-industry news

talabat announces CEO transition as Tomaso Rodriguez steps down

Rodriguez will be succeeded by Toon Gyssels, who returns to the company and will formally assume the position of CEO on November 21

Gulf Business
Gulf Business

15 October, 2025

talabat announces CEO transition as Tomaso Rodriguez steps down
Image: Supplied

TT

16

Talabat Holding, the on-demand online ordering and delivery platform in the Middle East and North Africa, announced that CEO Tomaso Rodriguez will step down after six years in the role as part of a planned leadership transition.

Rodriguez will be succeeded by Toon Gyssels, who returns to the company and will formally assume the position of CEO on November 21.

The transition reflects talabat’s focus on maintaining sustained growth and leadership while preparing for the next phase of innovation in the delivery sector.

Rodriguez will continue to support the company as a member of the talabat board, focusing on strategy and stakeholder engagement in a non-executive capacity. He will also work closely with Gyssels during the handover period.

“Tomaso has done a great job during six impactful years as CEO and I am delighted that he is remaining on the board to help shape Talabat’s strategy going forward,” said Pieter-Jan Vandepitte, chairperson of talabat’s board of directors. “With Toon’s outstanding entrepreneurial experience and proven track record in the platform delivery technology sector, we are confident that he will drive Talabat’s next chapter of innovation and growth in the region. His appointment is an exciting step forward as we continue to strengthen our position in this dynamic market.”

Reflecting on his tenure, Rodriguez said, “The last six years as CEO of talabat have been nothing short of amazing. I’ve been privileged to work with an incredibly talented team that managed to grow the business more than nine-fold. More recently, I was privileged to guide the company through a record-breaking IPO, and I couldn’t be more proud of what we achieved. I am looking forward to closely supporting talabat’s strategy going forward as a Board member, and assisting Toon as he moves into the CEO role.”

Gyssels’ previous roles at talabat

Toon Gyssels/ Image: Supplied

Gyssels previously spent four years at talabat, serving as COO and later as interim CEO. During that period, he played a key role in expanding Talabat’s operations across MENA, transforming its logistics infrastructure, and launching new verticals such as Q-commerce and cloud kitchens.

Most recently, Gyssels served as COO at Kitopi and CEO of its On Demand business unit, where he contributed to building the company into a next-generation food and beverage player in the region.

Earlier in his career, he worked with McKinsey & Company and has since led growth and transformation mandates across several technology scale-ups in the MENA region, with a strong focus on AI-driven business innovation.

“talabat has achieved a great deal in recent years, and I’m excited to rejoin at such a pivotal point in its journey,” Gyssels said. “Together with the team, my focus will be on accelerating innovation and ensuring we are well positioned to capture the opportunities ahead in one of the most dynamic markets in the world.”

The company expressed its appreciation for Rodriguez’s leadership, crediting him for his contributions to the company’s rapid growth and for guiding it through its record-breaking initial public offering on the Dubai Financial Market in December 2024.

Founded in Kuwait in 2004, talabat has grown into the region’s leading on-demand delivery platform, serving more than 6.5 million active customers across eight markets, including the UAE, Kuwait, Qatar, Egypt, Bahrain, Oman, Jordan, and Iraq.

A subsidiary of Delivery Hero SE, the platform continues to focus on expanding its offerings and market presence through technology-driven innovation.

Commvault’s Fady Richmany on cyber resilience in the ‘nonstop confidence’ era

Richmany outlines how Commvault’s new innovations are enabling organisations to recover faster, maintain operations under pressure, and build lasting digital trust

Neesha Salian
Neesha Salian

15 October, 2025

Commvault’s Fady Richmany on cyber resilience in the ‘nonstop confidence’ era
Image: Supplied

TT

16

As cyberattacks grow more frequent and complex across the region, Commvault is using GITEX GLOBAL 2025 to spotlight the next frontier in cyber resilience. Fady Richmany, corporate VP and GM for Emerging Markets at Commvault, says the company’s mission this year is to help organisations operate with “nonstop confidence” — even under active threat.

From Cleanroom Recovery and Air Gap Protect to AI-driven threat detection and zero-trust controls, Commvault’s showcase underscores a simple but urgent message: in a higher-risk digital economy, recovery speed and data integrity matter as much as prevention.

In this interview with Gulf Business, Richmany explains how Commvault is redefining business continuity, why resilience has overtaken protection as a boardroom priority, and where the industry is headed next.

What is Commvault showcasing at GITEX GLOBAL?

With rapid digital transformation turning the region into a hotspot for increasingly sophisticated cyber threats, this year, our focus is on empowering organisations with Cleanroom Recovery and advanced cyber resilience, helping to enable nonstop business continuity, rapid recovery, and confident operations even under threat. Visitors to our stand will get hands-on demonstrations of our solutions, for example, Cloud Rewind, designed for faster recovery and business continuity.

We’re also demonstrating our Cleanroom Recovery offering with Air Gap Protect, a truly isolated, on-demand recovery environment that enables secure testing and post-attack analysis. For identity protection, we’ll highlight our Active Directory Recovery capabilities, offering full forest-level restoration to safeguard access controls. And with Clumio for S3, we’re bringing scalable cyber resilience to AWS, protecting vast data lakes, applications, and databases with automated security and rapid recovery.

These technologies are built to support the concept of the minimum viable company (MVC) – helping organisations in the Middle East identify and recover their most critical systems first to resume business operations quickly through AI-driven threat detection, immutable backups, and zero-trust controls. We are also hosting hands-on demos, strategic discussions, and collaborative planning sessions to help partners strengthen their offerings, differentiate their services, and deliver greater long-term value to our joint customers in an evolving threat landscape.

How do you anticipate the security solution market to grow in 2025?

The Middle East and Northern Africa’s cyber security threat landscape has drastically changed in the last year.

Businesses throughout the MENA region continue to rapidly digitalise, however, through 2024, further risks have been brought about by new technologies, while traditional ransomware-as-a-service risks remain due to the economic growth many countries in the region experience.

In Q1 of 2024, the Middle East and Northern Africa (MENA) region experienced a dramatic 183 per cent year-on-year increase in distributed denial-of service (DDoS) attacks, with the main targets being the government and energy sectors. Consequently, both traditional threats and new technologies will remain significant vectors of attack pushing organisations to adopt multi-layered protection and cyber recovery strategies.

This is why data protection has become such a priority for business leaders in the Middle East. In 2025, 40 per cent ranked it as their top concern. This is where our cloud-first innovations like Cleanroom Recovery, Clumio Backtrack, and Cloud Rewind can be transformative solutions. They are designed to not only help companies rapidly recover data and infrastructure but be able to test their recovery plans.

By what percentage are ransomware attacks growing in the Middle East?

Ransomware is escalating rapidly across the Middle East and has evolved into a greater threat to business continuity, critical infrastructure, and public trust.

Between 2020 and 2024, ransom demands surged from an average of $700,000 to as high as $8–9m. In one notable case, a GCC financial institution was paralysed for 11 days, with customer access blocked and recovery delayed for weeks, even after a multimillion-dollar ransom was paid.

By 2025, the Middle East and Africa accounted for approximately 6 per cent of global ransomware incidents, though the actual figure may be higher due to underreporting and limited response infrastructure. Threat actors remain highly active in the region, while ransomware-as-a-service models are expanding into sectors including healthcare, education, and manufacturing.

Financial services are among the most targeted, representing 2121 per cent of cybersecurity incidents in the UAE alone. Yet, the country also reports one of the lowest ransomware rates globally, with fewer than five incidents per 10,000 workloads in H1 2025. Globally, healthcare was the most attacked sector in Q1 2025, accounting for26 per cent of reported cases.

To counter this evolving threat, organisations must prioritise proactive patching, immutable backups, and frequent cyber recovery testing during good times to help ensure enterprises are prepared for the bad times.

How can businesses build resilience without paying ransoms?

True cyber resilience begins with the recognition that no system or network is completely immune to attack. What matters is the ability to keep critical operations running during a cyber incident and to recover quickly afterward. This is a concept simply known as Minimum Viability. It is the practice of identifying which systems, identity services, networks and people are considered as critical to business operation. Once these are identified, they should be prioritised when under an attack, so that the business can continue to operate until full restoration is achieved.

This is why data protection has become such a priority for business leaders in the Middle East. In 2025, 40 per cent ranked it as their top concern, well above the global average. The global ransomware protection market, valued at nearly $30bn, is also expected to double by 2029, which reflects how urgently businesses and governments are investing in defenses.

Smaller businesses remain the most vulnerable, representing almost 80 per cent of global ransomware victims in 2025 and nearly half of all cases in the UAE. These organizations often lack the resources of larger enterprises and leave critical gaps in their defenses.

Even with a clear understanding of the risks, many leaders still see ransom payments as a last resort. A Commvault survey of UK business leaders in 2025 showed that while nearly all supported a ban on private-sector ransom payments, three in four admitted they would still pay a ransom if it meant saving their company. This gap between principle and practice reinforces the importance of readiness and recovery planning. Businesses that invest in resilience will be far less likely to face the impossible choice of paying criminals or shutting down.

Without disclosure laws, how can firms stay transparent with stakeholders?

Transparency is first and foremost about trust. Even without formal disclosure laws, organisations that communicate openly with customers, partners, and regulators build trust with these stakeholders to become integral technology partners, enabling critical partnership in a crisis.

Cyber resilience depends on preparation. A ransomware event cannot be the first time IT, Security, Legal, and other teams work together. With CrowdStrike estimating an 84-minute window before data is exfiltrated or destroyed, firms need rehearsed response plans that include asset mapping, drills, and clear shutdown procedures. The first step would be to rapidly contain the issue, while also moving quickly to secure the systems you have identified as your minimum viable company (MVC), the core systems and infrastructure needed in order for the business to operate, even at half restoration. Then, assess the damage by quickly assessing what data was exposed, what contractual or regulatory obligations apply, and then begin to utilise a clean, isolated recovery environment, all the while checking that your backup data has not been corrupted.

Throughout this process, communication must be immediate and structured. Employees, customers, and regulators all expect timely, clear updates that explain impact and remediation steps. In the Middle East, where 73 per cent of executives cite customer trust as the top driver of cybersecurity investment, openness is not only good governance, but also a competitive advantage. Extending transparency beyond incidents through regular publication of threat intelligence and independent audit results reinforces that security is treated as a board-level priority and that stakeholder trust is central to long-term growth.

What technologies help businesses face threats without compromise?

The prevalence of cyber activity in today’s digital world has meant that stopping every attack is no longer realistic. Global cybercrime costs are projected to reach $13.82tn by 2028, which makes resilience the real priority. Businesses need to ensure rapid recovery and maintain operational continuity even when compromise occurs.

AI is playing a pivotal role in this shift. On one hand, it lowers the barrier for cybercriminals by enabling phishing, deepfakes, and reconnaissance at scale. On the other, when applied responsibly, it strengthens defenses. Modern data protection platforms now combine AI-driven threat detection, immutable storage, and cleanroom recovery environments so that when ransomware strikes, critical data can be restored quickly and securely without reinfection.

Commvault brings these capabilities together through air-gapped backups, zero-trust access controls, and automated cleanroom recovery. Our Cleanroom Recovery solution provides an isolated environment in the cloud to safely test, validate, and restore clean data, while AI-enabled Cleanpoint Validation can help pinpoint the last clean recovery point. This helps ensure critical systems can be brought back online with speed and integrity.

As well as this, once a breach or a bad actors has been isolated, a Cleanroom can allow key activities that make a solid recovery protocol to take place, such as forensic analysis and rapid containment and recovery. With this, recovery plans are fortified and strengthened.

However, with the increased sophistication of cyber-attacks and incidents, standard recovery protocols might not be enough. This is because these protocols rely on the assumption that backup data is clean, while it may be corrupted, adding excessive time to recovery attempts. This is why businesses need to approach their recovery process methodically and cautiously, following strict guidelines, that vendors like Commvault help to educate and guide businesses and IT teams on, that consider rapid containment of the issue, ensuring a clean foundation to recover from, data validation and a systematic and safe recovery.

What are your plans to help stabilise the ransom attacks?

At Commvault, our goal is to shift the balance of power away from attackers and back to businesses. For us, stabilizing the impact of ransomware means doing our part to help ensure organisations are equipped to withstand incidents and recover with speed and confidence.

To achieve this, we apply a multilayered security framework built on zero trust principles and aligned with the National Institute of Standards and Technology Cybersecurity Framework. This approach covers the full lifecycle of risk management by helping organisations identify vulnerabilities, protect data, monitor threats, respond to attacks, and recover quickly. Ransomware protection is a central part of this effort. By delivering infrastructure that is designed to offer immutable and indelible storage, we help organisations defend against ransomware and zero-day threats, and help ensure that critical data cannot be deleted, encrypted, or altered.

This advanced protection is powered by the Commvault Cloud, powered by Metallic AI, which provides unified data resilience across on-premises, cloud, and SaaS applications. The platform simplifies visibility and control, and leverages AI to automate processes such as threat prediction, anomaly detection, and clean backup validation. Within Commvault Cloud, Cleanroom Recovery offers an isolated recovery environment to test and restore data safely, while Autonomous Recovery can help accelerate recovery times with forensic analysis, continuous replication, and automated failover. Cloud Rewind, meanwhile, enables businesses to go beyond restoring data to rapidly rewinding and rebuilding dynamic, distributed cloud applications after outages or attacks. Together, these capabilities give enterprises the confidence to face ransomware without compromise, keep operations running, and protect the trust of their stakeholders.

As well as the technology behind the effort to fight ransomware, awareness of how to deal with and respond to these attacks is equally important. Introducing regular tabletop simulation exercises into organisations’ recovery training, testing and planning protocols is a great way to understand the severity of an incident and define roles and responsibilities during crisis management.

At Commvault, we help introduce our customers to these practices with our Minutes to Meltdown and Cyber Recovery Range sessions, where we simulate a live ransomware attack to give those in attendance a clearer understanding of how quickly you must react to an ongoing crisis.

By adopting these solutions, what percentage of attacks can be prevented?

No cybersecurity strategy can guarantee the prevention of every ransomware attack. Threat actors are constantly developing new techniques, which makes complete protection unrealistic. What can be achieved, however, is the ability remain in a state of continuous business if an attack is successful.

By layering key capabilities (like immutable backups, air gapped copies, and Active Directory forest-level recovery) with AI-driven anomaly detection, the likelihood of rapidly recovering from a successful attack can be significantly increased.

What we at Commvault do is we take this a step further by focusing on cyber resilience. Even if an attacker penetrates the perimeter, our Cleanroom Recovery, Autonomous Recovery, and Cloud Rewind technologies offer layered support to help customers restore data and cloud applications, minimize downtime, and continue operations safely. This combination can help businesses prevent complete business failure from occurring and turn ransomware into a risk that can be managed and limited rather than an existential threat.

What are some of the best practices that businesses in the UAE should adopt to manage cybersecurity for their data/ brand?

The prevalence of cyber activity in today’s digital world has meant that stopping every attack is no longer realistic.

Commvault recently ran a consumer survey in UAE which revealed that while 71 per cent of respondents believe businesses are doing enough to protect, secure, and recover data after a breach, 44 per cent would consider no longer doing business with an organisation if it suffered an attack. Half of those who disagreed cited the challenge of protecting data scattered across multiple cloud environments. These results underline how quickly trust can be lost following an incident and reinforce the urgency for enterprises to strengthen cyber resilience and recovery readiness.

AI is playing a pivotal role in this shift. On one hand, it lowers the barrier for cybercriminals by enabling phishing, deepfakes, and reconnaissance at scale. On the other, when applied responsibly, it strengthens defenses. Modern data protection platforms now combine AI-driven threat detection, immutable storage, and cleanroom recovery environments so that when ransomware strikes, critical data can be restored quickly and securely without reinfection.

Commvault brings these capabilities together through air-gapped backups, zero-trust access controls, and automated cleanroom recovery. Our Cleanroom Recovery solution provides an isolated environment in the cloud to safely test, validate, and restore clean data, while AI-enabled Cleanpoint Validation can help pinpoint the last clean recovery point. This helps organisations to bring critical systems back online with speed and integrity. Once a compromised entity has been isolated, a cleanroom can allow key activities that make a solid recovery protocol to take place, such as forensic analysis and rapid containment and recovery. With this, recovery plans can be fortified and strengthened.

However, with the increased sophistication of cyber-attacks and incidents, standard recovery protocols might not be enough. That’s because these protocols rely on the assumption that backup data is clean, while it may be corrupted, adding excessive time to recovery attempts. This is why businesses need to approach their recovery process methodically and cautiously following strict guidelines. Vendors like Commvault help to educate and guide businesses and IT teams on, that consider rapid containment of the issue, ensuring a clean foundation to recover from, data validation and a systematic and safe recovery.

What are your plans for the upcoming months?

First, I’ll say that partnerships have been a key part of our success in FY25. For example, we strengthened our collaborations across hyperscalers including Microsoft, AWS, and Google. We also deepened our alliances with leading technology and security partners such as Pure Storage, CrowdStrike, BeyondTrust, and DataBricks.

In FY26, we will continue to build on this momentum – expanding efforts to protect AI data stored with leading cloud partners and doubling down with cloud marketplaces to make it easy as possible for customers to transact based on their specific needs. These alliances have positioned us as a trusted leader in data security and resilience. Our global strategy continues to focus on evolving the industry’s best partner ecosystem to help customers advance cyber resilience.

In parallel, we will scale our awareness and readiness programs. This focus on awareness is a major driver of our growth and credibility. Introducing regular tabletop simulation exercises into organisations’ recovery training, testing, and planning protocols is a great way to understand the severity of an incident and define roles and responsibilities during crisis management.

At Commvault, we help introduce our customers to these practices with our Minutes to Meltdown and Cyber Recovery Range sessions, where we simulate a live ransomware attack to give those in attendance a clearer understanding of how quickly you must react to an ongoing crisis. These initiatives continue to help organisations of all sizes understand their true cyber posture and close the gaps before it is too late.

How do you anticipate the industry to grow in the next few months?

The industry is entering a pivotal phase of accelerated growth, driven by the convergence of AI, cloud, and the urgent need for cyber resilience. These technologies have transformed how we operate, but they’ve also introduced unprecedented complexity and risk. Cyber resilience has now become the ultimate measure of business survival in a digital-first world. We’re seeing this reflected in the data: in Asia, data volumes grew by 31 per cent in 2023 and surged to 40 per cent in 2024, while 63 per cent of organisations now operate across multi-cloud or hybrid infrastructures (SODR Asia 2025).

As digital adoption deepens across sectors, the UAE is steadily strengthening its role in the regional technology environment, laying a strong foundation for future growth ever-evolving cyber security landscape. Yet, this rapid digital progress brings with it an increasing exposure to cyber threats which demands smarter, faster, and more secure recovery strategies.

At Commvault, we’ve embraced this shift. Cyber resilience has become a boardroom priority, with organizations doubling down on preparedness to ensure continuity in the face of growing threats.

Space42, e& to develop, deploy vehicle-to-everything tech across UAE

Since 2021, Space42 has logged over 600,000 kilometres of autonomous driving and completed 20,000 passenger trips through TXAI, its flagship robotaxi service

Neesha Salian
Neesha Salian

15 October, 2025

Space42, e& to develop, deploy vehicle-to-everything tech across UAE
Image: Supplied

TT

16

Space42 has signed a memorandum of understanding (MoU) with e& UAE to jointly develop and deploy vehicle-to-everything (V2X) technologies aimed at advancing autonomous mobility and smart city infrastructure across the UAE.

The collaboration will merge Space42’s Sovereign Mobility Cloud and autonomous vehicle solutions with e& UAE’s 5.5G, edge computing, and secure communication technologies, laying the groundwork for 6G readiness.

Both companies plan to co-develop pilot projects, regulatory frameworks, and business models to enable large-scale connected and autonomous mobility nationwide.

V2X technology: How it works

V2X technology allows vehicles to communicate with other cars, road infrastructure, and pedestrians, enhancing safety and efficiency through real-time situational awareness and traffic analytics. The technology also supports over-the-air updates, enabling autonomous vehicles to refine maps and share data with nearby vehicles through edge nodes.

“This partnership brings together innovation on the ground and in the cloud. By combining Space42’s autonomous systems with e& UAE’s advanced networks, we can turn vehicles into more intelligent, connected and embodied agents that move safely through our cities,” said Hasan Al Hosani, CEO of Smart Solutions at Space42. “This work also builds on Space42’s efforts to integrate space, AI, and mobility technologies into everyday life, advancing the UAE’s vision of building sustainable, efficient, and autonomous transportation systems.”

Masood M Sharif Mahmood, CEO of e& UAE, added: “Together with Space42, we’re combining UAE-wide 5.5G, edge compute and secure communications with the Sovereign Mobility Cloud to let vehicles ‘see’ more, react faster and share trusted data with roads, signals and pedestrians. Our goal is to help regulators and city operators stand up safe, certifiable pilots that improve road safety and keep traffic moving, while laying a clear path from today’s 5.5G to tomorrow’s 6G era.”

Read: GCEO Hatem Dowdidar on how e& is redefining the future of tech and connectivity

Space42 and e& will collaborate in three main areas

The three areas include:

  • Connected infrastructure and networks: Integrating terrestrial and non-terrestrial networks, edge computing, and roadside units with Space42’s Sovereign Mobility Cloud for large-scale V2X communication.

  • Autonomous and connected mobility pilots: Testing AV shuttles, robotaxis, and logistics fleets across Abu Dhabi and other smart mobility zones to enhance traffic flow and safety.

  • Ecosystem and commercial models: Working with the Integrated Transport Centre (ITC), Department of Municipalities and Transportation (DMT), and Abu Dhabi Police to establish national standards and certification frameworks for commercial rollout.

The initiative aligns with the UAE’s National AI Strategy 2031, which aims to position the country as a global leader in artificial intelligence, particularly in next-generation mobility. It also supports the mission of the Smart Autonomous Systems Council by integrating AI, edge computing, and secure data networks to create adaptive, interconnected systems for vehicles, infrastructure, and people.

Since 2021, Space42 has logged over 600,000 kilometres of autonomous driving and completed 20,000 passenger trips through TXAI, its flagship robotaxi service, demonstrating how autonomy can move from pilot projects to public use when supported by robust digital infrastructure.

At the heart of that ecosystem is Space42’s Sovereign Mobility Cloud and Digital Twin of Abu Dhabi, enabling vehicles to interact with their environment in real-time by fusing satellite, sensor, and city network data, turning every journey into intelligence that strengthens the UAE’s wider mobility ecosystem.

Cybersecurity requires collaboration, private sector incentives: SAMENA Telecom Council CEO

Bocar Ba emphasises capacity building in developing nations and cyber diplomacy as critical pillars for addressing interconnected security threats

Neesha Salian
Neesha Salian

14 October, 2025

Cybersecurity requires collaboration, private sector incentives: SAMENA Telecom Council CEO
Image: SAMENA Telecommuncations Council

TT

16

At the recent Global Cybersecurity Forum in Riyadh, Bocar Ba, CEO of the SAMENA Telecommunications Council, outlined a comprehensive vision for global cybersecurity that extends far beyond technology. In this interview with Neesha Salian, editor of Gulf Business, Ba discussed how the forum has evolved from a purely technical cybersecurity discussion five years ago to encompass cyber safety, cyber economics, cyber diplomacy, cyber crime, and cyber defense.

Ba emphasised that cybersecurity is fundamentally about interdependency rather than common interest, requiring meaningful engagement where all stakeholders — governments, private sector and developing nations — benefit from collaboration. He stressed that the weakest links in the global system, often found in developing countries experiencing rapid digital transformation, pose risks to the entire interconnected infrastructure.

With cyber breaches costing trillions of dollars and most attacks originating from network edges rather than core infrastructure, Ba called for standardisation, capacity building, investment in human capital, and a new generation of cyber diplomats to address these challenges through frameworks that provide visibility for the next 20 to 30 years.

Here are excerpts from the discussion.

How has the Global Cybersecurity Forum evolved since its launch?

The forum’s scope has widened significantly year by year based on the relevance of the subject, becoming a truly global platform. Five years ago, when we started conversations with speakers and the audience, it was purely about cybersecurity. Now it has expanded to encompass not only cyber safety, but also cyber economics, cyber diplomacy, cyber crime, and cyber defense. It has transformed from a purely technical issue into a global issue that affects economics and geopolitics.

What does the SAMENA Telecommunications Council bring to the cybersecurity conversation?

When we speak about cybersecurity, we usually think about technology and innovation, and protecting consumers, enterprises, and nations. But being mindful about this subject is the prerogative of governments and international organisations, including civil society.

All these aspects and discussions require unlocking access to capital to make it happen. When you look at the distribution of roles of different stakeholders, yes, it’s valid to talk about security at large, but someone has to fund it — and that is the role of the private sector. The question is: what does the private sector get out of it?

What is the private sector’s role in cybersecurity, and what challenges exist in securing their engagement?

The private sector in its role is led by business profits and sustainability. It’s the role of government to protect people, enterprises, and nations — that is not the role of the private sector. The private sector brings technology, innovation, and wants to do business.

We’ve all acknowledged that cybersecurity is a concern of everyone across the value chain, but each party needs to get something out of it. When a government succeeds in having a solid foundation, solid framework, and solid environment about cybersecurity, they have fulfilled their KPI. But for the private sector, addressing cybersecurity might be an obligation, but they have no incentive.

That’s why when we talk about collaboration, I advocate not for sympathy or empathy — I advocate for engagement, meaning each party needs to get something out of it. It’s important for the private sector to get something, and when I’m saying get something, it’s not on a very selfish base. Cybersecurity could be a business case for making money.

We need to have a dialogue, put everything on the table, and see how each party can benefit. We could be sitting on different sides of the table and have joint objectives — you get something, I get something. This is what we have to define to make it meaningful.

What are the main challenges impeding seamless collaboration on cybersecurity?

The key challenge is that cybersecurity is perceived as a technological issue, but it’s not only a technological issue. I think we need to build capacity — this is very important. Advocacy, spreading the gospel at every single layer. Because the way we address it today, we only speak to one stakeholder.

We’re talking about people and populations, but cybersecurity is also a concern for enterprises. Why? The infrastructure that we have — it could be a power plant, an airport, a hospital. But you’re very well aware of the massive arrival of the internet of things. Cybersecurity is also about objects. Therefore, it’s not only people and consumers, not only children for cyber safety, not only companies and infrastructure, but also objects.

What we’re facing today is, if we want to address the issue properly at all layers, we have to work on the standardisation of the equipment that will be connected on the network. This is very important.

Why is focusing on developing nations critical to global cybersecurity?

There is a race, with very advanced nations presenting and displaying what has been done and their success stories. But if we acknowledge that cybersecurity is based on a system where we are all interconnected, the weakest point could corrupt the entire system beyond borders. Therefore, competence and capacity building is not only about the strongest nations — we need to equip the weakest nations. I’m talking about the developing countries.

It’s very important to develop capacity building. The entire market today, if you look at the growth, is across Asia, Middle East, and Africa. These nations where we see digital transformation happening, with huge percentages of growth, they are the weakest in terms of competence. If we have a breach of security in those nations, it can affect all the other nations.

These are elements that should be taken into consideration. It’s not only having the most advanced technology or the most advanced system, but where do we have the weakest point where the breach can happen? We talk about inclusivity — G20 this year will be about inclusivity.

Inclusivity means including also the weakest link in the system.

Where do most cyber attacks originate from in network infrastructure?

We see most of the cyber attacks are not happening from the core network — it is happening from the edge. This is where we don’t have standardisation, and we need to address interoperability and a number of technical issues.

As technologists, we used to have this natural mistake — we always want to leapfrog, we always want to be more and more advanced. As you know, the core infrastructure now, we talk about 5.5G, we are even starting the discussion on 6G, which will be bringing more and more challenges. So it’s important to have a trusted foundation because we are in an era of massive growth.

How does interdependency shape the cybersecurity conversation?

You rightly mentioned digital development is affecting every single aspect of our life. Digital becomes the platform of our life whether we talk about digital identity, hospitals, education, we’ve seen that during Covid-19. So it is central to our life. Therefore, it’s extremely important to have a solid digital infrastructure.

The discussion centers on how we ensure this infrastructure is solid. What’s critical to understand is the interdependency at all layers —and interdependency is stronger than common interest. Common interest can be selfish, but interdependency means we need each other to survive. This interdependency drives us toward negotiation and discussion.

What role does cyber diplomacy play in addressing cybersecurity challenges?

This is where I believe cyber diplomacy is an important subject. Why? Because we need to use the power of diplomacy with the clarity of data. The evidence — the cost of cyber breach is today measured in terms of trillions of dollars.

At a leadership level, I believe cybersecurity needs to be brought in terms of discussion at a leadership level. Private sector to the CEO level, government even to the presidential level. So we need to have leadership. And leadership is about discussing with the other nations, the other frontiers. So I believe cyber diplomacy is a very, very important subject to be addressed. Having a new generation of cyber diplomats is important.

I don’t want to use the term “cyber” because it brings us back to technology and technicalities. But today, the key and most important point is collaboration.

How should collaboration be structured and measured?

Collaboration has to be framed. You cannot say collaboration and put a full stop. What kind of collaboration? It has to be defined. We need to have some commitment. We must be able to develop some new index to be able to understand exactly where we are. What have we said last year? What have we done this year? Where are we? And measure the progress.

Plus, investment in human capital — this is extremely important.

What is your message about cybersecurity education?

The same way today, every single one of our children, when they go out, we tell them, be careful, stay safe. The same way in the digital world, we have to use the same terminology: be careful, stay safe. So education, education, education. And this is important. It touches upon the point of cyber safety for child online protection as well.

Again, the key reason for challenges is ignorance, lack of knowledge, lack of education. If we want to connect the unconnected, we need to have the infrastructure ready. Therefore, the discussions we are having now are about much more cyber diplomacy, cooperation between different nations. How can we improve that? How can we make sure that being a safe country means having a safe neighbourhood? So from one neighborhood, you move to another neighborhood, having an entire safe ecosystem.

As technology development is advancing, opportunities are appearing, but we are facing new cybersecurity challenges.

What makes the SAMENA Telecommunications Council an effective platform for addressing sensitive cybersecurity issues?

Through the platform we have now and being recognised as a very meaningful convening platform, my key role is to bring on the table a subject that nobody wants to discuss because there are so many sensitivities in this subject. But it has to be discussed. Until and unless we put those challenges on the table, it won’t be discussed. Hence, it won’t be solved.

So number one is setting the right agenda for the different stakeholders to discuss. Setting also the right level of priorities.

What are the council’s priorities for the coming months?

The more we advance in technology development, the more we need investment. And once again, this is very important: private sector needs to be incentivised, not only for the sake of profitability, because the use of the profits could be reinvested in the digital economy. But we cannot keep asking only one side to make the effort.

Cybersecurity capacity building costs a lot of money. Digital transformation costs a lot of money. Private sector is not looking for profitability today, it is looking for sustainability and predictability.

We need to sit down — government, private sector, inspired by the academia, and centering the whole discussion around the consumer, the customer, and the people — and make sure that we can build together with engagement and commitment a roadmap for the next 20 to 30 years where we have visibility. So this is where we can have a plan that will engage transparent consultation, that will engage all the stakeholders, and we can work hand in hand together. This is what I’m trying to build through the council.

How does globalisation factor into the council’s work?

We need to integrate one important factor: globalisation. Today in a country — in Saudi Arabia, in UAE, Qatar — we have no problem as stakeholders. But there is a new stakeholder: the nations. So we want to widen the G20 to the G21. We want to increase the size of the market. We are talking about having one market, for example, in Africa. If we have one market, we have to make sure that decisions are not fragmented. Frameworks are unified. Then we can scale and have one market. These are the challenges that we will be addressing very soon.

How do you ensure that growth in digital infrastructure is managed securely?

We have to ensure that the infrastructure is robust, solid, and resilient. And if we have that, it will take us to mass adoption, especially with the developing nations, the new generation, new equipment. And mass adoption means another exponential growth. Therefore, we need to look at it all with the same level of priority. It’s not “we are strong, we are secure today on site A, and we will look after site B tomorrow”. It has to be done at the same time.

Bridging the cybersecurity talent gap: BCG’s Shoaib Yousuf shares insights

Boston Consulting Group’s Shoaib Yousuf discusses why the cybersecurity talent gap is actually a workforce mismatch problem and how organisations can build resilience in the quantum era

Neesha Salian
Neesha Salian

14 October, 2025

Bridging the cybersecurity talent gap: BCG’s Shoaib Yousuf shares insights
Image: Supplied

TT

16

At the Global Cybersecurity Forum (GCF) 2025 in Riyadh, Boston Consulting Group and GCF unveiled The Quantum Leap: Navigating the Future of Computing, a comprehensive study examining how quantum technologies are transitioning from laboratory research to commercial reality.

The report reveals quantum computing is poised to unlock over $50bn in value across industries, with oil and gas alone facing potential savings of $6-30bn — while simultaneously presenting critical cybersecurity threats that could render traditional encryption obsolete.

Gulf Business editor Neesha Salian sat down with Shoaib Yousuf, MD and partner at BCG during the forum, to discuss the evolving cybersecurity landscape, the critical talent gap threatening the industry, and why organisations need to shift from viewing cybersecurity as a compliance checkbox to treating it as a competitive advantage and economic imperative.

You’ve been quite active at GCF 2025. Tell us about the sessions you were involved in.

Historically, we have been hearing about the gap in cybersecurity talent for the last 20 years, and the gap is widening. Last year, we decided to take this problem statement and understand what really is this gap, including where is the geographical split, which sectors need it most, and translate it into tangible roles.

We collaborated with GCF last year to do a very detailed report, and the session this year was about raising awareness and translating this into actionable insights so we can be at the forefront of bridging that gap.

It was a fantastic session. One key insight that came out was how to link this gap to the threat landscape. As you see, the cybersecurity threat landscape is evolving and has become quite dynamic. We have the data but haven’t done the analysis yet, so these were very good takeaways for me, and hopefully in the next version of the report we’ll take that into consideration as well.

Could you share some of the key highlights from your report about how the cybersecurity sector is set to grow, especially given the evolving threat landscape?

First, we broke down the entire mega number of three million into geographical splits. Second, we linked this with sectors, which sectors have the highest job opportunities but also the gap. Financial services, energy, for example. This is super important because if I’m entering the cybersecurity space, I know which sector has more opportunities for me, and also which sector is evolving with more opportunities for upskilling and reskilling.

Then we linked that gap to cybersecurity functional roles: is it incident management, compliance, architecture? This is insightful for both supply and demand to understand which functional roles in which geographical split and sector are important.

We also went further to understand the challenges across the value chain. One challenge that’s super important is retention. In cybersecurity, it has become a high-churning workforce. People are moving quite rapidly, either because of salaries, work culture, or employee benefits. Retention has become a big issue.

The second challenge is that because the cybersecurity landscape is evolving, organisations need to focus not only on increasing salaries but on the entire value proposition around learning and development. You need to make sure talent continues to stay relevant.

What should be the key approach from governments, businesses, and societies when they approach cybersecurity?

Historically, cybersecurity in some organisations was seen as a compliance checkbox — something to tick for corporate policies, the board, or regulatory requirements. But this has changed. It has become a competitive advantage. It’s not a tick box anymore; it’s for the assurance and trust of customers. Organisations have started changing their mindset.

Second, as a topic which moved from a compliance checkbox to a value differentiator, it has also become a topic for economic growth and national security. If you look at the OECD definition and the latest UN frameworks, they talk about cybersecurity as a much bigger economic imperative for national security and sovereignty.

Every organisation and policymaker needs to play a role in building capacity. Organisations need to make sure they can serve their own needs. Everyone wants talent with three to five years of experience, but nobody is solving this problem at the pipeline level. You need to have certain seats in your organisation opening roles for internships and work experience.

I was in a session with people from SABIC and national entities, and I told them: your organisation needs to have at least some percentage of your employees as talent incubators. You need to play a role in building that talent pipeline.

I gave them an example of BCG. As consultants, we don’t hire consultants with eight or 10years of experience. We go all the way from university and make them into consultants over 10 to 12 years, and then we produce the next generation of leaders in the market. We need to apply the same approach to cybersecurity.

As a regulator, they need to play a much more active role in capacity building, academies, upskilling, and reskilling. My cybersecurity skills from two years ago might not be relevant today because technology is changing, processes are changing with AI — everything is getting re-engineered. It’s the regulator’s responsibility to make sure the workforce stays competitive. We should look at the incentives, frameworks, and initiatives to incentivise upskilling, reskilling, and talent incubation programmes.

In terms of challenges and opportunities, particularly in the GCC where governments are very proactive, what stands out? How do evolving technologies impact the future?

Historically, the GCC and many countries have seen cybersecurity more from a regulatory point of view, a very regulatory-driven environment with a lot of initiatives launched by the government with certain controls and standards. GCC, Southeast Asia, even Europe has become very heavy on regulations. That’s why you see a lot of capacity and workforce focused on compliance analysts, auditing backgrounds, and implementing controls.

However, with technology shifting, organisations need to build much more engineering capability, operational capability, threat intelligence capability, and incident management capability. If you go to the US, they’ve always been building products and engineering, so their talent is more quantitatively solid.

This is one challenge: how to balance the workforce to cover the entire spectrum of the cybersecurity workforce framework — not only assurance and regulatory but also shifting toward more engineering roles and operational roles so they can build their own products and capabilities.

How can you measure cyber resilience, particularly with the potential impact of quantum technologies?

I love this question because resilience means different things to so many different people. At the basic level, resilience is not about 100 per cent protection. One of the unique things about cybersecurity is that you will always get attacked, you will always get breached. It’s a continuously evolving topic. There’s nothing like achieving 100 per cent security and moving on. You’ll always have security that you believe is great, but it will get broken with quantum or advanced technology, and then you have the next challenge.

Resilience doesn’t mean 100 per cent cybersecurity. Resilience means if something happens, how quickly can we respond and bring it to a level that’s acceptable to us. It’s okay to get sick — vaccines aren’t about never getting the flu; we get flu shots to minimise the impact. I see cybersecurity controls and capabilities like vaccine shots. We will get attacked, but we are immune and resilient to bring the damage down. If you don’t do it, it can be life-threatening.

For me, resilience is about building that mindset and capability to sustain yourself. A lot of organizations have a “zero attack policy,” but that’s the wrong way to start.

What are the three things CISOs or CEOs are talking to you about now, and how has that changed since two years ago?

Cybersecurity is a topic that has always been very hard to justify in terms of investments. How much investment is good enough? With cloud, you can show savings and productivity gains. When you talk to technology leaders about business cases, it usually makes sense. But with cybersecurity, it’s always very difficult to justify what budget you should spend.

This is one challenge we see from CISOs: what is the right budget I should spend and fight for? One initiative that GCF has launched with the World Economic Forum — where BCG will be contributing — is the Center for Cyber Economics. We’re trying to create a model to bring clarity on cost avoidance or the potential impact you could have avoided if you had invested a certain amount.

I’m not saying we have a perfect formula, but CISOs will continue to face this challenge. There are a lot of Gartner and Forrester reports and regulations that say you should spend a certain percentage of IT spend on cybersecurity, but there is no magic formula. It all depends on your starting point: the complexity of your architecture, the maturity of your organisation.

This is one challenge we see with CISOs: not where to spend, but justifying how much to spend and convincing management that this money is good enough to give you a good level of assurance. And good assurance doesn’t mean 100 per cent resilience.

These are business problems, and this is where BCG differentiates itself — we don’t talk control language or technology language. We typically address those business challenges with our clients.

Tenable VP Maher Jadallah on how the Middle East can secure its digital ambitions

As the Middle East races toward its digital transformation goals, Tenable’s Maher Jadallah says it’s time for organisations to shift from reacting to cyber threats to managing their exposure before it’s exploited

Neesha Salian
Neesha Salian

14 October, 2025

Tenable VP Maher Jadallah on how the Middle East can secure its digital ambitions
Image: Supplied

TT

16

Cybersecurity in the Middle East is at a tipping point. With nations accelerating toward ambitious digital agendas, the attack surface is expanding faster than most organisations can secure it. Maher Jadallah, VP for the Middle East and North Africa at Tenable, believes the solution lies in a unified, proactive approach. In this interview with Gulf Business, he explains how Tenable is helping regional enterprises gain full visibility across IT, cloud, and OT systems, manage fragmentation, and stay ahead of an evolving threat landscape driven by AI and digital convergence.

How is Tenable helping organisations in the Middle East shift from reactive cybersecurity to proactive exposure management?

Tenable is helping organisations in the Middle East execute a strategic shift from simply reacting to security alerts to establishing a proactive exposure management discipline. This transition is essential given technology is a central pillar in achieving the goals of both the Dubai Economic Agenda “D33” and Saudi Vision 2030. As digital transformation accelerates to meet these ambitions, so does the risk of cyber exposure.

The solution requires moving beyond a traditional, siloed approach to security. The focus must be on three core pillars: Unified Visibility; Risk Prioritisation; and Actionable Intelligence.

  • First, organisations need a comprehensive, continuous view of every asset—from traditional IT to cloud infrastructure, AI workloads, and operational technology (OT).
  • Second, they must prioritise not just individual flaws, but the handful of critical attack paths that pose the greatest business risk.
  • Finally, this risk must be translated into clear, quantifiable intelligence that security and executive teams can use to drive decisive investments.

By embracing this unified discipline, organisations can confidently pursue their national digital agendas knowing they are consistently eliminating their priority cyber exposures.

Tenable’s recent Cloud and AI Security 2025 report shows that 82 per cent of organisations now operate hybrid environments and 63 per cent use multiple cloud providers, creating fragmentation, blind spots and governance challenges. How can enterprises in the Middle East address these gaps and secure such complex infrastructures?

Enterprises in the Middle East must address the gaps created by fragmentation and complexity by adopting a unified exposure management strategy. Tenable’s recent Cloud and AI Security 2025 report shows that 82 per cent of organisations now operate hybrid environments and 63 per cent use multiple cloud providers, a fragmentation that leads to dangerous blind spots. This challenge is heightened by the context of technology being a central pillar in achieving the goals of both the Dubai Economic Agenda “D33” and Saudi Vision 2030. As these ambitious digital transformation efforts accelerate, so too does the complexity and risk of cyber exposure.

To secure these infrastructures, organisations must consolidate visibility across all environments into a single, continuous view. They should utilize advanced capabilities to identify and trace the logical attack paths that span across different security domains, connecting weaknesses in the cloud with on-premises assets. Crucially, they must prioritise remediation based on the exposures attackers are most likely to exploit, such as critical misconfigurations and excessive permissions.

This strategic, unified approach allows organisations to move from a reactive state to a proactive and predictive one, ensuring that the velocity of digital change is matched by the resilience of their security posture.

With the rise of OT-based cyberattacks, how urgent is the need for dedicated OT security solutions in the Middle East?

The need for dedicated Operational Technology (OT) security solutions in the Middle East is critical and immediate. The region’s rapid digitalisation of key sectors like oil and gas, manufacturing, and utilities is fuelling ambitious goals such as the Dubai Economic Agenda “D33” and Saudi Vision 2030. However, this acceleration has created a significant challenge: a major convergence of IT and OT networks. This convergence exposes historically isolated industrial control systems to escalating cyber threats, posing a direct risk to the technological pillars of these national agendas.

Cyberattacks on critical infrastructure can lead to devastating real-world consequences, including physical damage, disruption of essential services, and severe regulatory penalties. To address this, organisations must implement a comprehensive framework that achieves three things: deep situational awareness across all connected OT assets; unified risk context to understand how a weakness in the IT network could compromise an OT system; and strong process integration to ensure IT and OT teams collaborate effectively.

Ultimately, prioritising a comprehensive OT security programme is not just a defensive measure, it is a fundamental operational necessity for maintaining safety, continuity, and the success of the region’s long-term development plans.

What are some of the latest cybersecurity trends you’re observing globally and within the region, and how is Tenable addressing them?

They’re two critical trends shaping the security landscape, especially in the Middle East: the persistent challenge of fragmentation and the seismic impact of AI. These trends play out against a high-stakes backdrop given the region’s national ambitions with “D33” and Saudi Vision 2030. Every new cyber exposure, therefore, carries significant strategic risk to the nation’s future.

First, let’s talk about fragmentation. The modern attack surface is vast, stretching across IT, multi-cloud, OT, and identity systems. When organisations use dozens of scattered, siloed security tools, it actually makes the problem worse, creating more noise and complexity than security. Organisations can overcome this by adopting a unified exposure management programme. This means moving away from point-in-time scanning to gaining a single, continuous source of truth for all risk across the entire environment, cutting through the noise and allowing security teams to be decisive.

Second, there is AI as a dual-use technology. Attackers are weaponising generative AI to launch faster, more personalised, and sophisticated attacks. But the good news is that defenders are fighting back by leveraging AI-driven insights to switch from a reactive to a predictive and proactive strategy. This allows security teams to analyse massive data sets, pinpoint where they are most likely to be attacked next, and neutralise those critical risks before they can impact the digital foundation needed to achieve the region’s ambitious national agendas.

Read: Cybersecurity: Why ‘public-private-people’ partnerships hold the key

More news in food-industry