Data sovereignty starts with on-premises security
Rashed Al Momani, General Manager for Middle East at Kaspersky, explains why on-premises cybersecurity remains a strategic option for businesses prioritising sovereignty, resilience and operational control.
15 June, 2026
TT
16
The Gulf’s digital economy is expanding at an exciting, yet daunting speed. Governments are digitising public services, critical infrastructure is becoming increasingly connected, and businesses are relying on data to drive everything from operations and decision-making to customer experience and growth. Yet as organisations accelerate their digital ambitions, a fundamental question is moving from the server room to the boardroom: who ultimately controls the data that powers the modern organisation?
In an era defined by AI-driven cyberthreats, geopolitical uncertainty, and increasingly stringent regulatory expectations, this changing reality is reshaping how organisations think about data sovereignty and, ultimately, how they choose to secure their most critical assets. This is why on-premises cybersecurity solutions remain the most durable strategic play, particularly among organisations seeking greater control over sensitive data, critical systems, and long-term operational resilience. Here are four key factors why on-premises solutions are driving this shift:
Data sovereignty is reshaping cybersecurity decisions
As organisations expand their digital footprints, questions around where data is stored, which jurisdictions govern it, and how it moves across borders are becoming increasingly important. This is especially critical in sectors such as government, military, defence, healthcare, financial services, energy, telecommunications, and other critical infrastructure industries, where operational disruption can have far-reaching economic and societal consequences. The growing cyber risk facing these sectors underscores the importance of maintaining greater control over critical systems and data. According to Kaspersky telemetry, 19.6% of industrial control systems (ICS) globally had malicious objects blocked in Q1 2026, with security solutions detecting malware from more than 10,000 malware families targeting industrial automation environments.
Greater control in an increasingly uncertain world
Across the Gulf, organisations are reassessing where sensitive information resides and how critical security infrastructure is managed. While cloud-based security continues to play an important role in many environments, organisations handling highly sensitive, regulated, or mission-critical data are increasingly evaluating whether greater direct control over their cybersecurity ecosystem can support broader resilience objectives.
On-premises cybersecurity infrastructure is increasingly part of that conversation because it allows organisations to maintain ownership of security systems and retain greater control over where sensitive data is processed and managed.
Business continuity depends on operational independence
Cybersecurity is now central to maintaining business continuity during disruption. Threat actors are increasingly targeting supply chains, vendors, and interconnected ecosystems, while geopolitical uncertainty continues to highlight dependency risks.
In this environment, organisations are placing greater emphasis on operational independence and reducing reliance on third-party infrastructure for critical security functions. While cloud-based security remains an important component of many cybersecurity strategies, dependence on external providers can introduce additional points of failure, particularly during service outages, connectivity disruptions, or broader external incidents.
On-premises security helps address these challenges by keeping core security infrastructure under direct organisational control. By eliminating dependency on third-party providers for critical security operations, organisations can ensure that essential security functions continue running even during external internet outages, cloud service disruptions, or other events outside their control. This strengthens business continuity, supports operational resilience, and provides greater certainty that security capabilities remain available when they are needed most.
Greater resilience through controlled architecture
On-premises environments allow organisations to design and operate security infrastructure within tightly controlled architectures. This reduces reliance on external connectivity and limits exposure to broader internet-facing risks. It also enables more predictable operations, stricter governance over updates, and stronger containment of security environments. As a result, on-premises environments can offer an additional layer of resilience by ensuring that core security systems remain fully governed, contained, and under direct organisational control, even in highly volatile threat landscapes.
The ability to maintain visibility, control, and certainty over critical digital assets will continue to shape cybersecurity strategies across the Gulf. As organisations face increasing regulatory pressure, evolving threat landscapes, and growing infrastructure complexity, deployment choices are becoming a strategic decision rather than a technical one. In this context, on-premises cybersecurity remains a key option for organisations that prioritise control, sovereignty, and resilience in how their security environments are designed and operated. At Kaspersky, we recognise that cybersecurity architecture must align with operational reality. Different organisations require different deployment models depending on their infrastructure, risk exposure, and regulatory obligations.
- Rashed Al Momani is general manager for Middle East at Kaspersky





















