The end of the password? GCC cybersecurity leaders sound the alarm on identity’s new frontline
From AI-generated phishing to runaway machine identities, six regional security leaders share why the credential is now the single most exploited attack surface — and what organisations should do about it
13 May, 2026
TT
16
When World Password Day was first marked over a decade ago, the prescription was simple: longer passwords, more symbols, fewer birthdays. As the digital community observed the day on May 7, that prescription has aged badly.
Across the GCC, cybersecurity leaders are arguing that the password itself is the problem — and that organisations still treating identity as a user-education issue are protecting the wrong perimeter entirely.
“Attackers are not breaking in anymore. They are logging in,” says Meriam ElOuazzani, vice president for the Middle East, Turkey and Africa at Censys . “Last year, 82 per cent of intrusions involved no malware at all. Credentials were the door, and the door was already unlocked.”
That reframing — from intrusion to authenticated access — sits at the heart of how identity security is being rebuilt across the region. The stakes have moved up the corporate ladder accordingly.
From IT concern to boardroom priority
Across every spokesperson interviewed for this piece, the same theme recurs: identity is no longer an IT department issue. It is a business risk now tracked at board level.
“Identity security is now a core business priority across the Middle East, particularly in sectors such as oil and gas, utilities, and manufacturing,” says Mike Hoffman, field CTO for oil and gas at Dragos.
“Many cyberattacks begin with credential theft, phishing, or password reuse, often allowing attackers to move from IT into OT environments. Because cyber incidents can disrupt operations, impact safety, and cause financial loss, identity security is no longer just an IT issue — it is a business risk that requires executive attention.”
Ezzeldin Hussein, regional senior director, solution engineering for META at SentinelOne, agrees the lens has changed. “Identity and password security have evolved to become a board-level business priority as identity is now the primary attack surface. With cloud adoption, remote work, and expanding digital services, a compromised credential can directly have an effect on revenue, processes, and reputation.”
For Ranjith Kaippada, managing director at Cloud Box Technologies, the case is now about reputation as much as resilience. “Trust has taken a front seat. Even a single credential breach can damage years of reputation that a brand has built. In the UAE, most breaches originate from compromised credentials rather than sophisticated exploits.”
ElOuazzani identifies a structural mismatch behind the urgency. “Cloud acceleration has outpaced identity governance. Organisations expanded fast, often across multiple cloud environments, and the access controls did not keep pace. The exposure is real, and in many cases, it is already inside the environment.”
The passwordless pivot
If there is one consensus this World Password Day, it is that the password’s long tenure is finally drawing to a close. The successor technologies — phishing-resistant multi-factor authentication, FIDO2, biometric passkeys — have matured, and adoption is accelerating.
“Every organisation has suffered from a password breach or phishing attack, and as emerging identity technologies like passkeys and FIDO2 phishing-resistant authentication are now more mature there is a growing movement toward modernisation,” says Chester Wisniewski, director and global field CISO at Sophos. “Traditional MFA methods like time-based codes were often resisted by business leaders as cumbersome, but biometric passkeys are simple to use and gaining momentum.”
His recommendation is the bluntest of the group. “Stop using passwords. They are simply secrets. We are bad at keeping secrets and we are even worse at storing them. Adopt passwordless authentication for both convenience and security, and someday World Password Day can be a thing of the past.”
Jay Reddy, head of growth at ManageEngine, argues that even MFA — once considered the gold standard — is no longer a blanket answer. “MFA is no longer a blanket solution if it can be phished or bypassed. Replacing passwords and vulnerable factors like SMS or email OTPs with phishing-resistant methods such as FIDO2 and passkeys is becoming critical.”
Hussein points to regional infrastructure already supporting the shift. “Businesses are beginning to use identity-first security approaches, such as national digital identity frameworks like UAE PASS, robust verifying methods like FIDO2, and zero-trust principles.”
AI: weapon and shield
Underpinning the urgency is the rapid weaponisation of generative AI. Threat actors are using it to generate convincing phishing campaigns, deepfake personas, and automated credential theft at industrial scale.
“AI is making identity security more important than ever,” says Hoffman. “Threat actors are increasingly leveraging AI-generated personas, fake LinkedIn profiles, and sophisticated social engineering techniques to gain initial access into IT and OT environments. With the rise of generative AI, these tactics are becoming increasingly scalable and convincing.”
Hussein describes a dual-use dynamic. “AI will play two roles — defenders will use it to correlate endpoint, identity, and cloud signals in real time, while attackers will use it to automate phishing, deepfakes, and credential theft.”
Reddy adds the labour-market angle. “AI cuts both ways. It has made it easier for cybercrime to scale, while also increasing reliance on AI within security platforms to keep pace — especially with the documented cybersecurity skills shortage across the GCC.”
For Kaippada, the future lies in adaptive systems that mirror the sophistication of the attackers. “Adaptive identification, which uses behavioural biometrics and contextual cues to evaluate risk in real time, is the way of the future. AI-to-AI authentication — in which machines are used to check other machines — is one change that goes unnoticed.”
The machine identity explosion
Perhaps the most under-discussed shift is the explosion of non-human identities. Every API key, service account, automated workflow, and now AI agent represents a credential — and most organisations have no idea how many are active in their environments.
“Service accounts and application automation have created a proliferation of API keys, often with over-privileged access to company data,” Wisniewski warns. “Modern attackers are targeting these non-human identities and causing massive data breaches. This problem is only likely to get worse with the rapid adoption of agentic AI.”
ElOuazzani sees the same blind spot in client environments. “Most security leaders I speak with cannot tell me how many autonomous agents are active in their environment, let alone what data those agents are touching. That is not a tool problem. That is a structural one.”
Reddy frames it as a question of scale. “As automation scales, agentic AI will increasingly execute tasks independently, expanding the identity surface beyond what traditional governance models were designed to handle.”
What to do to protect yourself
The advice across the group converges on a handful of practical actions.
For Hoffman, it begins with how credentials are constructed in the first place. “Organisations should replace complex passwords with long, memorable passphrases combined with multi-factor authentication. Passphrases are easier for users to remember and harder for attackers to crack.”
For Hussein, it begins with a mindset shift. “Assume that passwords alone are already compromised and act accordingly. Companies should give importance to phishing-resistant verification, use least privilege access, and adopt continuous identity monitoring.”
For ElOuazzani, awareness campaigns are not the answer. “Stop treating this like a user education problem. Every World Password Day, organisations push awareness campaigns, circulate tip sheets, remind employees to use strong passwords. And every year, credentials remain one of the most reliable entry points for attackers. Audit what your organisation’s external infrastructure exposes right now, today, before you send a single internal memo.”
For Reddy, the priority is unifying fragmented identity stacks. “When identities are spread across silos, policy enforcement becomes inconsistent by default. A single, authoritative view of identity enables risk-based access decisions — where access is granted based on context, behaviour, and real-time risk rather than static roles.”
And for Kaippada, the answer is structural. “Stop treating passwords as a primary defence and start treating them as a liability. It is not about stronger passwords — it is about reducing dependence on them altogether to significantly shrink your organisation‘s total attack surface.”
Wisniewski offers the most aspirational close — a future in which the annual ritual itself is obsolete. “Someday World Password Day can be a thing of the past.”
That day is not here yet. But across the GCC, the cybersecurity industry is working — visibly, urgently — to bring it closer.


























