Back to all tech news

Commvault’s Fady Richmany on why resilience now beats prevention

The corporate VP and general manager for emerging markets explains why organisations winning in cybersecurity are no longer trying to prevent breaches, they are building to recover from them at speed

Neesha Salian
Neesha Salian

30 June, 2026

Commvault’s Fady Richmany on why resilience now beats prevention
Image: Supplied

TT

16

The window between a cybersecurity vulnerability becoming public and an attacker exploiting it has collapsed from 23 days in 2025 to barely a day in 2026. No human watching dashboards can keep pace with that velocity.

At SHIFT Dubai, Fady Richmany, corporate VP and general manager for emerging markets at Commvault, explains why AI-powered threat detection is no longer optional, and why the real advantage now sits with organisations that have stopped trying to prevent breaches and started building to recover from them at speed.

How can AI help identify cybersecurity threats faster? Please provide a percentage and how many threats has it been able to identify in this year so far?

The honest answer is that speed has become the whole game. The window an attacker needs to move from a vulnerability becoming public to actively exploiting it has fallen from around 23 days in 2025 to barely a day in 2026, according to PwC, and a human watching dashboards simply cannot keep pace with that anymore. What AI does well is sit across enormous volumes of data and identity activity and recognise the patterns that signal something is wrong. This would include aspects like an unusual access request, or a privilege that quietly changes, or data that starts moving when it should be sitting still. AI surfaces those signals in near real time rather than days later, and that is the difference between containing an incident and explaining one afterwards.

The industry numbers support this. IBM’s 2025 Cost of a Data Breach report found that the global average breach cost fell by 9 per cent year on year, the first decline in five years, and the reason was faster detection and containment driven by AI-enhanced tools. The organisations using AI and automation extensively identified and contained their breaches 80 faster than everyone else and saved close to $1.9m in the process. The catch is that only about a third of organisations are using it that way today, so the advantage still sits with a minority who have embraced it.

At Commvault, we put AI to work in exactly this place, watching for anomalies across data and identity, drawing on third-party threat intelligence so we are never relying on a single view, and pointing customers to a clean recovery point the moment something looks wrong.

What best practices should organisations adopt when implementing AI-related cybersecurity solutions?

Start with the data, because every AI system is only as trustworthy as the data feeding it. If that data is poisoned or quietly tampered with, the integrity of everything downstream is compromised, so you need to know what you hold, classify it, and govern who and what is allowed to touch it before it ever reaches a model or an agent. That governance piece is exactly why we recently brought Satori into the portfolio.

The second thing is identity, and I would place it close to the top. AD is one of the hottest threat vectors for bad actors to exploit. Nine out of ten attacks target AD because it controls access to data, systems, and applications – without it, business operations can grind to a halt. Agentic AI is multiplying the problem, because every autonomous agent you deploy is effectively a new identity, a non-human one that lives on data and becomes its own door into the environment.

Protecting identity on its own is no longer enough. It has to be wired together with your data security and your recovery so that the three areas work as one discipline rather than three teams who only meet during a crisis.

The third is to accept that you will be breached one day and to build for that eventuality well in advance. Strong walls are necessary and you should still build them, but I always say that resilience begins where security ends. So, the real question becomes, how cleanly and how quickly you can recover when something gets through? That means testing recovery continuously rather than once a year, keeping a known clean copy you can actually trust, and rehearsing with the security and infrastructure teams in the same room. We wrap all of that into what we call resilience operations, or ResOps, which treats resilience as a living operating model built on people, process and technology rather than a tool you switch on and forget.

What are some common challenges and mistakes made by organisations in deploying AI cybersecurity solutions?

The most common and most damaging mistake is leaving the work in silos. In a large enterprise, you typically find one team running the collaboration platforms, another running infrastructure, another handling backup and recovery, another in security operations, and another in analytics. On an ordinary day, that division of labour looks perfectly sensible. The moment a cyber incident lands, it becomes chaos, because five or six departments who have rarely spoken to each other suddenly have to coordinate while forensics are still working out what happened and how far it spread. We call that the ‘IT collision’, and if those teams have never run the drill together, it is the hardest position an organisation can find itself in.

The second mistake is pouring the entire budget into prevention. I have seen organisations spend a lot building the highest possible wall around the castle, and they still get breached, because someone always finds a way in. That money would go a great deal further if some of it were redirected toward the dark day when the breach actually arrives, so that the answer to “what now” is a resilient operation that can restore identity, data and operations at speed.

The third is deploying AI on top of data that nobody is governing. IBM found that 97 per cent of the organisations that suffered an AI-related breach lacked proper access controls around those systems, and that most had no governance policy in place at all. People rush to switch on the capability and worry about who can reach the underlying data afterwards, which is precisely the wrong order to do it in. Instead, organisations need to establish governance before deployment, with clear controls around data access, identities, and accountability. AI is only as trustworthy as the data and safeguards behind it.

What are some emerging AI cybersecurity trends?

The trend underneath all the others is the explosion of machine identity. We have spent years learning how to secure human users, and now every AI agent we deploy arrives as a new non-human identity that breathes on data and has to be governed and protected like any other. G42 Group CEO Peng Xiao has talked about building and deploying a billion agents, and when you sit with a number like that you realise the attack surface is expanding faster than most security models were ever designed to handle.

Alongside that, attackers now have frontier AI in their hands, which is why the time from a vulnerability becoming public to it being exploited has collapsed from weeks to roughly a single day. The defensive response is AI against AI, using intelligence to spot the anomaly and point to the clean recovery point faster. We are also seeing data governance move to the front of the conversation, because both the value and the risk sit in the data feeding these models, and organisations are starting to govern how that data is used before it reaches an agent rather than after the fact.

Looking a little further out, resilience itself is becoming more predictive and more automated, with systems that can forecast where a recovery might fail and increasingly detect, validate and recover with far less human intervention. In the Middle East region, there is a particularly strong thread around sovereignty, where each country sets its own rules on where data lives and how it can be accessed, and the technology has to adapt to each of those rather than assume one model fits everyone.

What’s next for your business?

We are committed to our work for our customers and partners in the Middle East, and our SHIFT event in Dubai last week was the clearest signal of that. We used the keynote to talk about resilience reimagined for the AI era, we heard Dr Mohamed Al Kuwaiti, head of Cyber Security for the UAE Government, set out the national picture with the UAE absorbing close to 800,000 attacks a day, and we announced the Commvault Innovation Centre of Excellence with the UAE Cyber Security Council in Abu Dhabi. That centre matters to me personally, because it is where we will sit with government and with universities to research, develop and train local talent in cyber resilience, and building that homegrown capability is how a country stays ready over the long term rather than the short.

Beyond that, our focus is on helping customers move from owning a recovery tool to running resilience as a discipline. We are bringing identity, data security and cyber recovery together on a single platform in Commvault Cloud Unity so that recovery is clean, fast and complete when it matters most, and we are continuing to extend that platform into the AI estate itself.

The thread running through all of it is simple to say and hard to do well. Resilience is no longer a back-office insurance policy, it belongs at the centre of how every AI-era business is designed and run, and our job is to keep making that achievable for the organisations and the nations we work with across the region.

Saudi Arabia extends tax penalty waiver until December 2026: Key details revealed

The authority has encouraged taxpayers to review the initiative through its simplified guide, which explains the extension decision, the categories of fines covered and eligibility requirements

Nida Sohail
Nida Sohail

30 June, 2026

Saudi Arabia extends tax penalty waiver until December 2026: Key details revealed

TT

16

Saudi Arabia has extended its initiative to waive tax fines and financial penalties for taxpayers across all tax systems by a further six months, providing businesses and individuals with additional time to regularise their tax affairs and strengthen compliance.

The Zakat, Tax and Customs Authority (ZATCA) announced that the extension follows a decision issued by the Minister of Finance and will take effect from July 1, 2026, remaining in force until December 31, 2026, a Saudi Gazette report said.

Read more-Traveling to Saudi? New cash, gold declaration rules are now in effect

Under the initiative, taxpayers are eligible for exemptions from fines related to late registration under all tax systems, delayed tax payments, late submission of tax returns across all tax regimes, and penalties linked to corrections made to value added tax (VAT) returns.

Eligibility criteria outlined

ZATCA said taxpayers seeking to benefit from the initiative must be registered with the authority for tax purposes, submit all required tax returns, and settle the full principal amount of any outstanding tax liabilities.

The authority added that taxpayers may also apply for an installment plan, provided the request is submitted during the validity of the initiative and all approved installments are paid on their scheduled due dates in accordance with the payment plan approved by ZATCA.

However, the authority stressed that the initiative does not extend to penalties resulting from tax evasion violations, fines imposed under Article 45 of the VAT Law, penalties that were settled before the initiative came into effect, or penalties associated with tax returns due after June 30, 2026.

ZATCA further clarified that even if the initiative is extended beyond December 31, 2026, any future extension would continue to exclude penalties linked to tax returns due after June 30, 2026.

The authority has encouraged taxpayers to review the initiative through its simplified guide, which explains the extension decision, the categories of fines covered, eligibility requirements, installment payment procedures, and practical examples to help taxpayers understand the available relief measures.

ZATCA also urged eligible taxpayers to make use of the extended initiative before it expires on December 31, 2026.

Seven in 10 UAE consumers now prefer digital wallets: Survey

The survey was conducted between March and April 2026 and included 1,050 UAE residents

Rajiv Pillai
Rajiv Pillai

30 June, 2026

Seven in 10 UAE consumers now prefer digital wallets: Survey

TT

16

More than seven in 10 consumers in the UAE say they have become increasingly willing to pay using digital wallets such as Apple Pay, Google Pay and Samsung Wallet instead of cash or physical cards, highlighting the country’s accelerating shift towards digital payments.

According to a survey of 1,050 UAE residents conducted by Dubai-based global insights consultancy SixthFactor, 70.7 per cent of respondents said their willingness to use digital wallets has increased over the past few years.

The research also revealed notable differences across income and education groups, suggesting that while digital payment adoption is widespread, uptake has been strongest among higher-income and more highly educated consumers.

Among households earning Dhs30,000 or more per month, 75.5 per cent said they had become more willing to use digital wallets, the highest level recorded across income groups. By comparison, only 59.1 per cent of consumers earning less than Dhs10,000 per month expressed the same view, creating a gap of 16.4 percentage points.

Education levels also influenced adoption. Consumers with secondary-level education reported a willingness rate of 66.6 per cent, rising to 73.5 per cent among bachelor’s degree holders and 73.6 per cent among those with postgraduate or professional qualifications.

Himanshu Vashishtha, founder and global CEO of SixthFactor, said: “Seven in ten consumers saying they have become more willing to pay with digital wallets is a strong finding, and it reflects how quickly payment behaviour has shifted in the UAE over a relatively short period.

“The more interesting part of the data is where that shift has been less pronounced. The income and education gaps are a reminder that markets do not move at the same speed for everyone. For banks, retailers and payment providers, those segments are where the next phase of real growth lies.”

The survey was conducted between March and April 2026 and included 1,050 UAE residents representing a broad cross-section of income, education and demographic groups. The findings underscore the continued evolution of the UAE’s digital payments ecosystem as consumers increasingly adopt contactless and mobile-first payment methods.

UAE reopens Lebanon travel, Emirates issues advisory: Key details to know

The latest government announcement comes as Emirates has advised customers to expect significantly higher passenger volumes during the summer holiday period

Nida Sohail
Nida Sohail

30 June, 2026

UAE reopens Lebanon travel, Emirates issues advisory: Key details to know

TT

16

The UAE has resumed travel for its nationals to the Lebanese Republic, marking a significant easing of travel restrictions as the country prepares for one of its busiest summer travel seasons.

The Ministry of Foreign Affairs (MoFA) announced that UAE nationals are permitted to travel to the sisterly Lebanese Republic effective Monday, June 29, 2026, while reminding travellers that compliance with mandatory registration requirements remains a key condition for departure.

Under the updated travel procedures, the ministry said UAE nationals must register through the Twajudi service before travelling. Passengers will not be allowed to depart through the country’s ports of exit until the registration process has been completed. The ministry added that failure to register could result in the suspension of travel procedures and legal accountability, a WAM report said.

Read more-Traveling to Saudi? New cash, gold declaration rules are now in effect

UAE nationals are also required to provide all necessary information through the Twajudi service, including their place of residence in Lebanon and emergency contact details. Travellers must notify the Ministry through the service upon their return to the UAE and ensure their information is updated if any changes occur during their stay.

In the event of an emergency, the ministry advised UAE nationals abroad to contact its dedicated emergency hotline at +971 80024 to facilitate a prompt response and timely assistance.

Emirates prepares for busy summer travel season

The latest government announcement comes as Emirates has advised customers to expect significantly higher passenger volumes during the summer holiday period, urging travellers departing from Dubai to allow additional time to complete airport formalities.

According to the airline’s latest travel advisory, passengers should arrive at least three hours before departure from Dubai, as security and immigration processing times may be longer than usual. Emirates also recommends that passengers be at their boarding gate at least 60 minutes before departure.

To minimise delays caused by increased road traffic around Dubai International Airport, the airline has encouraged travellers to plan extra travel time or consider using the Dubai Metro to Emirates Terminal 3.

Emirates is also promoting several check-in options designed to streamline the airport experience. Customers can check in online or through the Emirates mobile app, use self-service check-in and bag-drop kiosks, complete baggage drop up to 24 hours before departure (or 12 hours for US-bound flights), or opt for Home Check-in services.

The airline added that Emirates Skywards members can register for Emirates Biometrics through the Emirates app before travelling to benefit from facial recognition services across the airport. Travellers can also make use of Emirates City Check-in facilities in Ajman and at ICD Brookfield Place in DIFC, with the latter extending its operating hours from July 1.

Emirates further advised customers to ensure their contact information is updated through Manage Your Booking so they can receive the latest travel notifications and operational updates throughout their journey.

IHG to launch its luxury and lifestyle brands in Saudi by 2028

The company operates more than 7,000 hotels globally across 21 brands and has a development pipeline of over 2,300 properties

Neesha Salian
Neesha Salian

30 June, 2026

IHG to launch its luxury and lifestyle brands in Saudi by 2028
Image: Supplied

TT

16

IHG Hotels & Resorts plans to introduce all six of its Luxury & Lifestyle brands in Saudi Arabia by 2028, expanding its footprint in one of its fastest-growing global markets as the kingdom accelerates its tourism transformation under Vision 2030.

The company said each of its luxury and lifestyle brands is either already present or in development in the kingdom, as it deepens its exposure to a market targeting 150 million annual visitors by 2030.

IHG, which opened its first Saudi property InterContinental Riyadh in 1975, now operates 48 hotels in the kingdom with 62 in its development pipeline, making Saudi Arabia one of its largest growth markets globally.

The group said its expansion strategy spans luxury, premium, essentials and extended stay segments, but highlighted luxury and lifestyle as a key growth driver as demand rises for design-led and experience-focused hospitality.

Helping shape hospitality in the kingdom, says IHG exec

“Saudi Arabia is one of the world’s most exciting hospitality markets and one of the most strategically important for IHG,” said Haitham Mattar, MD, Middle East, Africa & Southwest Asia. “We are not simply growing our footprint; we are helping shape the future of hospitality in the kingdom.”

He added that rising demand in the kingdom is shifting toward “distinctive luxury experiences with authentic local character.”

IHG recently opened Kimpton KAFD Riyadh, marking the Middle East debut of the Kimpton brand, while other projects include Six Senses Amaala expected in 2026, Six Senses AlUla in 2027 and Regent Jeddah Corniche in 2027, which will mark the brand’s regional debut.

Hotel Indigo & Residences Al Khobar is also scheduled for 2028 as part of the group’s broader pipeline of luxury openings.

“Luxury & Lifestyle is becoming a defining part of that journey, as guests increasingly seek design-led, culturally connected and memorable experiences,” said Maher Abou Nasr, MD for Saudi Arabia, IHG Hotels & Resorts.

IHG said it has strengthened its regional operating structure with a dedicated Riyadh office opened in 2023 to support owners and partners.

The company operates more than 7,000 hotels globally across 21 brands and has a development pipeline of over 2,300 properties.

In pictures: First Etihad Rail passenger service arrives in Abu Dhabi from Fujairah

Customers have been able to book journeys and purchase tickets through the Etihad Rail mobile application and official website from June 23, 2026

Nida Sohail
Nida Sohail

30 June, 2026

In pictures: First Etihad Rail passenger service arrives in Abu Dhabi from Fujairah

TT

16

The UAE has taken a major step towards transforming domestic travel after the first Etihad Rail passenger service successfully arrived in Abu Dhabi from Fujairah, marking the beginning of a new chapter for the country’s national transport network and wider economic development.

The inaugural trial service departed from Fujairah Station and arrived at Mohamed bin Zayed City Station in Abu Dhabi, with the milestone celebrated by passengers and officials, a WAM report said.

Travellers who took part in the historic journey described the experience as a blend of speed, comfort and reliability, highlighting the significance of becoming among the first passengers to travel on the UAE’s long-awaited national passenger railway.

Network expansion planned across the UAE

The trial service marks the start of a phased rollout of the UAE’s passenger rail network. Scheduled passenger operations will commence on September 30, connecting Abu Dhabi, Dubai, Al Dhaid and Fujairah. The network will then expand to stations in Al Dhafra Region in December 2026, followed by Sharjah in March 2027.

Fares on the Abu Dhabi–Fujairah route will start at Dhs55 for Comfort Class and Dhs120 for Premium Class. The passenger fleet comprises 13 trains, each capable of carrying up to 400 passengers. Customers have been able to book journeys and purchase tickets through the Etihad Rail mobile application and official website from June 2026.

The launch comes less than five years after the UAE unveiled its vision for the UAE Railway Programme under the Projects of the 50 initiative in 2021. Delivering the passenger rail project ahead of schedule reflects the country’s ability to execute large-scale infrastructure developments while supporting long-term economic growth, improving connectivity and creating new opportunities for businesses, investors and communities across the Emirates.

Integrated travel experience

Beyond transportation, the new passenger stations are designed to provide an integrated travel experience. Facilities will include cafés, restaurants, retail outlets and several international brands, complemented by onboard dining services to enhance passenger comfort and convenience.

The project aims to meet the expectations of citizens, residents, visitors and investors while reinforcing the UAE’s position as a regional leader in transport, logistics and infrastructure development.

More news in tech