GISEC Global 2026: AI on both sides of the firewall
As GISEC Global 2026 opens in Dubai today under the theme ‘Cyber First: The New Digital Order’, 10 industry leaders tell Gulf Business what is really shaping the region’s security agenda. Their answers converge on a single force moving faster than any control can keep up with: artificial intelligence
16 September, 2026
TT
16
When the Middle East and Africa’s cybersecurity community gathers at the Dubai Exhibition Centre in Expo City from September 16 to 18, it does so at a crucial moment. GISEC Global 2026, the 15th edition of what organisers call the world’s third-largest cybersecurity event, expanded 20 per cent year-on-year, will draw more than 25,000 professionals and 750-plus brands from over 180 countries, under a theme that captures the mood: Cyber First: The New Digital Order.
In its launch announcement, the head of the UAE Cyber Security Council, Dr Mohamed Al Kuwaiti, framed the stakes plainly, describing AI, geopolitical instability and the rapid evolution of digital technology as forces “fundamentally reshaping the cybersecurity landscape.”
The organisers set the tone with a statistic drawn from the World Economic Forum’s Global Cybersecurity Outlook 2026: 94 per cent of organisations expect AI to be the biggest driver of cybersecurity change over the coming year, and 87 per cent already identify AI-related vulnerabilities as their fastest-growing risk.
Ask the companies converging on Dubai what that reshaping looks like in practice, and a striking consensus emerges. “If I had to point to one thing that has reshaped the security and identity conversation across the region this year, it’s AI — and specifically, how fast it has moved from pilot projects to production,” says Dr Kamel Heus, vice-president of sales for MEA at Saviynt, who cites the same WEF figures. For him, they point in one direction: “Identity has to become the control plane for AI, not an afterthought.”
Speed and scale
The first, most obvious change is tempo. “AI is changing the tempo of exploitation more than the underlying objective,” says Meriam ElOuazzani, vice-president for the Middle East, Turkey and Africa at Censys. She points to hard numbers: Verizon’s 2026 Data Breach Investigations Report found vulnerability exploitation has become the leading initial access vector, “accounting for 31 per cent of breaches, while AI is helping compress the time between vulnerability disclosure and exploitation from months to hours.” Recorded Future, she adds, found that 68 per cent of the actively exploited vulnerabilities it tracked in the first half of 2026 “required no prior authentication”, lowering the barrier to attack still further.
For Maher Jadallah, vice-president for the Middle East and North Africa at Tenable, that speed is the defining priority. “The single biggest priority for organisations is managing the explosive speed and scale of AI-driven security threats,” he says. “Advanced AI models now allow attackers to discover and attempt to exploit vulnerabilities at machine speed. Traditional, manual 30-day patch cycles and linear ticketing processes simply cannot keep up.”
Anomali sees the same acceleration from the threat-intelligence side. “As threat actors increasingly use AI to scale and accelerate attacks, from phishing campaigns to CEO impersonation attempts, security teams are under more pressure than ever to do more with limited resources,” says Samer Jadallah, the firm’s vice-president for the Middle East and Africa, at GISEC for the first time this year.
The surface you can’t see
If attackers move faster, defenders’ problem is that they increasingly cannot see where they are exposed. “The major change I have seen isn’t the sophistication of the threat so much as the surface area organisations have to manage,” says ElOuazzani. M&A, third-party access and shadow IT, she warns, “create assets and dependencies that sit outside the inventories and processes security teams rely on” — and attackers “are working from the external view, not the asset register.”
AI itself is now a fast-growing part of that unseen estate. Censys’s 2026 State of the Internet research, she says, found exposure of AI and LLM tools “increased by more than 60 per cent in nine months, from roughly 183,000 to more than 294,000 public IPs across 43 technologies.” Ownership is murkier still: she cites model context protocol (MCP) as a cautionary example, a protocol that “does not require authentication or authorisation by default,” with Censys observing internet-accessible MCP services “advertising capabilities including database queries and command execution.”
The fix, several argue, is a shift in discipline. Tenable’s Jadallah calls it moving “from basic vulnerability discovery to exposure management”, mapping the entire digital footprint to see “which weaknesses actually lead to core business assets,” rather than “drowning in a backlog of theoretical threats.” Sujoy Banerjee, regional business director for the UAE at ManageEngine, makes visibility the foundational priority: “complete and continuously updated visibility” across “users and identities, devices, applications, networks, and infrastructure. Without this visibility, security teams may struggle to identify vulnerabilities, detect unusual activity, or determine which risks require the most immediate attention.”
Identity becomes the control plane
Nowhere is the AI surge more disruptive than in identity. “AI agents and other non-human identities are no longer a niche corner of the identity landscape; they’re becoming the majority,” says Saviynt’s Heus. “The ratio of non-human to human identities already sits at roughly 82 to 1, and it’s climbing fast… Yet around two-thirds of organisations say they lack the tools to govern their AI systems and LLMs properly. You cannot govern what you cannot see.”
Traditional identity management, built for “predictable human behaviour and largely static permissions,” breaks down when agents are “provisioned in seconds, operate continuously without direct human oversight, and call downstream applications and APIs programmatically.”
His prescription, echoed across the show floor, is to treat every agent like a privileged user: give it its own identity, a named accountable owner “from creation through retirement,” zero standing privilege, and runtime authorisation that checks “whether this specific action, by this agent, in this context, aligns with its intended purpose right now.” His headline for GISEC is blunt: identity must be treated as foundational infrastructure for AI, not an afterthought.
ManageEngine’s Banerjee agrees the perimeter has shifted: organisations must protect “not only human identities, but also privileged, machine, and application identities,” with “directory-independent visibility and control” as those identities spill beyond traditional boundaries.
The autonomous SOC and human influence
The flip side of AI-enabled attacks is AI-enabled defence, and much of GISEC 2026’s agenda – Autonomous SOC, Governed AI, Agentic AI – sits here. Anomali’s Jadallah expects “AI adoption within SOC environments to accelerate significantly,” with organisations “moving past experimentation and starting to embed AI directly into their security workflows,” alongside “growing investment in unified data strategies” to fix the fragmented visibility that hampers detection.
But the recurring caveat is governance. “Agentic AI will fundamentally change how security operations teams work,” says Harish Chib, vice-president for emerging markets, Middle East and Africa at Sophos, “bringing greater speed, scale and automation.”
His firm’s “Agentic SOC” principle draws the line clearly: “AI delivers the speed and scale, while human analysts remain responsible for the outcome… The future is not AI replacing defenders; it is AI enabling defenders to operate at machine speed with confidence and control.”
ManageEngine’s Banerjee calls the same idea “governed autonomy”, AI that augments rather than replaces judgement, with “clear thresholds for when human approval is required, particularly for actions that could have a significant operational or business impact.”
Where the digital meets the physical
For operators of critical infrastructure, the AI arms race collides with a domain that tolerates far less risk. “The biggest misconception,” says Bachir Moussa, regional vice-president for EMEA South at Nozomi Networks, “is that OT cybersecurity is simply IT security applied to a different environment. It isn’t. A breach in an operational setting doesn’t just risk data; it can disrupt production, compromise safety, halt operations, and in some cases touch national infrastructure.”
And in the Gulf, he warns, the build-out is testing the safeguards: “extraordinary investment is flowing into energy, transportation, manufacturing, smart cities, and digital infrastructure,” and the real question is “whether [security] can evolve as fast as the connectivity and automation it’s meant to protect.”
Encouragingly, he adds, most regional organisations “no longer treat security as an afterthought, but as a strategic enabler of growth.” That IT/OT convergence, notes Ned Baltagi, managing director for the Middle East, Turkey and Africa at SANS Institute, is one more source of “new dependencies, attack surfaces and governance requirements.”
Beyond protection: resilience, recovery and a regulatory floor
If attacks are inevitable, resilience is the new benchmark, and in the UAE it is becoming mandatory. Sophos’s Chib points to the National Cyber Security Strategy and the roll-out of NCAP, under which resilience “becomes something organisations must demonstrate: that controls exist, that they function together under pressure, and that response times hold up when it matters most.”
For Commvault, that is the whole conversation. “At GISEC Global 2026 we will be engaging with customers and partners on how organisations can move beyond cyber protection towards true cyber resilience,” says Fady Richmany, corporate vice-president and general manager for emerging markets. He expects “recovery speed, AI-driven resilience and operational readiness to become increasingly critical as organisations navigate a more complex threat landscape and prioritise business continuity,” showcasing the firm’s integrated resilience, AI capabilities and “ResOps” recovery-readiness approach.
The unifying instinct is to stop bolting security on after the fact. “Cybersecurity needs to become more proactive and continuous,” says Salah Suleiman, managing director for the South Gulf at TrendAI, showcasing the TrendAI Vision One unified platform and capabilities spanning “AI-powered cyber risk analytics and quantification, virtual patching, and AI security and digital twin technologies.” His warning captures the theme of the week: “As AI adoption accelerates, security cannot be added later. It needs to be built into how AI is designed, deployed and managed from the start.”
The longer game
Two priorities sit further out but demand action now — and GISEC has built dedicated tracks around both, including a Quantum Security Summit hosted by the UAE Cyber Security Council and the Technology Innovation Institute, and a Global Quantum Drill billed as the world’s largest quantum-readiness exercise. The first is post-quantum security.
“The threat of ‘harvest now, decrypt later’ makes post-quantum security an immediate concern rather than a distant issue,” says Tenable’s Jadallah — adversaries can “steal encrypted sensitive data today and store it until quantum capabilities mature.” The starting point, again, is visibility: “continuous asset discovery to inventory all digital assets, sensitive data stores and encryption dependencies,” then hardening access and closing the paths to high-value data.
The second is people. “The priority is ensuring that AI adoption does not outpace AI security maturity,” says SANS’s Baltagi, pointing to capability gaps “at the intersections between disciplines”, cybersecurity and AI, IT and OT, cloud and automation. His answer is a shift “from periodic training toward continuous, role-based development,” because “technology investment alone does not create resilience.”
That, in the end, is the throughline running through all 10 voices and the banner above the door in Expo City. In a “new digital order” where AI sits on both sides of the firewall, the winners will not be whoever buys the most tools, but whoever can see their whole environment, govern their AI and identities from day one, respond at machine speed, and keep a human firmly in charge of the decisions that matter.




















