As AI adoption accelerates across the Gulf, the cybersecurity conversation is shifting from prevention alone to resilience, governance and the ability to respond at machine speed. For Sultan Mahmood Malik, chief security officer at Huawei Gulf North, the emerging risk is not one technology in isolation but the convergence of AI-powered attacks, cloud expansion, critical infrastructure exposure and increasingly interconnected digital systems.
In this interview, Malik discusses how AI is changing the economics of cyber threats, why boards need to treat resilience as a business responsibility, the growing sophistication of ransomware, and the security implications of the Gulf’s rapid investment in AI, cloud and data centres. He also explains why organisations should already be preparing for quantum-era risks and argues that cybersecurity frameworks will need to become more adaptive as the threat landscape evolves.
As companies across the UAE and Gulf accelerate their adoption of AI, what new cybersecurity risks are emerging that business leaders may still be underestimating?
Malicious actors are already using AI to automate reconnaissance, draft convincing phishing content and scale social engineering that once required real time and skill to execute. That changes the economics of cyber threats: work that used to take a determined adversary days or weeks can now run continuously, against many targets at once. Frontier AI models have shown strong vulnerability discovery capabilities, and on average the newly discovered vulnerabilities can be weaponised within four hours.
At the same time, as organisations deploy AI systems of their own, new categories of risk emerge around the models and data behind them. For example, prompt injection, data leakage and non-compliant outputs are active design considerations.
Huawei addresses these concerns by enhancing our secure-by-design approach with AI capabilities throughout the R&D process, leveraging harness engineering to strengthen our world-class vulnerability management capabilities and increasingly embedding native security capabilities into our solutions; all of these measures significantly strengthen our customers’ overall security posture. This reflects our broader approach of using AI for Security while ensuring Security for AI.
Furthermore, Huawei addresses AI security challenges through layered guardrails covering data security, model security, model risk management, application security and operations, which are built on four roots of trust: encryption engines, confidential computing, trusted computing and trusted interconnection.
This approach is backed by sustained investment. Huawei allocates around 5 per cent of its annual R&D investment to cybersecurity and privacy protection, amounting to approximately $10bn over the past decade. These efforts are supported by more than 3,800 cybersecurity and privacy protection specialists worldwide.
Huawei is talking about moving from cyber defence to cyber resilience. What does that shift mean in practical terms for a CEO or board, and how should companies measure whether their businesses can actually withstand and recover from an attack?
For years, cybersecurity conversations centred on prevention – firewalls, detection tools and patching faster than malicious actors could exploit. That mindset assumed a determined threat could eventually be kept out.
But genuine resilience starts from a different premise: that disruption will happen, and the real test is how quickly the business can detect and contain it while continuing to operate.
For Huawei, built-in resilience means moving from post-incident repair to active architectural defence. Security frameworks must be adaptive and capable of automated evolution, helping critical business operations remain online even during machine-speed attacks.
For a CEO or board, that shifts cybersecurity from a function owned by IT into a governance responsibility owned by the business. It means asking which services genuinely cannot go down, how long the organisation can tolerate an outage before it becomes existential, and whether recovery has actually been tested under realistic conditions. Ultimately, those preparations determine whether an organisation proves resilient or becomes a victim.
Measurement follows from those questions, and it starts before an incident happens. Was the environment secure by design, with native security capabilities rather than added afterwards? How agile are the controls, and can they detect and adapt to new attack patterns? Key indicators include recovery time and recovery point objectives for critical systems, the time required to detect and contain an incident, and the results of regular simulation exercises. Together, these provide measurable evidence of resilience.
Resilience is proven under pressure, and boards that ask for evidence of both preparation and recovery, not just assurance of protection, are asking the right question.
Ransomware remains one of the biggest threats to business continuity. Are attacks in the Middle East becoming more sophisticated, and which sectors are currently most exposed?
The region is not immune to ransomware threats. That is because their nature and sophistication have changed. AI is enabling attackers to automate reconnaissance, craft more convincing lures and move faster once inside a network, while double-extortion tactics that combine encryption with data theft have become standard practice rather than the exception.
Sectors that cannot tolerate downtime, including critical infrastructure, government services, finance, healthcare and oil and gas, are consistently the most exposed, because operational continuity is what ransomware is designed to exploit. Attackers increasingly target backups directly, on the assumption that an organisation without a viable recovery path is more likely to pay.
That’s why we developed the industry’s first Multilayer Ransomware Protection solution, which counters attacker tactics at every stage, from intrusion and spread to infection and compromise of the production system, and ultimately, backups themselves. It works through active collaboration between network and storage, rather than relying on any single control, to achieve zero data loss.
The UAE is investing heavily in AI, cloud infrastructure and data centres. How do you secure this rapidly expanding digital infrastructure without slowing innovation and adoption?
Security and innovation are treated as opposing forces more often than they should be. This happens when security is treated as an afterthought, rather than embedded in the process from the outset. At Huawei, we believe in a secure-by-design approach, where security is considered as part of the innovation process rather than as an item to check off a list.
This is particularly important when building large-scale national or enterprise infrastructure, especially infrastructure supporting sovereign clouds, AI and associated data centres. Security needs to be embedded at every layer: within the cloud platform itself, in the underlying computing infrastructure through approaches such as confidential computing, across data and network security, and through end-to-end monitoring and governance.
Responsible AI governance is also essential as AI moves from generating content to operating through autonomous agents. Security must therefore extend beyond monitoring what AI says to governing what it does, with clear controls over identity, privileges and execution and human oversight retained for high-risk decisions. Huawei’s AI management system achieved ISO/IEC 42001 certification in March 2026, reinforcing our commitment to systematic and responsible AI governance.
What do you see as the biggest cybersecurity threat to the Gulf — AI-powered attacks, attacks on critical infrastructure, supply-chain vulnerabilities, quantum-related risks or something we are not yet paying enough attention to?
If we had to choose a single label, AI-powered attacks would be the obvious answer, with quantum computing also emerging as a significant concern. But that slightly misses the point. The more accurate picture over the next three to five years is convergence.
AI isn’t a new, isolated category of threat; it’s a force multiplier acting on vulnerabilities that already exist across products, identity, and the growing interdependence between cloud, data centres and critical infrastructure. Quantum computing presents a different emerging challenge, particularly to the confidentiality of communications and data.
Organisations should begin preparing now by identifying where legacy cryptography is used, prioritising long-lived sensitive data and building crypto-agile architectures that can accommodate new algorithms as standards and technologies evolve.
As economies across the Gulf become more digitally interconnected, an incident in one system has the potential to cascade into others. That’s why we need to think about security as “Secure by Design, Resilient by DNA”. Organisations need dynamic, evolving and adaptive cybersecurity governance frameworks that can keep pace as technology and the threat landscape evolve, while continuing to support organisational functions and business objectives as paradigms shift.