The Middle East’s cyber security landscape is entering a new phase, defined not only by accelerating digital transformation and artificial intelligence (AI) adoption, but also by growing concerns over sophisticated cyber attacks targeting governments, critical infrastructure and private-sector organisations.
Addressing this issue at GISEC Global 2026, H.E. Dr Mohamed Al Kuwaiti, head of cyber security for the UAE government, outlined how the country is strengthening its cyber resilience through a combination of AI innovation, sovereign cyber capabilities, national preparedness programmes and international collaboration.
“Cyber threats do not respect geography, jurisdiction or diplomatic protocol,” said Al Kuwaiti. “We are here not to serve the UAE only. We are here to serve the cyber security community, society and citizens to protect their data, their privacy and themselves.”
His comments come as regional organisations face a rapidly evolving threat landscape shaped by AI-enabled cyber crime, state-sponsored activity, ransomware campaigns, supply chain compromises and attacks against operational technology environments.
AI: from productivity tool to cyber battlefield
Artificial intelligence dominated discussions throughout GISEC, reflecting its growing role as both a cyber security enabler and a threat multiplier. The UAE has positioned AI at the centre of its national transformation agenda, with Al Kuwaiti reiterating the country’s ambition to become a fully AI-driven nation by the UAE Centennial 2071 programme.
“Fifty percent of our government services need to be agentic in nature. We have already started that journey, and many government entities are already on board,” he said.
However, the rapid adoption of AI is also changing the nature of cyber attacks. “We have seen attacks perpetrated using AI, empowered by AI, whether cyber crime, cyber terrorism or cyber warfare,” said Al Kuwaiti.
According to the Cyber Security Council, the UAE experiences more than 800,000 cyber attacks per day targeting national infrastructure and strategic assets: “Here, we’re not speaking about DDoS attacks. We’re speaking about sophisticated attacks, advanced persistent threats, supply chain attacks, ransomware and wipers targeting critical infrastructure.”
Across the region, organisations are increasingly deploying AI-driven security operations platforms, autonomous threat detection systems, behavioural analytics and security copilots to cope with growing attack volumes and increasingly complex threat actors.
Industry analysts expect AI-powered security tools to become a standard component of enterprise security architectures across the Gulf over the next five years.
Sovereign cyber capabilities gain momentum
A major theme emerging from GISEC was the growing focus on cyber sovereignty. Governments throughout the Middle East are investing heavily in local data infrastructure, sovereign cloud environments and domestically developed security technologies as geopolitical tensions and supply chain concerns continue to rise.
Al Kuwaiti revealed that several new initiatives launched by the UAE cyber security Council and its partners are built around sovereign AI capabilities designed to protect national infrastructure.
“Many of the initiatives we are announcing with our partners are AI-empowered and sovereign in nature, supporting our critical infrastructure and beyond,” he said.
Among the announcements was the release of the UAE’s V7 cyber security model, designed to detect malware, identify vulnerabilities and support penetration testing activities.
“This fine-tuned malware detection model has added great value to us,” Al Kuwaiti said. “When benchmarked against other systems, it ranked highly and achieved more than 94.7% detection accuracy.” The model forms part of a broader national strategy to reduce dependence on external technologies while strengthening domestic cyber capabilities.
Quantum security moves into focus
While AI dominated headlines, quantum computing emerged as another major discussion point at GISEC, for many security leaders, quantum technologies represent both a transformative opportunity and a future cyber security challenge.
“Today, we are speaking about artificial intelligence,” said Al Kuwaiti. “Tomorrow, we will be speaking about quantum. As a matter of fact, there is a whole venue of quantum here.”
“We cannot do this ourselves. We need partners, we need to work together, and that is what creates collective readiness”
H.E. Dr Mohamed Al Kuwaiti, UAE government
Although large-scale quantum computing remains in its early stages, cyber security experts warn that future quantum systems could eventually render many current encryption methods obsolete. This has prompted governments and enterprises worldwide to begin planning migration strategies towards post-quantum cryptography.
The UAE has increasingly positioned itself as a regional hub for advanced research in quantum technologies, with public and private sector organisations exploring quantum communications, quantum-safe encryption and future-ready security architectures. Regional CISOs attending GISEC highlighted growing interest in understanding how quantum developments could affect long-term risk management and compliance programmes.
National resilience through collaboration
Beyond technology, Al Kuwaiti stressed that cyber security resilience depends on preparation, information sharing and collaboration. One of the key pillars of the UAE’s approach has been the development of a nationally coordinated cyber security ecosystem centred around public-private cooperation.
The country’s National Security Operations Centre (SOC) plays a central role in this effort by connecting multiple sectors and facilitating threat intelligence sharing.
“We brought the national SOC to be active, connected to many sectors and able to coordinate information sharing,” said Al Kuwaiti. The UAE has also invested heavily in cyber readiness exercises involving financial services organisations, energy providers and government agencies.
“Before many of these attacks occurred, we conducted numerous cyber drills and exercises. This increased our readiness and demonstrated the strength of our partnerships.”
According to Al Kuwaiti, every significant cyber attack targeting UAE critical infrastructure during recent regional tensions was detected, contained and recovered from through coordinated response mechanisms. “Every single one of those attacks was detected, responded to, recovered from and disrupted,” he added.
Human capital remains critical
Despite advances in AI, automation and emerging technologies, Al Kuwaiti argued that people remain the most important component of cyber resilience: “The human being is still one. We need to upskill them, reskill them and make sure they are ready to leverage these technologies for positive use.”
The UAE has embedded cyber security and AI education into school curricula from kindergarten through secondary education, while expanding national awareness programmes designed to improve cyber hygiene across society.
The approach aligns with what Al Kuwaiti described as the UAE’s five-pillar cyber security framework, built around governance, protection, innovation, capacity building and partnerships. “Our community must be the first line of defence,” he said.
From defence to collective resilience
As governments and enterprises across the Middle East continue to embrace AI, cloud computing and digital services, cyber security leaders increasingly recognise that traditional perimeter-based security models are no longer sufficient.
The message from GISEC 2026 was clear: resilience, collaboration and technological innovation will define the next chapter of regional cyber security.
“We cannot do this ourselves,” said Al Kuwaiti. “We need partners, we need to work together, and that is what creates collective readiness.”
