
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.

Organisations across the UAE and Saudi Arabia are accelerating their adoption of artificial intelligence (AI), but many are doing so without the security foundations needed to manage the risks that accompany these deployments, according to Sam Tayan, regional vice-president for META at Illumio.
Summary
As boards and executives push for faster AI implementation to drive efficiency, automation and innovation, security teams are being challenged to maintain visibility and control across increasingly complex environments. Tayan warns that the speed of adoption is often outpacing organisations’ ability to understand how AI systems interact with sensitive data, business applications and third-party services. “Organisations are most exposed around data, APIs [application programming interfaces] and access controls,” said Tayan.
“Many are rushing to connect AI systems to sensitive information, business applications and third-party services without fully understanding those dependencies.” According to him, AI is not necessarily creating entirely new vulnerabilities, but it is amplifying existing weaknesses within enterprise environments. “If organisations don’t understand how those systems interact or what access AI has been granted, they’re effectively expanding their attack surface at machine speed. AI doesn’t necessarily create new risks, but it can magnify existing weaknesses and allow them to spread at far greater speed and scale.” Visibility must extend beyond monitoring tools Tayan argues that many organisations mistakenly view visibility as simply having dashboards, alerts and monitoring tools in place.
In reality, security leaders need a much deeper understanding of how systems, applications, identities and data interact before approving AI deployments. “Before approving an AI deployment, security leaders need to understand three things: what the AI can access, what it can connect to, and what happens if it’s compromised,” he added. “Too often, visibility is reduced to dashboards and alerts when the real requirement is context.” This means security teams must be able to map how data, APIs, applications and identities connect across the environment, understand where trust relationships exist, and identify how those relationships could potentially be exploited.
“The goal is not simply to observe activity, but to understand the potential impact of an AI system’s behaviour,” said Tayan. “Without that context, organisations risk deploying AI into environments they don’t fully understand, making it far harder to predict, contain or recover from a security incident.” The challenge is becoming increasingly important as AI projects rarely operate in isolation. Generative AI assistants, customer service platforms and automation tools often require access to cloud services, internal databases, identity systems and customer information, creating a broader attack surface that organisations must manage.
From prevention to containment Tayan believes organisations must also rethink their approach to cyber security by accepting that breaches are inevitable and focusing on limiting their impact. “Effective breach containment means assuming an attacker, or a compromised AI system, will get in, and designing your environment accordingly,” he said. “The objective is to stop a single compromise becoming an organisational crisis.” Tayan points to segmentation and least-privilege access controls as critical measures for reducing the potential blast radius of an attack.
“That starts with understanding how data, identities, applications and AI systems are connected, then using segmentation and least-privilege access to prevent lateral movement and reduce potential blast radius,” he said. Beyond preventive controls, organisations also need the ability to respond quickly when incidents occur. “If an AI system, workload or account is compromised, security teams must be able to quickly identify the risk, isolate affected systems and contain the impact before it spreads,” said Tayan.
“In an AI-driven world, resilience is increasingly defined not by whether a breach occurs, but by how effectively you can limit the blast radius when it does.” Boards urged to prioritise resilience The discussion comes at a time when cyber incidents are becoming increasingly costly. IBM’s 2025 Cost of a data breach report found that the average cost of a data breach in the Middle East has reached $7.29m USD, with security complexity, AI adoption and shadow AI among the factors contributing to higher costs. For Tayan, this means boards need to look beyond AI deployment targets and focus on organisational resilience.
“The first thing boards need to recognise is that AI doesn’t just introduce new capabilities; it accelerates both good and bad outcomes,” he said. “If organisations deploy AI on top of poorly understood data flows, excessive privileges and weak internal controls, they’re effectively scaling cyber risk alongside innovation. “Boards should focus less on how quickly AI can be deployed and more on whether the organisation can remain resilient when something goes wrong,” said Tayan.
“That means investing in observability, segmentation and containment strategies that limit the impact of a breach.” As AI adoption continues to gather pace across the Middle East, he believes the organisations best positioned for long-term success will be those that balance innovation with security readiness. “In an era of machine-speed attacks, the organisations that succeed won’t be those that deploy AI the fastest, but those that can contain the consequences when something inevitably goes wrong,” said Tayan. Read more about the UAE AI infrastructure investment in the Middle East enters a new geopolitical reality : As the region builds large-scale compute capacity, technology leaders are focusing on resilience, supply chains and semiconductor dependencies.
UAE positions cyber security as pillar of national resilience and digital growth : Strategic investment and coordination reinforce the country’s ability to withstand complex cyber threats.
KazaSec's take
Incidents like this rarely start with the headline event itself, they usually trace back to an exposed remote-access endpoint, an unpatched perimeter system, or a credential phished weeks earlier. The organizations that recover fastest are the ones that tested their defenses and their incident response plan before they needed them.
Coverage details
Related security advisories
Relevant from KazaSec
More security news
We help organizations find and fix the gaps before they make headlines.