Abdullah Mohammad Khorami, Chief Business Officer, Salam, explains how his company is fortifying critical aviation and healthcare systems against increasingly sophisticated cyberattacks.
Aviation and healthcare are among the most heavily targeted critical sectors. What unique cybersecurity challenges do organizations in these industries face, and how is Salam helping customers strengthen their cyber resilience?
Aviation and healthcare are lifelines. When systems in either of these sectors are compromised, the consequences extend far beyond data loss; they can directly impact human safety and public trust. It is well established that these two industries are among the most frequently attacked globally, and Saudi Arabia is no exception. The National Cybersecurity Authority (NCA) alone detected and responded to over 2,000 cyber incidents, issuing more than 12,000 proactive cyber alerts and reports to national entities, with common targets including cloud infrastructure, digital public services, and industrial systems facing ransomware and phishing threats. That scale of threat activity underscores the urgency with which organizations in these sectors must act.
For healthcare organizations specifically, the challenge is deeply personal; they are custodians of some of the most sensitive data that exists: patients’ medical histories, personal identifiers, and treatment records. A breach is a violation of patient dignity and trust. Aviation, on the other hand, contends with highly complex operational environments where a single vulnerability in interconnected systems can cascade across an entire network of flights, logistics, and passenger data. At Salam, we approach these challenges through a comprehensive suite of services that span the full cybersecurity spectrum, from defensive and offensive security to Governance, Risk, and Compliance (GRC). Our goal is to build cyber resilience that allows our clients to operate with confidence, even in the face of sophisticated and persistent adversaries.
As airports, airlines, hospitals, and healthcare providers adopt AI, cloud, and IoT technologies, how is Salam ensuring that security is built into these digital transformation initiatives from the outset?
Digital transformation is happening right now, and at remarkable speed. The adoption of AI, cloud platforms, and Internet of Things (IoT) devices is reshaping how these sectors deliver services and manage operations. However, every new technology introduced also expands the potential attack surface, and if security is treated as an afterthought rather than a foundational element, organizations expose themselves to significant risk.
At Salam, our philosophy is clear: security must be embedded from day one of any digital initiative, not bolted on at the end. We offer AI-driven solutions designed to accelerate threat detection and response, enabling early protection before incidents can escalate into full-scale breaches. Equally important is how we manage the intersection of AI and data privacy. Any personal or sensitive data that is processed through AI tools must be rigorously protected, and Salam enforces strict data filtering and protection protocols to ensure that confidential information is never exposed, leaked, or misused through these platforms. Our cybersecurity operations leverage advanced technologies to deliver improved response times and comprehensive threat coverage.
With regulations around data privacy and critical infrastructure becoming more stringent in Saudi Arabia, how does Salam help customers in aviation and healthcare meet compliance requirements while maintaining operational efficiency?
Regulatory compliance is a moving target, and for organizations in aviation and healthcare, the stakes of non-compliance are exceptionally high. Saudi Arabia’s regulatory environment is maturing rapidly, with the NCA’s guidelines and recommendations, including sandbox frameworks, setting a rigorous standard that aligns with global benchmarks such as NIST, GDPR, and the Personal Data Protection (PDP) Law. Navigating this landscape while simultaneously maintaining day-to-day operational efficiency is a genuine challenge for most organizations.
Salam’s approach to compliance is both structured and adaptive. We support our clients in understanding what regulations require and practically implementing, monitoring, and sustaining compliance over time. A critical part of this is training and awareness because technology alone cannot achieve compliance if the people operating within these systems are not equipped with the knowledge to recognize and respond to threats appropriately.
Importantly, we recognize that user behavior in healthcare is fundamentally different from that in aviation. A clinical professional interacting with patient management systems behaves very differently from an airline operations technician managing flight systems. Our clients range from reactive organizations, those who engage us after an incident, to proactive ones who commission 360-degree vulnerability assessments to identify and address weaknesses before they are exploited. Both approaches have their place, but we consistently advocate for the proactive model.
Ransomware and supply chain attacks continue to disrupt critical services worldwide. What strategies and security services does Salam recommend to help organizations in these sectors prepare for, detect, and recover from such threats?
Ransomware and supply chain attacks represent two of the most disruptive and increasingly prevalent threat vectors facing critical sectors today. We have seen these attacks paralyze hospital networks, ground airline operations, and compromise entire ecosystems of interconnected vendors and service providers. The NCA’s securing of over 75 major national and international events reflects just how active and sophisticated this threat environment has become in the region.
Salam’s recommendation begins with a foundational truth: technology is only as effective as the team managing it. The right tools without the right people are insufficient. Beyond leadership, we provide comprehensive training and awareness programs to build a security-conscious culture at every level of an organization. We combine this with the implementation of appropriate cybersecurity technologies and services, all calibrated to the specific operational context and end-user behavior of each client. Understanding how an organization functions, its workflows, its dependencies, and its vendor relationships is essential to building a defense that is both robust and realistic. Preparation, detection, and recovery are a continuous cycle, and Salam’s services are designed to support all three simultaneously.
Healthcare organizations increasingly rely on connected medical devices, while aviation depends on highly interconnected operational technologies. How important is securing these connected environments, and what role does network security play in protecting them?
The convergence of Operational Technology (OT) and the Internet of Things (IoT) in both healthcare and aviation has created environments of extraordinary complexity. In a modern hospital, connected medical devices, from infusion pumps to diagnostic imaging equipment, are continuously exchanging data across networks. In aviation, operational technology governs everything from baggage handling systems to air traffic communication infrastructure. The security of these connected environments is mission-critical.
At Salam, we recognize that traditional IT security approaches are insufficient for OT and IoT environments, which often operate on legacy systems, have limited patching windows, and cannot tolerate downtime. Understanding how devices behave, what they communicate, when, and with what allows us to detect anomalies that may indicate a compromise before it disrupts operations. Network security serves as the connective tissue of this approach, ensuring that the boundaries between IT and OT environments are properly managed and that lateral movement by threat actors is contained. Protecting these connected environments is ultimately about protecting the integrity of the services they enable: patient care and safe air travel.
Saudi Arabia’s Vision 2030 is accelerating digital transformation across both aviation and healthcare. How does Salam see its role evolving as a trusted technology and cybersecurity partner in supporting these national priorities?
Vision 2030 is a blueprint for transforming how Saudi Arabia operates, competes, and serves its citizens. Digital transformation is at the heart of this vision, and as aviation and healthcare organizations accelerate their modernization journeys, the cybersecurity infrastructure underpinning these efforts becomes ever more critical. A digital transformation that is not secure is a vulnerability at national scale.
Salam sees itself as an active contributor to this national mission. Our approach is guided by the NCA’s guidelines and regulations, which serve as the authoritative framework for cybersecurity practice in the Kingdom. This alignment is an active commitment to building security ecosystems that support the ambitions of Vision 2030 responsibly and sustainably. As more national entities embrace digital tools and platforms, with over 1,600 already benefiting from the NCA’s Haseen cybersecurity portal, the ecosystem of organizations requiring sophisticated cybersecurity support will continue to grow.
Looking ahead, what emerging cybersecurity trends should CIOs, CISOs, and business leaders in aviation and healthcare prepare for over the next three to five years, and what practical advice would you offer them to stay ahead of evolving threats?
The cybersecurity landscape of the next three to five years will look fundamentally different from what organizations face today, and leaders who do not anticipate this shift risk being caught unprepared. The single most significant driver of this change is artificial intelligence. As AI becomes more widely available, it is simultaneously empowering defenders and equipping attackers. The attacks of tomorrow will be qualitatively different, more sophisticated, more targeted, and more automated, because AI enables threat actors to analyze vast amounts of available data and identify attack vectors at a speed and scale that was previously impossible.
The way we frame this internally is straightforward: there is now an AI hacker on one side and an AI agentic protector on the other. The question is which side stays ahead. For CIOs, CISOs, and business leaders, our practical advice is this: do not wait for a breach to catalyze action. Invest in building a proactive security posture now, with the right team, the right technology, and a culture of continuous learning and adaptation. Ensure that security is part of every digital investment decision. Stay closely aligned with national regulatory frameworks such as NCA guidelines, and engage with partners who understand both the technical and operational realities of your sector.











