GISEC Global 2026 arrives at a moment when the Middle East is no longer participating in the global cybersecurity conversation — it is shaping it. Across the halls of the Dubai Exhibition Centre, the region’s security leaders, innovators, and critical‑infrastructure operators converge around a single truth: AI has accelerated the tempo of cyber risk, and the Middle East is responding with a discipline, urgency, and ambition that is setting a new global benchmark. The show floor reflects a region that has matured beyond point solutions and reactive defense. What emerges instead is a unified narrative of sovereign capability, anticipatory strategy, and architectures built for the world that is coming, not the world that was.

Architecture over reaction
For Ramkumar Balakrishnan, CEO of AmiViz, the shift is philosophical. “Reactive security is finished,” he says. “Enterprises need architecture built for the threat environment they face today, not the one from five years ago.” AmiViz enters GISEC with three connected themes: sovereign security architecture, AI‑driven threat defence, and operational resilience — a triad that reflects how regional enterprises are rebuilding their foundations for identity‑centric, AI‑accelerated threats.
AmiViz’s presence at GISEC is defined by live architecture demonstrations rather than slide decks. Balakrishnan emphasizes identity as the new perimeter, AI‑generated phishing as nearly indistinguishable from legitimate communication, and the need for zero‑trust identity frameworks that evolve with attacker behaviour. Partner conversations focus on vertical‑specific threat scenarios across government, finance, and critical infrastructure, with every engagement ending in a concrete next step rather than a brochure. AmiViz’s message is clear: layered, intelligent resilience is the only viable path forward.

Seeing what the adversary sees
For Meriam ElOuazzani, Vice President for META at Censys, visibility is no longer about what defenders can see — it is about what attackers see first. “Organizations are no longer asking whether they have exposure,” she says. “They’re asking what they cannot see yet.” Her theme of Internet intelligence reframes cybersecurity as a question of control: who owns your data, your infrastructure visibility, and your response capability.
At GISEC, Censys highlights authentication as the new battlefield, noting that vishing intrusions doubled in early 2026 and nearly half of breaches involved third‑party exposure. Censys gives enterprises the attacker’s view of their own infrastructure before adversaries exploit it. ElOuazzani describes how meaningful conversations at GISEC often begin with a confession — an unaccounted asset after an M&A integration or exposed infrastructure discovered by a journalist. For Censys, that is where real work begins: mapping blind spots, aligning visibility with governance, and grounding resilience in truth rather than assumptions.

Prevention at the point of interaction
For Ram Narayanan, Country Manager at Check Point Software Technologies, Middle East, prevention must evolve for the AI era. “Detection alone is too late,” he says. “AI‑driven social engineering and identity compromise require prevention at the point of interaction.” Check Point’s AI Network Firewall turns existing firewalls into AI‑aware control points, giving teams visibility into prompts, models, and autonomous agents while applying inline controls to govern usage and protect data.
At GISEC, Check Point demonstrates practical use cases around shadow AI visibility, prompt protection, autonomous agent governance, and hybrid‑environment defence. Powered by ThreatCloud AI, the platform prevents malicious links, impersonation attempts, and AI‑powered campaigns across email, identity, endpoint, cloud, and network. Narayanan’s message resonates across the show floor: secure AI adoption without slowing innovation.

Resilience in the agentic era
For Ayman Hammoudeh, Senior Director, Sales Engineering and Field CISO at Cohesity, resilience is a measurable state, not a slogan. “Agentic AI is now embedded in enterprise operations,” he says. “That creates new dependencies across data, applications, and infrastructure.” Cohesity’s focus on cyber resilience in the AI era helps organizations protect those environments, govern sensitive data, and recover quickly to a trusted state when disruption occurs.
At GISEC, Cohesity introduces the concept of a Minimum Viable Company — identifying the people, systems, and dependencies most critical to operations. Hammoudeh explains that identity‑based attacks and advanced phishing remain highly effective, while AI increases the speed and scale of threats. Cohesity’s approach prepares organizations for disruption by defining clean recovery points and restoring essential services first. Their conversations at GISEC focus on real incident scenarios, helping customers understand where gaps exist and how technology, processes, and partnerships can address them.

Building AI resilience: Secure what’s next
For Hadi Anwar, CPX CEO, resilience must be proactive. “Our theme, ‘Building AI Resilience: Secure What’s Next,’ tackles the urgent need for defence in a shifting digital landscape,” he says. CPX showcases frameworks across AI, physical, and OT security, alongside end‑to‑end cyber resilience capabilities that link directly to business outcomes.
At GISEC, CPX features more than twenty partner pods demonstrating co‑innovated defence capabilities across AI, cyber, OT, and physical security. Anwar emphasizes that escalating AI‑powered attacks and expanding digital footprints mandate resilient defence postures. CPX’s executives lead mainstage discussions on critical‑infrastructure defence, reinforcing that ecosystem collaboration is essential for long‑term maturity. Their message is clear: resilience is regional, and leadership is collective.

Defense at machine speed
For Roland Daccache, Director of Sales Engineering MENA at CrowdStrike, AI has changed the nature of defence. “AI is changing what organizations have to defend and how they defend it,” he says. CrowdStrike’s Falcon Guardian secures AI agents at runtime, where they execute, while its Agentic Identity Provider establishes every AI agent as a trusted identity.
At GISEC, CrowdStrike demonstrates how AI agents execute code, access systems, and move data with real credentials at machine speed. Continuous Identity provides real‑time, risk‑aware enforcement, granting access when needed and revoking it the moment it’s not. Daccache emphasizes coordinated investigations across endpoint, identity, SaaS, cloud, and network — turning what once took hours into minutes. His message reflects the region’s mindset: defence must match the velocity of AI‑driven attacks.

Runtime authorization for autonomous agents
For Mortada Ayad, VP Sales META at Delinea, identity governance must evolve for AI agents. “Authentication tells you whether an agent should have access,” he says. “It doesn’t control what that agent does next.” Delinea showcases runtime authorization, which applies policy at the moment an action is attempted — allowing, blocking, or escalating before execution.
At GISEC, Delinea highlights how enterprises are introducing thousands of non‑human identities through automation and AI agents. Their approach reduces standing privilege, enforces least‑privilege and just‑in‑time access, and governs what identities can do once authenticated. Working alongside regional partners Shifra and Defa3, Delinea emphasizes that identity governance is the control plane for secure AI adoption. Their conversations focus on translating policy into practical controls that limit the impact of compromise.

Unified, AI‑assisted protection
For Elias Tsapsidis, General Manager at ESET Middle East, Greece, Cyprus & Malta, unified protection is essential. “Our focus is unified, AI‑assisted security across endpoint and cloud,” he says. ESET highlights ESET PROTECT, Cloud Workload Protection, enhanced Incident Graphs, AI Advisor, and advanced LiveGuard analysis.
At GISEC, ESET addresses identity and OAuth abuse, AI‑enabled social engineering, and risks around AI agents and skills. Tsapsidis notes rising ClickFix variants, record QR‑code phishing, and thousands of malicious AI skills. ESET responds through prevention, telemetry, XDR, cloud visibility, and contextual investigation. Their conversations prioritize practical demonstrations over technology in isolation, helping customers explore investigation, threat hunting, and response in real environments.

Predict, don’t react
For Ashraf Koheil, VP of Sales META & AUZ at Group‑IB, predictive resilience is the future. “Digitalization and fraud are converging,” he says. “Identity‑based attacks and AI‑enabled threats are merging with financial crime.” Group‑IB’s Innovation Hub showcases Prevyn AI, Cyber‑Fraud Fusion, Incident Management Center, and Cyber Fraud Intelligence Platform.
At GISEC, Group‑IB invites customers and partners to explore live demonstrations, interactive zones, and direct access to regional experts. Koheil emphasizes translating intelligence into action — anticipating adversaries’ next moves and disrupting attacks before escalation. Their approach combines global threat intelligence with regional expertise, helping enterprises strengthen proactive resilience.

Containment as a discipline
For Mohannad Meri, Senior Systems Engineer META at Illumio, containment is the cornerstone of resilience. “Our focus is AI velocity — how organizations defend when attackers exploit weaknesses at machine speed,” he says. Illumio’s platform unites Illumio Insights and Illumio Segmentation to identify lateral‑movement risk and contain breaches in real time.
At GISEC, Illumio demonstrates how it maps application dependencies, surfaces risky communications, and contains compromised workloads. Meri emphasizes that breaches will occur, and containment ensures compromised accounts cannot become pathways to wider disruption. Their conversations connect breach containment with regional priorities such as critical‑infrastructure protection, Zero Trust, and regulatory requirements.

Preemptive security from the network up
For Mohammed Al‑Moneer, Senior Regional Director at Infoblox, preemptive security begins at the network foundation. “It requires more than another alerting tool,” he says. “It requires a trusted platform that connects network context, threat intelligence, and intelligent action.”
Infoblox’s focus at GISEC is showing how DNS can serve as an early control point against identity‑driven attacks, AI‑powered phishing, and rapid impersonation campaigns that now move from exposure to impact at machine speed. By unifying visibility across DNS, DHCP, IPAM and external exposure, Infoblox helps security teams understand what is exposed, what is being targeted, and what should happen next. Al‑Moneer’s message is straightforward: resilience starts with visibility, and visibility starts with the network.

Workforce security as the first line of defense
For Dr. Martin Kraemer, CISO Advisor at KnowBe4, the human layer remains the most critical. “No one needs another shiny new box,” he says. “They need something that actually reduces real‑world risk.” His focus is workforce security — the layer that makes identity, cloud, and AI controls actually work.
KnowBe4’s presence at GISEC centers on securing the entire workforce through content‑driven attack analysis, targeted coaching, and remediation before threats turn into incidents. Kraemer grounds conversations in regional benchmarks and long‑term maturity, emphasizing that credential theft, AI‑compressed attack timelines, and personalized phishing require continuous behaviour improvement rather than one‑off tools. His message is clear: resilience begins with people who are prepared.

AI‑powered automation for hybrid complexity
For Praneeth V., Technical Evangelist at ManageEngine, the region’s biggest challenge is complexity. “Hybrid environments and lean security teams are under pressure,” he says. “Automation is no longer optional.” ManageEngine’s themes — AI‑powered security automation, IAM, and unified visibility — reflect this reality.
At GISEC, ManageEngine demonstrates how Zia Agents automate alert correlation, EDR triage, access reviews, and investigations, freeing analysts for higher‑value decisions. Its Identity Access capability delivers unified access management across hybrid and unmanaged environments, addressing identity‑based attacks that dominate regional breaches. Partner conversations focus on delivering integrated IT‑security platforms that support long‑term maturity, helping organizations govern AI adoption, accelerate investigations, and enforce consistent access policies across diverse environments.

Sanitizing the unseen threats
For Hussam Sidani, Vice President for MENA at OPSWAT, hidden threats pose the greatest danger. “AI‑generated and adaptive threats evolve faster than traditional detection,” he says. “Seemingly legitimate files can conceal malicious content.” OPSWAT’s theme — Sanitize the Unseen — reflects the need to prevent hidden threats from reaching critical systems.
At GISEC, OPSWAT showcases its AI Content Inspector, CIP Mobile Lab, and Nuclear Plant Model Reactor, offering hands‑on demonstrations of deep file inspection, content sanitization, and coordinated IT‑OT protection. Sidani emphasizes layered prevention across email, web traffic, storage, and removable media — the entry points attackers exploit most. The company also invests in regional skills development through complimentary OPSWAT Academy CIP certifications, strengthening practical cybersecurity expertise and helping critical‑infrastructure operators build long‑term resilience.

Sovereign resilience through local capability
For Alexey Usanov, Head of Positive Labs R&D Center at Positive Technologies, cybersecurity is inseparable from sovereignty. “National resilience means controlling your infrastructure, your data, and your technology,” he says. “You cannot outsource sovereignty.” His message reflects a regional shift toward self‑reliance.
At GISEC, Positive Technologies introduces a comprehensive laboratory for security research on microelectronics and embedded systems, giving customers a full R&D center and training ground for reverse‑engineering specialists. Usanov emphasizes long‑term maturity through joint research programs, trained engineers, and local teams capable of verifying their own hardware — a model that strengthens supply‑chain security and reduces dependence on external validation. His approach is collaborative: sharing tooling and methodology openly to help the region inspect and secure its own digital foundations.

Skills for the AI‑accelerated future
For Ned Baltagi, Managing Director for META at SANS Institute, the region’s challenge is preparing people for technologies reshaping defence. “AI is changing how organizations operate and how attackers behave,” he says. “Skills must evolve with it.” SANS brings the Gulf Edition of the AI Security Maturity Model, the AI Cybersecurity Career Guide, and new GIAC certifications focused on offensive AI and model integrity.
At GISEC, SANS instructors lead certified training, technical workshops, and case studies across AI, ICS/OT, cloud, containers, and third‑party risk. Baltagi highlights quantum readiness as a rising priority, supported by executive briefings and practical workshops on quantum‑resistant algorithms. Their partnership with the UAE Cybersecurity Council reinforces a long‑term commitment to regional capability development, ensuring practitioners can secure AI systems, protect critical infrastructure, and translate technical risks into business priorities.

Identity as the control plane for AI
For Dr. Kamel Heus, Vice President of Sales for MEA at Saviynt, identity governance has become the defining challenge of the AI era. “Non‑human identities already outnumber humans 82 to 1,” he says. “Identity must become the control plane for AI.” Saviynt’s showcase includes Zuma, the Agent Access Gateway, and its converged Enterprise Identity Cloud.
At GISEC, Saviynt demonstrates how continuous access monitoring, zero standing privilege for AI agents, just‑in‑time access, and biometric verification limit what compromised credentials can exploit. Heus uses live demos and short talks to deepen partner engagement and educate the market on identity‑centric security for agentic AI. His message resonates across the region: identity is no longer a feature — it is the architecture that determines whether AI accelerates innovation or accelerates risk.

Unified defense for an AI‑driven threat landscape
For Harish Chib, Vice President for Emerging Markets at Sophos, the region’s threat landscape demands consolidation. “Identity compromise, ransomware, phishing, and shadow AI require unified defence,” he says. Sophos showcases innovations across AI‑native defence, unified security operations, next‑generation SIEM, XDR, MDR, and AI governance.
At GISEC, Sophos engages customers and partners through strategic discussions on ransomware resilience, MDR, platform consolidation, and coordinated protection across endpoint, network, identity, email, cloud, and third‑party environments. Chib emphasizes that fragmented tools create blind spots attackers exploit. Sophos Fusion’s unified architecture helps organizations reduce complexity, accelerate investigations, and strengthen coordinated response — a model built for the speed and scale of AI‑enabled threats.

Exposure management at machine speed
For Walid Natour, Director of Security Engineering at Tenable, exposure management is now the region’s most urgent priority. “Attackers exploit toxic combinations across identity, cloud, and OT,” he says. “Legacy tools create noise instead of clarity.” Tenable highlights exposure management powered by agentic AI like Hexa AI, unifying visibility across cloud, identity, OT, and AI systems.
At GISEC, Tenable demonstrates how Tenable One maps complex relationships, isolates critical chokepoints, and automates remediation to neutralize identity‑based risks and AI‑accelerated exploits. Natour emphasizes hands‑on exposure management demonstrations that help leaders operationalize risk reduction with clear, business‑aligned metrics. His message is direct: proactive exposure management is the only way to stay ahead of AI‑driven risk.

Understanding threats, not just detecting them
For Hüseyin Fatih Akar, Senior Security Product Manager at VMRay, the future of defence lies in clarity. “Threat intelligence must be built from observed behaviour, not generic feeds,” he says. VMRay’s UniqueSignal feed delivers behaviour‑verified indicators that reflect real threats facing regional enterprises.
At GISEC, VMRay demonstrates how behavioural analysis defeats evasive malware, enriches EDR alerts, triages phishing at volume, and supports incident response with full execution visibility. Akar emphasizes that long‑term maturity is built through workflows that hold up under real conditions, junior analysts who can operate at a higher level, and automation teams trust enough to leave running. His philosophy is simple: understanding a threat’s behaviour is the foundation for every AI‑driven workflow that sits on top.

Quantum Resilience Over Uncertainty
For Dr. Victor Juan Mateu, the shift is foundational. “The transition to quantum‑resistant cryptography is no longer optional,” he says. “The UAE has already established the governance needed to ensure readiness for the quantum era — now enterprises must accelerate adoption.”
TII’s strategy for 2026 reflects a region where identity‑based attacks, AI‑driven threats, and advanced phishing campaigns are escalating in sophistication. Mateu highlights how AI now amplifies both attacker capability and defender productivity, demanding equally intelligent countermeasures. Their solutions span agent‑identity frameworks that strictly govern access and AI‑powered applications for deep security analysis and policy adherence. At GISEC, TII is showcasing global quantum‑resistant cryptography trends and the UAE’s alignment with leading nations, helping organisations build migration roadmaps that accelerate adoption while minimising operational disruption.
GISEC Global 2026 makes one reality impossible to ignore: the Middle East is no longer following cybersecurity’s global trajectory — it is setting it. Across quantum‑resistant cryptography, agentic‑AI governance, identity‑centric architectures, sovereign capability, and unified defence platforms, the region’s leaders are building security models engineered for machine‑speed threats and geopolitical complexity.
What emerges from this year’s conversations is a shared regional doctrine: resilience as architecture, identity as the control plane, AI as both catalyst and adversary, and sovereignty as the foundation for long‑term maturity. Every exhibitor, every keynote, every partner engagement reinforces the same message — the future belongs to those who can anticipate, adapt, and collaborate faster than the threats that challenge them.
GISEC Global 2026 doesn’t just showcase what’s next. It shows who is building what’s next — and the Middle East is firmly at the center of that future.











