Why cybersecurity has become a boardroom priority across the Middle East
The article explains that cybersecurity has moved into boardroom-level strategic planning across the Middle East, driven by a rise in AI-enabled attacks and digitalisation of regional economies. Security firm Kaspersky warns adversaries are increasingly using AI for phishing, malware development and faster cyberattacks.

Cybersecurity has moved from IT backroom concern to boardroom priority across the Middle East as organisations confront a rise in AI-enabled attacks and more sophisticated threat campaigns. Security firm Kaspersky warned that attackers are increasingly deploying artificial intelligence “to generate phishing campaigns, develop malware and accelerate cyberattacks more broadly,” a message the company underlined while presenting new research at its Cyber Security Weekend for the Middle East.
“Attackers are increasingly turning to AI to generate phishing campaigns, develop malware and accelerate cyberattacks more broadly,” Kaspersky said, stressing that the scale and speed of incidents are changing the calculus for corporate leadership and risk committees.
Executives and directors in the META (Middle East, Turkey and Africa) region are responding by elevating cybersecurity into strategic planning and risk-management discussions rather than leaving it solely to IT departments. The shift reflects concern over automated, AI-driven social engineering and malware development that can rapidly exploit human and technical vulnerabilities across geographically dispersed operations.
Regional context underscores why the change in boardroom priorities is gaining traction:
- The UAE economy expanded 3% in Q1 2026, highlighting continued digitalisation across public and private sectors that increases attack surface areas.
- Dubai recorded 348 million public transport and mobility journeys in H1 2026, reflecting large-scale digital systems that require protection.
- The GCC pharmaceutical market has surpassed $30 billion and is growing by about 7.5% annually, while the regional biotechnology market is forecast to reach $2.6 billion by 2028—sectors that are attractive targets for cyber espionage and disruption.
- Major industrial and infrastructure investments such as Saudi Arabia’s SR9.2 billion ($2.46 billion) electric vehicle manufacturing deals—expected to add to GDP and create more than 2,600 jobs—introduce complex supply chains and digital control systems that need cybersecurity oversight.
These commercial trends intersect with Kaspersky’s findings: automated phishing and AI-assisted code generation can accelerate attacks and increase the volume of successful intrusions. For boards, the implication is twofold—first, financial and reputational risks are more immediate as digital services underpin core operations; second, traditional cybersecurity metrics and governance frameworks must be updated to account for AI-driven threat dynamics.
Organisations that have already reacted are broadening their response beyond technical controls. Boards are expanding incident response playbooks, investing in continuous monitoring and threat intelligence, and mandating tabletop exercises that include scenarios driven by AI-augmented adversaries. Cyber insurance, third-party risk management, and executive training on cyber risk are also being elevated as part of enterprise risk frameworks.
Looking ahead, industry observers say the emphasis on cybersecurity at the board level will likely deepen as AI tools become more accessible to attackers and as regional digitalisation accelerates. Executives will need clearer metrics to assess cyber preparedness, and boards will increasingly demand evidence that security investments reduce enterprise risk—not only by hardening infrastructure but also by improving organisational resilience to rapid, AI-enabled campaigns.
Related Startups
Stay in the loop
Join our weekly newsletter and get the latest MENA startup news, funding rounds, and insights delivered straight to your inbox.