Human Error and Shadow AI Identified as Primary Cyber Blind Spots as GISEC Global 2026 Concludes in Dubai

UAE

DUBAI — The greatest cybersecurity vulnerability confronting organizations across the United Arab Emirates is neither the inherent complexity of cloud computing nor the sophistication of artificial intelligence models, but rather human error, unmapped data dependencies, and fragmented oversight, regional cybersecurity leaders concluded at the conclusion of GISEC Global 2026 in Dubai.

Security practitioners and enterprise technology executives converged on an uncomfortable reality: the overwhelming majority of modern enterprise breaches do not originate from technical firewall collapses, but rather from organizations failing to track where sensitive data resides or who holds administrative access privileges across external supply chains.

The warnings coincide with findings from a recent IBM cybersecurity study conducted across the United Arab Emirates, which revealed that 96 percent of corporate executives surveyed do not fully understand their organization’s artificial intelligence dependencies across third party software vendors, foundation models, and external compute infrastructure. Furthermore, 74 percent of enterprise leaders reported persistent challenges in complying with national data residency and sovereign governance requirements when migrating information across cloud and border environments.

Industry specialists noted that the acceleration toward hybrid cloud infrastructures saw many regional enterprises prioritize deployment velocity and operational scale over architectural governance, operating on the flawed premise that security controls could be bolted on after operational rollout.

Rajeev Nair, Senior Vice President of Special Projects at sovereign cloud and digital enablement provider Core42, emphasized that enterprise operational risk is shifting from traditional network perimeters to deep architectural visibility. Nair stated that as artificial intelligence becomes deeply embedded in core operations, institutions require comprehensive clarity regarding physical data residency, user access rights, operational controls, and cascading dependencies across external technology providers.

The findings reflect broader cautions issued by Dr. Mohamed Al Kuwaiti, Chairman of the UAE Cybersecurity Council, who reiterated that the human element remains the principal target for threat actors leveraging advanced social engineering, credential harvesting, and AI generated deception. Technical authorities are urging institutions across the Gulf to pivot from perimeter defense alone toward continuous auditing, identity governance, and strict data asset classification to secure expanding digital infrastructures.

Previous
Previous

UAE Cyber Security Council Inks Strategic Pact with Cyble to Elevate National Threat Intelligence and Critical Infrastructure Defense

Next
Next

du Deploys World’s First Six Carrier Aggregation on Commercial 5G Advanced Network in Strategic Partnership with Nokia