Tenable, a cybersecurity firm, is emphasizing the need for organizations to shift their focus from traditional vulnerability management to a more comprehensive approach centered on exposure management and resilience. Gavin Millard, Tenable’s Vice President of Intelligence, highlighted these points ahead of the company’s participation in GISEC Global 2026, a major cybersecurity conference in the Middle East.

Millard noted that the Middle East is experiencing rapid digital transformation, driven by significant investments in artificial intelligence (AI), cloud infrastructure, smart cities, and interconnected technologies. While these developments offer substantial opportunities for innovation and economic diversification, they also increase the complexity of the cyber environment, posing new challenges for security teams.

At GISEC, Tenable plans to present strategies for moving beyond reactive, segmented security measures toward unified exposure management. This approach integrates vulnerabilities, identity risks, misconfigurations, asset criticality, and attack pathways to provide a holistic understanding of cybersecurity risk. According to Millard, simply identifying vulnerabilities is no longer sufficient; organizations need to understand which potential exposures attackers could exploit and the possible business impact.

The acceleration of AI adoption in the UAE and broader Gulf region presents additional security challenges. Millard pointed out that AI itself is not the primary risk; rather, the issue lies in managing the access permissions granted to AI systems. Many organizations incorporate third-party AI components without proper oversight, sometimes granting administrative privileges that go largely unaudited. In sectors such as government, finance, and healthcare, this creates over-privileged identities sitting near sensitive data and critical systems, effectively expanding the attack surface. Millard urged that AI components be treated as part of identity governance to mitigate these risks.

The region’s investments in smart cities and critical infrastructure also amplify the need for cyber resilience. As interconnected systems spread across multiple cloud environments, traditional perimeter defenses no longer align with organizational boundaries. Tenable’s data indicates that 82% of organizations operate hybrid environments and 63% use multiple cloud providers—a trend reflected globally but accelerated in the Middle East. This reality means that a vulnerability in one cloud account could cascade to affect vital services such as traffic management or utility substations. Cyber resilience, Millard emphasized, involves understanding the pathways that lead to service disruptions rather than simply adding more controls.

Looking ahead, Millard forecasted that cybersecurity will continue to evolve significantly over the next five to ten years. He anticipates increased automation in both attack and defense activities and a shift toward continuous validation of security controls. The human role, he said, will increasingly focus on prioritizing protection for critical assets. Identity management will emerge as the cornerstone of security, given that most entities within IT environments will be software-based, making access control the new perimeter.

For organizations in the Middle East, Millard advised developing a comprehensive inventory of assets across IT, cloud, identity, operational technology (OT), and AI systems. Strengthening governance over access rights and embedding security considerations early in transformation projects are essential steps, as retrospective fixes tend to be significantly more costly.