As cyber threats evolve rapidly, particularly with the rise of artificial intelligence, organizations in the Middle East and Africa are increasingly focusing on enhancing cybersecurity resilience across critical infrastructure. Harish Chib, Vice President for Emerging Markets, Middle East & Africa at Sophos, highlighted these trends in the lead-up to GISEC 2026, emphasizing the growing complexity of cyberattacks and the need for coordinated defensive strategies.
Chib explained that AI is influencing cybersecurity on multiple fronts. Threat actors are leveraging AI to accelerate and automate attacks, making detection more challenging. To counter this, defenders must adopt AI-enabled solutions that provide genuine utility without generating excessive noise. Sophos’ response to this challenge is its AI-native defense platform, Sophos Fusion, which integrates multiple security components—including endpoint, network, identity, email, cloud security, managed detection and response (MDR), extended detection and response (XDR), next-generation security information and event management (SIEM), threat intelligence, and third-party tools—into a unified protection framework.
Given the region’s swift digital transformation, Chib stressed the importance of protecting critical infrastructure, especially as enterprises and governments expand their digital operations. Effective cybersecurity must enable organizations to prevent, detect, and respond to incidents promptly without adding operational complexity.
Chib also addressed common misconceptions about ransomware and AI-driven threats. He noted that ransomware is often narrowly regarded as a malware issue, whereas attacks frequently begin through quieter means such as compromised identities or phishing. According to Sophos’ State of Ransomware report 2026, 79 percent of ransomware attacks initiated via identity-based vectors. Attackers typically spend significant time within networks escalating privileges before deploying ransomware.
Similarly, AI-driven threats are not a distant concern; adversaries are already employing AI to craft more convincing phishing campaigns, accelerate data collection, and scale operations beyond what was feasible manually. Chib advocated for enhanced identity security, greater environmental visibility, and coordinated response capabilities instead of relying on a multitude of isolated security products.
The shifting risk landscape, with cyber threats now deeply intertwined with geopolitical instability, has prompted regional boardrooms to reassess cybersecurity’s role. Cyber risk is being reframed as a matter of strategic resilience, alongside business continuity and reputation management. This broader perspective reflects the region’s interconnected digital economies, exposure to geopolitical tensions, supply chain vulnerabilities, and increasing regulatory demands. Boards are seeking clear, evidence-based assessments of preparedness, recovery capacity, and the effectiveness of security investments, areas where platforms like Sophos Fusion aim to deliver insight.
Looking ahead, Sophos plans to assist organizations in transitioning from reactive to proactive cybersecurity postures over the next 12 months. Many security environments have developed reactively, resulting in sprawling, difficult-to-manage infrastructures with limited visibility. Addressing capacity gaps is a key focus, as many entities, including governments, lack adequately sized security teams relative to current threats. This shortfall fuels demand for managed detection and response services, alongside cloud security and identity management, which have become priority areas given the shift of workloads to cloud environments and the corresponding attack surface.
Ultimately, Chib highlighted the rapid pace of transformation across the Middle East and Africa as both an opportunity and a vulnerability. With organizations evolving quickly, integrating security from the outset remains critical. Sophos aims to support this integration through scalable, open solutions aligned with clients’ evolving business needs.
