DUBAI: From the opening hour on 16 September to the close of GISEC Global 2026 on 18 September, CloudSEK's booth in Hall 3 at Dubai Exhibition Centre, Expo City Dubai, was rarely quiet. CISOs, security architects, SOC leads, compliance heads, government stakeholders and channel partners from across the GCC and beyond came through Booth B70. Many stopped for a demo, and many more stayed for a longer conversation about the problems they are dealing with right now.

Over three days, those conversations ran into the hundreds. They were candid and specific, and they kept returning to the same few questions: How exposed are we to AI we don't fully track? How far does our risk extend through our vendors? And which of the many alerts we receive actually matter?

GISEC Global 2026 brought together more than 25,000 attendees, over 750 exhibiting brands and participants from more than 180 countries, under the theme Cyber First: The New Digital Order. At our booth, that theme showed up as concrete questions from the people responsible for defending the region's banks, telecom networks, government systems, airports and real estate portfolios.

What security leaders told us

"Quieter doesn't feel safer"

Leaders from banking, telecom and government, the region's most targeted sectors, wanted to understand what the recent fall in hacktivist activity meant for them. DDoS campaigns and defacements have declined, but their attention has moved to ransomware and longer-dwell espionage, which are harder to detect and more damaging when they succeed. Many asked whether the quieter months should be read as a sign of relief or as a warning.

"We're adopting AI faster than we can govern it"

Almost every enterprise visitor raised this. Business units are rolling out LLM applications, AI agents and integrations faster than security teams can track them, and many organisations still have no formal governance policy for AI assets. Several CISOs told us they could not say with confidence how many AI endpoints, MCP servers or vector databases their organisation had exposed to the internet.

"Our risk doesn't stop at our perimeter"

Third-party risk is now a board-level concern across the region. When a vendor connects to your systems or holds your data, you inherit part of its attack surface, and sometimes the attack surface of its own suppliers. Leaders from real estate and aviation were especially engaged. Both sectors hold large volumes of customer data and run interconnected IT and operational systems. CloudSEK's work in the UAE has shown persistent attempts to harvest investor and customer data from real estate firms.

"We have findings. We need answers."

The most mature security teams described a different problem. They have plenty of alerts. What they lack is a reliable way to tell which exposures an attacker could chain together into a route to their most sensitive data.

Hourly briefings that kept the booth full

One of the biggest draws at Booth B70 was the hourly threat briefing. To coincide with GISEC, CloudSEK launched its Middle East Cyber Threat Landscape 2025-2026 report, and CloudSEK researchers presented the findings every hour across all three days. The sessions were short and grounded in data. They drew a steady audience of security practitioners, and many attendees stayed afterwards to discuss what the numbers meant for their own organisations.

The report covers 17 months of regional threat activity, from April 2025 to August 2026. Its key findings:

  • Monthly ransomware activity targeting the region rose more than twentyfold, from 17 threat intelligence feeds in April 2025 to 357 in June 2026.
  • The June 2026 peak alone was nearly ten times the previous month.
  • Overall threat activity peaked in March 2026, at 2,245 feeds.
  • The UAE recorded 2,588 threat activity indicators and Saudi Arabia 1,880.
  • Hacktivism spiked three times, in June 2025, October 2025 and March 2026, each time alongside a geopolitical escalation.

The briefings answered the question many visitors arrived with. Hacktivist activity fell sharply after March 2026, but ransomware kept climbing and reached its highest level during the quieter months that followed. The report also documents state-linked groups such as MuddyWater and points to AI-assisted malware development.

The practical guidance was straightforward: patch internet-facing edge devices now, and plan monitoring and staffing around June, October and March, the months that have historically brought surges.

The solutions we showcased

Each concern raised at the booth maps to a part of the CloudSEK platform, and the demo stations stayed busy throughout the event.

AIVigil: see your AI attack surface the way attackers do

AIVigil drew the strongest interest. It continuously discovers an organisation's internet-facing AI assets, including LLM endpoints, MCP servers, vector databases, agentic workflows, shadow AI and leaked AI credentials, and compiles them into an AI Bill of Materials. Each exposure is then scored on agent agency, authentication state, blast radius and live threat signals, so teams know what to fix first.

We used the 2026 LiteLLM supply chain attack to show why this matters. CloudSEK's threat intelligence team found that the incident exposed more than 2,500 companies and 434,000 CI/CD pipelines. It was an AI risk and a supply chain risk at the same time, and many affected organisations learned of their exposure only through third parties.

SVigil: continuous visibility into your supply chain

SVigil monitors third- and fourth-party vendors for vulnerabilities, deep and dark web exposure and wider digital risk. It replaces the once-a-year vendor questionnaire with continuous monitoring. That resonated with organisations facing tighter operational resilience expectations.

Nexus: from scattered signals to validated attack paths

Nexus answers the fourth concern. Its AI agents correlate exposures across the external attack surface, threat intelligence and third-party ecosystems into an attack graph, showing security teams the paths that actually lead to their data.

Visitors also explored XVigil for digital risk and brand protection, BeVigil for external attack surface monitoring, and CloudSEK Threat Intelligence for tracking the threat actors and actively exploited vulnerabilities relevant to their sector.

CHALLENGE RAISED AT THE BOOTH
CLOUDSEK SOLUTION
Untracked AI deployments and leaked AI credentials
AIVigil
Vendor and supply chain exposure
SVigil
Too many findings, unclear priorities
Nexus
Brand abuse, data leaks and dark web mentions
XVigil
Unknown internet-facing assets
BeVigil
Knowing which threats and CVEs matter
CloudSEK Threat Intelligence
Challenge Untracked AI deployments and leaked AI credentials
CloudSEK Solution AIVigil
Challenge Vendor and supply chain exposure
CloudSEK Solution SVigil
Challenge Too many findings, unclear priorities
CloudSEK Solution Nexus
Challenge Brand abuse, data leaks and dark web mentions
CloudSEK Solution XVigil
Challenge Unknown internet-facing assets
CloudSEK Solution BeVigil
Challenge Knowing which threats and CVEs matter
CloudSEK Solution CloudSEK Threat Intelligence

A quick self-assessment

Many visitors asked how their organisation compared with others. These are the five questions we most often asked in return:

  1. Do you have a current inventory of every AI model, agent, MCP server and vector database your organisation exposes to the internet?
  2. Would you know within 24 hours if an AI API key leaked in a public code repository?
  3. Do you monitor your critical vendors continuously, or assess them once a year?
  4. Can you see leaked credentials and dark web exposure linked to your third parties?
  5. When an exposure alert fires, can you tell whether it leads to your customer data?

If you answered "no" or "not sure" to two or more, your attack surface likely has blind spots worth examining.

Recognition at GISEC Global 2026

CloudSEK received the GISEC Partners & Supporters Award 2026 at GISEC Global 2026 in Dubai. The award was presented by H.E. Dr. Mohamed Al Kuwaiti, Head of the UAE Cyber Security Council, in recognition of the partners, sponsors, distributors and contributors who helped make this year's edition a success.

The same week, Rahul Sarkar of our regional team was named Cybersecurity Channel Sales Personality of the Year at the TahawulTech Channel Leadership Forum & Awards 2026, held in Dubai on 14 September.

Both reflect how CloudSEK is building in the Middle East. We combine local investment with a partner-led model. An on-the-ground team covers customer success, partner management and technical support, and a structured partner programme focuses on enablement, certification and incentives.

What's next

We left Dubai with a clear picture of where the region is heading. Security leaders here are no longer asking whether AI, third parties and geopolitical tension create risk. They want to know how much of that risk they can see today, and how quickly they can close the gaps.

Thank you to everyone who visited Booth B70, shared their challenges and pushed our thinking. Our team is following up on every conversation.

Missed us at GISEC?

  • Read the research: Download the Middle East Cyber Threat Landscape 2025-2026 report.
  • Check your exposure: Find out whether your organisation was affected by the LiteLLM supply chain attack with our free breach checker.
  • See the platform: Book a demo of AIVigil, SVigil or Nexus with our Middle East team.

Dubai, until next time.

توقع التهديدات السيبرانية ضد مؤسستك