Contact

What are you looking for?

Six takeaways from GISEC Global 2026

September 28, 2026

GISEC Global closed its 15th edition in Dubai this September after three days at Dubai Exhibition Centre, Expo City, under the theme "Cyber First: The New Digital Order." 

We took part in the event, bringing together our Digital Trust experts and partners to connect with industry professionals, customers and business leaders from across the cybersecurity and technology ecosystem. Over the three days, our team had engaging conversations about the challenges organizations are facing, from evolving cyber threats and regulatory requirements to AI governance and digital trust, and how stronger assurance can help organizations build cybersecurity resilience and demonstrate compliance.

Throughout the event, one shift stood out. As threats become faster, more autonomous and harder to detect, organizations are being asked to demonstrate more than what they say about their security posture. They need evidence that their systems, processes and controls can stand up to scrutiny.

SGS at GISEC Global 2026
SGS Middle East Digital Trust at GISEC 2026
Business Assurance team of SGS in GISEC Global 2026

Here are six signals from GISEC Global 2026 that show why cybersecurity is increasingly about proof:

Almost every stage returned to the same triangle: AI as a weapon, AI as a target and AI as a defense. Ransomware campaigns are increasingly AI-assisted, and published industry research puts the share of affected organizations who say AI made attacks more effective at around two thirds.

The counterweight raised repeatedly by security leaders was that automation has to keep human judgment at the center of decisions that matter. 

Runtime governance for AI agents was among the most repeated messages across the exhibition floor, and the question kept coming back in practical terms: who owns an autonomous agent's credentials, what is it allowed to do unsupervised, and who signs off when it acts?

Non-human identities are multiplying quickly in enterprise environments, and many organizations still struggle to maintain a complete inventory of them. They do not go through onboarding, and they do not attend awareness training.

The dedicated Quantum Security Summit moved the discussion from the future potential of quantum computing to the practical work of preparing today's infrastructure, covering national post-quantum cryptography roadmaps, migration timelines and implementation experience from critical entities.

The operative phrase was crypto agility. Knowing where your cryptography lives, who owns it and how quickly it can be replaced, well ahead of the point where quantum threats become practical.

A two-hour operational technology tabletop required participants to assess compromised systems and make decisions under pressure. The takeaway was that critical infrastructure resilience depends not only on technology but on preparedness, coordination and rapid organizational decision-making.

For a region built on energy, water, ports, logistics and manufacturing, that distinction is not academic.

Law enforcement sessions described a criminal ecosystem that is increasingly organized and AI-enabled. Speed is now decisive in disrupting stolen funds before they cross jurisdictions, and AI is being deployed on the defensive side to analyze data, identify money-mule accounts and detect deepfakes. 

The scale is documented. Entrust's 2026 Identity Fraud Report, based on more than a billion verification events, found deepfakes account for one in five biometric fraud attempts. 

Discussion on the Critical National Infrastructure Stage concluded that cyber sovereignty does not require complete technological independence. It requires regional cooperation and public-private partnerships.

The scale of the challenge is significant. The UAE blocks around 600,000 cyberattacks every day, equivalent to about 25,000 attacks an hour or 416 every second. According to Al Bayan, Dr. Mohamed Al Kuwaiti, head of the UAE Cyber Security Council, the attacks vary widely in type and increasingly involve artificial intelligence, making them more complex and difficult to detect. 

The recurring message was that the community remains the first line of defense.

The breach that never made the news

That thread came together in the SGS session on the Critical National Infrastructure Stage, delivered by Arun Thomas, Chief Technology Officer of NetSentries, now part of SGS.

Presented as a sector-relevant incident narrative rather than a product walkthrough, "The Breach That Never Made the News" traced how critical national infrastructure across the GCC is becoming dependent on connected IT, OT, HMI, ICS, SCADA, cloud, AI and Industry 4.0 ecosystems. That transformation improves efficiency, intelligence and service reliability. It also expands hidden exposure through suppliers, legacy systems, remote access, unmanaged dependencies and converging operational networks.

The narrative moved from hidden exposure to near-miss prevention, then translated the lessons into a practical assurance roadmap: certification readiness, IT and OT digital assurance, HMI, ICS and SCADA security, secure-by-design architecture, predictive security simulation, exposure management, post-quantum cryptography readiness and AI-based security assessment.

The priority it set out is to identify, validate and reduce realistic risk pathways before they escalate into operational disruption, safety consequences, regulatory exposure or loss of public trust.

So what does this mean for businesses?

The common denominator across these signals is not another security tool. It is assurance.

When threats adapt at machine speed, a point-in-time claim about your security posture ages badly. Boards, regulators, customers and supply chain partners are increasingly asking a different question: can you show it? Independently, against a recognized standard, and refreshed as the technology moves.

That changes what a security program has to produce. Controls remain the work. Evidence becomes the deliverable.

How SGS Digital Trust supports that shift

SGS Digital Trust brings together our digital assurance capabilities across four pillars: Connected Products and Technologies, Digital Services and Infrastructure, Data and Artificial Intelligence, and Organizations and People. 

SGS Digital Trust solutions

  • Cybersecurity Certification and Assurance

    Demonstrate security, privacy and compliance through independent certification and assurance against international and industry standards.

  • Cybersecurity Testing
    Identify vulnerabilities and strengthen digital products, systems and environments through independent cybersecurity testing and assessment. 
  • AI Governance and Trust
    Build responsible AI practices and demonstrate effective governance through ISO/IEC 42001 certification and AI risk assessments. 
  • Cybersecurity Training
    Strengthen cybersecurity capabilities with practical training covering information security, privacy, cybersecurity and industry-specific standards. 
  • Digital Forensics
    Investigate cybersecurity incidents, uncover digital evidence and support organizations in understanding and responding to security breaches. 
  • Preemptive Exposure Management
    Identify exploitable exposures before attackers do, prioritize critical risks and reduce the window of opportunity for cyber threats. 

Our teams assess trust across safety, cybersecurity, privacy, fairness, transparency and sustainability. GISEC 2026 reinforced how these are increasingly becoming prerequisites for trusted digital business in the region.

The threats are getting faster. The proof needs to keep up.

Want to know more? Get in touch with our experts. 

Stay informed. Subscribe now.

For exclusive insights on management systems, ISO standards and sustainable business growth, subscribe to our monthly email newsletter.

About SGS

SGS is the world’s leading Testing, Inspection and Certification company. We operate a network of over 2,500 laboratories and business facilities across 115 countries, supported by a team of over 100,000 dedicated professionals. With more than 145 years of service excellence, we combine the precision and accuracy that define Swiss companies to help organizations achieve the highest standards of quality, compliance and sustainability.

Our brand promise – when you need to be sure – underscores our commitment to trust, integrity and reliability, enabling businesses to thrive with confidence. We proudly deliver our expert services through the SGS name and a portfolio of trusted specialized brands, including Applied Technical Services, Brightsight, Bluesign and Nutrasource.

SGS is publicly traded on the SIX Swiss Exchange under the ticker symbol SGSN (ISIN CH1256740924, Reuters SGSN.S, Bloomberg SGSN SW).

News & Insights

  • SGS - UAE - Dubai

SGS Building, Street no. N 203,

Jebel Ali Free Zone, P.O. Box: 18556,

Dubai, United Arab Emirates