CISO Middle East Issue 03 | Page 3

issue 03 editor’ s note

he cyber-threat landscape

T is entering a new phase in which attackers increasingly exploit trust rather than simply breach traditional defences. According to CrowdStrike’ s 2026 Global Threat Report, 2025 marked the year of the evasive adversary, with threat actors targeting supply chain partners, developer ecosystems, legitimate software and employees to gain access while avoiding detection.

Throughout 2026, these tactics have continued to evolve. Adversaries are exploiting gaps between fragmented security controls, moving across valid credentials, cloud authentication, SaaS applications, edge devices and unmanaged systems. AI is accelerating reconnaissance, phishing and technical operations, while also becoming a target as organisations embed it across their environments.
The speed of this transformation is particularly concerning. CrowdStrike reported that AI-enabled adversary activity surged 89 % in 2025. Its OverWatch team has also observed AI agent-triggered detection leads tracking at 2.5 times the rate of human-triggered leads, illustrating the growing volume and velocity of activity security teams must assess.
For CISOs, this creates an urgent need to defend at machine speed. When attackers can automate reconnaissance, exploit vulnerabilities and move laterally in minutes, security teams cannot rely on manual investigation and sequential decision-making alone. AI-powered detection, automated correlation and rapid response must work together to identify malicious behaviour across domains and contain threats before they escalate. Human oversight remains essential, but it must be supported by technology capable of matching the pace of automated attacks.
This issue’ s cover story,“ cybersecurity without blind spots”, explores why visibility has become fundamental to modern cyber defence. Meriam ElOuazzani, Vice President, Middle East, Turkey and Africa at Censys, explains how organisations must look beyond their known assets to understand adversary infrastructure and the third parties on which they depend.
As cyber-risk becomes increasingly interconnected, she argues that security
teams need high-quality Internet intelligence, richer context and an outside-in view of their environments to identify overlooked exposures and respond at the speed of attackers. The conversation also examines Censys’ growing regional presence and why better data is essential to building the next generation of security operations centres.
The implications extend beyond individual technologies. An attacker can move between identity, cloud, endpoint and perimeter infrastructure before disconnected security teams have assembled a complete picture. Traditional approaches that investigate alerts in isolation are increasingly inadequate against adversaries operating across multiple domains.
CrowdStrike’ s report makes the case for continuous, intelligence-driven threat hunting, supported by richer context and AI-powered analysis. The priority for organisations is to connect signals, understand adversary behaviour and respond before an intrusion escalates.
Jeevan Thankappan Managing Editor
WWW. INTELLIGENTCISO. COM / MIDDLE-EAST 3