Connect with us

Tech Features

How Cyber Risks Have Become Business Risks

Published

on

Cyber Risks

By Alain Sanchez, EMEA CISO, Fortinet.

Cyber risk is business risk. Anything that threatens IT threatens the company. We have become extremely dependent upon our digital assets. As a result, business leaders need to realize the magnitude of the change. The essence of what visionaries have shared with me in the last couple of months shows how much cybersecurity is now a permanent topic of discussion among chief information security officers (CISOs) and their corporate leadership.

Assessing Cyber Risks

Perhaps the most crucial role of the CISO is to rank cyber risks by order of actual impact.

Part of this assessment requires understanding the priorities inside the organization’s value chain and securing them accordingly. The second challenge is to look beyond the organization and see how outside forces may impact it. And among these external forces, we find the compliance framework. These new laws and regulations are necessary.

This very duality, good and complex, challenges many IT departments. They must ask themselves: How do we integrate legal considerations into what used to be a pure technological battlefield? The solution is to start from the top. The board of directors should always have this duality in mind. The more directors know about cyber risks and government regulations, the better. Consider the European Union’s Digital Operations Resilience Act (DORA). This legislation is focused on the European banking and financial system.

Mitigate Risks

In the past, resilience was more of a technical concept. It was about bringing back the servers. Today, it is a legal requirement documented by an auditable plan. We have moved from a series of technical steps to a contractual re-establishment of critical services.   

Four types of considerations underpin these plans:

  • • Prioritized recovery: A very delicate ranking that can only be established through a regular exchange between the board and the operations team. The board’s sign-off is crucial here. Otherwise, who would ever qualify their own activity as noncritical? However difficult to establish, this ranking is truly a fascinating exercise that brings the CISO and team to the heart of the business.
  • • Defending strategies: Assessing the right combination of products, services, staffing, and processes is crucial. Less is more in this matter. After years of accumulation, cyber officers have realized the hard way that a maelstrom of products and vendors was not very efficient. The next era of security will happen via convergence, not addition.
  • • Offer options: This is about providing information and an array of solutions in which, ultimately, the board makes the call. It is part of the CISO’s job to offer scenarios as a series of documented steps: investment 1, timeline 1, benefits 1, and risk 1. Then, the CISO can suggest a second and a third sequence of the above. Choosing how to proceed is the board’s job. This way, the CISO becomes an empowered execution lever for a consensual decision instead of being pinpointed as the only one to blame for the results.
  • • Executive leadership: The CISO needs to report directly to the CEO, otherwise the job is a “widow maker.” The consequences of unclear or diluted support go beyond the discomfort of the position; the survival of the company is at stake. In 2024 and beyond, submitting cybersecurity to any other consideration than the company strategy is a major governance mistake. Like the Titanic shipbuilders who traded rescue boats for rooms on the sundeck.

Cybersecurity is not only about avoiding icebergs. It is a holistic approach that embraces all the active and passive security dimensions into one integrated platform. Holistic here does not mean monopolistic. Legacy, old-school, best-of-breed, and point solutions are facts of life. However, the number of technologies, vendors, processes, and the magnitude of digital transformations call for simplification. Too often, this maelstrom turns into major incidents that operate as wake-up calls. Then the question is not about the 1 million dollars we did not spend, but about the 100 million dollars we just lost.

Tech Features

The Infrastructure Is Automated. Why Are the Processes Around It Still Manual?

Published

on

Article by Prasanna Rajendran, Vice President – EMEA, Kissflow

Across the Middle East, governments and enterprises are investing heavily in cloud infrastructure to support national digitization agendas, from Vision 2030 in Saudi Arabia to the UAE’s push toward AI-driven government services. Gartner forecasts that IT spending across the Middle East and North Africa will reach $169 billion in 2026, an 8.9 percent increase over 2025, with software spending alone growing 13.9 percent.

Infrastructure as code (IaC) is the practice of defining and provisioning computing infrastructure, including servers, networks, databases, and load balancers, using machine-readable configuration files rather than manual processes or interactive consoles. Rather than logging into a console to click through setup wizards, teams describe their entire infrastructure in version-controlled code that can be reviewed, tested, and deployed like any other software artifact.

For CIOs and IT leaders, this matters because IaC has become the operational standard for any organization running workloads at scale. Grand View Research valued the global IaC market at $1.2 billion in 2025 and projects it to reach $6.1 billion by 2033, a compound annual growth rate of 22.3 percent. That trajectory reflects a clear shift: enterprises are moving from manual, ticket-driven infrastructure management to automated, code-driven provisioning.

What is infrastructure as code?

At its core, IaC means defining resources such as virtual machines, storage volumes, network configurations, security policies, and access controls in declarative or imperative code files. Those files become the authoritative record of what your infrastructure looks like at any moment.

IaC generally follows one of two approaches, depending on whether teams want to define an outcome or prescribe the route to it. Declarative IaC describes the desired end state: you specify what you want, such as three servers, a load balancer, and a database cluster, and the tool works out how to get there. Terraform, AWS CloudFormation, and Azure Bicep all use this method. Imperative IaC instead specifies the exact steps to reach an outcome. You write procedural instructions: create this server, then attach this disk, then configure this network. Ansible and Chef follow that model more closely.

The declarative approach dominates enterprise adoption today because it is easier to maintain and less error-prone. You describe the outcome rather than the procedure, which keeps the code readable even as infrastructure complexity grows.

What separates IaC from traditional infrastructure management is version control. Every change is tracked in Git, reviewed through pull requests, and deployed through automated pipelines. This is the mechanism Gartner points to when it describes IaC as the route to cloud governance and self-service at scale.

Why infrastructure as code matters for enterprise IT

Manual infrastructure management does not scale. When an operations team provisions servers through tickets and console clicks, every environment differs slightly, every deployment carries risk, and every audit turns painful. IaC removes these problems systematically.

Consistency and reproducibility

IaC guarantees that the development, staging, and production environments are consistent. Configuration drift, the slow divergence of environments over time, disappears because every deployment is generated from the same code. When an incident occurs, you can rebuild an environment from scratch in minutes.

Speed and agility

Organizations using IaC provision entire environments in minutes rather than weeks. When business conditions change, whether through a product launch, a capacity spike, or a compliance deadline, IaC lets you respond at the speed of code.

Security and compliance

With IaC, security policies are embedded directly in infrastructure templates. Guardrails apply automatically. Compliance checks run in the CI/CD pipeline before any change reaches production. Security stops being a gate at the end of the process and becomes part of how infrastructure gets built.

Cost efficiency

IaC gives you precise control over resource provisioning. Idle capacity gets identified and decommissioned through code rather than through quarterly manual audits. Cost discipline has grown into a standing function for this reason: 59 percent of the 759 organizations Flexera surveyed for its 2025 State of the Cloud Report now run a dedicated FinOps team, up from 51 percent the year before.

Key infrastructure as code tools for the enterprise

Several tools now anchor enterprise IaC strategy, each suited to a different environment. Terraform and its open-source fork, OpenTofu, remain the dominant choice for cross-cloud work, offering declarative provisioning across multiple clouds using HCL. Organizations standardized on a single cloud often turn to native alternatives instead: AWS CloudFormation for AWS-centric environments, using JSON or YAML, and Azure Bicep for Azure-native deployments. Ansible takes an imperative, YAML-based approach and excels at configuration management and application deployment rather than pure provisioning. Pulumi appeals to developer-led teams by letting them define declarative infrastructure in familiar languages such as Python, TypeScript, or Go.

Common challenges when adopting infrastructure as code

Adopting IaC is not without friction. The most immediate obstacle is usually a skills gap, because IaC asks infrastructure teams to work the way developers do, with version control, code reviews, and CI/CD pipelines. That shift is cultural as much as it is technical, and it requires deliberate investment in training.

State management adds complexity of its own. Declarative tools maintain state files that track current infrastructure, and multi-team environments need remote state backends, locking, and workspace isolation from day one to avoid conflicts.

Legacy system integration is another common obstacle, since not everything can be expressed in code immediately. Most organizations start with new cloud workloads and progressively extend IaC to existing systems through API wrappers.

Governance and drift detection require ongoing discipline. IaC only delivers its full value once it becomes the sole path for infrastructure changes, which makes continuous drift detection and sustained cultural enforcement critical rather than optional.

Where workflow automation fits in an IaC-driven enterprise

Infrastructure as code solves the provisioning problem. Enterprise IT complexity does not stop there. The layer above IaC, covering the processes, approvals, and operational logic that run on top of provisioned infrastructure, is where most organizations still depend on fragmented tools, manual handoffs, and spreadsheet-based tracking. That gap is especially visible across the Middle East, where cloud adoption and ambitious national targets often outpace the operational processes needed to govern them.

Regulatory pressure widens the gap further. Gartner forecasts worldwide sovereign cloud IaaS spending at $80 billion in 2026, a 35.6 percent rise over 2025, with governments as the main buyers. Provisioning infrastructure inside a national boundary is one requirement. Proving that every approval, exception, and access grant on that infrastructure followed a governed path is another, and code alone does not answer it.

This is where workflow automation platforms operate as a digital backbone for enterprise operations. IaC automates the infrastructure layer. A no-code or low-code workflow platform automates the process layer: IT service requests, change management approvals, vendor onboarding, compliance workflows, and the hundreds of cross-functional processes that connect people, systems, and decisions across the enterprise.

For IT leaders across the region pursuing IaC adoption, particularly those operating under strict data residency and regulatory requirements, this kind of platform complements the strategy by giving business teams a way to build and manage operational workflows without adding to the IT backlog. IaC handles your infrastructure. Workflow automation handles everything that runs on it.

See how Kissflow governs the change approvals, access requests, and compliance workflows that sit on top of your cloud infrastructure in a 30-minute demo.

Continue Reading

Tech Features

Role of Digital Citizenship in Countering Misinformation and Protecting Social Cohesion in UAE

Published

on

Dr. Soumaya Abdellatif, Head of Sociology Department, Associate Professor, College of Humanities and Sciences, Ajman University

The greatest challenge of our time is not merely that people believe false information. It is that the very boundary between truth and opinion, fact and emotion, credibility and visibility, has become increasingly vague.

This shift signals a transformation in symbolic authority itself. Trust has not simply declined – it has been displaced. Traditional institutions no longer monopolize credibility, while digital platforms have multiplied voices without necessarily strengthening legitimacy.

In societies such as the UAE – built on coexistence, institutional trust, and the delicate management of cultural diversity, this challenge carries particular strategic weight. This is where digital citizenship ceases to be an educational slogan and becomes a matter of national importance.

Beyond Media Literacy

At its core, digital citizenship is a contemporary form of civic responsibility. It deals with how individuals participate in the digital public sphere, how they interpret information, and how they contribute – consciously or unconsciously, to the production of collective trust.

(1)As Manuel Castells once stated, power in network societies increasingly operates through control over communication flows. The question is no longer simply who speaks, but whose voice becomes visible, amplified, and believed.

Trust as Social Infrastructure

In the UAE, misinformation is not merely a media concern – it is also a matter of social architecture. The country’s model of stability rests on institutional credibility, intercultural coexistence, and high levels of public trust.

This explains why the UAE has invested heavily, not only in digital transformation, but also in institutional clarity and communication governance. (2) Federal Decree-Law No. 34 of 2021 on combating rumours and cybercrime reflects an important principle: digital stability is inseparable from social stability. The objective is not merely punitive regulation, but the protection of public confidence itself.

Youth, Families and the Transformation of Authority

Young people are not passive consumers of information; they are producers of narratives, identity, legitimacy, and influence. They shape public conversations long before institutions respond to them.

In previous generations, legitimacy flowed vertically: from institutions, schools, family structures, and recognised expertise. Today, authority is increasingly negotiated horizontally- through peers, influencers, networks, and algorithmic visibility.

In addition, families act as the first school of civic trust. Long before formal media literacy programs, individuals learn how to relate to truth, disagreement, and legitimacy inside the home.

Why Social Sciences Matter

The response to misinformation cannot be reduced to fact-checking mechanisms or technical media literacy alone. What is required is a deeper intellectual infrastructure – one that social sciences are uniquely positioned to provide.

Sociology, communication studies, political science, and anthropology do not merely teach individuals how to verify information; they teach them how power operates, how legitimacy is constructed, how public opinion is shaped, and how collective trust is sustained or eroded.

A National Priority

The UAE has positioned itself as a global leader in artificial intelligence, digital governance, and future-oriented policy. This ambition is both necessary and admirable.

In this scenario, digital citizenship is not a secondary educational concern. It is part of national security, social sustainability, and the long-term legitimacy of institutions.

The UAE is not only managing digital transformation; it is helping to define what responsible digital modernity should look like.

Because in the end, the future of social cohesion will not be decided by technology itself, but by who is trusted to interpret reality in the digital age.

Continue Reading

Spotlight

Clarity Before Compute: Why AI Strategy Must Come Before Infrastructure

Published

on


Enterprise AI has entered a new phase. The conversation is no longer centred on whether organisations should invest in artificial intelligence, but on how they can transform that investment into measurable business value.

By: Mohammed Hilili – General Manager, Lenovo Gulf

Across the GCC, enterprises are moving beyond experimentation. Pilot projects are giving way to enterprise-wide deployments as organisations seek to integrate AI into customer experiences, business operations, software development, cybersecurity and decision-making. Yet despite growing investment, many AI initiatives continue to struggle to deliver the outcomes leadership teams expect.

In my experience, the reason is rarely the technology itself. More often, organisations begin with the wrong conversation.

Too many AI discussions start with infrastructure specifications, GPU availability or the latest foundation models. These are undoubtedly important decisions, but they are not the first ones organisations should make.

The first question is much simpler.

What business problem are we trying to solve?

Without a clear answer, AI initiatives often remain isolated demonstrations of technical capability rather than platforms capable of delivering sustainable business value.

From AI Pilots to Enterprise Platforms

Across industries, organisations have spent the past two years experimenting with generative AI. Many have successfully launched departmental pilots that demonstrate what AI can achieve within a controlled environment. The greater challenge now lies in scaling those experiments across the enterprise.

That transition requires far more than additional computing power. It demands clear governance, high-quality data, well-defined business objectives and an architecture capable of supporting continuous growth. Successful AI adoption is increasingly becoming an organisational transformation exercise rather than simply another technology deployment.

Business Strategy Before Infrastructure

I recently worked with a leading regional financial institution looking to strengthen its research and development capabilities through AI. The ambition was clear, but many practical questions remained unanswered.

How much computing capacity would the organisation require? Which GPU architecture would support both current and future workloads? How could the environment remain scalable as AI adoption expanded across the business?

These may appear to be technology questions. In reality, they are strategic business decisions with long-term operational consequences.

Instead of beginning with hardware selection, we started by understanding the organisation’s objectives. Together with the leadership team, we assessed AI readiness, identified priority business outcomes and defined what success would look like before discussing infrastructure.

Only after establishing that foundation did we determine the appropriate compute resources, architectural approach and deployment model required to support long-term growth.

The result was not simply a successful implementation but an AI platform capable of evolving alongside the organisation’s ambitions.

AI Readiness Extends Beyond Technology

Many organisations still view AI readiness primarily through the lens of infrastructure. In reality, readiness begins much earlier.

Leadership alignment, data quality, governance frameworks, cybersecurity, skills development and measurable business outcomes all influence whether an AI initiative succeeds or stalls. Infrastructure remains essential, but it should support strategy rather than define it.

The organisations achieving the strongest results are those treating AI as a long-term business capability rather than a series of disconnected technology projects.

Building for a Hybrid AI Future

Enterprise AI environments are also becoming increasingly hybrid. Certain workloads will remain on-premises to address latency, compliance or data sovereignty requirements, while others will leverage the scalability of public cloud environments.

This makes architectural flexibility increasingly important. Organisations need infrastructure strategies capable of supporting multiple deployment models while allowing AI workloads to evolve alongside changing business priorities.

Selecting technology is therefore no longer simply about purchasing hardware. It is about building an adaptable foundation capable of supporting continuous innovation over many years.

The GCC Opportunity

The GCC is uniquely positioned to accelerate enterprise AI adoption. Governments across the region continue investing heavily in digital transformation, sovereign AI capabilities and next-generation cloud infrastructure while strengthening regulatory frameworks around data governance and cybersecurity.

These investments provide organisations with an increasingly mature environment in which to deploy AI at scale. However, long-term success will depend less on access to technology than on the ability to align AI investments with clear operational priorities and measurable business outcomes.

As AI becomes embedded within core enterprise operations, leadership decisions made today will determine competitive advantage for years to come.

Why Clarity Still Comes Before Compute

Technology will continue evolving at remarkable speed. New AI models, specialised processors and deployment approaches will continue reshaping the enterprise landscape.

What will remain constant is the importance of making the right decisions before investing.

At Lenovo, this philosophy shapes how we work with customers. We believe AI is not simply a product to deploy, but an organisational capability that develops over time. By combining advisory expertise with infrastructure, lifecycle services and long-term planning, organisations can reduce uncertainty, optimise investment and build AI platforms that continue creating value as business needs evolve.

The organisations that lead in the AI era will not necessarily be those with the largest AI budgets or the most powerful infrastructure. They will be those that begin with business clarity, build the right foundations and scale with purpose.

Because in enterprise AI, infrastructure enables transformation—but clarity makes it possible.

Continue Reading

Trending

Copyright © 2023 | The Integrator