Tech Features
WHEN MEDICAL SCANS END UP ONLINE: THE QUIET RISK HOSPITALS CAN FIX FAST

Attributed by Osama Alzoubi, Middle East and Africa VP at Phosphorus Cybersecurity
As Saudi Arabia races ahead in digital healthcare transformation, a quieter vulnerability lingers in the background: medical imaging systems that can be found – and sometimes accessed – directly from the public internet. Imaging infrastructure, diagnostic platforms, and hospital information systems are being modernized at speed improving outcomes, accelerating workflows, and bringing advanced clinical capabilities to more communities. But beneath this progress lies a quieter risk that rarely makes headlines: medical imaging systems being exposed on the public internet due to simple configuration errors.
Not a dramatic cyberattack. Not a threat actor breaching a firewall. Just avoidable misconfigurations that leave sensitive patient data reachable by anyone who knows where to look.
Medical imaging systems in Saudi Arabia face a persistent security challenge that differs from dramatic cyberattacks. Patient data exposure often occurs through configuration errors that leave systems accessible on the public internet. These technical oversights represent a significant vulnerability in healthcare’s digital infrastructure.
The Kingdom’s Personal Data Protection Law (PDPL) establishes strict requirements for handling health data. This legislation, modeled after international standards, mandates enhanced protection for medical information and imposes penalties for unauthorized disclosure. Hospitals must implement organizational and technical measures to prevent data exposure.
Radiology departments increasingly use digital platforms for case discussions and second opinions. Without proper configuration, these systems might allow unintended access to patient records. Teleradiology services, which expanded significantly during the pandemic, require secure transmission protocols to protect data during remote consultations.
When we hear about data breaches, we often imagine skilled hackers penetrating security systems. The reality is often simpler and more preventable. “Exposed” typically means a system is reachable from the public internet due to setup choices, not a sophisticated intrusion.
This happens in real-world healthcare settings for straightforward reasons: rushed deployments to meet clinical deadlines, vendor-supplied default configurations that were never changed, remote support access left open for convenience, and legacy systems that were connected to modern networks without proper security reviews.
The scale is significant. Research has identified over 1.2 million reachable devices and systems globally, including MRI scanners, X-ray systems, and related medical infrastructure. These are not theoretical vulnerabilities. They represent actual systems that can be found and accessed from anywhere with an Internet connection.
What gets exposed is more than images
Medical imaging files are not simply pictures. They carry identifiers and metadata that can connect scans directly to real people. Patient names, dates of birth, identification numbers, and clinical details often travel alongside the diagnostic images themselves.
This matters for several reasons. Beyond the obvious privacy violation, exposed patient imaging data creates risks of identity fraud, potential coercion or blackmail, serious reputational damage to healthcare institutions, and erosion of the trust patients place in their medical providers.
Security monitoring platforms have documented cases where exposed systems allowed direct access to both images and patient data—offering a level of detail that should never be open to anyone outside the clinical team.
Why this keeps repeating worldwide
Hospitals everywhere use similar device types and manage comparable data flows. The result is that the same setup mistakes appear repeatedly across different countries and healthcare systems. What starts as one hospital’s misconfiguration becomes everyone’s common failure mode.
The medical devices themselves often come with similar default settings. Imaging servers, picture archiving systems, and diagnostic viewers are deployed in comparable ways. When basic security steps are skipped during installation, the exposure follows a predictable pattern.
Health sector cybersecurity guidance from international authorities emphasizes the need for repeatable baseline controls precisely because these patterns recur. Reducing exposure requires not innovation, but consistent application of known protective measures.
Healthcare organizations face a common vulnerability pattern. A major healthcare provider addressed similar challenges across hundreds of hospitals, discovering that default passwords, vulnerable firmware, and device misconfigurations created entry points that threatened patient care and hospital operations across more than 500,000 connected medical and operational devices.
The Saudi-specific layer: connectivity at cluster scale
Saudi Arabia’s healthcare transformation includes the expansion of health clusters that connect multiple facilities into integrated networks. This approach improves care coordination and resource sharing, but it also means that one weak link can affect multiple sites.
National interoperability initiatives support the sharing of imaging and diagnostic reports across the healthcare system. The Saudi health ministry has established specifications for imaging data exchange through the national health information exchange platform, enabling providers to access patient scans regardless of where they were originally performed.
This connectivity is essential for modern healthcare delivery. It allows specialists to review scans remotely, supports second opinions, and ensures continuity of care when patients move between facilities. However, it also increases the need for consistent configuration rules and security standards across all connected sites.
When imaging systems within a cluster are not uniformly secured, the exposure risk multiplies. A misconfigured system in one facility can potentially provide access to data from across the entire cluster network.
A practical checklist hospitals can act on
Healthcare institutions can take concrete steps to reduce exposure risk. These are not theoretical recommendations but proven measures that address the most common vulnerabilities.
First, create a complete inventory. Every hospital should maintain a current list of what is connected to its network, including imaging devices, storage servers, viewing stations, web portals, and remote access tools. You cannot protect what you do not know exists.
Second, check external exposure. Verify that nothing sensitive is reachable from the public internet. This requires technical scanning from outside the hospital network to identify systems that respond to external queries. Many organizations discover exposures they did not realize existed.
Third, restrict remote access properly. Remote connections for maintenance and support should be tightly controlled, require strong authentication methods, and be removed entirely when no longer needed. Convenience should never override security when patient data is involved.
Fourth, implement safe setup procedures. Develop standard build guides for imaging systems, change all default passwords and settings, clearly document who owns each system, and establish responsibility for applying security patches and updates. Industry experience shows that default credentials remain one of the lowest barriers for attackers seeking entry into healthcare networks.
Fifth, conduct continuous checks. Exposure scanning should happen after any network changes, not just once annually. Healthcare networks evolve constantly, and new vulnerabilities can appear whenever systems are added or reconfigured.
These steps align with guidance from international cybersecurity authorities and health sector regulators, which emphasize reducing exposed services and strengthening baseline controls as priority actions for healthcare organizations.
The governance fix: make secure setup part of how clusters run
Individual hospital efforts are necessary but not sufficient. At the cluster level, governance structures must embed security into standard operations.
This begins with cluster-wide minimum standards for imaging systems and remote access. Every facility within a cluster should follow the same baseline security requirements, ensuring consistent protection regardless of which site a patient visits.
Clear ownership must be established for every system. Someone specific should be responsible for applying patches, approving access requests, and regularly checking for exposure. When accountability is diffuse, critical tasks get overlooked.
Procurement processes offer another leverage point. Purchase agreements should require vendors to provide secure default configurations, enable comprehensive logging capabilities, and commit to supported update cycles for the life of the equipment. Security should be a selection criterion, not an afterthought.
These governance approaches reflect sector framework guidance that encourages structured programs and repeatable controls rather than ad hoc responses to individual incidents.
Saudi Arabia has invested heavily in national cybersecurity frameworks and regulatory oversight across critical sectors, including healthcare. The foundation exists. The next step is ensuring those protections extend fully to the expanding ecosystem of IoT and IoMT devices — where simple configuration gaps can undermine otherwise sophisticated digital progress.
Prevent avoidable incidents
The goal is not perfection. Healthcare systems are complex, and some level of risk will always exist. The goal is removing the easiest path for data exposure: systems sitting openly on the public internet waiting to be found.
In connected healthcare, the quickest wins come from two simple principles: visibility and access control. Know what you have connected, and shut the doors that do not need to be open.
For Saudi Arabia’s health clusters, this represents an achievable objective. The infrastructure investments being made across the Kingdom’s healthcare sector create an opportunity to build security into expansion rather than retrofitting it later.
Medical imaging systems serve an essential clinical purpose. They should not also serve as unintended windows into patient data. With practical steps and consistent governance, hospitals can fix this quiet risk before it becomes a public incident.
In digital healthcare, exposure is rarely a mystery. It is usually a configuration. The question is not whether hospitals can fix it, but whether they will do so before patients pay the price.
Tech Features
Alteryx Launches New AI Capabilities to Bring Governed Analytics Anywhere Work Happens
Alteryx, the agentic analytics and automation company, today announced new AI capabilities across Alteryx One that connect enterprise-grade business logic directly to the AI agents’ teams already use. By extending governed workflows and datasets to external AI tools, organizations can “build once and govern once,” eliminating the need to recreate complex business logic from scratch. This approach allows enterprises to scale AI action with confidence, helping to reduce both security risks and runaway token costs.
- 71 percent of IT leaders report that AI initiatives are most successful when IT and business teams collaborate closely to bridge the gap between AI agents and enterprise business logic.
- NextWave achieved a 20x reduction in LLM token consumption using an Alteryx workflow during a complex Office of the CFO reconciliation between front-office and back-office data.
- Up to 93 percent reduction in token consumption and up to 85 percent increase in speed on tasks involving raw, ungrounded data, when combining an LLM with an existing, trusted Alteryx workflow.
- Up to 83 percent reduction in token costs and up to 65 percent increase in speed on tasks involving clean, grounded data.
- 65 percent of analysts confirm that AI delivers the most value when business logic is managed at the business level.
“Generative AI is brilliant at brainstorming, but it often struggles with the precision required for enterprise execution. Organizations don’t need agents that guess at business rules and burn through tokens; they need AI that operates on the same trusted business logic and governance that underpin the rest of the business,” said Ben Canning, Chief Product Officer at Alteryx. “By connecting existing tools to a governed business logic layer, we are allowing enterprises to stop the ‘re-work’ tax of rebuilding business rules for every new agent, ensuring that every AI-driven action is as reliable as the calculations they already trust.”
The latest capabilities include:
Ask Alteryx: With this release, Ask Alteryx evolves from an embedded assistant into the primary way users interact with Alteryx One, guiding new users step-by-step through their first workflow in Designer and giving everyone a natural-language front door to their data through Ask Alteryx for Live Query, with connections to Snowflake, Big Query, and Databricks for reading and writing data directly. Ask Alteryx checks existing workflows and data first, delivering a governed answer when one exists or building a new workflow when it doesn’t, with every output remaining inspectable, editable, reusable, and schedulable within Alteryx One.
Agent Studio: Enables business users to turn existing, already-governed datasets into conversational agents without rebuilding anything. Analytics teams maintain full control over which datasets and KPIs power agent responses, while finance and operations departments can instantly scope an agent to their reconciliation dataset or KPI dashboard data, so stakeholders can ask trend, root-cause, and variance questions in plain language and get governed, explainable answers back.
Alteryx Insights for OpenAI: Available through the ChatGPT Plugin Directory, this capability allows business users to generate answers based on analyst-approved data, calculations, and workflows. Employees can investigate revenue variances or resolve reconciliation issues directly, accessing trusted business logic without opening the platform or requiring an Alteryx seat. Alteryx will be expanding this surface integration strategy to bring governed logic to where teams already collaborate, including upcoming support for Claude, Gemini, Slack, and Microsoft Teams.
Alteryx MCP Server: The governed way to use Alteryx from whatever AI platform or agent you already work in. It lets AI agents interact with Alteryx as easily as a human would, finding the right data, building multi-step solutions, and turning them into governed, repeatable workflows. Agents can build, run, schedule, and discover Alteryx assets directly, with external AI requests inheriting Alteryx’s authentication, workspace context, role-based access controls, and permissions automatically, so every interaction carries the same security model and audit trail as if a person had done it. More capabilities, including connection creation and expanded scheduling, are expected to roll out later this year on the same governed connection.
Alteryx Skills: A GitHub install that teaches third-party agentic interfaces, OpenAI Codex, Microsoft Copilot, Claude Code, Gemini CLI, and more, how to build Alteryx assets the right way, closer to how Ask Alteryx already builds them. Rather than each tool guessing at Alteryx’s patterns on its own, Skills gives them Ask Alteryx’s own workflow-building know-how, so a financial calculation or reconciliation workflow gets built correctly the first time, without rebuilding logic or permissions separately for every tool your team uses.
Tech Features
The Infrastructure Is Automated. Why Are the Processes Around It Still Manual?

Article by Prasanna Rajendran, Vice President – EMEA, Kissflow
Across the Middle East, governments and enterprises are investing heavily in cloud infrastructure to support national digitization agendas, from Vision 2030 in Saudi Arabia to the UAE’s push toward AI-driven government services. Gartner forecasts that IT spending across the Middle East and North Africa will reach $169 billion in 2026, an 8.9 percent increase over 2025, with software spending alone growing 13.9 percent.
Infrastructure as code (IaC) is the practice of defining and provisioning computing infrastructure, including servers, networks, databases, and load balancers, using machine-readable configuration files rather than manual processes or interactive consoles. Rather than logging into a console to click through setup wizards, teams describe their entire infrastructure in version-controlled code that can be reviewed, tested, and deployed like any other software artifact.
For CIOs and IT leaders, this matters because IaC has become the operational standard for any organization running workloads at scale. Grand View Research valued the global IaC market at $1.2 billion in 2025 and projects it to reach $6.1 billion by 2033, a compound annual growth rate of 22.3 percent. That trajectory reflects a clear shift: enterprises are moving from manual, ticket-driven infrastructure management to automated, code-driven provisioning.
What is infrastructure as code?
At its core, IaC means defining resources such as virtual machines, storage volumes, network configurations, security policies, and access controls in declarative or imperative code files. Those files become the authoritative record of what your infrastructure looks like at any moment.
IaC generally follows one of two approaches, depending on whether teams want to define an outcome or prescribe the route to it. Declarative IaC describes the desired end state: you specify what you want, such as three servers, a load balancer, and a database cluster, and the tool works out how to get there. Terraform, AWS CloudFormation, and Azure Bicep all use this method. Imperative IaC instead specifies the exact steps to reach an outcome. You write procedural instructions: create this server, then attach this disk, then configure this network. Ansible and Chef follow that model more closely.
The declarative approach dominates enterprise adoption today because it is easier to maintain and less error-prone. You describe the outcome rather than the procedure, which keeps the code readable even as infrastructure complexity grows.
What separates IaC from traditional infrastructure management is version control. Every change is tracked in Git, reviewed through pull requests, and deployed through automated pipelines. This is the mechanism Gartner points to when it describes IaC as the route to cloud governance and self-service at scale.
Why infrastructure as code matters for enterprise IT
Manual infrastructure management does not scale. When an operations team provisions servers through tickets and console clicks, every environment differs slightly, every deployment carries risk, and every audit turns painful. IaC removes these problems systematically.
Consistency and reproducibility
IaC guarantees that the development, staging, and production environments are consistent. Configuration drift, the slow divergence of environments over time, disappears because every deployment is generated from the same code. When an incident occurs, you can rebuild an environment from scratch in minutes.
Speed and agility
Organizations using IaC provision entire environments in minutes rather than weeks. When business conditions change, whether through a product launch, a capacity spike, or a compliance deadline, IaC lets you respond at the speed of code.
Security and compliance
With IaC, security policies are embedded directly in infrastructure templates. Guardrails apply automatically. Compliance checks run in the CI/CD pipeline before any change reaches production. Security stops being a gate at the end of the process and becomes part of how infrastructure gets built.
Cost efficiency
IaC gives you precise control over resource provisioning. Idle capacity gets identified and decommissioned through code rather than through quarterly manual audits. Cost discipline has grown into a standing function for this reason: 59 percent of the 759 organizations Flexera surveyed for its 2025 State of the Cloud Report now run a dedicated FinOps team, up from 51 percent the year before.
Key infrastructure as code tools for the enterprise
Several tools now anchor enterprise IaC strategy, each suited to a different environment. Terraform and its open-source fork, OpenTofu, remain the dominant choice for cross-cloud work, offering declarative provisioning across multiple clouds using HCL. Organizations standardized on a single cloud often turn to native alternatives instead: AWS CloudFormation for AWS-centric environments, using JSON or YAML, and Azure Bicep for Azure-native deployments. Ansible takes an imperative, YAML-based approach and excels at configuration management and application deployment rather than pure provisioning. Pulumi appeals to developer-led teams by letting them define declarative infrastructure in familiar languages such as Python, TypeScript, or Go.
Common challenges when adopting infrastructure as code
Adopting IaC is not without friction. The most immediate obstacle is usually a skills gap, because IaC asks infrastructure teams to work the way developers do, with version control, code reviews, and CI/CD pipelines. That shift is cultural as much as it is technical, and it requires deliberate investment in training.
State management adds complexity of its own. Declarative tools maintain state files that track current infrastructure, and multi-team environments need remote state backends, locking, and workspace isolation from day one to avoid conflicts.
Legacy system integration is another common obstacle, since not everything can be expressed in code immediately. Most organizations start with new cloud workloads and progressively extend IaC to existing systems through API wrappers.
Governance and drift detection require ongoing discipline. IaC only delivers its full value once it becomes the sole path for infrastructure changes, which makes continuous drift detection and sustained cultural enforcement critical rather than optional.
Where workflow automation fits in an IaC-driven enterprise
Infrastructure as code solves the provisioning problem. Enterprise IT complexity does not stop there. The layer above IaC, covering the processes, approvals, and operational logic that run on top of provisioned infrastructure, is where most organizations still depend on fragmented tools, manual handoffs, and spreadsheet-based tracking. That gap is especially visible across the Middle East, where cloud adoption and ambitious national targets often outpace the operational processes needed to govern them.
Regulatory pressure widens the gap further. Gartner forecasts worldwide sovereign cloud IaaS spending at $80 billion in 2026, a 35.6 percent rise over 2025, with governments as the main buyers. Provisioning infrastructure inside a national boundary is one requirement. Proving that every approval, exception, and access grant on that infrastructure followed a governed path is another, and code alone does not answer it.
This is where workflow automation platforms operate as a digital backbone for enterprise operations. IaC automates the infrastructure layer. A no-code or low-code workflow platform automates the process layer: IT service requests, change management approvals, vendor onboarding, compliance workflows, and the hundreds of cross-functional processes that connect people, systems, and decisions across the enterprise.
For IT leaders across the region pursuing IaC adoption, particularly those operating under strict data residency and regulatory requirements, this kind of platform complements the strategy by giving business teams a way to build and manage operational workflows without adding to the IT backlog. IaC handles your infrastructure. Workflow automation handles everything that runs on it.
See how Kissflow governs the change approvals, access requests, and compliance workflows that sit on top of your cloud infrastructure in a 30-minute demo.
Tech Features
Role of Digital Citizenship in Countering Misinformation and Protecting Social Cohesion in UAE
Dr. Soumaya Abdellatif, Head of Sociology Department, Associate Professor, College of Humanities and Sciences, Ajman University
The greatest challenge of our time is not merely that people believe false information. It is that the very boundary between truth and opinion, fact and emotion, credibility and visibility, has become increasingly vague.
This shift signals a transformation in symbolic authority itself. Trust has not simply declined – it has been displaced. Traditional institutions no longer monopolize credibility, while digital platforms have multiplied voices without necessarily strengthening legitimacy.
In societies such as the UAE – built on coexistence, institutional trust, and the delicate management of cultural diversity, this challenge carries particular strategic weight. This is where digital citizenship ceases to be an educational slogan and becomes a matter of national importance.
Beyond Media Literacy
At its core, digital citizenship is a contemporary form of civic responsibility. It deals with how individuals participate in the digital public sphere, how they interpret information, and how they contribute – consciously or unconsciously, to the production of collective trust.
(1)As Manuel Castells once stated, power in network societies increasingly operates through control over communication flows. The question is no longer simply who speaks, but whose voice becomes visible, amplified, and believed.
Trust as Social Infrastructure
In the UAE, misinformation is not merely a media concern – it is also a matter of social architecture. The country’s model of stability rests on institutional credibility, intercultural coexistence, and high levels of public trust.
This explains why the UAE has invested heavily, not only in digital transformation, but also in institutional clarity and communication governance. (2) Federal Decree-Law No. 34 of 2021 on combating rumours and cybercrime reflects an important principle: digital stability is inseparable from social stability. The objective is not merely punitive regulation, but the protection of public confidence itself.
Youth, Families and the Transformation of Authority
Young people are not passive consumers of information; they are producers of narratives, identity, legitimacy, and influence. They shape public conversations long before institutions respond to them.
In previous generations, legitimacy flowed vertically: from institutions, schools, family structures, and recognised expertise. Today, authority is increasingly negotiated horizontally- through peers, influencers, networks, and algorithmic visibility.
In addition, families act as the first school of civic trust. Long before formal media literacy programs, individuals learn how to relate to truth, disagreement, and legitimacy inside the home.
Why Social Sciences Matter
The response to misinformation cannot be reduced to fact-checking mechanisms or technical media literacy alone. What is required is a deeper intellectual infrastructure – one that social sciences are uniquely positioned to provide.
Sociology, communication studies, political science, and anthropology do not merely teach individuals how to verify information; they teach them how power operates, how legitimacy is constructed, how public opinion is shaped, and how collective trust is sustained or eroded.
A National Priority
The UAE has positioned itself as a global leader in artificial intelligence, digital governance, and future-oriented policy. This ambition is both necessary and admirable.
In this scenario, digital citizenship is not a secondary educational concern. It is part of national security, social sustainability, and the long-term legitimacy of institutions.
The UAE is not only managing digital transformation; it is helping to define what responsible digital modernity should look like.
Because in the end, the future of social cohesion will not be decided by technology itself, but by who is trusted to interpret reality in the digital age.
-
News11 years ago
SENDQUICK (TALARIAX) INTRODUCES SQOOPE – THE BREAKTHROUGH IN MOBILE MESSAGING
-
Trending11 months agoOPPO A6 Pro 5G Review: Reliable Daily Driver
-
Tech News2 years agoDenodo Bolsters Executive Team by Hiring Christophe Culine as its Chief Revenue Officer
-
VAR1 year agoMicrosoft Launches New Surface Copilot+ PCs for Business
-
Automotive2 years agoAGMC Launches the RIDDARA RD6 High Performance Fully Electric 4×4 Pickup
-
Tech Interviews3 years ago
Navigating the Cybersecurity Landscape in Hybrid Work Environments
-
Tech News2 years agoToshiba Announces MG10-D Series of Enterprise HDDs with Capacities up to 10TB
-
Tech News1 year agoNothing Launches flagship Nothing Phone (3) and Headphone (1) in theme with the Iconic Museum of the Future in Dubai


