Connect with us

Uncategorized

SHADOW DATA: A HIDDEN RISK IN THE GULF

Published

on

By Yazen Rahmeh, a Cybersecurity Expert at SearchInform

Digital transformation across the UAE and Saudi Arabia brings new opportunities and prospects for enhancing efficiency and growth. However, it also causes new challenges to data protection. As digital environments expand, data spreads across endpoints, cloud storage, and internal environments, escaping oversight by security and compliance teams.

This is shadow data, and it may be one of your organization’s most underestimated risk.

What Is Shadow Data?

Despite all efforts, some business data can be stored and processed outside official IT systems. As a result, a company won’t even know that such datasets exist.

There are a lot of reasons behind the creation of shadow data. Basic examples are:

  • Files stored in personal accounts. An employee can send important files to personal email or cloud storage “just in case.”
  • Access to corporate data from personal devices. A person can log in to corporate cloud services from a personal tablet or laptop. As a result, sensitive documents can be downloaded to a personal device.  This usually happens when someone is working overtime or wants to keep important files readily available.
  • Unaccounted copies of sensitive data. An employee can simply copy and paste records from a CRM system or a customer spreadsheet into a file on their workstation. As a result, sensitive data may bypass security controls, increasing the risk of data leakage.
  • Some business units can adopt SaaS services without oversight. Employees usually do it to boost their productivity or if whitelisted tools are perceived as slow or bulky.
  • Test datasets and temporary databases. Sometimes confidential data can duplicate during migration from one service to another or if developers use production data for test or development environments.

These examples may seem abstract, but the recent Cybersecurity and Infrastructure Security Agency (CISA) data leak shows that shadow data is a real-world threat.

The leak reportedly originated from a contractor’s GitHub repository, which was being used as a working scratchpad. The repository exposed various sensitive records, including AWS keys and plaintext passwords for internal CISA systems. An individual had simply copied sensitive data to make their work more convenient. To do so, the contractor disabled GitHub’s default security setting that prevents users from publishing secrets in public repositories.

Why Shadow Data Is a Business Risk

Increased Risk of Data Leaks

Consider a common scenario: an employee stores confidential data on a personal laptop or cloud service. As a result:

  • Sensitive records could be stolen via phishing or malware, as the laptop isn’t protected by enterprise-grade security controls.
  • An employee could share the laptop with other individuals. Shared devices increase the risk of data exposure.
  • Unauthorized cloud backups. An employee may configure automatic file backups to a cloud service. As a result, sensitive data can leave the protected perimeter and be duplicated in cloud storage, increasing the risk of unauthorized access or data leakage.

That’s how a small and seemingly irrelevant piece of ungoverned data could lead to a major incident. In fact, in 2024, one in three data breaches involved shadow data, according to IBM’s Cost of a Data Breach 2024 report.

One of the most recent cases of data leaks, involving shadow data, is the Abu Dhabi Finance Week exposure. An independent researcher discovered unsecured cloud storage with ID details.

Event representatives stated that only the researcher accessed the data and that the incident affected a limited number of participants. According to them, the issue was caused by a misconfigured cloud storage system managed by a third-party provider.

The incident is the perfect example of shadow data, as the data was copied outside of secured corporate infrastructure and had been left unmanaged.

Regulatory Pressure

Shadow data also presents compliance risks. When using a cloud service, it is essential to verify the geographic location of the data center where the data is stored. Data could be stored at a data center in a different country if you didn’t specify a server location.

As a result, if shadow data includes confidential records such as customer details or transaction records, it will be transferred and stored abroad. From a legal perspective, such misconfiguration is a cross-border transfer and lead to regulatory fines for violations of data protection regulations.

Saudi Arabia’s Personal Data Protection Law dedicates a lot of attention to data residency and cross-border transfers. Organizations, especially in regulated sectors, such as financial institutions, may be required to store certain categories of data within the Kingdom. Companies may need regulatory approval before transferring data to foreign data centers to avoid penalties.

Emirati businesses have less strict conditions for cross-border data transfers. However, there are limitations for banking, payments, healthcare, and telecom organizations and governmental entities. Companies from these industries must store confidential data, such as health records, payment transactions, and customer data, within the country.

Lack of visibility equals lack of control, and regulators do not accept invisibility as an argument.

How to Bring Shadow Data Under Control

Eliminating shadow data entirely is unrealistic. The goal is to make it visible and manageable without slowing down the business.

A Practical Starting Checklist

  1. Discover regulated data, especially data subject to local PDPLs requirements, cybersecurity frameworks issued by National Cybersecurity Authority in the KSA, and Information Assurance Regulation by TDRA in the UAE. It is essential to identify all information that qualifies as confidential and valuable, incl. unaccounted copies of such data.
  2. Map where this data is actually stored and shared, not just where it should be. Sensitive data can be stored on-prem or in cloud environments. Look for data discovery solutions. Ideally, choose a solution that combines data discovery and data classification, like DCAP software.
  3. Classify files & distribute access rights. Use specialized tools to analyze file content and classify it in accordance with a local classification scheme. The next step is to assign user access rights to sensitive data based on employees’ roles and responsibilities.
  4. Control data transfer channels, including cloud storage, SaaS tools, and USB-devices. Use DLP systems to prevent unauthorized spread of sensitive data. Advanced DLP solutions monitor cloud services, as well as traditional channels, such as email or web browsers.

Conclusion

Data protection is not a one-time initiative. It is an ongoing discipline. Security achieved today must still hold tomorrow — and next year.

Organizations that treat data security as a strategic investment, rather than a compliance obligation, build resilience, regulatory confidence, and long-term business stability.

Shadow data may be invisible. But its consequences are not.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Uncategorized

EYWA Way of Water to be EMFIS® Certified for Low-Electromagnetic Environment in Dubai’s Business Bay

Published

on

Step into a bedroom at EYWA Way of Water and you will feel like entering a sanctuary. The invisible electromagnetic hum that fills every modern home has been filtered out. This allows the body to recover and improve residents’ longevity. Engineered quiet for the nervous system: This is the EMFIS® Certification quality seal, which will be granted to this waterfront residential development on the Dubai Water Canal in Business Bay. The project is targeting EMFIS® certification as part of a wider suite of international wellness benchmarks that includes LEED Platinum, WELL Platinum, and WiredScore Platinum.

The appointment builds on EMFIS’s earlier certification of EYWA – Tree of Life, which established the partnership between the two organisations and made EYWA one of the region’s first residential developments to certify electromagnetic hygiene as a measurable, independently verified building standard. At EYWA Way of Water, EMFIS® is applying the same methodology at greater scale across approximately 65 ultra-luxury residences spanning 2– to 5-bedroom apartments, duplexes, and a penthouse, designed by OAD (Zane Tetere-Sulce) with John R Harris as consultant. Delivery is expected around 2028.

At EYWA Way of Water, EMFIS® will pay particular attention to bedrooms, and verifying that shielding and infrastructure choices keep exposure within the bounds EMFIS® considers appropriate for long-term occupancy. All while preserving the aesthetics of the spaces. Where integrated at the design phase, as is the case at EYWA Way of Water, EMFIS’s approach has achieved reductions of up to 98.7% in low-frequency electric fields and 81.8% in high-frequency electromagnetic fields that are verified through independent third-party testing. That’s the difference between a room full of EMF pollution and one fit for a retreat.

Electromagnetic exposure remains the one dimension of indoor environmental quality that most healthy-building frameworks have yet to address. Modern buildings generate a continuous electromagnetic environment from internal wiring, Wi-Fi networks, smart systems, and external 5G infrastructure, operating around the clock regardless of occupancy. The World Health Organization classifies radiofrequency electromagnetic fields as possibly carcinogenic, and mounting regulatory action in Europe, including France banning Wi-Fi in daycare centres and Switzerland writing precautionary EMF limits for schools and hospitals into national law, reflects growing institutional recognition of the issue.

The Global Wellness Institute values the global wellness real estate market at $876 billion, on a trajectory to $1.8 trillion by 2030. In the UAE, the sector has grown from $3.3 billion in 2017 to $14.6 billion in 2025, expanding at 21% annually, making it one of the fastest-growing real estate categories in the region. Wellness-focused properties already command a price premium of 10 to 25% over conventional equivalents. EMFIS’s own benchmarked data across certified projects shows low-EMF certification specifically delivering an average added value of approximately 14%, reflecting a market that increasingly distinguishes between properties that carry a wellness label and those that can demonstrate independently verified wellness standards.

Federico Marangoni, Founder and CEO of EMFIS® commented “Green building told us how a building treats the world outside it. The next question – the one EYWA Way of Water is helping answer – is what a building does to the people inside it over the course of a lifetime. Electromagnetic pollution is the dimension of the indoor environment the industry has not yet had the tools to measure and certify. That is exactly the gap EMFIS® closes, and EYWA Way of Water is one of the clearest examples in the region of a developer addressing it at design phase, where it makes the most difference. EYWA Way of Water is pitched to offer the quietest square meters in Dubai.”

Mariska Stoffel, Director of Design & Development at R.Evolution  commented, “Architecture is becoming much more sophisticated in how it responds to human wellbeing. When people spend around 90% of their time indoors, we are shaping the environment where much of daily life happens. That means looking beyond aesthetics to the invisible conditions created by the building itself. Sleep and recovery are a key part of that, which is why EMFIS® provides an important benchmark for how we address electromagnetic exposure. At EYWA Way of Water, we are designing for people who take a long-term view of both capital and personal wellbeing, while creating healthier, more considered living environments in an increasingly connected world.”

Shailesh Bhandari, Director, John R Harris commented “At John R Harris & Partners, sustainability is embedded in our thinking from the first line of a project. EYWA Way of Water extends that principle into territory the industry is only beginning to navigate seriously: the electromagnetic environment that residents live within every day. Partnering with EMFIS® reflects our belief that truly well-crafted spaces actively support the health and longevity of those who inhabit them.”

EMFIS® has certified projects across eight countries in Europe and the Middle East and operates a GCC showroom in the UAE. Founded on research conducted at EPFL (École Polytechnique Fédérale de Lausanne) and recognised by Switzerland’s national standardisation body, a member of ISO, it is currently the only organisation in the world dedicated specifically to measuring, certifying, and managing electromagnetic exposure within the built environment. The appointment of EMFIS® to EYWA Way of Water is part of a growing pipeline of UAE and GCC projects in which electromagnetic environment certification is being integrated from the earliest stages of design, rather than treated as a post-occupancy consideration.

Continue Reading

Hospitality

Minor Hotels Announces Avani Kota Kinabalu in Malaysia

Published

on

Minor Hotels, a leading global hotel owner and operator, has announced Avani Kota Kinabalu, a 352-key premium lifestyle hotel set to open in Q1 2027. Forming part of The Logg Luyang integrated development by KTI Landmark, the property will introduce the Avani brand to Sabah and expand Minor Hotels’ presence in Malaysia.

Avani Kota Kinabalu will cater to leisure and corporate demand in Kota Kinabalu, one of East Malaysia’s principal commercial centres and a key gateway to Borneo. Approximately 10 minutes from Kota Kinabalu International Airport, the hotel will provide access to the city’s business districts, residential neighbourhoods and visitor attractions.

The announcement supports Minor Hotels’ strategy of expanding its lifestyle portfolio in destinations with growing domestic, regional and international demand. Avani Kota Kinabalu will also strengthen the group’s presence in Malaysia, joining Anantara Desaru Coast Resort & Villas in Johor, as it continues to pursue development opportunities across Asia.

Developed by KTI Landmark, The Logg Luyang will bring together hospitality, commercial and lifestyle components within the established Luyang neighbourhood. Avani Kota Kinabalu will serve as the development’s hospitality anchor, offering accommodation, dining, wellness and event facilities for hotel guests and the local community.

“Kota Kinabalu is evolving rapidly as a regional business and tourism hub, creating strong demand for a hotel that can move easily between corporate, leisure and social use,” said Winston Gong, General Manager of Avani Kota Kinabalu. “Our focus will be on delivering an efficient, locally relevant guest experience while building a property with genuine appeal to the city’s residents.”

Designed by Shah Architect, with landscape architecture by SD2 and interiors by INdulge, Avani Kota Kinabalu will feature 352 rooms tailored to business trips, short breaks and longer stays.

Avani Kota Kinabalu will feature five dining and social venues for hotel guests and the local community. The all-day dining restaurant will serve Sabahan, Malaysian, Korean and international cuisine, with live cooking stations, local specialities and a signature Avani Sunday Lunch. A contemporary Chinese restaurant will focus on Sabah Hakka heritage and regional flavours, while the Lobby Lounge will transition from a daytime meeting space into an evening venue serving afternoon tea, as well as cocktails and whiskies.

The Pantry will offer handcrafted bakery items, desserts and premium coffee for dining in or takeaway. On the rooftop, SEEN Restaurant & Bar will bring the established rooftop dining and nightlife concept to Sabah through globally inspired cuisine, mixology, curated music and destination-led experiences.

The hotel will also include dedicated meeting and banquet facilities for conferences, weddings and social events. Leisure facilities will include an infinity pool and AvaniFit gym, with nearby Tun Fuad Stephens Park offering access to outdoor recreation.

Avani Kota Kinabalu will combine accommodation, rooftop dining, wellness and event facilities within a major integrated development, strengthening Minor Hotels’ lifestyle offering in Malaysia and supporting the group’s continued expansion across Asia.

Continue Reading

Uncategorized

ServiceNow Expands Autonomous Security Vision with Unified AI-Powered Cyber Defense Platform

Published

on



The company introduces six integrated security solutions designed to help enterprises detect, prevent and respond to cyber risks at machine speed.

As organisations continue to accelerate AI adoption, cybersecurity teams are facing a rapidly expanding attack surface driven by AI agents, machine identities, cloud environments and increasingly complex enterprise infrastructures. Addressing these challenges, ServiceNow has unveiled a major expansion of its Autonomous Security vision, introducing six unified security solutions that combine AI-powered automation, governance and risk management into a single platform.

The announcement strengthens ServiceNow’s position as one of the industry’s fastest-growing enterprise security providers, bringing together exposure management, vulnerability detection, identity security, cyber-physical protection, incident response and compliance under a unified operational framework.

Tackling AI-era security complexity

Modern enterprises often operate dozens of disconnected security tools across endpoints, networks, cloud environments and identities, creating fragmented visibility and slower response times. ServiceNow estimates that many organisations manage more than 70 individual security solutions, making it increasingly difficult for security teams to identify and prioritise risks efficiently.

With Autonomous Security, ServiceNow aims to replace this fragmented approach with a unified system capable of continuously monitoring assets, identities and AI agents while providing business context, governance and auditability from a single platform.

The company’s broader vision, known as Shift Zero, focuses on embedding security into every stage of enterprise operations, moving organisations away from reactive incident response towards continuous prevention.

Six security pillars

At the centre of the announcement are six integrated solution areas covering the modern enterprise attack surface.

Unified Exposure Management

The platform consolidates vulnerability findings from multiple security tools into a single view, enriching them with threat intelligence and business context to help organisations prioritise remediation more effectively. A new Vulnerability Resolution AI Specialist is designed to automate triage and execute low-risk remediation tasks at enterprise scale.

Continuous Vulnerability Detection

ServiceNow is expanding visibility across applications, cloud environments and infrastructure with new capabilities that include application security, dynamic application security testing (DAST) and external attack surface management. Together, these tools aim to identify vulnerabilities before they can be exploited.

Cyber-Physical Security

Recognising the growing importance of operational technology (OT), IoT and connected medical devices, ServiceNow is introducing agentless discovery, continuous compliance monitoring and automated remediation workflows that minimise operational disruption while improving visibility across critical infrastructure.

Identity and Access Security

The company is also extending governance to non-human identities, including service accounts, cloud identities and AI agents. New capabilities enable organisations to manage permissions, automate key rotation and apply least-privilege principles consistently across both human and machine identities.

Agentic Incident Response

To help security operations centres respond faster, ServiceNow is introducing AI-driven incident response capabilities that automate investigation, threat enrichment, correlation and containment while escalating only high-risk decisions to human analysts.

Cyber Risk and Compliance

The final pillar focuses on continuous compliance rather than periodic audits. AI-powered monitoring continuously evaluates access rights, configuration changes and policy violations while generating compliance-ready reporting across major regulatory frameworks. The platform also introduces cryptographic asset management capabilities to support future migration towards quantum-resistant encryption standards.

AI Specialists automate security operations

Alongside the platform enhancements, ServiceNow introduced new AI Specialists capable of autonomously completing security workflows.

These specialised AI agents are designed to assist with vulnerability remediation, incident response, exposure management and continuous compliance monitoring, helping security teams automate repetitive tasks while maintaining governance and auditability.

The company believes these capabilities will allow enterprises to respond to threats at machine speed without sacrificing operational oversight.

Building a unified security ecosystem

ServiceNow’s latest security strategy is further strengthened through technologies integrated from Armis and Veza.

Armis contributes continuous visibility across connected devices and operational technology environments, while Veza enhances identity governance by mapping permissions across human users, machine identities and AI agents. Combined with ServiceNow’s AI Control Tower and orchestration capabilities, these technologies provide organisations with a centralised view of assets, identities and security operations.

Availability

Several new capabilities, including Agentic Exposure Management, Application Security, Dynamic Application Security Testing (DAST), External Attack Surface Management (EASM), Cyber Physical Security and AI Agent Access Security, are available immediately.

Additional features—including the Tier 2 SOC AI Specialist, Vulnerability Resolution AI Specialist, Continuous Control Monitoring and Cryptographic Asset Compliance—are expected to become available in December 2026.

Continue Reading

Trending

Copyright © 2023 | The Integrator