Uncategorized
SHADOW DATA: A HIDDEN RISK IN THE GULF
By Yazen Rahmeh, a Cybersecurity Expert at SearchInform
Digital transformation across the UAE and Saudi Arabia brings new opportunities and prospects for enhancing efficiency and growth. However, it also causes new challenges to data protection. As digital environments expand, data spreads across endpoints, cloud storage, and internal environments, escaping oversight by security and compliance teams.
This is shadow data, and it may be one of your organization’s most underestimated risk.
What Is Shadow Data?
Despite all efforts, some business data can be stored and processed outside official IT systems. As a result, a company won’t even know that such datasets exist.
There are a lot of reasons behind the creation of shadow data. Basic examples are:
- Files stored in personal accounts. An employee can send important files to personal email or cloud storage “just in case.”
- Access to corporate data from personal devices. A person can log in to corporate cloud services from a personal tablet or laptop. As a result, sensitive documents can be downloaded to a personal device. This usually happens when someone is working overtime or wants to keep important files readily available.
- Unaccounted copies of sensitive data. An employee can simply copy and paste records from a CRM system or a customer spreadsheet into a file on their workstation. As a result, sensitive data may bypass security controls, increasing the risk of data leakage.
- Some business units can adopt SaaS services without oversight. Employees usually do it to boost their productivity or if whitelisted tools are perceived as slow or bulky.
- Test datasets and temporary databases. Sometimes confidential data can duplicate during migration from one service to another or if developers use production data for test or development environments.
These examples may seem abstract, but the recent Cybersecurity and Infrastructure Security Agency (CISA) data leak shows that shadow data is a real-world threat.
The leak reportedly originated from a contractor’s GitHub repository, which was being used as a working scratchpad. The repository exposed various sensitive records, including AWS keys and plaintext passwords for internal CISA systems. An individual had simply copied sensitive data to make their work more convenient. To do so, the contractor disabled GitHub’s default security setting that prevents users from publishing secrets in public repositories.
Why Shadow Data Is a Business Risk
Increased Risk of Data Leaks
Consider a common scenario: an employee stores confidential data on a personal laptop or cloud service. As a result:
- Sensitive records could be stolen via phishing or malware, as the laptop isn’t protected by enterprise-grade security controls.
- An employee could share the laptop with other individuals. Shared devices increase the risk of data exposure.
- Unauthorized cloud backups. An employee may configure automatic file backups to a cloud service. As a result, sensitive data can leave the protected perimeter and be duplicated in cloud storage, increasing the risk of unauthorized access or data leakage.
That’s how a small and seemingly irrelevant piece of ungoverned data could lead to a major incident. In fact, in 2024, one in three data breaches involved shadow data, according to IBM’s Cost of a Data Breach 2024 report.
One of the most recent cases of data leaks, involving shadow data, is the Abu Dhabi Finance Week exposure. An independent researcher discovered unsecured cloud storage with ID details.
Event representatives stated that only the researcher accessed the data and that the incident affected a limited number of participants. According to them, the issue was caused by a misconfigured cloud storage system managed by a third-party provider.
The incident is the perfect example of shadow data, as the data was copied outside of secured corporate infrastructure and had been left unmanaged.
Regulatory Pressure
Shadow data also presents compliance risks. When using a cloud service, it is essential to verify the geographic location of the data center where the data is stored. Data could be stored at a data center in a different country if you didn’t specify a server location.
As a result, if shadow data includes confidential records such as customer details or transaction records, it will be transferred and stored abroad. From a legal perspective, such misconfiguration is a cross-border transfer and lead to regulatory fines for violations of data protection regulations.
Saudi Arabia’s Personal Data Protection Law dedicates a lot of attention to data residency and cross-border transfers. Organizations, especially in regulated sectors, such as financial institutions, may be required to store certain categories of data within the Kingdom. Companies may need regulatory approval before transferring data to foreign data centers to avoid penalties.
Emirati businesses have less strict conditions for cross-border data transfers. However, there are limitations for banking, payments, healthcare, and telecom organizations and governmental entities. Companies from these industries must store confidential data, such as health records, payment transactions, and customer data, within the country.
Lack of visibility equals lack of control, and regulators do not accept invisibility as an argument.
How to Bring Shadow Data Under Control
Eliminating shadow data entirely is unrealistic. The goal is to make it visible and manageable without slowing down the business.
A Practical Starting Checklist
- Discover regulated data, especially data subject to local PDPLs requirements, cybersecurity frameworks issued by National Cybersecurity Authority in the KSA, and Information Assurance Regulation by TDRA in the UAE. It is essential to identify all information that qualifies as confidential and valuable, incl. unaccounted copies of such data.
- Map where this data is actually stored and shared, not just where it should be. Sensitive data can be stored on-prem or in cloud environments. Look for data discovery solutions. Ideally, choose a solution that combines data discovery and data classification, like DCAP software.
- Classify files & distribute access rights. Use specialized tools to analyze file content and classify it in accordance with a local classification scheme. The next step is to assign user access rights to sensitive data based on employees’ roles and responsibilities.
- Control data transfer channels, including cloud storage, SaaS tools, and USB-devices. Use DLP systems to prevent unauthorized spread of sensitive data. Advanced DLP solutions monitor cloud services, as well as traditional channels, such as email or web browsers.
Conclusion
Data protection is not a one-time initiative. It is an ongoing discipline. Security achieved today must still hold tomorrow — and next year.
Organizations that treat data security as a strategic investment, rather than a compliance obligation, build resilience, regulatory confidence, and long-term business stability.
Shadow data may be invisible. But its consequences are not.
Hospitality
Minor Hotels Announces Avani Kota Kinabalu in Malaysia
Minor Hotels, a leading global hotel owner and operator, has announced Avani Kota Kinabalu, a 352-key premium lifestyle hotel set to open in Q1 2027. Forming part of The Logg Luyang integrated development by KTI Landmark, the property will introduce the Avani brand to Sabah and expand Minor Hotels’ presence in Malaysia.
Avani Kota Kinabalu will cater to leisure and corporate demand in Kota Kinabalu, one of East Malaysia’s principal commercial centres and a key gateway to Borneo. Approximately 10 minutes from Kota Kinabalu International Airport, the hotel will provide access to the city’s business districts, residential neighbourhoods and visitor attractions.
The announcement supports Minor Hotels’ strategy of expanding its lifestyle portfolio in destinations with growing domestic, regional and international demand. Avani Kota Kinabalu will also strengthen the group’s presence in Malaysia, joining Anantara Desaru Coast Resort & Villas in Johor, as it continues to pursue development opportunities across Asia.
Developed by KTI Landmark, The Logg Luyang will bring together hospitality, commercial and lifestyle components within the established Luyang neighbourhood. Avani Kota Kinabalu will serve as the development’s hospitality anchor, offering accommodation, dining, wellness and event facilities for hotel guests and the local community.
“Kota Kinabalu is evolving rapidly as a regional business and tourism hub, creating strong demand for a hotel that can move easily between corporate, leisure and social use,” said Winston Gong, General Manager of Avani Kota Kinabalu. “Our focus will be on delivering an efficient, locally relevant guest experience while building a property with genuine appeal to the city’s residents.”
Designed by Shah Architect, with landscape architecture by SD2 and interiors by INdulge, Avani Kota Kinabalu will feature 352 rooms tailored to business trips, short breaks and longer stays.
Avani Kota Kinabalu will feature five dining and social venues for hotel guests and the local community. The all-day dining restaurant will serve Sabahan, Malaysian, Korean and international cuisine, with live cooking stations, local specialities and a signature Avani Sunday Lunch. A contemporary Chinese restaurant will focus on Sabah Hakka heritage and regional flavours, while the Lobby Lounge will transition from a daytime meeting space into an evening venue serving afternoon tea, as well as cocktails and whiskies.
The Pantry will offer handcrafted bakery items, desserts and premium coffee for dining in or takeaway. On the rooftop, SEEN Restaurant & Bar will bring the established rooftop dining and nightlife concept to Sabah through globally inspired cuisine, mixology, curated music and destination-led experiences.
The hotel will also include dedicated meeting and banquet facilities for conferences, weddings and social events. Leisure facilities will include an infinity pool and AvaniFit gym, with nearby Tun Fuad Stephens Park offering access to outdoor recreation.
Avani Kota Kinabalu will combine accommodation, rooftop dining, wellness and event facilities within a major integrated development, strengthening Minor Hotels’ lifestyle offering in Malaysia and supporting the group’s continued expansion across Asia.
Uncategorized
ServiceNow Expands Autonomous Security Vision with Unified AI-Powered Cyber Defense Platform
The company introduces six integrated security solutions designed to help enterprises detect, prevent and respond to cyber risks at machine speed.
As organisations continue to accelerate AI adoption, cybersecurity teams are facing a rapidly expanding attack surface driven by AI agents, machine identities, cloud environments and increasingly complex enterprise infrastructures. Addressing these challenges, ServiceNow has unveiled a major expansion of its Autonomous Security vision, introducing six unified security solutions that combine AI-powered automation, governance and risk management into a single platform.
The announcement strengthens ServiceNow’s position as one of the industry’s fastest-growing enterprise security providers, bringing together exposure management, vulnerability detection, identity security, cyber-physical protection, incident response and compliance under a unified operational framework.
Tackling AI-era security complexity
Modern enterprises often operate dozens of disconnected security tools across endpoints, networks, cloud environments and identities, creating fragmented visibility and slower response times. ServiceNow estimates that many organisations manage more than 70 individual security solutions, making it increasingly difficult for security teams to identify and prioritise risks efficiently.
With Autonomous Security, ServiceNow aims to replace this fragmented approach with a unified system capable of continuously monitoring assets, identities and AI agents while providing business context, governance and auditability from a single platform.
The company’s broader vision, known as Shift Zero, focuses on embedding security into every stage of enterprise operations, moving organisations away from reactive incident response towards continuous prevention.
Six security pillars
At the centre of the announcement are six integrated solution areas covering the modern enterprise attack surface.
Unified Exposure Management
The platform consolidates vulnerability findings from multiple security tools into a single view, enriching them with threat intelligence and business context to help organisations prioritise remediation more effectively. A new Vulnerability Resolution AI Specialist is designed to automate triage and execute low-risk remediation tasks at enterprise scale.
Continuous Vulnerability Detection
ServiceNow is expanding visibility across applications, cloud environments and infrastructure with new capabilities that include application security, dynamic application security testing (DAST) and external attack surface management. Together, these tools aim to identify vulnerabilities before they can be exploited.
Cyber-Physical Security
Recognising the growing importance of operational technology (OT), IoT and connected medical devices, ServiceNow is introducing agentless discovery, continuous compliance monitoring and automated remediation workflows that minimise operational disruption while improving visibility across critical infrastructure.
Identity and Access Security
The company is also extending governance to non-human identities, including service accounts, cloud identities and AI agents. New capabilities enable organisations to manage permissions, automate key rotation and apply least-privilege principles consistently across both human and machine identities.
Agentic Incident Response
To help security operations centres respond faster, ServiceNow is introducing AI-driven incident response capabilities that automate investigation, threat enrichment, correlation and containment while escalating only high-risk decisions to human analysts.
Cyber Risk and Compliance
The final pillar focuses on continuous compliance rather than periodic audits. AI-powered monitoring continuously evaluates access rights, configuration changes and policy violations while generating compliance-ready reporting across major regulatory frameworks. The platform also introduces cryptographic asset management capabilities to support future migration towards quantum-resistant encryption standards.
AI Specialists automate security operations
Alongside the platform enhancements, ServiceNow introduced new AI Specialists capable of autonomously completing security workflows.
These specialised AI agents are designed to assist with vulnerability remediation, incident response, exposure management and continuous compliance monitoring, helping security teams automate repetitive tasks while maintaining governance and auditability.
The company believes these capabilities will allow enterprises to respond to threats at machine speed without sacrificing operational oversight.
Building a unified security ecosystem
ServiceNow’s latest security strategy is further strengthened through technologies integrated from Armis and Veza.
Armis contributes continuous visibility across connected devices and operational technology environments, while Veza enhances identity governance by mapping permissions across human users, machine identities and AI agents. Combined with ServiceNow’s AI Control Tower and orchestration capabilities, these technologies provide organisations with a centralised view of assets, identities and security operations.

Availability
Several new capabilities, including Agentic Exposure Management, Application Security, Dynamic Application Security Testing (DAST), External Attack Surface Management (EASM), Cyber Physical Security and AI Agent Access Security, are available immediately.
Additional features—including the Tier 2 SOC AI Specialist, Vulnerability Resolution AI Specialist, Continuous Control Monitoring and Cryptographic Asset Compliance—are expected to become available in December 2026.
Hospitality
Preserving Heritage Through Modern Hospitality
Exclusive interview with Chef Peter Chaine, Executive Chef at The Club Abu Dhabi
You first arrived in Abu Dhabi in 1987, expecting what you described as a short chapter in your career, yet nearly four decades later, The Club remains an integral part of your journey. What has made this place so special that it continues to feel like home?
I took up an appointment in December 1987 to join The Club in the capacity of Sous Chef and moved on to the reins of Executive Chef in August 1990. I have received the full support of the Committee, Management, Staff and Members to achieve what it is today. The path was never easy, but with the thought “The Club is the second home to its Members,” always at the back of my mind, my team and I are challenged to deliver consistency at all times. I drive myself to take full responsibility for any food on a plate produced at The Club. Sourcing the highest quality ingredients that our Members can enjoy at the most competitive price is predominantly a reason for our success. The regular changes of outlet menus and special dishes or nights offered in various outlets and areas within the property make it a unique experience for the diners. The appreciation from our membership is seen by their decisions to avail themselves of these events. This success has seen our staff retention levels, in comparison to industry competitors, be the lowest.
Having witnessed Abu Dhabi’s remarkable transformation over nearly four decades, how have you seen The Club evolve while preserving the sense of community and belonging that has defined it for generations?
I have always felt that The Club forms a major part of the expatriate community due to the offerings in place. Hosting various events with local dishes for the wide repertoire of membership has driven us to always focus on “under promising and over delivering”.
Today’s diners seek more than exceptional food, they value authenticity, storytelling and memorable experiences. How has your culinary approach evolved to meet these changing expectations while remaining true to The Club’s heritage? And, you’ve witnessed Abu Dhabi transform from a quiet coastal city into a global destination. If food could tell the story of that journey, what would it say?
As much as I have seen Abu Dhabi grow in the past decades, I say the same of The Club, too. We are proud to think that we are a heritage site offering modern food of the highest standard within the industry in the region. The varying nationalities of membership have grown considerably and helped us to be more of a globally recognised organisation. Staples that have been Fish and Chips have now moved over to Chicken Tikka Masala, Thai Green Curry or a Beef Nashif.
The Port, hosting storage facilities, has been cleared and transformed into an International Cruise Terminal, while the rear end of The Club has facilitated the new 4- to 5-lane main highway.
Having mentored generations of chefs and helped establish the Emirates Culinary Guild, what responsibility do experienced culinary leaders have in nurturing the next generation of talent, and what qualities do you believe young chefs should cultivate to succeed in today’s industry?
I have earned my present position of Vice President in The Emirates Culinary Guild, as I was always interested in innovation and modernisation of dishes. I competed amongst some of the best and helped gain recognition for The Club within the fraternity of hospitality establishments in the UAE. Being there to offer assistance to colleagues when they collected many accolades for individuals and for the club is an achievement itself. We believe in nurturing the youth by way of offering regular on the job trainings where we can then look to maintain the standards while sustaining the level of enthusiasm for business growth.
Rapid Fire questions:
What does success mean to you today?
Success to me today is that we meet all expectations and deliver to the highest standards consistently.
A signature dish everyone should try at The Club?
My signature dish is none, as I expect the diners to be adventurous and place all trust in the hands of the chef’s creations and interpretation of a dish, and try all we have to offer.
A young chef every aspiring professional should learn from?
The industry I came into almost 4 decades ago has evolved; thus, we cannot expect the staff to work the long hours we worked, give up weekends or parties for work. However, the need to offer 8 honest and productive hours to the establishment should be the vision. The work and lifestyle balance is very important for the youth of tomorrow. They need to be aware that good mental health is vital for success in achieving a happy family. I would also like to see a future that brings a positive attitude as being most important. Whatever you do is never going to be enjoyed if you are not in that frame of mind. Training can be provided, but a positive attitude has to be instilled from the initial education.
-
News11 years ago
SENDQUICK (TALARIAX) INTRODUCES SQOOPE – THE BREAKTHROUGH IN MOBILE MESSAGING
-
Trending10 months agoOPPO A6 Pro 5G Review: Reliable Daily Driver
-
Tech News2 years agoDenodo Bolsters Executive Team by Hiring Christophe Culine as its Chief Revenue Officer
-
VAR1 year agoMicrosoft Launches New Surface Copilot+ PCs for Business
-
Automotive2 years agoAGMC Launches the RIDDARA RD6 High Performance Fully Electric 4×4 Pickup
-
Tech Interviews2 years ago
Navigating the Cybersecurity Landscape in Hybrid Work Environments
-
Tech News1 year agoNothing Launches flagship Nothing Phone (3) and Headphone (1) in theme with the Iconic Museum of the Future in Dubai
-
VAR2 years agoSamsung Galaxy Z Fold6 vs Google Pixel 9 Pro Fold: Clash Of The Folding Phenoms


