GCC Cybersecurity Leaders Warn: Passwords Are the Weakest Link in Your Defence Strategy
From SentinelOne and Sophos to Dragos and Censys, GCC cybersecurity leaders are united: passwords are a liability, attackers are logging in rather than breaking in, and the region's identity security posture must change now.

A professional at a laptop representing the growing debate on password security and identity governance across GCC organisations in 2026.
Across the GCC, the conversation about identity security has shifted. It is no longer a technical discussion held within IT departments. It is a board-level concern, a business risk, and increasingly, the single greatest vulnerability facing organisations that have spent years building robust infrastructure but left the front door unlocked.
The numbers make the case bluntly. Last year, 82 per cent of intrusions involved no malware at all, according to Meriam ElOuazzani, Vice President for the Middle East, Turkey and Africa at Censys. "Attackers are not breaking in anymore," she said. "They are logging in. Credentials were the door, and the door was already unlocked."
That framing, from intrusion to authenticated access, defines the challenge facing security leaders across the region. And the urgency has moved up the corporate ladder accordingly.
Identity as a board-level risk
In sectors including oil and gas, utilities, manufacturing and financial services, the consequences of a compromised credential extend far beyond a data incident. They reach into operational continuity, physical safety and financial exposure.
Mike Hoffman, Field CTO for Oil and Gas at Dragos, put it plainly. "Many cyberattacks begin with credential theft, phishing, or password reuse, often allowing attackers to move from IT into OT environments. Because cyber incidents can disrupt operations, impact safety, and cause financial loss, identity security is no longer just an IT issue. It is a business risk that requires executive attention."
Ezzeldin Hussein, Regional Senior Director at SentinelOne, agreed the lens has fundamentally changed. "Identity and password security have evolved to become a board-level business priority as identity is now the primary attack surface. With cloud adoption, remote work, and expanding digital services, a compromised credential can directly affect revenue, processes, and reputation."
For Ranjith Kaippada, Managing Director at Cloud Box Technologies, the stakes are even more personal. "In the UAE, most breaches originate from compromised credentials rather than sophisticated exploits," he said. "Even a single credential breach can damage years of reputation that a brand has built."
ElOuazzani identified a structural mismatch as the root cause. Cloud acceleration has outpaced identity governance across the region. Organisations expanded quickly, often across multiple cloud environments, and access controls did not keep pace. "The exposure is real," she said, "and in many cases, it is already inside the environment."
The end of the password
If there is one point of consensus across the GCC cybersecurity community, it is that the password itself has become the liability. The successor technologies, including phishing-resistant multi-factor authentication, FIDO2, biometric passkeys and national identity frameworks such as UAE PASS, have matured to the point where migration is no longer a future consideration. It is a present imperative.
Chester Wisniewski, Director and Global Field CISO at Sophos, offered the most direct assessment. "Stop using passwords. They are simply secrets. We are bad at keeping secrets and we are even worse at storing them. Adopt passwordless authentication for both convenience and security."
Jay Reddy, Head of Growth at ManageEngine, argued that even MFA in its traditional form is no longer a sufficient answer. "MFA is no longer a blanket solution if it can be phished or bypassed. Replacing passwords and vulnerable factors like SMS or email OTPs with phishing-resistant methods such as FIDO2 and passkeys is becoming critical."
Hussein pointed to regional infrastructure already in place to support the shift. "Businesses are beginning to use identity-first security approaches, including national digital identity frameworks like UAE PASS, robust verification methods like FIDO2, and zero-trust principles."
AI on both sides of the perimeter
Underpinning the urgency is the rapid weaponisation of generative AI. Threat actors are using it to generate convincing phishing campaigns, create deepfake personas and automate credential theft at a scale that was not possible even eighteen months ago.
Hoffman described the dynamic in operational technology environments specifically. "AI is making identity security more important than ever. Threat actors are increasingly leveraging AI-generated personas, fake LinkedIn profiles, and sophisticated social engineering techniques to gain initial access into IT and OT environments."
Hussein framed it as a two-sided equation. "Defenders will use AI to correlate endpoint, identity, and cloud signals in real time, while attackers will use it to automate phishing, deepfakes, and credential theft."
Reddy added the workforce dimension. "AI cuts both ways. It has made it easier for cybercrime to scale, while also increasing reliance on AI within security platforms to keep pace, especially with the documented cybersecurity skills shortage across the GCC."
Kaippada described where this leads. "Adaptive identification, which uses behavioural biometrics and contextual cues to evaluate risk in real time, is the way forward. AI-to-AI authentication, in which machines are used to check other machines, is one change that goes largely unnoticed but carries significant implications."
The machine identity explosion
One of the most under-addressed challenges in the region is the explosion of non-human identities. Every API key, service account, automated workflow and AI agent represents a credential. Most organisations have limited visibility into how many are active in their environments and what data they can access.
Wisniewski was direct about the risk. "Service accounts and application automation have created a proliferation of API keys, often with over-privileged access to company data. Modern attackers are targeting these non-human identities and causing massive data breaches. This problem is only likely to get worse with the rapid adoption of agentic AI."
ElOuazzani found the same blind spot consistently in client conversations. "Most security leaders I speak with cannot tell me how many autonomous agents are active in their environment, let alone what data those agents are touching. That is not a tool problem. That is a structural one."
What security leaders should do now
The practical recommendations from across the group converge on a clear set of priorities. Eliminate default and shared credentials. Enforce strong, phishing-resistant authentication. Extend identity governance to devices, not only users. Unify fragmented identity stacks to enable risk-based access decisions. And audit external infrastructure exposure before launching another awareness campaign.
"Stop treating this like a user education problem," said ElOuazzani. "Every World Password Day, organisations push awareness campaigns, circulate tip sheets, remind employees to use strong passwords. And every year, credentials remain one of the most reliable entry points for attackers. Audit what your organisation's external infrastructure exposes right now, today, before you send a single internal memo."
Kaippada offered the clearest strategic reframe. "Stop treating passwords as a primary defence and start treating them as a liability. It is not about stronger passwords. It is about reducing dependence on them altogether to significantly shrink your organisation's total attack surface."
For enterprise security teams across MENA, the direction of travel is clear. The question is no longer whether to move away from passwords but how quickly that transition can be executed across complex, multi-cloud, hybrid environments, where legacy systems and risk appetite have historically slowed progress the most.
Salma Mubarak
Cloud Security & AI Security ContributorSalma is a cloud security architect and AI risk analyst specializing in DevSecOps, SaaS security, and infrastructure protection. She focuses on identifying cloud misconfigurations, AI vulnerabilities, and implementing zero-trust security frameworks for modern organizations.
At MENA Cyber Wire, Salma breaks down complex cybersecurity and AI risk concepts into clear, practical insights for founders, IT managers, and security professionals across the MENA region.