Genetec Warns Middle East Firms: AI Is Accelerating Credential Attacks on Physical Security Systems

Genetec has urged Middle East organisations to strengthen credential governance across connected physical security systems, warning that AI is accelerating the speed and scale of attacks against cameras, access control and cloud infrastructure.

Salma Mubarak
Cloud Security & AI Security Contributor4 min read
A security professional monitoring physical security systems from a control room, representing the growing need for identity and credential governance across connected physical security infrastructure in the Middle East.

A security professional monitoring physical security systems from a control room, representing the growing need for identity and credential governance across connected physical security infrastructure in the Middle East.

Genetec, the global leader in enterprise physical security software, has issued a direct warning to organisations across the Middle East: artificial intelligence is transforming the speed and precision of credential-based attacks, and the physical security systems that protect buildings, people and critical assets are increasingly in the crosshairs.

The warning comes from Firas Jadalla, Regional Director for the Middle East, Turkey and Africa at Genetec, who stated that the traditional approach to credential management, relying on periodic password changes and basic cyber hygiene, is no longer an adequate defence. "AI is changing the speed and scale of cyber risk," Jadalla said. "Attackers can now move faster and are using AI to impersonate people, tailor social engineering attacks, uncover vulnerabilities at scale, and evade detection. To respond, organisations need to actively govern access and identity across their systems, not just set controls once and hope they hold."

The scale of the problem is well documented in Genetec's own research. The company's Enterprise Physical Security in the Cloud Era study, drawing on insights from more than 7,300 physical security professionals worldwide, found that 58.7 per cent of organisations have experienced an increase in phishing and smishing attacks. A further 41 per cent reported a rise in overall physical or cyber incidents, while 43.5 per cent identified social engineering as a leading attack vector.

Across the Middle East, where organisations are investing heavily in smart, connected infrastructure as part of broader digital transformation agendas, the security posture of physical systems is an area of growing concern. Connected cameras, access control platforms, servers and cloud services all rely on credentials that, if compromised, provide direct entry into sensitive operational environments. The passwords used to connect directly to physical devices are among the most frequently overlooked, yet they represent one of the most reliable entry points for attackers who know where to look.

Genetec's guidance focuses on three interconnected priorities for organisations in the region.

The first is strengthening identity and credential controls at every layer of the physical security stack. This means eliminating default and shared credentials, enforcing strong authentication including passkeys and multi-factor authentication, and extending those controls to devices themselves. Where possible, static device passwords should be replaced with certificate-based authentication, supported by centralised management and regular rotation schedules.

The second priority is closer alignment between IT and physical security teams. As physical security systems become more deeply integrated with enterprise networks, the gap between the two disciplines creates exploitable blind spots. Bringing these teams together under a shared set of security standards improves visibility into access risks and enables more coordinated incident response when something goes wrong.

The third is a governance-first approach to managing physical security infrastructure. Genetec argues that these systems should be managed with the same rigour applied to other mission-critical technology: regular access reviews, controlled update cycles, and long-term partnerships with vendors who can demonstrate transparency and operational resilience.

The timing of this warning is significant. The release comes on the same week that the UAE Cyber Security Council launched the UAE Cyber Factory initiative and formalised a partnership with Palo Alto Networks to strengthen AI-driven national cyber resilience. These developments collectively signal that the region's approach to cybersecurity is maturing rapidly, and that the boundaries between physical and digital security are narrowing in ways that demand new operational frameworks.

For enterprise security leaders and facility managers across the MENA region, Genetec's message is clear. The assumption that physical security systems exist in a separate risk category from IT infrastructure is no longer valid. A compromised camera credential or an exposed access control system is as consequential as a breached enterprise account. Governance frameworks that account for this convergence are not optional additions. They are foundational to any credible security posture in 2026 and beyond.

Genetec serves more than 42,500 customers across 159 countries, with an extensive network of accredited partners and consultants serving government and enterprise clients throughout the Gulf.

Salma Mubarak

Cloud Security & AI Security Contributor

Salma is a cloud security architect and AI risk analyst specializing in DevSecOps, SaaS security, and infrastructure protection. She focuses on identifying cloud misconfigurations, AI vulnerabilities, and implementing zero-trust security frameworks for modern organizations.

At MENA Cyber Wire, Salma breaks down complex cybersecurity and AI risk concepts into clear, practical insights for founders, IT managers, and security professionals across the MENA region.

Intelligence Focus Areas

physical security cyber convergenceGCC identity governanceenterprise security Middle Eastmena cyber newsgulf cyber security news