2025 GCC Cybersecurity in Review: Key insights from the SANS Threat Landscape Report

2025 GCC Cybersecurity in Review: Key insights from the SANS Threat Landscape Report

The cybersecurity landscape across the Gulf Cooperation Council (GCC) countries is evolving rapidly, presenting unique challenges and opportunities for technology and security leaders. The SANS Institute 2025 GCC Cybersecurity Threat Landscape Report serves as a vital compass; offering an in-depth, regional assessment of the prevailing cyber-risks, defence strategies and skills gaps. In this article, Frank Kim, Venture Advisor at YL Ventures (Fellow at SANS Institute), discusses how the research sets out a clear, data-driven picture of the GCC’s current security posture, benchmarking local realities against global best practices.

Can you introduce the SANS Institute 2025 GCC Cybersecurity Threat Landscape Report and explain what the research set out to achieve?

Cyber-risks in the GCC are evolving faster than ever and the SANS Institute 2025 Threat Landscape Report uncovers what security leaders in the region need to know right now. This environment is markedly shaped by the complex geopolitical situation and the critical regional assets currently at play.

To gain specific insight into these challenges, we conducted a comprehensive survey and interview series. This involved canvassing 200 security leaders, professionals and practitioners specifically operating within the GCC.

The scope of the research spanned the entire region, encompassing Saudi Arabia, Bahrain, the UAE, Qatar, Oman and Kuwait. The objective was clear: to establish a granular view of the security concerns, considerations and direct threats being confronted by leadership in that specific geographical domain.

The research reveals high cyber-risk but low spending (0-25%) on detection and response. Why is this resource imbalance so persistent and what mindset shift is required for leadership?

That is an intriguing finding. Whilst a comparative analysis with other global regions would be illuminating, I contend that this phenomenon primarily reflects the varying stages of security maturity among different organisations.

This maturity level is clearly contingent upon core organisational attributes, notably the industry sector and the sheer size of the organisation. When we look closely at the survey data we see that the spending is roughly distributed across a spectrum, ranging from those with arguably the lowest expenditure, to those with the most significant spending, with several intermediate tiers separating them.

Therefore, this distribution strongly suggests an existence of inconsistent or divergent security priorities amongst the respondents and the diverse range of industries within which they operate.

With rising ransomware and critical OT concerns like System Vulnerabilities and External Access Risks, how can organisations effectively prioritise defence strategy and talent acquisition?

When we discuss cybersecurity strategy, we are fundamentally referring to the construction of a comprehensive plan. This plan must first establish a baseline: where does the organisation currently stand and what are its existing capabilities?

Some organisations may demonstrate deficiencies from a threat detection and response perspective, while being more advanced in other domains. Critically, various regulatory bodies across the Gulf states such as the Saudi Arabian Monetary Authority (SAMA) explicitly mandate the implementation of a coherent strategy. This means an organisation must operate with a definitive plan, which necessitates adherence to a recognised framework.

The encouraging news emanating from the research is the acknowledgement of several country-specific frameworks. For instance, Qatar has its own, the UAE has a dedicated framework and Saudi Arabia’s National Cyber Security Authority has established another. These all represent essential best practices. They guide organisations in addressing foundational security requirements, developing corresponding capabilities and ultimately providing a structured playbook or ‘cookbook’, if you will, to ensure systematic compliance and effective risk management.

Given the top ICS/OT concerns are System Vulnerabilities and External Access Risks, which SANS training and control frameworks are best suited to help OT professionals mitigate these risks?

Security, much like good health and hygiene, is an ongoing, continuous affair. The consistent trend shows that implementing foundational best practices effectively mitigates a large percentage of malicious attacker activity. A highly popular foundational framework in the Gulf region is the CIS (Center for Internet Security) Controls. Many countries have tailored versions, such as Saudi Arabia’s Essential Cyber Controls (ECC). The class that details the implementation and auditing of these controls is SEC566.

Regarding the never-ending stream of vulnerabilities and system risks, organisations must develop a mature vulnerability management programme. This requires a strategic approach, which is the focus of our LDR516 class on strategic vulnerability and threat management.

Finally, concerning external access risks, these are fundamentally identity-related issues. The prevailing consensus is that identity is the new perimeter. While many of our cloud courses cover identity components, we are launching a dedicated new class in 2026 called SEC559, which will specifically focus on identity security and corresponding threat defence.

How does SANS’ training in Security Architecture and DevSecOps integrate with Performance Reviews to strategically close proven skills gaps?

This highlights two indispensable components: architecture and DevSecOps. A central challenge, both regionally and globally, is the escalating complexity across the technology, business and threat landscapes. This necessitates that security teams design a comprehensive architecture capable of addressing this confluence of advanced factors. A prime example is the shift to the cloud: virtually every large organisation is multi-cloud, often by design or incidentally via acquisitions. Constructing this appropriately requires leveraging cloud-native capabilities.

This links directly to DevSecOps, which involves implementing automated pipelines and corresponding controls. We must adopt a strategic approach, viewing security from a defensible architecture and Zero Trust perspective.

For professionals seeking to build these specific competencies, relevant SANS training courses are available:

  • The foundational principles of Defensible Architecture and Zero Trust are covered in SEC530
  • Cloud Security Architecture is the focus of SEC549
  • Cloud-Native Security, automation and DevOps are addressed by SEC540

Many organisations monitor regularly but under-resource response. How do SANS’s incident response courses help teams translate basic monitoring data into rapid, effective containment and eradication?

Addressing the Security Operation Centre (SOC) is crucial. It is arguably the most challenging capability within any security programme, spanning the entire career ladder, from the junior analysts with eyes on glass right up to the executive leadership team. The difficulty lies not just in the technical aspects of detection and monitoring, but fundamentally in the human and communication elements.

To support this broad scope, we offer a spectrum of training:

  • For the hands-on SOC analyst training, SEC450, covers skills for cyberdefence operations.
  • More advanced technical skills, such as incident response, threat hunting and digital forensics, are addressed in SEC508.

However, effective monitoring requires more than technical capacity; it demands strategic leadership. Security officers and CSOs must understand how to build and operate a world-class SOC, a focus of the LDR551 course. Ultimately, successful incident management is a people problem. The LDR553 Cyber Incident Management class trains individuals to become effective incident commanders, who can decisively drive complex issues to a successful, co-ordinated resolution.

AI/ML and Cloud/Serverless create new security challenges. Looking ahead, which critical, non-traditional security domains should GCC organisations be investing in today?

Cloud is unequivocally the future trajectory for organisational infrastructure. However, this is inextricably linked to the rise of Artificial Intelligence (AI), encompassing both Generative and Agentic AI. Critically, the adversary is leveraging AI to significantly accelerate their malicious operations.

I highlight the cloud because it is the most common delivery platform for these AI services. The confluence of cloud and AI, especially the proliferation of autonomous agents, makes identity management an even more profound challenge.

We are increasingly dealing with agents operating on our behalf, sometimes without our direct knowledge which drastically complicates the trust boundary from an identity perspective.

Another significant element raised in the report is the evolution of computing power, particularly the use of powerful GPUs for AI. More consequentially, Quantum Computing is now on the visible horizon. Its emergence will necessitate that security teams globally focus immediately on large-scale mitigations, such as implementing Post-Quantum Cryptography (PQC), to counter the imminent threat posed by a viable quantum computer.

Browse our latest issue

Intelligent CIO Middle East

View Magazine Archive