{"id":136277,"date":"2026-01-22T16:30:16","date_gmt":"2026-01-22T16:30:16","guid":{"rendered":"https:\/\/www.intelligentcio.com\/me\/?p=136277"},"modified":"2026-01-22T16:30:16","modified_gmt":"2026-01-22T16:30:16","slug":"beyond-shadow-ai-and-the-detection-gap-in-the-gccs-machine-learning-strategy","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2026\/01\/22\/beyond-shadow-ai-and-the-detection-gap-in-the-gccs-machine-learning-strategy\/","title":{"rendered":"Beyond Shadow AI and the detection gap in the GCC\u2019s Machine Learning strategy"},"content":{"rendered":"\n<p>As the GCC undergoes a massive shift towards AI-driven digital economies, a disconnect is emerging as organisations race to adopt Machine Learning while remaining fundamentally blind to the threats already inside their networks. In this article, Rob Lee, Chief AI Officer and Chief of Research at SANS Institute, discusses the <em>SANS 2025 GCC Cybersecurity Threat Landscape Report<\/em> findings and explores the dual-edged sword of AI, addressing how to defend against AI-powered adversaries while managing the internal \u2018Shadow AI\u2019 risks created by an eager workforce.<\/p>\n\n\n\n<p class=\"has-cyan-bluish-gray-background-color has-background\">Read more insights in the\u00a0<em>2025 GCC Cybersecurity Threat Landscape CXO Priorities Report, in collaboration with SANS Institute<\/em>\u00a0<a href=\"https:\/\/www.cxopriorities.com\/Reports\/SANS%20Institute\/2025%20GCC%20Cybersecurity%20Threat%20Landscape%20CXO%20Priorities%20Survey%20in%20collaboration%20with%20SANS%20Institute\/index.html\">here<\/a>.<\/p>\n\n\n\n<p><strong>What was the primary goal of the <em>SANS 2025 GCC Cybersecurity Threat Landscape Report<\/em>?<\/strong><\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignleft size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"370\" height=\"370\" src=\"https:\/\/www.intelligentcio.com\/me\/wp-content\/uploads\/sites\/12\/2026\/01\/image-1-1.webp\" alt=\"\" class=\"wp-image-136280\" style=\"width:257px;height:auto\" srcset=\"https:\/\/www.intelligentcio.com\/me\/wp-content\/uploads\/sites\/12\/2026\/01\/image-1-1.webp 370w, https:\/\/www.intelligentcio.com\/me\/wp-content\/uploads\/sites\/12\/2026\/01\/image-1-1-300x300.webp 300w, https:\/\/www.intelligentcio.com\/me\/wp-content\/uploads\/sites\/12\/2026\/01\/image-1-1-150x150.webp 150w\" sizes=\"auto, (max-width: 370px) 100vw, 370px\" \/><figcaption class=\"wp-element-caption\"><strong><em>Rob Lee, Chief AI Officer and Chief of Research at SANS Institute<\/em><\/strong><\/figcaption><\/figure><\/div>\n\n\n<p>Fundamentally, capturing a high-fidelity snapshot of regional organisational behaviour is critical. Much like any rigorous threat landscape survey, our objective is to decipher how entities interpret disparate data points and identify which metrics are truly pivotal for executive decision-making. &#8216;Cybersecurity&#8217; is a term so frequently invoked it can border on marketing jargon, yet the reality is a discipline in a state of perpetual evolution.<\/p>\n\n\n\n<p>Understanding these shifts allows organisations to conduct a robust peer analysis. It compels leadership to ask the difficult questions: Are our vulnerabilities unique, or are they systemic? Is our strategic lens aligned with the broader market, or are we overlooking critical vectors entirely? This form of comparative analysis is indispensable; it provides the empirical evidence required for organisations to reassess and, where necessary, recalibrate their overarching security strategies in lockstep with industry trends.<\/p>\n\n\n\n<p><strong>Roughly a third of respondents are unaware of the number of attacks they&#8217;ve experienced. What does this visibility gap tell us about the state of detection capabilities in the region and why is this more important than the attacks themselves?<\/strong><\/p>\n\n\n\n<p>When we scrutinise the figures, particularly the reported one-third of organisations lacking visibility, I suspect the reality is far more sobering. There is an inherent reluctance in our industry to admit to &#8216;digital blindness\u2019. The fundamental axiom remains; you cannot defend against what you cannot see. However, we\u2019re now entering a paradigm where we only recognise what is already known, leaving us dangerously exposed to the novel.<\/p>\n\n\n\n<p>The proliferation of AI-powered attacks has altered the battlefield. We are seeing a marked increase in the velocity and sophistication of these strikes, which threatens to widen the existing &#8216;visibility gap&#8217; into a chasm. Most regional networks suffer from a chronic lack of telemetry; they simply cannot distinguish critical signals from the background noise.<\/p>\n\n\n\n<p>It is a challenge analogous to airport security. When managing a high-volume flow, security teams inevitably focus on documented, known threats. Yet, as we often see, the unknown or the highly sophisticated can slip through the cracks.<\/p>\n\n\n\n<p>The other side of this coin is perhaps more concerning: organisations that believe they have an accurate attack count but are operating on a false sense of security. We must question what &#8216;accurate&#8217; truly looks like and whether we\u2019re benchmarking against peers who are equally misinformed, or whether we\u2019re chasing a definitive metric that for now remains entirely elusive. In this evolving landscape, the pursuit of true visibility is no longer an IT goal, it is a strategic necessity.<\/p>\n\n\n\n<p><strong>Around a quarter of respondents rated cyber risk as &#8216;very low&#8217; while the same number rated it &#8216;high&#8217; in the same region. What&#8217;s driving that divergence and which group should we be more concerned about?<\/strong><\/p>\n\n\n\n<p>The stark divergence in risk perception across the GCC is deeply concerning. This polarisation reflects dramatically different levels of cybersecurity maturity among organisations responding to the same environmental threats.<\/p>\n\n\n\n<p>The &#8216;very low&#8217; risk cohort is particularly telling. While this group may include a few mature programmes that have successfully mitigated their exposure, it likely comprises organisations that simply cannot see the attacks they are facing. Given the documented 32% visibility gap, it is a near-certainty that the majority of these respondents fall into the latter category, equating a lack of data with a lack of danger.<\/p>\n\n\n\n<p>Conversely, the &#8216;high risk&#8217; group likely represents organisations with superior telemetry who are witnessing the true volume of threats hitting their perimeter, or perhaps those recently humbled by a breach.<\/p>\n\n\n\n<p>What is most striking here is the total lack of convergence. An even distribution across these four risk categories suggests there is no shared baseline for assessing cyber risk within the region. Without a common language for risk or a unified approach to visibility, the GCC remains a landscape of disparate silos, making collective regional resilience an uphill climb.<\/p>\n\n\n\n<p><strong>Just over 25% of people allocate less than a quarter of their security budget to detection and response. Given ransomware is the leading growing threat, how is the remaining spend being absorbed?<\/strong><\/p>\n\n\n\n<p>Central to the issue is the deployment of prevention technologies that fail to mitigate the risks that matter most. We\u2019re witnessing a dynamic where organisations \u2018throw money at the problem\u2019 yet don\u2019t scrutinise the diminishing residual returns. A standard business decision has been misapplied: many firms hesitate to double their investment for a marginal 2% gain in efficacy but continue to funnel capital into stagnant areas.<\/p>\n\n\n\n<p>Typically, budgets are absorbed by legacy perimeter defences, compliance-driven endpoint protection and network hardware that is deployed but never properly tuned. We see identity projects that languish for years. However, the modern adversary&#8217;s business model is built almost entirely on post-initial access activity.<\/p>\n\n\n\n<p>If an organisation allocates 75% of its resources to preventing initial access and only 25% to detecting lateral movement, privilege escalation and exfiltration staging, it has optimised for the wrong threat model. The entities that navigate ransomware most effectively are not necessarily those with the largest budgets, but those that have rebalanced towards detection and response. They have moved past the fallacy of total prevention and accepted the \u2018when, not if\u2019 reality of a breach.<\/p>\n\n\n\n<p><strong>AI\/ML prevails as the top emerging security challenge and the leading area organisations require training providers to develop new content. Are security teams trying to defend against AI, deploy AI, or both simultaneously?<\/strong><\/p>\n\n\n\n<p>The cybersecurity industry frequently obsesses over nation-state actors, yet we are currently overlooking a more immediate risk: Shadow AI. Employees uploading sensitive corporate financials to unsanctioned tools like ChatGPT often represent a greater data breach potential than a ransomware attack. Security teams are struggling to manage the liability of an untrained workforce operating outside traditional governance.<\/p>\n\n\n\n<p>We are effectively fighting on three fronts: monitoring AI-powered attacks, deploying AI defensively and securing internal AI systems. These require entirely distinct skill sets. While adversaries, such as China leverage AI to move through networks in seconds rather than days, our defensive response remains hampered by a lack of depth. The 22% of organisations seeking AI\/ML training are the only ones being honest about their limitations; frankly, that figure is dangerously low.<\/p>\n\n\n\n<p>To bridge this gap, security leaders must look beyond traditional silos. AI transformation budgets often contain untapped risk and governance funding. By securing even 5% to 10% of these broader AI budgets, security teams could drastically increase their headcount of trained specialists. In a market where automated tools have yet to achieve maturity, the only viable \u2018stop-gap\u2019 remains a highly trained human element.<\/p>\n\n\n\n<p><strong>Cloud security specialists and penetration testers are equally in demand and security architects less so. Given that architecture is the top training priority, why aren&#8217;t organisations hiring accordingly?<\/strong><\/p>\n\n\n\n<p>In cybersecurity recruitment, we see a recurring bias towards the immediate. Cloud specialists and penetration testers solve visible problems with tangible deliverables; hiring managers know exactly how to evaluate their output. In contrast, Security Architects are the strategic bedrock of an organisation. They design systems that pre-empt emergency fixes, yet because their success is often \u2018invisible\u2019 measured by the absence of a crisis, their impact is significantly harder to quantify.<\/p>\n\n\n\n<p>There is a glaring contradiction in the GCC landscape. While security architecture is the top training priority with 19% of organisations looking to upskill existing staff, hiring practices tell a different story. When a role is vacant, management often defaults to tactical hires because \u2018the fires are burning\u2019. Furthermore, high-calibre architects are both rare and expensive; it is far easier to hire a penetration tester at market rates than to pay the premium an architect requires.<\/p>\n\n\n\n<p>The long-term consequence is a cycle of technical debt. Without architectural oversight, organisations continue to build fragile infrastructures, only to hire more tactical staff to fix entirely predictable problems. Until we value the architect as much as the firefighter, we remain trapped in a reactive loop.<\/p>\n\n\n\n<p><strong>System vulnerabilities and patching tops ICS\/OT concerns. In environments where you often can&#8217;t patch without shutting down production, how are organisations addressing this&nbsp; challenge?&nbsp;<\/strong><\/p>\n\n\n\n<p>Global events, such as the strategic disablement of power grids, demonstrate that adversaries target OT networks with near-total assurance of success. These systems represent one of cybersecurity\u2019s most intractable dilemmas. We are frequently managing SCADA environments built on antiquated foundations, like Windows XP, which are now effectively \u2018hard-coded\u2019 into the infrastructure.<\/p>\n\n\n\n<p>These systems were never designed for the modern era &#8211; they are \u2018unpatchable\u2019, yet irreplaceable. To move beyond this, organisations must adopt a tripartite defensive posture:<\/p>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li>Compensating Controls: Implementing rigorous network segmentation and strict access protocols to isolate legacy nodes<\/li>\n\n\n\n<li>Risk-Based Prioritisation: Identifying critical assets that require bespoke protection when traditional patching is impossible<\/li>\n\n\n\n<li>Enhanced Monitoring: Developing the telemetry required to detect \u2018the bad\u2019 as it happens, rather than after a kinetic failure<\/li>\n<\/ol>\n\n\n\n<p>The challenge is exacerbated by a niche talent market. Critical utilities often lack the capital to compete for the rare specialists trained in both legacy OT and modern security. In this environment, constant vigilance is not merely a goal; it is the only alternative to systemic failure.<\/p>\n\n\n\n<p><strong>In a region with documented nation-state threat activity, nearly a third of organisations check for regional threats quarterly at best. What is the realistic exposure window this creates?<\/strong><\/p>\n\n\n\n<p>The report highlights a staggering oversight: many organisations still monitor for nation-state activity only quarterly. While I suspect some respondents may have misunderstood the question, the implications of such a visibility window are dire. In an era where AI is compressing attack timelines from months to mere days and soon, minutes, a three-month gap in monitoring is an open invitation for persistence.<\/p>\n\n\n\n<p>The GCC is a primary target for sophisticated nation-state actors focused on long-term espionage and prepositioning for future conflict. These adversaries are patient; they don\u2019t \u2018flip tables\u2019 like common burglars. Instead, they operate silently and wait for a specific trigger. If you only check your perimeter every 90 days, an attacker can enter, install a persistent threat and vanish before your next scheduled audit.<\/p>\n\n\n\n<p>This is where AI becomes a defensive necessity. Human monitoring is prone to the monotony of the perimeter walk, but AI provides the continuous, high-frequency telemetry required to catch these subtle movements. While the 35% of organisations performing daily or weekly checks face skyrocketing costs, they are the only ones with a fighting chance. To achieve true resilience, we must move beyond periodic audits and embrace proactive, AI-assisted threat hunting as a continuous operational standard.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>As the GCC undergoes a massive shift towards AI-driven digital economies, a disconnect is emerging as organisations race to adopt Machine Learning while remaining fundamentally blind to the threats already inside their networks. In this article, Rob Lee, Chief AI Officer and Chief of Research at SANS Institute, discusses the SANS 2025 GCC Cybersecurity Threat [&hellip;]<\/p>\n","protected":false},"author":55,"featured_media":136283,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[14804,139,15994,809,12449,20272],"tags":[10751,352,21728],"class_list":["post-136277","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","category-industry-expert","category-middle-east","category-more-news","category-north-america","category-technology","tag-rob-lee","tag-sans-institute","tag-shadow-ai"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/136277","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/55"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=136277"}],"version-history":[{"count":4,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/136277\/revisions"}],"predecessor-version":[{"id":136284,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/136277\/revisions\/136284"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/136283"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=136277"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=136277"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=136277"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}