MENA News
Jul 27, 2026
MENA News


SANS Institute's new Gulf-edition maturity model gives regional enterprises a stage-by-stage benchmark for AI security readiness, replacing improvisation with a shared standard.
[For more news, click here]
For years, chief information security officers across the Gulf have approached artificial intelligence the way pilots approach turbulence: braced, reactive, and hoping the instruments hold. That posture is starting to shift. SANS Institute, the global cybersecurity training and certification organization, has given the region something it has largely lacked: a structured way to measure how ready an organization actually is to secure the AI systems it is racing to deploy.
The Gulf edition of the SANS AI Security Maturity Model, released this week, is not a warning label. It is a diagnostic tool, built to help enterprises figure out where their AI governance stands today and what comes next. The timing is deliberate. Banks, government agencies and telecom operators across the region have spent the past two years embedding AI into everything from fraud detection to customer service, often faster than their security programs could keep pace.
The urgency behind the eBook traces back to a number that has alarmed security researchers for months: how quickly attackers can turn a disclosed vulnerability into a working exploit. Chris Cochran, Field CISO and Vice President of AI Security at SANS Institute and the framework's author, has watched that window collapse in real time.
"Across the Gulf, organizations are adopting AI for innovation and growth, but the pace of cyber threats continues to intensify," Cochran said. "As highlighted in our latest SANS global cybersecurity report, attackers are already using AI to increase the speed and sophistication of attacks, while time-to-exploit has fallen from more than two years in 2019 to less than 24 hours today. Security leaders can no longer rely on reactive approaches. They need a consistent way to evaluate their readiness, establish stronger governance, and build resilience as AI becomes integral to business operations."
That shrinking runway is precisely why a maturity model, rather than another list of best practices, matters. Best practices tell an organization what to do. A maturity model tells it where it stands relative to that goal, and what the next concrete step looks like.
The framework rests on three pillars: Protect, Utilize and Govern. Protect covers the technical work of securing AI systems themselves, from unverified third-party models to the data pipelines feeding them. Utilize flips the lens, treating AI as a tool that can strengthen cybersecurity operations rather than only threaten them. Govern addresses the policy layer, the rules and oversight structures that determine whether AI use across an organization is deliberate or accidental.
Layered underneath those pillars are five stages of maturity, ranging from organizations with little or no formal AI governance to those running adaptive, self-correcting AI security programs. Each stage comes with practical controls, measurable indicators and recommended next actions, alongside a self-assessment tool that lets a security team benchmark its current capability without hiring outside consultants first.
What distinguishes the Gulf edition from a generic checklist is its alignment with frameworks regulators already recognize, including the NIST AI Risk Management Framework, ISO/IEC 42001, the EU AI Act and the Cloud Security Alliance's AI Controls Matrix. That alignment matters practically. A bank in Riyadh or Dubai does not need to build a Gulf-specific compliance vocabulary and a separate one for European or American regulators. The model gives it one language that satisfies both.
Ned Baltagi, Managing Director for the Middle East, Turkey and Africa at SANS Institute, framed the release as an answer to conditions specific to the region rather than an import of a global template.
"The Gulf Edition of the AI Security Maturity Model rightfully addresses the region's unique priorities and regulatory landscape," Baltagi said. "This will help the regional organizations to build trust in AI, strengthen cyber resilience, and enable innovation with confidence."
That distinction, between a template that happens to work in the Gulf and one built around its regulatory landscape from the outset, is the difference between a document enterprises skim once and one they actually use to plan their next fiscal year of security investment.
SANS Institute plans to carry the framework beyond the eBook itself. On August 4 at 3:00 p.m. Gulf Standard Time, the organization will host a webcast with Cochran walking attendees through how to apply the self-assessment tool and build out a maturity roadmap inside their own organizations. For CISOs who have struggled to translate AI risk into language a board will fund, that session offers something rarer than another framework: a rehearsal for the conversation itself.
The broader significance of the release is less about any single eBook and more about a pattern taking shape across the region's technology sector. As Gulf governments push AI adoption as a matter of national strategy, from Saudi Arabia's sovereign AI ambitions to the UAE's smart-government programs, the security infrastructure underpinning that push has increasingly needed its own roadmap, not just enthusiasm. A maturity model does not eliminate risk. What it does is give enterprises, for the first time in a structured, regionally grounded way, a shared vocabulary for measuring how far they still have to go, and a clear next step to get there.
Forcepoint Launches a Platform That Governs AI by Governing the Data Inside It
Why Human Oversight Is Becoming the Real Scaling Engine for Gulf Fintech's AI Agents
How Outpost24's New CyberFlex Program Helps Security Teams Keep Pace With AI-Era Risk
Related Articles