Huawei Gulf North’s Chief Security Officer Sultan Mahmood Malik on Building Cyber Resilience
Khalid Athar: As AI adoption accelerates, how is the cybersecurity threat landscape evolving for governments and enterprises?
Sultan Mehmood: Thank you very much, Mr. Khalid. This is a very good question to begin with. AI adoption is progressing at an unprecedented pace at the moment. And it is not only governments, enterprises, or other legitimate entities that are adopting AI into their businesses and operations. Cybercriminals are actually taking the lead in adopting AI to fast-track and improve their offensive capabilities.
Take, for example, the skill level that was previously required to launch certain sophisticated attacks, was very high. Today, offensive AI tools can lower the barriers to entry, enabling threat actors, who can now launch sophisticated phishing and scamming attacks at a very rapid pace, while requiring less technical capability.
What we can see as a result is that the fundamental threat landscape has evolved. As attack cycles become increasingly compressed, organisations may have only minutes—or, in some cases, seconds—to detect and respond to malicious activity. Responders who were equipped for analyst-level or human-level speed cannot match the machine-level speed of these attacks. So, this is exactly what we are seeing across not only governments and enterprises, but virtually any entity. This is how threats are evolving at this pace.
KA: How is Huawei integrating security and privacy into its AI, cloud and network infrastructure?
SM: Huawei believes in embedding security and privacy protection into all of its activities, whether it is R&D, business processes, or human resources. We follow secure-by-design and privacy-by-design principles, integrating security requirements into our products and solutions from the initial design stage and throughout their lifecycle.
With the advantages of AI, we are further enhancing all of these capabilities. For example, we have strengthened our R&D process. Our R&D process was already very comprehensive and one of the best in the industry, but now we have enhanced it with our AI-driven capabilities. This helps our research and development teams design at a better pace, test a large number of test cases using automation, and verify many things using AI capabilities. Obviously, Huawei believes that humans must remain in the loop, so our experts continue to oversee critical decisions while using AI capabilities to enhance the overall process.
This commitment is supported by sustained investment. In 2025, Huawei invested approximately USD27.5 billion in R&D globally, representing 21.8% of its revenue. Approximately 5% of our R&D investment is dedicated to cybersecurity and privacy protection, and Huawei has invested around USD10 billion in these areas over the past decade.
The second aspect is about the capabilities that our customers should have. Huawei also believes that devices should be secure and should have their own native security capabilities. Huawei embeds security functions into almost all of its products and solutions, including core networks, routers, and transmission equipment, to help customers strengthen protection and resilience across their infrastructure. Last but not least, Huawei believes that security is not just the function of one entity or one organization. Huawei fundamentally believes in continuing to collaborate with industry bodies, regulators, and customers so that the entire value chain is protected. Cybersecurity, as we always say, is a shared responsibility, and Huawei continues to recognised industry standards and best practices and collaborating with customers to make sure that resilience is a function and business priority of the organization rather than just an IT security function
“Cybersecurity, as we always say, is a shared responsibility.”
KA: What are the biggest cybersecurity challenges faced by organizations in the Middle East today?
SM: As I just mentioned, AI-driven attacks and AI-powered cybercriminals are key challenges by default. During periods of geopolitical tension, we have seen phishing and scamming go to the next level and I believe these are likely to continue in the coming days as well.
Of course, ransomware attacks and denial-of-service attacks have been around for many years, and I believe they will remain significant. Looking further ahead, quantum computing presents an emerging security challenge. Although the timeline remains uncertain, organisations should begin assessing their exposure and preparing for post-quantum security, particularly where sensitive data must remain protected for many years.
So, these are a few things that we believe every organization must pay attention to because the threats are either already present or likely to become more prominent as technologies and attack capabilities continue to evolve.
KA: How can governments, technology providers and enterprises collaborate more effectively to strengthen cyber resilience?
SM: That is also a very good question. As I mentioned before, cyber resilience is not just about having a very good or secure product. Cyber resilience, in my humble opinion, is a function of multiple aspects and requires collaboration across different stakeholders.
For example, vendors must provide secure products. At the same time, governments need to work together with vendors, technology operators, the ecosystem, and industry organizations to put forward laws, guidelines, and regulations that foster a culture across the ecosystem in which parties feel more positive and open to collaboration.
They should not just compete with each other for business value but actively collaborate so that, as a sector and as an industry, we build security and create a secure future for everyone, not just for one business or one entity.
Cyber resilience will be tested only when there is a critical incident, and that critical incident will determine whether an entity was resilient—whether it faced the challenge, overcame it, and kept functioning—or whether it became a victim. This can only be possible through preparedness and collaboration from the beginning. It also requires regular testing, incident-response planning, information sharing and a clear understanding of the roles and responsibilities of all parties across the ecosystem.
KA: With 5G-Advanced and increasingly intelligent networks, how are security requirements changing for telecom operators?
SM: That is a very good question. When we talk about 5G-Advanced, in my opinion, it is not just for consumers, nor does it only relate to high speeds. 5G-Advanced is fundamentally designed for industries. It fundamentally changes how industries operate.
For example, factories, airports, and ports can leverage 5G-Advanced capabilities to bring automation, efficiency, and greater safety for workers in the field. We have many solutions at our booth here that focus on oil and gas and mining, and they all leverage 5G-Advanced.
From that perspective, operators become enablers of industry. We are also entering an area where it is not just IT; operational technology is also coming into play. The convergence of IT and OT comes into play, and it is all enabled by 5G.
What operators, in my humble opinion, need to do is build capabilities that will allow them to enable vertical industries. Vertical industries are fundamentally built around high-volume, high-value organizations. When operators have the ambition to modernize or help those industries transform, they need to understand how OT works, how to secure OT, and how OT can bleed into IT.
They need to provide confidence to industry verticals that they can help them transform in a very secure and resilient manner. In sectors such as oil and gas, operational continuity and safety are critical, and even a short disruption can have significant operational and financial consequences.
“Quantum computing is coming. It’s only a question of when. Preparation for post-quantum security must begin now”
Any cyberattack, for that particular matter, could potentially disrupt such billion-dollar operation. That is why resilience and reliability is of highest concern. However, we have seen successful cases in oil and gas, airports, and ports where 5G adoption is happening.
The lesson we have learned from those operators is that they build these capabilities and provide a full-stack view and full-stack capabilities to vertical industries.
KA: Looking ahead, which emerging cyber threats and technologies do you expect to have the greatest impact over the next three to five years?
SM: The first is Quantum computing is coming. Its potential impact on current cryptographic systems means organisations should not wait until the technology reaches maturity before acting. They should begin assessing their cryptographic assets and dependencies and planning for post-quantum cryptography and quantum-safe migration.
The second is AI. What we have seen so far is not the peak of AI. We have seen frontier AI models. You have seen some news that they can break through sandbox environments and attack or hack some organizations. Threat actors are actively leveraging AI, but in my humble opinion, this is not the peak. The peak is yet to come, when general-purpose computing and AI infrastructure will be largely available and more economical at scale. At that point, threat actors could be at the peak of their capabilities.
“The window of opportunity for the defenders remains open, but it may not remain open for a very long time. Organisations must act now to build AI-enabled resilience”
We still have an opportunity. The window of opportunity for defenders is still open, but it may not remain open for very long. This is the right time for organizations to think about how they can evolve and how they can prepare frameworks in which they can proactively take advantage of AI capabilities rather than become victims. At Huawei, we describe this approach as “AI for Security and Security for AI”—using AI to strengthen cyber defence while also protecting AI systems, models and data. So, these are the two things, in my opinion, that will define the next three to five years, or perhaps the rest of the decade.













