SID & GAMBLE
← All insights Cybersecurity

Cybersecurity in the Middle East and US: the difficult work begins after the warning

June 23, 2026 · 6 min read · By Kay Nyanzira

Spending is up and the tools are multiplying. The harder question of who closes the gap between a vulnerability found and a vulnerability fixed is shaping hiring on both sides of the world.

A security team can know that a system is vulnerable and still be unable to fix it quickly. Verizon’s latest investigation found that exploitation of software vulnerabilities was the initial route into 31% of the breaches it examined, up from the previous year, while the median time to resolve a critical vulnerability had lengthened to 43 days. [1] One figure concerns how attackers got in. The other concerns how long repairs took. Together, they frame the question running through the cybersecurity market in 2026: who will do the work that follows the warning?

Spending is rising. Gartner forecast worldwide information security spending of $240 billion in 2026, a 12.5% increase over its 2025 estimate. For the Middle East and North Africa, it forecast $4 billion, up 10.1%, though Gartner analyst Shailendra Upadhyay noted that “organizations in MENA are being cautious with new spending during turbulent times.” Security software was expected to account for 48% of the region’s spending, with cloud security posture management among the sources of growth. [2][3] But spending tells you what an organization bought. It does not tell you whether an exposed application has been repaired, a cloud account has the right permissions, or a factory can keep operating through an incident. A tool may identify the vulnerable application. Repairing it is another matter when the service belongs to a business unit that cannot take it offline, a supplier controls the software, or a fix risks breaking the system it is meant to protect. Cybersecurity becomes difficult at the point where a technical answer meets an operating decision.

IBM’s February threat index, drawn from incidents its teams observed in 2025, reported a 44% increase in attacks beginning with exploitation of public-facing applications. North America accounted for 29% of the activity IBM tracked, the largest regional share in its dataset. [4] The US market makes the operational difficulty especially visible. Organizations have spent years adding applications, cloud services, and outside providers, each serving a clear business purpose, each creating another point where access must be granted, monitored, and eventually removed. Verizon found third-party involvement in 48% of the breaches it examined, not necessarily the vendor’s fault in every case, but evidence that an organization’s defenses increasingly depend on systems and relationships outside its direct control. [1]

AI adds a further complication. In January, the World Economic Forum reported that 64% of surveyed organizations had processes to assess the security of AI tools, up from 37% a year earlier. [5] The fact that more organizations are asking the question does not tell us how thorough their assessments are, and Gartner’s February assessment was specific about what comes next: “Cybersecurity leaders must identify both sanctioned and unsanctioned AI agents.” [6] An inventory comes before an effective control. A company cannot govern a system it does not know is operating.

The Middle East reaches the same problem through a different mix of institutions. Government services, energy facilities, transport systems, banks, and new digital businesses all have reasons to strengthen their defenses, and the consequences of an outage differ sharply from one to the next. Losing access to an office application is disruptive. Losing visibility into an industrial operation presents a different order of risk entirely.

Saudi Arabia provides one measure of the market’s scale. Its National Cybersecurity Authority reported that organizations in the kingdom spent SAR15.2 billion on cybersecurity products and services in 2024, up 14% from 2023, with private-sector entities accounting for 68% of that spending. The country’s measured cybersecurity workforce had already passed 21,000 professionals, up 9% from the year before. [7] In the UAE, the Cyber Security Council announced a partnership in May with the Advanced Technology Research Council to work on the transition to cryptography designed to withstand future quantum threats which is an effort on a longer horizon than a company’s next software patch, and evidence that the region’s security work now stretches from immediate operations to the design of national infrastructure. [8] The World Economic Forum’s 2026 survey found that 84% of respondents from the Middle East and North Africa expressed confidence in their country’s ability to protect critical infrastructure, though survey confidence and tested resilience are not the same thing. [5]

The two markets have different starting points. In the US, much of the work involves reducing exposure across extensive existing technology and supplier networks. In the Middle East, security is also being built into expanding services and infrastructure. Both require the tasks that follow a strategy announcement: identifying assets, controlling access, testing systems, and preparing people to respond. Whether organizations have enough of the right capability to carry those out is a separate question. ISC2’s 2025 workforce study found that hiring managers most often prioritized cloud security, AI, security engineering, security analysis, and risk assessment, and notably stopped publishing its former estimate of a single global “workforce gap,” finding that respondents placed greater emphasis on specific skills than on headcount alone. [9] An Accenture analysis in June reached a related conclusion: of the cybersecurity roles it studied globally, 59% called for both technical and strategic skills, while 40% of the workforce matched that profile. [10] Those figures help explain why a team can have vacancies and still struggle to find someone able to resolve its most pressing problems.

For the third quarter, I expect security spending to continue, with decisions becoming more exacting. US organizations will have reason to focus on cloud access, vulnerable applications, supplier connections, and the speed of incident response. In the Middle East, protection of digital public services and critical operations should remain prominent alongside cloud and identity security. AI will add work in both places: Gartner’s June assessment identified AI application compromise and software supply chains among the threats where attackers held a significant advantage, which strengthens the case for testing AI applications and understanding the software they rely on, without making every new AI security product an urgent purchase. [11]

In the US, CompTIA counted nearly 587,000 active technology job postings in May, including roughly 269,000 newly added that month, with cybersecurity engineers and analysts among the occupations with the highest posting volumes. New York, Washington, and Dallas had the heaviest concentrations. [12] ISC2’s hiring-manager survey points to cloud security, security engineering, analysis, and risk assessment. Accenture’s study suggests employers also want people who can connect technical decisions to business consequences such as engineers who can secure cloud environments and applications, specialists who can manage identity and access, and teams able to investigate and respond when preventive controls fail. [9][10] In the Middle East, the evidence is less precise about monthly vacancies but carries a direction. Hays’ 2026 GCC guide identifies cybersecurity among the areas putting technology hiring teams under pressure in the UAE and Saudi Arabia, and Gartner expects cloud security posture management to help drive regional software spending. [3][7][13]

US employers are trying to reduce exposure across systems already woven into daily business. Middle Eastern employers are doing that while adding new services and infrastructure. The common requirement, and the one that explains why the market’s growth has not made the work easier, is for people who can close the gap between a vulnerability identified and a vulnerability resolved, the 43 days that Verizon measured, and the operating decisions that fill them.

Sources

[1] Verizon, 2026 Data Breach Investigations Report, May 2026. [2] Gartner, Worldwide information security spending forecast, July 29, 2025. [3] Gartner, MENA information security spending forecast, October 6, 2025. [4] IBM, 2026 X-Force Threat Intelligence Index findings, February 25, 2026. [5] World Economic Forum, Global Cybersecurity Outlook 2026, January 12, 2026. [6] Gartner, Top Cybersecurity Trends for 2026, February 5, 2026. [7] Saudi National Cybersecurity Authority, Key Economic Indicators in the Cybersecurity Sector, September 17, 2025. [8] UAE Advanced Technology Research Council, Cyber Security Council partnership, May 11, 2026. [9] ISC2, 2025 Cybersecurity Workforce Study, December 4, 2025. [10] Accenture, Reinventing the Cyber Workforce, June 2, 2026. [11] Gartner, Four Critical Threats for Cybersecurity Leaders, June 2, 2026. [12] CompTIA, Tech Jobs Report findings for May, June 5, 2026. [13] Hays, GCC Salary Guide 2026, January 2026.

S&G
Kay Nyanzira
Managing Director, Sid & Gamble
Share on LinkedIn

Want to talk this through?

Whether you are hiring or considering your next move, we are always open to a confidential conversation.

Get in Touch →