25 Jun Taming people and AI
Managing human behaviour and agentic AI will be key to cybersecurity in 2026, according to Dr Martin Kraemer, CISO Advisor at KnowBe4.
Today’s organisations are not short on security technology, yet the number of successful attacks keeps growing. As we head further into 2026, reducing the likelihood of a major cyber incident requires a clear focus on two key areas: understanding and controlling human behaviour, and establishing proper frameworks for agentic AI. This focus on human behaviour is increasingly echoed across cybersecurity dialogues globally and regionally. At recent forums like the Hili Cybersecurity Summit in Abu Dhabi, senior officials including Dr Mohamed Al Kuwaiti, Head of the UAE’s Cybersecurity Council, emphasised that “people are the first line of defence” and that cyber resilience must be embedded into national education, policy and operations.
From deepfakes to supply chain breaches, the region is confronting threats not just through technology but through awareness, training and cross-sector collaboration.
Deployment of AI agents necessary, but not without frameworks
The shortage of experienced security specialists is structural, while organisations are increasingly under pressure and facing cyberattacks. Therefore, a faster and demonstrable response is essential. While Security Operations Centres were designed for years around human analysis, we are seeing autonomous AI agents increasingly taking over operational tasks. Think of triage, enrichment of reports and initiating initial responses and measures.
In regions where AI is rapidly being embedded into national infrastructure, from 5G-enabled smart cities to digital government platforms, the question is no longer when, but how deeply automation should be trusted. As OT and IT systems converge and AI-driven attacks grow more targeted, security teams must rethink the boundaries between human oversight and autonomous response.
In organisations with mature processes, this demonstrably leads to a 30 to 50 percent reduction in mean time to respond. This is not an optimisation, but a necessary adjustment. The question is no longer whether AI agents will be deployed, but how far their autonomy extends. Security teams must explicitly determine which decisions can be automated and where human oversight remains mandatory. If these frameworks are lacking, the risks only increase. AI agents operate based on assumptions, context and training data. Employees increasingly rely on automated decisions, sometimes without full insight into the underlying considerations. Consequently, errors arise not from a single weak link, but from unclear role divisions and a lack of governance.
Reducing the impact with a good incident response plan
In countries where ports, energy systems and digital platforms form the backbone of economic and national services, incident preparedness is quickly becoming a boardroom priority. This position also makes organisations in these countries vulnerable. Cyberattacks on ports, energy supplies and transport systems are no longer a distant concern. By 2026, these types of attacks will increasingly have a direct impact on business continuity and society.
This also changes the focus of security teams. Prevention remains important, but we must be realistic: every organisation will sooner or later face the consequences of a cyberattack. A well-prepared response to the question of what steps your organisation should take if it is hit by an attack is important. A well-thought-out incident response plan, regularly practised by all relevant stakeholders, ensures that your organisation can mitigate the impact of a cyberattack.
Securing digital identity is becoming crucial
Across the globe, governments are rapidly advancing digital identity systems that integrate directly into national platforms as seen in healthcare, education, financial services and citizen portals. In countries like the UAE and Saudi Arabia, digital ID is becoming the access point for everything from government benefits to private sector transactions.
As digital identities become more deeply embedded into daily life, the stakes rise. Identity is no longer just a login, it is the key to services, trust and control. Securing it is now a critical priority for both public and private sector leaders.
This fundamentally changes the role of digital identity. Identity is no longer just a means of logging in, but forms the gateway to services, transactions and trust relationships. As more processes and interactions become dependent on digital identity, the impact of misuse also increases. Identity security is becoming more critical than ever, both technically and organisationally.
The focus of cybersecurity in 2026 will shift from preventing incidents, to managing their impact. Organisations that systematically incorporate risk management around human behaviour and agentic AI into their security strategy will demonstrably increase their resilience.
Sorry, the comment form is closed at this time.