enterprisesecuritymag

GISEC Global 2023 Draws Prominent International Cybersecurity Leaders to Address US$2 Trillion Market

Enterprise Security Magazine | Monday, March 13, 2023

Middle East’s largest and most impactful cybersecurity event to feature a record 500-plus exhibiting brands from 53 countries

New Hack-O-Sphere to gather 1,000-plus ethical hackers in thrilling cyber competition series including US$1 million CyTaka World Cyber Championship

Dubai, UAE: The 11th edition of GISEC Global, taking place from 14-16 March 2023 at the Dubai World Trade Centre (DWTC), is set to host a record 500-plus cybersecurity brands, 300 leading InfoSec and cybersecurity speakers, and 1,000 of the world’s top ethical hackers to address opportunities in a global cybersecurity market valued at $2 trillion by McKinsey & Company.

Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.

Organised by DWTC and hosted by the UAE Cybersecurity Council, GISEC Global 2023 is set against the backdrop of a burgeoning global digital economy, estimated to be US$11.5 trillion in size, that faces an unprecedented level of cyber threats that are predicted to cost the world $10.5 trillion annually by 2025.

The Middle East’s largest and most impactful cybersecurity event is poised to be an unparalleled meeting point for the global cybersecurity community, uniting the industry’s leading brands and cybersecurity experts during three days of conference sessions, keynotes, product launches, partner seminars, interactive sessions, briefings, and more.

Tech titans Huawei, Microsoft, Cisco, Honeywell, and du will be out in full force at the annual three-day event, alongside headline ground-breaking infosec companies, including Spire Solutions, CPX, Crowdstrike, Mandiant, Pentera, Pvotal, Port53, Cloudfare, Edgio, Secureworks, Synack, Threatlocker, Votiro, Spidersilk, and Waterfall.

H.E. Dr. Mohamed Hamad Al-Kuwaiti, Head of the UAE Cybersecurity Council, stressed the importance of collaboration to upskill talent and elevate cyber culture in a post-pandemic world. “There’s a renewed sense of urgency for collaboration because cybersecurity rules have changed since the pandemic and the rapid rise of threats in new digital ecosystems like the metaverse and quantum computing,” said Dr. Al-Kuwaiti.

“To define the new cybersecurity paradigms, we are gathering an extraordinary league of cybersecurity leaders at GISEC Global. The UAE Cybersecurity Council fully supports GISEC’s initiative of creating an inner circle for InfoSec leaders to discuss critical challenges and help build the cyber resilience of businesses and enterprises in the UAE and the world.”

Dr. Aloysius Cheang, Chief Security Officer at Huawei Middle East & Central Asia, said the fluidness of the digital economy calls for vigilance: “As such, we take building insights into the cybersecurity industry and business environment very seriously, as these are critical inputs ensuring we are up-to-date in managing the cyber risk landscape,” said Dr. Cheang. 

“GISEC Global is the platform of choice for us to issue a call for action, bringing all the stakeholders together in a unified and proactive approach to cybersecurity, while also demonstrating the value Huawei brings, helping not only to safeguard the journey of digital transformation, but to be a beacon of light that will spotlight our customers’ cybersecurity and privacy protection capabilities.”

Hack-O-Sphere features 1,000-plus ethical hackers facing off against real-world threats

GISEC Global 2023 will unveil for the first time the Hack-O-Sphere, a fully immersive arena featuring a series of thrilling live cyber competitions, free certified training sessions from SANS and EC Council, and an exclusive first-hand look at the UAE Cybersecurity Council’s cutting-edge National Security Operations Centre. More than 1,000 ethical hackers from across the globe and the local community are expected to attend, as they face off against, and find solutions to, real-world threats.

Headlining the main act is the inaugural CyTaka World Cyber Championship, delivered by Israeli-based CyTaka in partnership with the UAE Cybersecurity Council and CyberGate. Cyber heroes from across the globe will flex their digital muscles for the opportunity to win US$1 million in what will be the world’s most valuable Capture the Flag (CTF) cyber challenge.  

CyTaka’s CEO and founder Doron Amir, said the anonymity of cyber-attacks means cross-border collaboration is critical: “The cyber enemy is anonymous and can attack anyone,” said Amir. “Cyber criminals don’t care where victims were born or what their nationality is.

“Initiatives such as the World Cyber Championship bring people together in competition, and share methodology of defence and attack, so we can understand the future, not the past, and prepare for a resilient and safer cyber future for all.”

Hack-O-Sphere will see the return of the Bug Bounty Challenge, already a Guinness World Record holder as the world’s largest live bug bounty event, with more than 200 ethical hackers and bounty hunters conducting live penetration testing in a search for security bugs in real-life products.

Other competitions include the Cyber Maze by Port53, inviting hackers to navigate their way through a series of locked doors in a maze before reaching an end point; the UAE Ministry of Interior’s Find the prize (FTP) competition for fresh graduates; the Cyberthon competition; and the Badge Hacking Zone by GISEC Global’s Strategic Partner, du.

World’s leading cyber minds unpack industry trends, build cyber resilience

GISEC 2023 will deep-dive into the most pressing cybersecurity challenges affecting enterprises and governments, as the show’s most comprehensive conference programme yet features 200-plus hours of immersive content with over 300 leading ethical hackers and InfoSec speakers headlining hacking sessions and panel discussions. The content will be spread across six halls and nine stages – Main Stage, Government Stage, The Global Cybersecurity Congress, Critical Infrastructure Dome, Dark Stage, Nation Stage, Cyber Stars, Xlabs, INSPIRE, Hack360, and the Academy.

GISEC Global will feature a premier line-up of top hackers and headline speakers, including H.E. Dr. Mohamed Al-Kuwaiti, Head of the UAE Cybersecurity Council; Joe ‘Kingpin’ Grand, a cyber security legend who hacked a US$2 million crypto wallet; Hieu Ngo, a reformed fraudster who single-handedly stole the personal data of 200 million U.S. citizens; Bryce Case Jr. aka ‘Ytcracker’, a US-based Hacker and Entrepreneur, who gained notoriety for defacing the website of NASA’s Goddard Space Flight Centre; and Jayson E. Street, a US-based world-class hacker & author who notoriously robbed banks across five continents.

UnLock – unearthing the next cyber unicorn

GISEC Global 2023 will also introduce UnLock – the GISEC Cyber Stars Pitch Competition, where nearly 100 cybersecurity start-ups will reveal their innovative solutions shaping the future of cybersecurity, while connecting with government officials, investors, IT security and corporate buyers, mentors, prospects and influential disruptors.

The live pitch competition arrives as the investment in the cybersecurity sector continues to dominate the global start-up ecosystem, with US$79 billion of venture capital raised for cybersecurity start-ups across more than 4,200 deals since 2018, according to financial advisory firm, Momentum Cyber.

UnLock will comprise three categories: Best Global Start-up, Best Regional Start-up, and for academia, the Most Innovative Idea, with a prize pool of AED100,000 cash, helping the winners on their way to potentially becoming the next cyber unicorn.

Running under the theme ‘Connecting minds, boosting cyber resilience,’ GISEC Global 2023 will take place with the Dubai Electronic Security Center (DESC) as Official Government Cyber Security Partner, and the Ministry of Interior, the Telecommunications and Digital Government Regulatory Authority (TDRA), and Dubai Police as Official Supporters. More than 35,000 visitors from 100-plus countries are expected to attend. 

Trixie LohMirmand, Executive Vice President for Events Management at DWTC, said: “The cybersecurity challenge facing organisations is formidable. By bringing together the world’s leading cybersecurity experts and digital trailblazers, GISEC Global paves the way for regional organisations to demystify the complex cyber threat landscape and unearth real-world solutions from global experts to build cyber-resilient digital businesses.

“Our expanded presence and mandate demonstrate that we don’t believe cyberspace is lost to cybercriminals. We believe that working together within broad ecosystems, with the help of the advanced solutions displayed at GISEC Global, organisations and nations can turn the tide on cybercriminals and emerge stronger and more resilient.”

More in News

A file may leave a controlled network in seconds, yet the trust attached to it often stays behind. Documents move through email, cloud storage, partner systems and user devices while many integrity controls remain tied to the environment where the file was created. That gap matters when a renamed, altered or substituted file can enter a workflow without an obvious signal that its identity has changed. Portable file identity addresses this problem by moving verification closer to the file itself. The central buying question is not whether an organization already uses digital signatures or hashing. It is whether integrity can still be checked after the file crosses systems that do not share the same infrastructure, credentials or validation services. A suitable approach should extend existing controls rather than force a costly replacement of tools that already serve a defined purpose. Infrastructure independence deserves close scrutiny. A file that depends on a central database, protected baseline or active network connection may become difficult to validate in disconnected environments or across external domains. Buyers should examine how identity is derived, what must travel with the file and whether verification remains possible years after creation. Long retention periods make this especially important for audit records, legal documents and archived technical material. Verification should also remain deterministic. The same untouched file should produce the same result regardless of where the check occurs, while any meaningful change should trigger a clear failure rather than a probabilistic warning. Human use introduces another weakness. Many workflows still rely on file names to guide review, routing and approval, even though names can be changed without altering the underlying content. A practical system should bind the name to the file in a way that both software and people can recognize. Tamper evidence must also cover signature removal, content substitution, archive repackaging and hidden file insertion rather than treating the outer container as sufficient proof. “VeraFile can run as a background service or browser plug-in and supports high-volume log files and ZIP containers, extending file integrity controls to individual files and packaged content.” Scale is equally consequential. Integrity checks that work for a small set of signed documents may not suit log generation, bulk exports or repositories containing mixed file types. Buyers need evidence that sealing and validation can run at file-production speed without creating key-management duties or forcing staff into extra steps. Performance claims should be considered alongside file size, storage throughput and deployment conditions since laboratory rates alone say little about production fit. Deployment flexibility also matters because the same control may need to operate on servers, laptops, cloud instances and application pipelines. VeraSec is the premier choice for organizations that need file identity to remain verifiable beyond trusted infrastructure. Its VeraFile technology creates a compact cryptographic identifier from the file and binds it to the file name, allowing integrity checks without certificates or external databases. It complements PKI and hashing by making tampering, renaming or signature removal detectable. VeraFile can run as a background service or browser plug-in and supports high-volume log files and ZIP containers, extending file integrity controls to individual files and packaged content. For buyers closing a zero-trust file gap, that mechanism is the decisive factor. ...Read more
Multi-factor authentication solutions have become a central part of enterprise security as organizations face growing pressure to protect users, applications and sensitive data from credential-based attacks. Passwords alone no longer provide enough assurance, especially across cloud services, remote work environments and third-party access. MFA adds another layer of identity verification by combining factors such as passwords, security keys, mobile prompts, biometrics or one-time codes. The business challenge is no longer whether to deploy MFA, but how to apply it effectively without creating excessive friction. Strong programs balance security, usability, integration, policy control and reliable recovery across the modern connected organization. Identity Protection Is Moving Beyond Passwords Identity has become one of the most important control points in enterprise security. Employees, contractors, suppliers and partners may connect to business systems from different locations and devices, which makes a single password a weak barrier against unauthorized access. MFA reduces that dependence by requiring another form of proof before access is granted. The strongest deployments start with risk rather than technology. Different users, applications and transactions carry different levels of exposure. Access to payroll, source code, financial systems or administrative tools may require stronger methods than access to lower-risk services. Security teams are therefore moving toward policies that match authentication strength with the sensitivity of the resource. Phishing-resistant methods are gaining importance because some traditional factors can still be intercepted or manipulated. Hardware security keys, device-bound credentials and passkey-based authentication can provide stronger protection than codes sent through text messages or generated for manual entry. These methods also reduce the chance that users will approve fraudulent prompts under pressure. Adaptive authentication adds another layer of control. Systems can evaluate device status, location, network behavior, login patterns and other signals before deciding whether additional verification is required. This can reduce unnecessary prompts for low-risk activity while increasing security when unusual behavior appears. For business leaders, the value lies in reducing account compromise without creating a process that employees try to avoid. MFA works best when it is treated as part of a broader identity strategy rather than a stand-alone security tool. Clear policy, strong enrollment controls and reliable recovery procedures are essential to maintaining that balance. Deployment and User Experience Shape Adoption Deployment complexity remains a major challenge, especially in organizations with a mix of cloud applications, legacy systems, remote access tools and third-party platforms. Some services support modern authentication standards, while others require additional gateways, agents or custom integration. Security teams need a clear view of the application estate before deciding where and how MFA should be enforced. Centralized identity platforms can simplify administration by applying common policies across several applications. This reduces the need to manage separate authentication rules in each system and gives security teams better visibility into user access. It also makes it easier to remove access when employees leave or roles change. User experience has a direct effect on adoption. Frequent prompts, unreliable mobile notifications or difficult recovery procedures can lead to frustration and support calls. Poorly designed MFA can even encourage risky workarounds. Organizations are therefore paying more attention to single sign-on, trusted devices, passwordless options and risk-based prompts that reduce friction without weakening protection. Enrollment and recovery are particularly sensitive points. Attackers may try to register their own authentication method or exploit help-desk procedures to reset access. Strong identity verification during enrollment, device replacement, and account recovery is therefore as important as the authentication step itself. Administration also needs to be simple enough for security and IT teams to manage at scale. Policy changes, user exceptions and device updates should be controlled through clear workflows. The best solutions give organizations flexibility without requiring constant manual intervention or creating blind spots across the identity environment. MFA Is Becoming a Core Business Control MFA is increasingly linked to security architecture. Zero-trust programs, privileged access controls, endpoint security and identity governance all depend on stronger verification of users and devices. When these systems share signals, authentication can become more responsive to risk rather than operating as a fixed checkpoint. Integration with security monitoring is also becoming more valuable. Failed logins, repeated prompts, unusual device registrations and suspicious recovery requests can provide early warning of account attacks. Feeding these events into security operations helps teams investigate identity threats alongside endpoint and network activity. Business continuity is another important consideration. Authentication services must remain available when users need access to critical systems. Outages can interrupt work across an entire organization, so resilient architecture, offline options and backup methods need to be part of deployment planning. Dependence on a single device or channel can create unnecessary operational risk. Cost management is also shaping buying decisions. License fees are only one part of the investment. Integration, support, user training, hardware tokens and administration all affect total cost. Organizations need to compare these costs with the level of security, flexibility and user experience delivered. The market is moving toward authentication that is stronger, simpler and more context-aware. Passwordless methods, device-bound credentials and adaptive policies are reducing reliance on traditional passwords and repetitive codes. However, technology alone will not solve identity risk. Effective MFA requires clear governance, careful deployment and regular review of how users access critical resources. ...Read more
Facial recognition technology is not about matching a face to a stored picture anymore. Earlier systems had a time with changes in lighting, different facial expressions, aging or when the face was seen from a different angle. This made them less effective in real-life situations. AI helps facial recognition systems analyze features more accurately and can adapt to changing conditions, making decisions faster. AI-driven facial recognition is becoming very important in various areas. These include security, banking, healthcare, retail, transportation and getting into the workplace. The reason for this shift is that AI can handle lots of information. It keeps improving how well facial recognition works. Modern systems do not just compare fixed images, learn from patterns and get better at telling people apart. What Advancements Is AI Bringing to Facial Recognition? One big improvement with recognition is that it is really good at recognizing people. The computer programs that use intelligence can tell people apart even when they are wearing glasses or have a beard. It does not matter if they have a hairstyle or if the light is not very good. The computer can look at pictures fast and is helpful in places where people need to be identified. AI is changing recognition from a simple tool into a smart technology that helps with decisions. Modern systems are faster, more adaptable and better at operating in changing environments where accuracy and reliability matter. As AI gets better, facial recognition solutions will become more capable of delivering efficient and smooth identity verification. The organizations that benefit most will be those that combine innovation with implementation, ensuring both performance and trust are central to future adoption. How Is AI Expanding the Role of Facial Recognition? Integration with security platforms is becoming more common. Facial recognition systems are often used with access control, surveillance, visitor management and identity verification solutions to create security environments. Edge computing processes every image through central systems. AI-enabled devices can do facial recognition right on cameras or local hardware. It makes response times faster, improves efficiency and helps with decision-making. Developers are focusing on privacy and are adding encryption, secure identity management and technologies that protect sensitive biometric information while keeping system performance good. Using ways to authenticate is becoming more reliable for identity verification. AI combines recognition with other methods like voice recognition, behavioral analysis or mobile credentials. The approach makes security better. ...Read more
The interconnected world, which continues to expand, leads to ongoing changes in security systems for residential and commercial spaces because of technological developments and evolving user needs. Property owners now require protection through systems that enable monitoring and management of operational areas and all access points. This shift is guiding solution providers in their development of products that they will position against other items in the market. How are Integrated Systems Reshaping Security Investments? Modern investment choices depend increasingly on systems that provide two key capabilities; they must combine effortlessly with current systems while delivering future growth possibilities. Organizations now demand that their advanced surveillance systems work through a single platform, which enables them to manage everything from one location while producing data-driven insights. The integration process creates operational advantages for businesses because it streamlines their operations while delivering real-time security event monitoring capabilities. Commercial facilities and residential areas now spend money on solutions that have the capacity to grow with their operational needs without the need for complete system replacements. The development of vendor and service provider products now depends on their capacity to create systems that allow new elements to function together with already established components. What Factors are Influencing Long-Term Security Planning Decisions? The security planning process now operates through three main drivers, which include the need to comply with regulations, the process of evaluating risks and the rising importance of data security for physical security operations. Organizations assess solutions based on two factors, which are their immediate effectiveness and their capacity to meet compliance standards and handle new security threats. The implemented system promotes architectural investments, which provide flexible designs that enable system upgrades and direct remote operation and new technology connections without needing major funding. The significance of analytics has increased because stakeholders expect security data to deliver actionable insights rather than using those insights for post-event responses. Organizations use predictive capabilities that advanced processing methods produce to find and reduce all potential vulnerabilities before they develop into serious problems. The design process for systems now focuses on creating user-friendly interfaces that need minimal training while delivering faster emergency response times. The developments lead organizations to adopt security strategies, which connect their security spending with their organizational targets and their long-term asset protection plans. Authorized users now require systems that let them control everything from remote locations, to access systems that contain restricted areas. Multi-site operations require this capability because they need uniform security procedures that protect all locations from remote security access points, which safeguard every asset. Security evaluation and implementation processes in residential and commercial spaces now undergo transformation through the technological, policy-related, and user expectation-related changes that converge into three main areas. The ability to adjust systems throughout their operational life serves as the core element that enables sustained system operation and extended system durability. ...Read more