Dr. Mazen Abduljabbar, Country Manager – Saudi Arabia, Commvault

Riyadh "Riyadh Daily"
As Saudi Arabia Scales AI, Cyber Resilience Moves From IT Priority to Business Imperative

At LEAP 2026, Commvault’s Dr. Mazen Abduljabbar discusses how the Kingdom’s rapid AI and cloud transformation is creating new opportunities while introducing a new generation of cyber risks that organisations must be prepared to recover from.

The conversation around artificial intelligence is increasingly moving beyond experimentation and pilot projects toward real-world implementation across businesses, government entities and critical digital services. At the same time, the Kingdom’s expanding cloud infrastructure is creating the foundation for a more AI-driven economy.

But with greater digital capability comes greater exposure.

For organisations operating in this environment, the challenge is no longer simply how to adopt AI securely. It is increasingly about whether they can maintain business continuity when something goes wrong, and how quickly and confidently they can recover.

That was a central theme for Commvault at LEAP 2026, where the company engaged with customers, partners and industry stakeholders around the changing requirements for data security, identity protection and cyber recovery.

Speaking to Riyadh Daily during the event, Dr. Mazen Abduljabbar, Country Manager – Kingdom of Saudi Arabia at Commvault, discussed how the Kingdom’s accelerating AI adoption is changing the cyber risk landscape, why recovery is becoming as important as prevention, and what organisations should prioritise as they scale their AI and cloud environments.


From AI experimentation to enterprise implementation

For Abduljabbar, the shift taking place in Saudi Arabia is clear: AI is moving beyond experimentation and becoming increasingly instrumental across a wide range of businesses and organisations.

That transition has important implications for cybersecurity and resilience.

AI is enabling organisations to become more productive, efficient and capable of moving faster, but it is also expanding the potential surface of impact. As businesses integrate AI more deeply into their operations, the number of systems, applications, identities and data environments that need to be protected continues to grow.

This makes resilience an increasingly important component of the Kingdom’s digital transformation.

Rather than focusing solely on protecting data, organisations need to understand where their data and workloads reside, how they are being used, which identities have access to them, and whether critical systems can be recovered cleanly and confidently when disruption occurs.

Commvault has also adopted AI across its own operations, incorporating AI into areas spanning data design and protection through to cybersecurity. The company’s approach reflects a broader view that resilience needs to be built into technology environments from the outset rather than addressed only after a security incident.


A new layer of risk: AI-driven identities

The evolution of AI is also changing the nature of the enterprise security perimeter.

Generative AI has introduced new challenges around data access, authorisation and the security of large language models and prompts. The emergence of agentic AI adds another layer, as AI agents can interact with data and applications and operate through non-human identities.

These identities need to be governed and protected alongside traditional human identities.

As AI becomes increasingly integrated into enterprise workflows, organisations need greater visibility into what these agents can access, what permissions they have, how their activities are verified and how information moves through AI environments.

This also raises concerns around shadow IT and the uncontrolled use of AI tools and services outside established organisational controls.

For Abduljabbar, these developments reinforce the need for a more holistic approach that brings together data security, identity resilience and cyber recovery rather than treating each as an isolated security function.


Why recovery is becoming the new resilience benchmark

For years, cybersecurity strategies have focused heavily on prevention, detection and containment. But as digital environments become more complex and cyber threats move faster, the ability to recover is becoming an equally important measure of resilience.

The focus is shifting toward what happens after an incident.

Organisations need to be able to identify affected data, determine what remains clean, validate recovery points and restore critical applications and systems with confidence.

This thinking is central to Commvault’s Resilience Operations, or ResOps, approach.

Rather than positioning resilience as a single security product or a final recovery step, ResOps is designed as a continuous operating model. It brings together activities including data discovery and classification, anomaly detection, continuous scanning and the identification of clean historical data that can be used for recovery.

The approach is intended to create a continuous cycle of resilience rather than a fragmented collection of security and recovery processes.

The importance of this capability becomes particularly clear in real-world incidents.

Abduljabbar highlighted the example of a semi-government organisation in Saudi Arabia where IT personnel accidentally deleted databases containing both historical and newly generated data. Because Commvault was already in place, the organisation was able to restore the affected data and return to normal operations before the end of the day.

The example illustrates a broader shift in the definition of cyber resilience. The question is no longer only whether an organisation can prevent an attack or detect an incident, but whether it can recover its business when disruption occurs.


Bringing resilience together across hybrid and multi-cloud environments

As enterprise technology environments become increasingly distributed, maintaining resilience through multiple disconnected tools can introduce another layer of complexity.

Organisations today may operate across several clouds, applications and infrastructure environments, with different tools responsible for different aspects of data protection, security and recovery.

Commvault’s response is centred on Commvault Cloud Unity, which brings together cyber recovery, identity resilience and data security within a unified platform.

The objective is to provide organisations with a single experience for managing resilience across increasingly complex environments, allowing different workloads and applications to be managed through a common platform.

This becomes particularly relevant as businesses expand their use of hybrid and multi-cloud infrastructure.

By bringing different elements of resilience together, organisations can gain greater visibility across their environments while reducing the operational complexity associated with managing multiple disconnected solutions.

For Commvault, the combination of Unity and the ResOps operating model represents a shift from managing individual security and recovery functions toward treating resilience as a continuous, organisation-wide capability.


Data sovereignty extends beyond where data is stored

Saudi Arabia’s growing emphasis on data sovereignty adds another dimension to the resilience conversation.

As more critical workloads move toward local cloud infrastructure, organisations are paying increasing attention to where their data is stored and processed. But sovereignty is not simply a question of physical location.

The way data is protected, secured and ultimately recovered is becoming equally important.

For organisations operating critical workloads in the Kingdom, keeping data and workloads within the country is only one part of the equation. They also need confidence that applications, data and identities can be recovered quickly and cleanly following a cyberattack, outage or human error.

This places resilience alongside sovereignty as an important consideration in the design of local cloud environments.

As Saudi Arabia continues to develop its digital infrastructure under Vision 2030, organisations will increasingly need to consider not only where critical data resides, but also how effectively they can maintain control and continuity around that data when disruption occurs.


Preparing for the next 12–18 months

Looking ahead, the pace of AI and cloud adoption means organisations cannot afford to treat resilience as something to address after their digital environments have already become complex.

For Saudi organisations, priorities should include data security, identity protection, cyber recovery and continuous resilience as connected elements of a broader strategy.

AI itself is also becoming part of that equation.

As AI-driven threats become more sophisticated, organisations will increasingly need AI-enabled capabilities to help identify, understand and respond to emerging risks. Commvault is incorporating AI across its platform, including capabilities designed to support areas such as customer support, onboarding and issue resolution.

The broader principle is that AI will increasingly need to be part of the defence against AI-driven risk.

For organisations embarking on the next stage of their AI and cloud journey, the emphasis is therefore shifting from reacting to incidents toward preparing for them before they occur.

Building resilience early allows organisations to design security, recovery and continuity into their technology environments rather than attempting to retrofit these capabilities after a crisis.

That approach is particularly relevant as Saudi Arabia moves deeper into its AI and cloud transformation.

The Kingdom’s digital ambitions are creating significant opportunities for businesses and public-sector organisations, but the ability to realise those opportunities will depend not only on how quickly organisations can adopt new technologies, but also on how confidently they can withstand disruption.

In this environment, cyber resilience is moving beyond its traditional role as an IT concern and becoming an essential part of how digital businesses are designed, operated and protected.

tweet
Related News
Comments.