Protecting energy, infrastructure and continuity in the Middle East

Protecting-energy,-infrastructure-and-continuity-in-the-Middle-East

In this ISJ exclusive, Digital Content Editor, Eve Goode speaks with Saad AlQahtani, a Security Expert about critical infrastructure in the Middle East.

What are the biggest security threats to critical infrastructure in the Middle East?

Critical infrastructure in the Middle East is constantly under pressure as it has the role of providing energy not just for local communities but for the world.

The ME’s Power plants, airports, ports and large data centers are expected to operate with reliability, meeting the high demands of energy supply from global and local regions.

Critical infrastructures has no room for delay and identifying threats can be challenging as there are often limited chances to overlook any weaknesses that could threaten crucial infrastructure operations.

There are a range of threats that must be monitored including minor mistakes like improper identity verification, ignoring security procedures and more serious issues that could negatively impact the ongoing operations.

To determine the biggest security threats, single point of failure is the biggest as putting too much reliance on a single point of control, single primary power source or one security hub could cause failure. This is where taking advantage of available technology is a good move.

Using tech can become a double-edged sword as although its helpful to modernise security operations, it could also put the infrastructure at risk of threats.

Once tech is involved, this means that the infrastructure is now at risk of cybersecurity attacks which could cause a total digital security operations shutdown.

Utilising technology can become a real issue for organisations when the staff monitoring the systems have insufficient training as this leaves room for mistakes which can result in operational delay.

What regional factors have the most influence over security planning in the Gulf?

Planning security in the Gulf requires a deeper look at the area of operations and the factors that must be considered when designing a plan.

Plans are often influenced by environmental (extreme heat or humidity) and supply chain factors which often means switching standard operating procedures (SOPs) for specific climate conditions and continuous surveillance of supply chain movements.

Infrastructure that is located in the extremely hot or humid areas requires designated SOP and relies on imported equipment, raw materials and spare parts from outside the region.

While a detailed plan for tackling threats is essential, the quality of the employed security staff matters just as much.

In the end, the efficiency of well-trained and prepared staff will outweigh the overall security plan if a threat were to occur.

Although most companies can readily supply guards, few guards really understand how to secure complex environments like industrial sites, ports or large data centres.

This can leave many organisations having to build serious internal oversight to ensure that the basics are completed correctly.

What makes security risk management in the Middle East different from other regions?

Security risk management (SRM) focuses on protecting assets and maintaining business continuity.

Applying SRM principles in the Middle East will yield fundamental differences in economic, environmental and cultural factors compared to other regions.

Infrastructures in the ME region not only supply the local areas but also extend their production to include international markets.

Imposing SRM is on a high level of urgency and importance, given the risk that the issue could advance beyond the infrastructure and effect other parts of the world.

Additionally, in contrast to other regions, infrastructures could become a target for cybersecurity attacks and acts of sabotage. The diversity of risks the region faces means there needs to be a particular SRM pattern that includes physical security, cybersecurity and crisis management.

Heavy reliance on oil and gas, energy and water desalination puts economic stability and basic needs at risk, requiring careful SRM focus on business continuity and crisis management.

Moreover, the private sector that is backed by the government plays a fundamental role in protecting critical infrastructure and strict legislation forms a distinctive SRM model.

What is one piece of advice that you would give to Middle Eastern Security companies on how they can support business continuity?

The Middle East region is an attractive destination with new opportunities.

As the area grows, it is exposed to new projects and as many sectors expand their operations, security will become a critical concern. Yet it’s an excellent opportunity to seize!

Diversity of projects, new markets and the relocation of major companies’ headquarters to the region require a high-standard security service.

I would encourage new companies to enter this field to benefit from this situation as many organisations will be looking at new ways to secure themselves from potential threats.

The companies that are supplying these new organisations with security must act as true business partners rather than just security suppliers.

Security companies must understand their role and its importance in maintaining business continuity and managing crises, rather than simply providing infrastructure with regular guarding services.

Companies must conduct an real SRM based on the asset assessment and regional threats to minimise the threat if an attack were to occur.

The last thing I would advise on is that companies must invest in security. This includes investing in training for staff so they have sufficient knowledge of operations, business continuity and crisis management when it comes to potential threats.

How do you think security challenges in the Middle East will evolve over the next decade?

The Middle East region is beginning to grow with new opportunities but as this happens, the security challenges that the regions face are becoming more complex.

Operations are scaling up meaning that facilities must be much bigger and more dynamic than they used to be.

As the security threats continue to grow with the growing region, they are expected to shift from traditional to hybrid threats.

The challenge can go from being a physical attack to a cyber-attack very quickly and I think as the region continues to grown, we will be more susceptible to cyber-attacks on our smart cities, ports and airports.

Another risk companies must consider is insider threats. As companies continue to grow, the risk of staff will need to increase, with this comes huge responsibility of protecting the companies infrastructure from any inside threat.

For the past few years the incorporation of AI into systems has become rife. The use of AI can be seen as a double-edged sword, while it does offer features like early detection, behaviour analysis and rapid decision-making, it can also be used for high-intelligence attacks, deepfakes and the undermining of older systems that some infrastructures may still use.

The organisations that have prepared themselves in advance will be the ones that come out on top. They prepared early, train often and stay sharp.

Real resilience isn’t built during crisis; it’s constructed long before anything goes wrong.

Share this content

Latest Issue

Connect with us

Free digital subscription

Receive the latest breaking news straight to your inbox