Resilience in motion: why Kuwait’s real test in 2027 is resilience

cyber resilience Kuwait

In September, ahead of Cybersecurity Awareness Month, we spoke with Hashem Qtaishat, Senior Director at BDO Kuwait, who leads advisory services across digital transformation, cybersecurity, technology risk, operational resilience, data governance and AI governance.

We discussed the resilience challenges organisations should be preparing for, the growing importance of operational resilience and how businesses can balance innovation, cybersecurity and trusted AI adoption in an increasingly interconnected risk landscape.

Hashem Qtaishat is a Senior Director leading Digital Transformation, Cybersecurity, Technology Risk, Operational Resilience, Data Governance and AI Governance advisory services across the GCC. He has more than 25 years of experience delivering large-scale cybersecurity, resilience, digital transformation, governance, risk and regulatory compliance programmes.

He has led numerous cybersecurity assessments, operational resilience initiatives, regulatory compliance engagements and digital transformation programmes across Kuwait, Saudi Arabia, the UAE, Jordan and Iraq.

What cyber risks should Kuwaiti organisations prepare for by 2027?

The biggest risk facing organisations in Kuwait is the growing concentration of critical services across interconnected digital ecosystems.

Regulatory frameworks such as the CBK Cybersecurity Framework (CSF), the CBK Cyber & Operational Resilience Framework (CORF) and the CITRA Cloud Computing Regulatory Framework have strengthened expectations around cybersecurity, resilience, cloud governance and data management. However, many organisations remain dependent on a relatively limited number of telecommunications providers, cloud platforms and critical third parties.

“As AI accelerates digital transformation, cyber incidents are increasingly becoming operational resilience events. Organisations therefore need to focus not only on preventing attacks, but also on ensuring that critical services remain available during disruption.

The organisations best prepared for 2027 will focus on resilience rather than compliance alone: strengthening critical service continuity, reducing concentration risk, balancing data residency requirements with regional cloud adoption and continuously assessing exposure across suppliers, cloud services, identities and business processes.

Those that recover quickly and maintain trust during disruption will have a clear competitive advantage.”

Hashem Qtaishat, Senior Director, BDO Kuwait

What is the biggest cybersecurity myth in Kuwait?

That cybersecurity is primarily a compliance or technology exercise.

Across Kuwait, organisations have invested significantly in aligning with regulatory requirements and strengthening security controls. Compliance remains essential, but compliance alone does not create resilience. An organisation can satisfy regulatory requirements and still remain vulnerable to operational disruption, cloud outages, third-party failures, identity-related threats or emerging AI risks.

The direction of regulation in Kuwait increasingly emphasises resilience, governance and critical service continuity. The evolution from the CBK CSF to CORF reflects a broader shift from implementing controls towards the ability to anticipate, withstand, recover from and adapt to disruption.

The most mature organisations therefore focus on business outcomes rather than control activities alone. Cybersecurity today is not simply about protecting technology. It is about preserving trust, enabling innovation and ensuring that the organisation can continue operating confidently through disruption.

Where should Kuwaiti organisations start with cyber resilience?

The first investment should be visibility into critical business services and their dependencies.

Many organisations invest in new security technologies before fully understanding which services, data, cloud platforms, suppliers, telecommunications providers and identities are essential to their operations. Without this visibility, resilience investments can fail to address the most material business risks.

This is becoming increasingly important as regulatory expectations continue to evolve towards operational resilience. Organisations need to understand concentration risks, alternative processing arrangements, cloud dependencies, critical third parties, data classification obligations and recovery capabilities.

Before investing in additional controls, leaders should identify what must remain operational during disruption and understand how those services are delivered.

The foundation of cyber resilience is visibility: organisations cannot effectively protect, govern or recover what they do not fully understand.

How is AI changing cybersecurity in Kuwait?

AI is fundamentally changing cybersecurity by accelerating both attackers and defenders.

Threat actors can use AI to enhance social engineering, automate reconnaissance, identify vulnerabilities and scale attacks at greater speed. At the same time, organisations are using AI to strengthen threat detection, automate investigations, prioritise risks and accelerate response capabilities.

“AI is also expanding the attack surface through machine identities, autonomous agents, AI-enabled processes and growing volumes of sensitive data. This creates new governance, security, privacy and resilience challenges.

For organisations in Kuwait, the priority is to balance AI-driven innovation with regulatory expectations, cloud governance obligations, data classification requirements and operational resilience objectives.

The organisations that succeed will not necessarily be those that deploy AI the fastest, but those that govern it effectively, maintain accountability and use AI to strengthen resilience while preserving trust and confidence.”

Hashem Qtaishat, Senior Director, BDO Kuwait

Cybersecurity Awareness Month at BDO

Resilience in Motion is BDO's opportunity to put resilience into practice, not simply talk about it.

BDO Kuwait's cybersecurity, resilience and governance specialists work with financial institutions, government entities and critical infrastructure organisations to move beyond compliance checklists and strengthen the capabilities that support real resilience — from visibility into critical services and third-party dependencies to continuity planning, cloud governance and responsible AI adoption.

This approach helps organisations respond to the evolving expectations of regulators including the CBK and CITRA while building the operational resilience required for an increasingly interconnected digital environment.