During Cybersecurity Awareness Month, we spoke with Shoukat Shah, Lead, Technology and Digital Advisory at BDO Saudi Arabia, who advises organisations on cybersecurity, data privacy, AI governance, technology risk and digital transformation.
We discussed how cyber risk is evolving in the Kingdom, the growing convergence of cybersecurity, privacy and AI governance and why organisations need to look beyond compliance to build resilience in an increasingly complex threat landscape.
Shoukat Shah advises government entities, financial institutions, energy companies and industrial groups on cybersecurity, data privacy and AI governance. He brings more than 15 years of experience across three continents, including roles at KPMG, RSM and the Victorian Auditor-General's Office in Australia. He holds the CIPM, CIPP/E and AIGP certifications from the IAPP, alongside CISA, ISO 27001 Lead Auditor and SWIFT CSCF Assessor credentials.
What cyber risks should Saudi organisations prepare for by 2027?
The greatest risk facing Saudi organisations in 2027 will not arrive as a single threat, but as several risks that compound one another.
Saudi Arabia is digitising at a pace few markets can match, with giga-projects, cloud migration, connected government services and rapid AI adoption creating new capabilities across the economy. Attackers are adapting just as quickly. Through 2025 and 2026, ransomware continued to evolve into an organised industry, stolen credentials remained a significant route of entry and social engineering became increasingly sophisticated with the use of AI.
“By 2027, I expect Arabic-language deepfake fraud, including convincing voice and video impersonation of senior executives, to become routine rather than exceptional.
What concerns me most is how these risks intersect. Every new AI system is simultaneously an attack surface and a privacy obligation under the PDPL. Every additional vendor on a major project widens the perimeter. In energy and manufacturing, where operational technology and information technology increasingly converge, a breach can extend beyond data loss into physical disruption.
Organisations that continue to manage cybersecurity, privacy and AI as separate programmes will be exposed first. My advice is to bring them together under an integrated governance structure aligned with NCA and SAMA expectations and to test incident response against AI-enabled scenarios well before 2027.”
Shoukat Shah, Lead, Technology and Digital Advisory, BDO Saudi Arabia
What is the biggest cybersecurity myth?
That a clean compliance report means an organisation is secure.
I have delivered many assessments over the years against the NCA Essential Cybersecurity Controls (ECC), SAMA Cyber Security Framework and ISO 27001, and I make the same point at every closing meeting: a compliance assessment describes a point in time. Frameworks provide a baseline, but resilience requires continuous attention.
“The pattern I see repeatedly is genuine effort spent achieving compliance, followed by a year of relative quiet, followed by surprise when an incident appears in an area the framework did not anticipate.
The organisations that impress me treat the framework as a floor and spend their real energy on the unglamorous work: knowing their assets, testing their response and questioning their vendors.
A close second misconception is that cybersecurity belongs to the IT department. It does not. When operations halt and regulators call, it becomes a board matter. Boards that discover this during an incident have discovered it too late.”
Shoukat Shah, Lead, Technology and Digital Advisory, BDO Saudi Arabia
Where should organisations start with cyber resilience?
Visibility.
Before the firewall upgrade, the SOC contract or anything with “AI-powered” on the label, an organisation should be able to answer three straightforward questions: What do we have? Who can access it? What happens when it breaks?
I have audited organisations with substantial security budgets that could not produce a reliable asset register, and I have seen more modestly funded teams contain incidents effectively because they understood their environment in detail and had rehearsed how they would respond when something went wrong.
My first investments are therefore often the less fashionable ones: a maintained inventory of systems and data, including cloud services that may otherwise be overlooked; disciplined identity and access management, with multi-factor authentication widely enforced and privileged accounts treated like vault keys; and an incident response plan that has actually been exercised with executives in the room.
None of this may stand out in a board presentation. All of it can determine whether an incident becomes an inconvenience or a crisis.
Resilience is largely the result of good cyber hygiene applied consistently, long before it is needed.
How is AI changing cybersecurity?
Both sides of the contest have become faster. Attackers can use AI to create convincing phishing content in different languages and dialects, clone voices and accelerate elements of reconnaissance and targeting. Defenders can use the same class of technologies to enrich alerts, identify anomalies and prioritise threats that analysts might otherwise struggle to detect quickly.
That arms race receives considerable attention. The quieter and potentially more significant shift is that AI itself has become something organisations need to govern, not simply use.
“Every model an organisation deploys creates questions that extend beyond traditional cybersecurity. What data trained it? What decisions does it make about people? What happens when it is wrong? Who is accountable?
SDAIA has established clear principles and frameworks around responsible AI, while the PDPL applies to personal data processed through these systems. Saudi Arabia's regulatory environment is increasingly placing greater emphasis on how AI is governed, controlled and monitored.
My advice is to give AI the treatment finance received decades ago: an inventory, an owner, controls and an audit trail. Companies doing this now will be able to adopt AI faster, not slower, because trust is what allows AI to scale.”
Shoukat Shah, Lead, Technology and Digital Advisory, BDO Saudi Arabia
Cybersecurity Awareness Month at BDO
Resilience in Motion is BDO's opportunity to put cyber resilience into practice.
BDO Saudi Arabia's cybersecurity, privacy and AI governance specialists work with boards and executive teams to turn frameworks into action: from NCA- and SAMA-aligned governance to PDPL-ready data programmes and AI governance designed for an evolving regulatory and technology environment.

