Mazen Adnan Dohaji, Senior Vice President and General Manager, IMETA
AI adoption across the Middle East’s defense sector is introducing increased insider risk. AI-driven technologies are making sensitive data more accessible, exposing defense operations to rising threats from not just external actors, but from within their own operations.
According to Exabeam research, 70% of cybersecurity professionals in the Middle East now view insider threats as a top concern. With the rise of AI, the speed, scale, and sophistication of insider threats have rapidly increased, making it easier for both malicious insiders and well-intentioned personnel to compromise systems.

As the defense sector explores AI use cases including decision-making during conflict and analyzing vast amounts of defense data, strengthening operations against insider threats becomes a nationwide priority. Overcoming this national security challenge is essential to enabling regional stability and cyber resilience within the sector.
The Shifting Threat Landscape for Defense
Insider threats are disrupting security operations across the Middle East. While external attacks more frequently capture headlines, insider threats can be even more damaging. Defense personnel, contractors, and third-party partners often operate with privileged access to sensitive systems, weapons platforms, intelligence databases, and command-and-control environments. This legitimate access makes insider threats harder to detect, slower to respond to, and more likely to bypass traditional security measures.
Whether malicious, accidental, negligent, or a result of compromised credentials, AI is adding to the insider threat challenge across defense environments through:
- Supercharging Social Engineering Attacks: Generative AI (GenAI) tools are often manipulated to produce highly convincing content including deepfake fraud, phishing emails, and realistic documentation to bypass traditional detection methods. Impersonating trusted personnel can trick trusted users into transferring funds, disclosing credentials, and interacting with malicious links.
- AI Agents Acting as Insider Threats: As the defense sector increasingly explores AI agents to automate tasks and assist with decision-making, these systems gain access to sensitive data and internal workflows. AI agents can act as unintentional insiders when they are misconfigured, exploited or behave unpredictably, expanding the attack surface and introducing new risks. This reflects the rise of the “agentic enterprise,” where enterprises now operate with both human employees and digital workers, as AI agents act across systems, data, and APIs, increasing operational velocity and expanding insider risk.
- Unauthorized Tools Exposing Vulnerabilities: Defense personnel who use unauthorized tools like GenAI chatbots are unintentionally allowing opportunity for data leakages and executing unauthorized commands. This is known as ‘Shadow AI’. AI-powered chatbots often operate outside of IT visibility, putting defense operations at risk of compliance violations, intellectual property loss, and creating hard to detect insider activity.
The current model for security operations is being reshaped by forces it was never designed to withstand. Without proper visibility, advanced analytics, and strong governance, insider threats often go under the radar. This gives insiders the time and access they need to exploit sensitive data and disrupt critical operations.
Accelerating technology, AI-driven threats, and expanding digital complexity demand a fundamental change in modern enterprise defense.
From Risk to Resilience
Whether the risk comes from AI technologies themselves, or AI-enabled human actors, insider threats involve the same AI tools that defenders depend on, turning technology into both a weapon and a defense.
In response, the Middle East’s defense sector is increasingly evaluating AI-powered security analytics to stay ahead. These advanced tools help detect unusual user behavior, identify potential insider threats, and automate responses, often preventing damage before it occurs.
To maximize the effectiveness of these tools, building a strong and resilient defense against AI-enabled insider threats requires a multi-layered security strategy that:
- Establishes Strong AI Governance: As AI security tools become embedded in defense operations, robust governance frameworks to ensure responsible use become essential. Clear policies around data access, model training, and system oversight help prevent intentional or accidental AI misuse. This reduces the risk of insider threats originating from poorly managed or unmonitored AI tools.
Utilizes Agent Behavior Analytics: For years, user and entity behavior analytics (UEBA) transformed how organizations manage human insider risk by learning normal behavior and identifying meaningful deviations. As digital workers scale, that behavioral model must extend to agents. Agent Behavior Analytics (ABA) applies baselining, anomaly detection, and contextual reasoning to AI-driven actors, establishing visibility, accountability, and control at the speeds required by these new threats. By treating agents as first-class security subjects, ABA directly addresses the governance challenge introduced by autonomous systems.
- Harnesses Agentic AI: Many cybersecurity teams across the Middle East continue to face a critical skills gap, making it harder to detect and respond to insider threats in a timely manner. Agentic AI, autonomous, decision-making AI, addresses this challenge by continuously investigating alerts, prioritizing insider-related incidents, and initiating responses without constant human intervention.
- Educates Personnel: By conducting regular anti-phishing training using simulated emails that target vulnerable users, the defense sector can reduce the risk of compromised insiders. They can also build on this by training personnel to spot and anonymously report risky behavior to HR or IT to help prevent insider threats.
As the Middle East continues to digitize and adopt advanced technologies, prioritizing user awareness, responsible adoption, and proactive technologies will be essential in overcoming AI-driven insider risk. This is vital for establishing an insider threat-ready foundation across the region’s critical defense sector.
Turning AI from Threat to Advantage
AI is not only redefining both the scalability and speed of threats in the Middle East but also acts as one of the most powerful tools for insider threat defense. To keep pace, the region must evolve its insider threat strategies.
The challenge is no longer incremental optimization. It is systemic redesign.
This means expanding visibility to include both human and non-human actors, aligning leadership and security operations, and investing in behavioral analytics that can surface subtle, context-driven signals of risk. Defense entities that proactively combine technology, governance, and culture will be the ones that are best equipped to handle AI-enhanced insider threats.





Be the first to comment