Rami H Hazime, Regional Sales Director, Gulf and Levant at OPSWAT, at GISEC 2026 told GEC Newswire that AI-built threats and an unavoidable need for outside data have forced operators to treat every incoming file as hostile.
Operators of the region’s most sensitive assets long believed the safest network was one nothing could enter. Oil and gas facilities, intelligence departments and defence ministries adopted a rule of no files in and no files out, believing isolation alone would keep attackers out.
Hazime said that belief had collapsed. Operators, he said, “thought a few years ago that it’s so critical, the only way for me to protect it is by isolating it”, and he added that “this myth is broken”.
Even the most guarded facility depends on information from outside. “No matter how critical your infrastructure is, you still require data to come in, intelligence reports, satellite imagery,” Hazime said, pointing also to firmware updates that must be installed and telemetry that must travel out to monitor equipment.
AI has handed attack tools to people with no hacking pedigree
That flow of data now meets a larger pool of attackers. Hazime said generative AI had compressed the experience once needed to build malicious code, letting novices bury payloads where conventional scanners rarely look. “Now, anyone can sit and develop a threat, hide it inside headers, hide it inside pixels of an image,” he said.
OPSWAT, founded 23 years ago, has built its business on stopping threats at the point of entry. Its product for zero-day attacks is content disarm and reconstruction, which assumes every file is malicious. Hazime said the process strips a file “to zeros and ones”, removes macros, hidden source code and active links, and passes on a clean copy in the original format. He said it works alongside AI tools that identify machine-generated code, forged passports and fake invoices. OPSWAT did not supply any figures on failure rates.
Oil fields and defence ministries are swapping software firewalls for one-way hardware
The second shift concerns how trusted and untrusted networks meet as IT and operational technology converge. Hazime described a move away from software segregation towards data diodes, hardware that permits information to travel in only one direction.
Controlled connectivity also demands a record of who submitted each file, when it moved and under which certificate. That rests on an uncomfortable premise. “You have to assume that things will go wrong. If they go wrong, how are we going to deal with it?” Hazime said. Organisations in the UAE, he said, were mature enough to treat readiness as something “I have to invest, I have to be ready.”



