BDO UAE’s Madan Mohan: AI to be a powerful defensive capability, new attack surface | Asian Business Review
606 views

BDO UAE’s Madan Mohan: AI to be a powerful defensive capability, new attack surface

This comes amidst the technology significantly improving the speed, accuracy, and scale of security operations.

In 2025, the Middle East’s technology industry continued its rapid transformation into a major global technology and innovation hub, with the region seeing strong growth in artificial intelligence investment and international tech companies expanding their presence through large-scale partnerships and infrastructure investments.

This industry development is closely aligned with the experiences of BDO UAE Director Madan Mohan, who has over 19 years of expertise across the banking, insurance, telecommunications, and manufacturing sectors, specialising in data privacy, business continuity management, information security governance, and risk assessment.

He has worked closely with Boards, CXOs, and cross-functional teams spanning IT, cybersecurity, privacy, and internal audit, and has been recognised for his work in implementing privacy frameworks.

Speaking with the Middle East Technology Excellence Awards 2026 as part of the panel of judges, he sheds light on the evolution, maturity, and future of cybersecurity and risk governance, including common governance gaps, indicators of effective cybersecurity practices, and the impact of artificial intelligence and automation on emerging risks. He also shares some strategies for proactively adapting to evolving data privacy and regulatory requirements.

With over 19 years of experience, how has the role of cybersecurity and risk governance evolved in shaping enterprise strategy?

Over the past 19 years, cybersecurity and risk governance have evolved from primarily technical and compliance-driven functions into strategic business enablers. Earlier, organisations viewed cybersecurity as an IT responsibility focused on perimeter security, antivirus solutions, and regulatory compliance. Today, cyber risk is recognised as an enterprise-wide business risk that directly impacts revenue, reputation, customer trust, operational resilience, and regulatory obligations.

The role of cybersecurity leaders has expanded significantly, with CISOs and risk professionals now actively participating in board-level discussions, business strategy, digital transformation initiatives, cloud adoption, and emerging technology programmes such as AI and blockchain. Modern risk governance frameworks help organisations balance innovation with security by embedding risk management into business decision-making processes.

The increasing sophistication of cyber threats, stringent regulatory requirements, and growing dependence on digital ecosystems have shifted the focus from reactive security to proactive risk management, continuous monitoring, threat intelligence, and resilience planning. Cybersecurity is now a key component of Environmental, Social, and Governance (ESG) objectives, third-party risk management, and enterprise resilience strategies.

Ultimately, effective cybersecurity and risk governance enable organisations to confidently pursue growth, adopt new technologies, meet stakeholder expectations, and maintain trust in an increasingly interconnected digital economy. Rather than being viewed as a cost centre, cybersecurity has become a strategic function that supports sustainable business success and competitive advantage.

What are the common governance gaps you see in cybersecurity and information risk management?

One of the most common governance gaps is the lack of board-level visibility and ownership of cyber risk. Many organisations still treat cybersecurity as an IT issue rather than an enterprise risk. Other frequent gaps include unclear roles and responsibilities, weak third-party risk management, outdated policies, insufficient risk reporting, ineffective security awareness programmes, and limited integration between business, technology, and risk functions. Additionally, organisations often struggle with continuous monitoring, risk-based decision-making, and measuring the effectiveness of security controls, resulting in compliance-driven rather than resilience-driven cybersecurity programmes.

What indicators best demonstrate that an organisation has a mature and effective cybersecurity posture?

A mature and effective cybersecurity posture is demonstrated through a strong security governance framework, active board and executive oversight, and alignment of cybersecurity objectives with business goals. Key indicators include a risk-based security programme, continuous monitoring, timely detection and response to incidents, effective vulnerability and patch management, and regular security testing. Mature organisations also maintain robust third-party risk management, comprehensive employee awareness programmes, and measurable security metrics. Compliance with recognised standards such as ISO 27001, NIST, and industry regulations, combined with a culture of continuous improvement and cyber resilience, reflects a well-governed and proactive cybersecurity environment.

What impact do you expect AI and automation to have on both strengthening cybersecurity and creating new categories of risk?

Artificial Intelligence (AI) and automation are transforming cybersecurity by significantly improving the speed, accuracy, and scale of security operations. Organisations are increasingly using AI-powered tools to analyse vast amounts of security data, identify anomalies, detect threats in real time, automate incident response, and reduce the workload on security teams. AI also enhances threat intelligence, vulnerability management, fraud detection, and security monitoring, enabling organisations to respond to cyber threats more proactively and efficiently.

At the same time, AI is creating entirely new categories of risk. Threat actors are leveraging AI to develop more sophisticated phishing attacks, automate malware creation, conduct deepfake-enabled fraud, and execute highly targeted social engineering campaigns. The growing adoption of AI introduces challenges related to data privacy, model security, algorithmic bias, intellectual property protection, and regulatory compliance. Organisations must also address risks such as unauthorised AI usage, data leakage through AI platforms, and manipulation of AI models through adversarial attacks.

As AI adoption accelerates, cybersecurity programmes must evolve to include AI governance, model risk management, secure AI development practices, and continuous monitoring of AI systems. Ultimately, AI will be both a powerful defensive capability and a new attack surface. Organisations that establish strong AI governance and risk management frameworks will be better positioned to harness its benefits whilst minimising emerging risks.

How do you foresee regulatory frameworks around data privacy and protection evolving, and how should organisations stay ahead of them?

Data privacy and protection regulations are expected to become more stringent, globally harmonised, and focused on accountability, cross-border data transfers, AI governance, and individual rights. Regulators will increasingly demand stronger transparency, privacy-by-design practices, and evidence of continuous compliance. To stay ahead, organisations should adopt proactive privacy governance frameworks, regularly assess regulatory changes, implement robust data classification and retention practices, and integrate privacy requirements into business and technology initiatives from the outset. Continuous monitoring, employee awareness, and aligning with standards such as GDPR, UAE PDPL, and other regional regulations will help organisations remain compliant and resilient.

As a judge for the Middle East Technology Excellence Awards 2026, what qualities of innovation will stand out most when evaluating nominees?

When evaluating nominees for the Middle East Technology Excellence Awards 2026, I will look for innovation that delivers measurable business value, not just technological sophistication. The strongest candidates will demonstrate how emerging technologies such as AI, automation, cloud, cybersecurity, and data analytics solve real business challenges, improve customer experiences, and drive operational efficiency. Equally important are scalability, sustainability, security, and governance considerations. I will also value solutions that foster digital transformation, strengthen resilience, and create a positive impact on society, customers, and stakeholders. Ultimately, innovation stands out when it is practical, transformative, and delivers tangible, long-term outcomes.

Join Asian Business Review community

Follow the link for more news on

Join Asian Business Review community
Since you're here...

...there are many ways you can work with us to advertise your company and connect to your customers. Our team can help you design and create an advertising campaign, in print and digital, on this website and in print magazine.

We can also organize a real life or digital event for you and find thought leader speakers as well as industry leaders, who could be your potential partners, to join the event. We also run some awards programmes which give you an opportunity to be recognized for your achievements during the year and you can join this as a participant or a sponsor.

Let us help you drive your business forward with a good partnership!