Participants in the tenth edition of the Arab Cybersecurity Conference called for expanding responsibility for protecting data and digital systems to include all ministries, institutions, and companies, rather than limiting it to technical departments or specific sectors. The call came during a press conference held on the sidelines of the event, which is held under the auspices of the Ministry of Communications and Information Technology, the Ministry of Finance, the Ministry of Industry, and the National Telecom Regulatory Authority.
Dr. Bahaa Hassan, President of the Arab Cybersecurity Conference, said that institutions are required to develop specialized personnel and allocate budgets for training, technical infrastructure, and capacity building, amid the growing volume and complexity of attacks. He considered treating cybersecurity as an item that can be postponed no longer acceptable, particularly with the expanding reliance on digital services and the increasing amount of data in circulation.
The Banking Sector’s Experience as a Regulatory Reference
Hassan praised the experience of the Central Bank of Egypt, considering that the higher level of readiness within banks was linked to the existence of a proactive vision that required banking institutions to spend on training and skills development. He called for extending this model to state institutions and private-sector companies, rather than allowing the level of compliance to vary from one sector to another.
Engineer Ahmed Bahaa, Vice President of iSec, said that other sectors need clear regulatory frameworks similar to the models existing in sectors such as banking and financial oversight, pointing to oil and telecommunications as fields that need clearer rules for data protection and risk management. He added that compliance should also include franchise companies, as they likewise handle customer data, addresses, numbers, and sensitive information.
Artificial Intelligence and the Shortage of Expertise
Bahaa Hassan described artificial intelligence as a dual-use tool in cybersecurity; it can be used to assess risks and detect attacks early, but it is also used to carry out more complex attacks. According to the participants, this requires greater cooperation among institutions, countries, and experts, rather than relying on separate solutions within each entity.
Hassan pointed to the continuing shortage of specialists in the Egyptian market, with a large proportion of professionals choosing to work outside the country. He also criticized suspending training when institutions face financial pressures, stressing that skills development must be continuous. He said that iSec implements a program under which its engineers obtain three accredited certificates annually, in cooperation with the National Telecom Regulatory Authority.
What Is Changing in Practice?
The conference contributions present a vision that shifts cybersecurity from an internal technical activity to an administrative and regulatory commitment affecting broad sectors. However, the source does not specify new legislation, implementation dates, or defined enforcement mechanisms; therefore, the call to replicate the Central Bank’s experience and conduct periodic oversight remains a proposed framework, not a fully detailed announced policy.
The Arab Security Cyber Wargames competition, held as part of the conference activities, saw the participation of 350 teams from around the world, with 10 teams qualifying to compete for the top three places. The conference also includes workshops and the participation of Arab and international experts and speakers, along with the honoring of leaders from banks and government entities.
These discussions reflect the importance of partnership among the state, the private sector, training institutions, and scientific research institutions. However, their practical impact will depend on turning general calls into measurable requirements, providing sustained funding for training, and establishing clear rules that define institutions’ responsibilities for protecting data.