Mohammed Saty of PwC Middle East Explains Why Better Decisions Lead to Better Cybersecurity
DUBAI, UAE / ACCESS Newswire / September 15, 2026 / Cybersecurity teams rarely suffer from a shortage of information.
Press Release Disclaimer: This is a press release distributed through the XPR Media network. It has not been independently verified by our newsroom.

![]()
DUBAI, UAE / ACCESS Newswire / September 15, 2026 / Cybersecurity teams rarely suffer from a shortage of information. Most large organizations already have dashboards, vulnerability reports, threat intelligence, supplier assessments, compliance data, and alerts arriving every day. The harder part is deciding what deserves attention first.
Mohammed Saty, a strategic cybersecurity advisor and Director at PwC in Dubai, sees that as an executive challenge as much as a technical one. A business can know that a vulnerability exists and still struggle to decide whether it poses an urgent threat to an essential service, a manageable operational risk, or something that can reasonably wait.
That distinction becomes harder in connected environments. A destination, smart city, major sporting venue, or critical infrastructure project can involve thousands of systems and multiple organizations. Leaders cannot give every issue the same attention. They need to know where a cyber problem could become a business problem.
“Better decisions start with a clearer view of risk,” Saty says.

Photo Credits: PwC Middle East
The Hidden Cost of Delayed Cyber Decisions
A delayed cybersecurity decision does not always look dangerous at first.
There may be a known vulnerability that has not been fixed because another project took priority. A supplier may have access to an important system, but nobody has established how quickly that access needs to be reviewed. An older technology platform might remain in use because replacing it would interrupt operations.
Each decision can appear reasonable on its own. The difficulty arises when several of these dependencies exist simultaneously, and no one has a clear view of their combined business impact.
Consider a destination where visitors depend on transportation, payments, hotels, attractions, ticketing, mobile services, and public infrastructure. If one of those services is disrupted, the consequences may not remain within the organization that operates it. A payment outage can affect retailers. A transportation issue can affect venues. A compromised digital platform can undermine visitor trust.
This is why simply knowing that cyber risks exist is not enough. Leaders need to know what those risks are connected to.
That context changes the decision. A technical issue becomes easier to prioritize when an executive can see the service it supports, the people who depend on it, and what interruption would mean for the wider operation.
Why Good Data Still Produces Bad Decisions
A risk dashboard can be accurate and still leave an executive unsure about what to do next.
Suppose a report lists 500 vulnerabilities. Another report identifies 20. The first number looks worse, but that tells the board very little without knowing where those vulnerabilities sit. If the 20 affect systems responsible for essential services while most of the 500 are isolated from critical operations, the smaller number may demand far more attention.
The same problem appears with suppliers. A third party might receive a poor security assessment, but the real question for leadership is what the organization depends on that supplier to do. If its service stopped tomorrow, would customers notice? Would operations continue? Is there an alternative?
This is the gap between cyber data and business context.
Technical teams need detailed information because they are responsible for investigating and managing threats. Executives need a different view. They need enough technical understanding to appreciate the risk, but they also need to see the possible consequence in terms of operations, investment, reputation, trust, and resilience.
For Saty, clarity comes from connecting those two views rather than choosing between them.
A useful question for an executive is not only, “How serious is this threat?”
It is also, “What does this threaten?”
The Boardroom Question Every Cyber Leader Avoids
Eventually, every cybersecurity strategy reaches an uncomfortable question: how much risk is the organization prepared to live with?
There is no realistic environment in which every vulnerability can be addressed immediately and every asset receives the highest possible level of protection. Organizations have limited budgets, limited people, and competing priorities. At the same time, their digital environments continue to expand.
That means choices are unavoidable.
A board may decide that disruption to a particular service is unacceptable. Another system may tolerate several hours of downtime. A certain third-party dependency may justify additional investment, while another risk can reasonably be accepted.
Making those distinctions does not weaken cybersecurity. It gives the security function a clearer mandate.
The difficulty is that accepting risk requires someone to own the decision. Cyber teams can explain the technical exposure and possible scenarios, but decisions about business impact, investment, and acceptable disruption cannot rest solely with the security function.
For major destinations and other complex environments, this becomes particularly important because the consequences may cross organizational boundaries. One organization can own a system while several others depend on the service it provides.
Cybersecurity therefore becomes a leadership conversation about what the organization values enough to protect first.
Start With What Cannot Be Lost
One way to simplify the discussion is to stop beginning with the list of threats.
Begin with the outcome.
For a tourist destination, leaders might decide that transportation, visitor access, payments, safety systems, and essential hospitality services must remain available. At a major sporting event, the priority could include ticketing, venue access, broadcasting, crowd management, and operational technology.
Once those priorities are clear, teams can trace what sits behind them. Which systems keep those services running? Which suppliers have access? Where are the dependencies? How quickly would each service need to recover?
The cybersecurity conversation becomes much more practical at that point.
Instead of debating hundreds of technical issues in isolation, leaders can compare them against the services and outcomes the organization has already decided matter most. Security investment can then follow business importance rather than simply following whichever threat appears most alarming on a dashboard.
Better Decisions Make Cybersecurity More Useful
Cybersecurity will continue to become more complicated. Destinations are adding connected services. Cities are becoming smarter. Organizations are using more AI. Major developments depend on growing networks of technology providers, infrastructure operators, and digital platforms.
Trying to remove all that complexity is unrealistic.
The leadership challenge is to see through it.
For Saty, this means giving executives a view of cyber risk that helps them decide, not simply informing them that threats exist. When technical risk is connected to business impact, leaders can decide what needs immediate action, where investment will make the greatest difference, and what level of risk the organization can reasonably carry.
That is also where cybersecurity becomes more valuable to the business. It can support ambitious transformation without asking leaders to choose between innovation and protection.
The organizations that handle cyber risk well will not necessarily be the ones with the most data. They will be the ones that can identify what matters, understand what threatens it, and make the necessary decision while there is still time to act.
About Mohammed Saty
Mohammed Saty is a strategic cybersecurity advisor with more than 15 years of experience helping executives make confident decisions in complex environments. He combines deep technical expertise with a practical business perspective to turn cybersecurity, AI, and digital transformation challenges into clear priorities and actionable strategies.
His work spans complex environments, including smart cities, destination developments, major sporting events, critical infrastructure, and large-scale transformation. He has supported governments, ministries, and global organizations in aligning technology, risk, and business priorities to strengthen resilience and support long-term growth.
Originally from Khartoum, Sudan, Mohammed holds a Bachelor of Science in Mathematics from the University of Science and Technology. He is now a Director at PwC in Dubai, where his work has evolved from deep technical cybersecurity expertise into strategic advisory. Mohammed is known for asking the questions that uncover what matters, challenging assumptions, and making complex issues easier to understand and act on. His approach helps leaders build trust, make better investment decisions, reduce risk, and move forward with greater confidence.
About PwC Middle East
PwC Middle East is part of the global PwC network and provides professional services across the region, helping organizations address complex business challenges and create sustainable value. Its teams work with governments, businesses, and institutions across areas including strategy, transformation, technology, cybersecurity, risk, assurance, tax, and consulting. PwC Middle East combines regional knowledge with the capabilities of its global network to help clients respond to changing markets, emerging technologies, and evolving business risks.
Follow Mohammed Saty on LinkedIn for further perspectives on cybersecurity, destinations, technology, and executive decision-making.
Contact information:
Organization: PwC Middle East
Email: support@strategyachievers.com
Website: https://www.pwc.com/m1/en.html
Contact Person: Mohammed Saty
SOURCE: PwC Middle East
View the original press release on ACCESS Newswire

