Resilience in motion: when a physical attack becomes a cyber crisis

Resilience in motion: when a physical attack becomes a cyber crisis
This September, ahead of Cybersecurity Awareness Month, we spoke with Ghouse Mohammed, Manager – Advisory at BDO Bahrain, who advises organisations on cybersecurity, information security, data privacy, technology risk and business continuity, about the cyber risks organisations should be preparing for, the growing convergence of physical and digital threats and what resilience looks like in an increasingly interconnected world.

Ghouse Mohammed is a Manager – Advisory at BDO Bahrain, with extensive experience in cybersecurity, IT audit, information security, data privacy, technology risk and business continuity. He has led and supported advisory and assurance engagements across Bahrain, Oman and Qatar, working with organisations in financial services, telecommunications, manufacturing and other sectors. His approach focuses on making cybersecurity practical and business-focused, embedded into everyday decision-making rather than treated solely as a technology function.


What cyber risks should Bahrain prepare for by 2027?

If I had to pick one risk, it's the convergence of geopolitical conflict with hybrid cyber-physical attacks on infrastructure. Recent incidents in the GCC have demonstrated how physical disruption to major technology and cloud infrastructure can have an immediate impact on digital services. Not because of a traditional cyberattack, but because physical infrastructure itself can become part of the threat landscape. That completely changed how I think about cloud security.

The region has a significant concentration of critical infrastructure, including financial services, energy facilities, telecommunications networks, data centers and major hyperscale cloud regions. In relatively concentrated environments, disruption to the right facility or dependency can create a much wider ripple effect across organisations and sectors.

On top of that, threat actors continue to actively target organisations across the GCC. Recent threat intelligence has highlighted password-spraying campaigns, reconnaissance activities, distributed denial-of-service attacks and other attempts targeting enterprise and cloud environments. The region has also experienced a significant increase in cyber threats over the past several years, reinforcing the need for organisations to consider both cyber and physical dependencies when assessing resilience

“So, looking towards 2027, organisations need to prepare for hybrid scenarios where the digital and physical worlds increasingly collide. A disaster recovery plan should not only consider a server or application failure; it should also consider the possibility that an entire data center, cloud region, telecommunications dependency or supporting facility becomes unavailable. That means multi-region or appropriately diversified backups, tested failover procedures, alternative connectivity arrangements, clearly defined recovery priorities and a serious conversation at Board and executive-management level about where critical data and systems actually reside. Cyber resilience can no longer be viewed purely as an IT or cybersecurity issue. Organisations need to understand the physical infrastructure and third-party dependencies supporting their digital services and ensure that business continuity, disaster recovery and cybersecurity planning work together to address increasingly complex disruption scenarios,” – mentions Ghouse Mohammed.


What's the biggest cybersecurity myth in Bahrain?

One of the most common cybersecurity misconceptions I hear is that small businesses in the region are “too small to be targeted.” The reality is that attackers look for the easiest point of entry. Small and medium-sized businesses may hold valuable customer information, payment data, employee credentials, remote-access connections, or links to larger organisations and supply chains.


This is particularly relevant across the region, where SMEs form a significant part of the business landscape and increasingly rely on cloud platforms, remote access, digital payments, third-party service providers and connected systems. That growth in digital adoption also increases exposure to phishing, credential theft, ransomware, weak access controls and unpatched systems.


Another misconception is that a strong password alone is enough. It isn't. A stolen or compromised password can still give an attacker access unless additional controls, such as multi-factor authentication, secure configuration, monitoring, patching and user awareness, are in place. The key message is simple: organisations should stop asking whether they're “important enough” to be attacked and start asking whether they're “easy enough” to compromise.

Where should Bahraini organisations start with cyber resilience?


I would start with multi-factor authentication (MFA), particularly for privileged, administrative, remote-access and cloud accounts. It may sound basic, but compromised credentials remain one of the most common ways attackers gain access. A password can be phished, reused, guessed or exposed through another breach. MFA adds an important additional barrier and can significantly reduce the likelihood that a stolen password alone results in account compromise.

For organisations across the region, this matters even more as businesses increasingly rely on cloud services, remote working, third-party platforms, digital payments and interconnected systems. The more identities and access points an organisation has, the more important strong authentication becomes. MFA should be treated as the starting point rather than the complete solution: it needs to be supported by basic cyber hygiene such as timely patching, endpoint protection, secure configuration, privileged-access controls, employee awareness, backups, monitoring and incident-response readiness.

“Before investing heavily in sophisticated cybersecurity technologies, make sure the fundamentals are working properly. Start with identity. Protect the accounts that can cause the greatest damage if compromised and build your cyber resilience from there,” – says Ghouse Mohammed.


How is AI changing cybersecurity in Bahrain?


AI is strengthening how organisations defend themselves while also giving attackers new capabilities. For businesses in the region, this is becoming increasingly relevant as organisations accelerate their use of cloud services, digital platforms, APIs, automation and AI-enabled technologies.

On the defensive side, AI is helping cybersecurity teams analyse large volumes of security events, identify unusual behaviour, detect potential threats faster and automate parts of incident response. This is particularly valuable in sectors such as financial services, telecommunications, energy and critical infrastructure, where organisations need to monitor increasingly complex and interconnected environments.


However, attackers have access to many of the same capabilities. AI can make phishing emails more convincing, automate reconnaissance, help identify vulnerabilities and create highly personalised social-engineering attacks. Deepfake voice and video technology adds another challenge: employees can no longer assume that a familiar voice, video call or well-written email is necessarily genuine.

Perhaps the biggest change is that AI is lowering the technical barrier to cybercrime. Activities that previously required significant technical knowledge can increasingly be assisted or automated using AI, while more sophisticated threat actors use it to increase the speed, scale and effectiveness of their attacks. For organisations in the region, the answer isn't simply to buy more AI-powered cybersecurity products. Businesses need to understand how AI is being used within their organisation, protect the data and systems connected to it, establish appropriate governance and strengthen their ability to detect AI-enabled attacks.


Technology also needs to be supported by people: employees should increasingly be trained to question unusual payment instructions, unexpected requests for credentials, changes to bank details and even seemingly genuine voice or video communications. AI will make cybersecurity faster on both sides. The organisations that build the right combination of technology, governance and human awareness will be better positioned to stay ahead.

Cybersecurity Awareness Month at BDO

Resilience in Motion is BDO's opportunity to put resilience into practice. BDO’s cybersecurity, IT audit and data privacy specialists in Bahrain work with organisations to strengthen cyber governance, technology controls, third-party risk and incident preparedness, from identity and access management to disaster recovery built for a world where digital and physical threats increasingly collide.