From 16 to 18 September 2026, I attended GISEC Global at the Dubai Exhibition Centre in Expo City Dubai. Spending all three days at the event gave me an opportunity to meet cybersecurity professionals, explore new products, and understand how different companies are approaching security in the age of artificial intelligence.

A Brief Introduction to GISEC

GISEC, originally known as the Gulf Information Security Expo and Conference, held its inaugural edition in Dubai in 2013. Since then, it has grown into one of the region’s most important cybersecurity gatherings.

The 2026 event was its 15th edition. It brought together more than 750 cybersecurity brands, over 350 cybersecurity leaders on stage, and professionals from more than 180 countries. Participants included government representatives, security leaders, ethical hackers, regulators, startups, and technology providers.

The event focused on AI security, data protection, cloud vulnerabilities, critical infrastructure, and the future of cyber resilience.

GISEC and Dubai Cyber Challenge stage signage inside Dubai Exhibition Centre.
The event brought together cybersecurity exhibitions, talks, demonstrations, and live challenges across three days.

My Main Observation

After spending three days exploring the exhibition, one idea stayed with me: cybersecurity has a limited number of core problems, but there can be many different solutions to each problem.

Traditional cybersecurity focuses on areas such as firewalls, Security Operations Centre solutions, VPNs, identity protection, and data security. Many vendors operate in these same areas, but each one approaches the problem differently.

The same pattern is now appearing in AI security.

As organisations rapidly adopt tools such as ChatGPT, Claude, and Codex, one of their biggest concerns is protecting sensitive information. Companies, particularly banks, fintech businesses, government entities, and other regulated organisations, do not want employees to accidentally send personal, confidential, or proprietary data to a public AI model.

Some organisations also need to ensure that their data does not leave the country because of regulatory, privacy, or data residency requirements.

Haseeb Sultan with the SANS and GIAC mascot on the GISEC Global exhibition floor.
Exploring the exhibition floor offered a direct look at how established vendors and startups are positioning new security products.

At GISEC, I found four different approaches to solving this single problem.

Four Approaches to AI Data Protection

1. Adding AI data protection to the existing firewall

The first approach was the simplest and most familiar.

Many organisations already route their incoming and outgoing network traffic through a corporate firewall. Firewall providers are therefore adding AI security and data loss prevention features to their existing products.

Before an employee sends a prompt or uploads a document to a public AI service, the firewall inspects the request. If it identifies personally identifiable information, confidential company data, or another restricted type of content, it can block the request.

This approach makes sense for banks, fintech companies, and other regulated organisations that already have strong network security infrastructure. Instead of introducing a completely new platform, they can extend the controls they already use.

2. Protecting data through a browser extension or desktop application

The second approach involves installing a browser extension or desktop application on employees’ devices.

When an employee uses an AI tool, the extension examines the prompt or uploaded content before it is submitted. If it detects sensitive or personal information, it can warn the user, remove the information, or block the request completely.

Several startups are building products around this approach. It can be useful for organisations that want protection directly on the employee’s device without making major changes to their network infrastructure.

Its success, however, depends on properly installing and managing the software across all relevant devices and browsers.

3. Providing a controlled enterprise AI platform

The third solution is to provide employees with a separate, company-approved AI platform.

Instead of allowing staff to access ChatGPT, Claude, or other AI services directly, the organisation asks them to use one controlled interface. Behind that interface, the company can connect approved public AI models, privately hosted models, or on-premises models.

The platform can inspect prompts, block sensitive content, maintain activity logs, apply access policies, and give administrators a central dashboard.

This provides the organisation with more control, but it also requires employees to change how they work. Rather than using their preferred AI tools directly, they must use the company’s approved platform.

4. Using another AI model to sanitise the prompt

The fourth approach was particularly interesting to me.

In this model, the security provider uses its own AI model as an intermediary. When a user enters a prompt, it does not immediately go to the final public AI model. It first passes through the provider’s security model.

That intermediary model analyses the prompt, identifies confidential information, and sanitises or removes anything that should not be shared. Only the cleaned prompt is then sent to the final AI model. The response can also pass through the same security layer before being returned to the user.

Compared with simple pattern matching, this approach may understand the context of sensitive information more effectively. However, it can also be more expensive and complex because the provider must operate its own model while paying for access to external AI models through APIs.

Different Solutions for Different Organisations

My biggest lesson was that none of these four approaches is automatically right or wrong. Each one is suitable for a different type of organisation.

An organisation that already has mature firewall infrastructure may prefer to add AI controls to its existing security stack. Another company may find a browser extension easier and more affordable. A highly regulated business may need a controlled enterprise platform, while an organisation with more complex data may benefit from an AI-powered sanitisation layer.

Cost is also an important consideration. Solutions that build on existing firewalls or endpoint controls may be less expensive because they use infrastructure the company already has. Platforms that host models, connect to multiple AI providers, or use an additional model to sanitise prompts will normally have higher operational and API costs.

The most advanced solution is not necessarily the best solution. The right choice depends on the organisation’s industry, regulations, existing technology, risk level, budget, and the experience it wants to provide to employees.

Participants seated with laptops in the Global Quantum X challenge hall at GISEC Global 2026.
Live challenges and working sessions reinforced that security decisions depend on context, constraints, and the people operating the technology.

My Overall Experience

GISEC Global 2026 was a valuable learning experience. It brought cybersecurity experts, vendors, startups, government representatives, and business leaders together in one place to discuss where the industry is heading.

For me, the most useful part was not simply discovering new products. It was seeing how different companies can examine the same problem and develop completely different ways of solving it.

AI security is still developing, and data protection is only one part of the challenge. However, the four approaches I saw at GISEC demonstrated something important: successful cybersecurity is not about finding one universal answer. It is about understanding the organisation, its risks, and its requirements, then selecting the solution that fits best.

That was my most important takeaway from three days at GISEC Global 2026.

Explore more writing →