Dr. Bahaa Hassan: Cybersecurity Is No Longer One Sector’s Responsibility as Attacks Intensify
Egypt should extend the cybersecurity framework developed across its banking industry to government institutions and private-sector businesses as cyberattacks grow in scale and sophistication, according to Dr. Bahaa Hassan, Chairman of the Arab Security Conference.
Speaking during a press conference on the sidelines of the 10th Arab Security Conference in Cairo, Hassan said cybersecurity can no longer be treated as the responsibility of a single ministry, technology department or industry.
Instead, every institution holding data or operating digital systems needs its own cybersecurity capabilities, trained professionals and dedicated investment, he said.
His comments come as the conference marks its tenth edition, bringing together government institutions, technology companies, cybersecurity specialists and industry executives to discuss how Egypt and the wider Arab region can strengthen their defenses against increasingly complex digital threats.

Central Bank Model Could Extend Beyond Financial Sector
Hassan highlighted the Egyptian banking industry as an example of how regulation and sustained investment can raise cybersecurity readiness.
He said the Central Bank of Egypt’s approach has encouraged banks to allocate resources to cybersecurity training and build specialized teams, creating a pool of professionals capable of responding to threats affecting the financial sector.
The challenge, he argued, is to take that experience beyond banking.
Government entities and private-sector companies should adopt similarly structured approaches to cybersecurity investment, skills development and risk management rather than waiting for an attack to expose weaknesses.
Hassan also called on organizations to allocate sufficient cybersecurity budgets covering technology, infrastructure, training and workforce development.
Cybersecurity Training Cannot Be the First Budget Cut
One of the biggest weaknesses remains the shortage of qualified cybersecurity professionals.
Hassan said Egypt continues to face a skills gap, compounded by the movement of experienced cybersecurity professionals into overseas markets.
That makes continuous training increasingly important, particularly as new technologies change both defensive capabilities and attack techniques.
Yet training programs can often be among the first expenses organizations reduce when financial pressures emerge.
Hassan argued that this approach is increasingly risky because cybersecurity skills need to evolve continuously alongside the threat landscape.
He said iSec, which has operated in the sector since 2007, follows a structured training program under which its engineers obtain three accredited certifications annually, with the program implemented in cooperation with the National Telecom Regulatory Authority (NTRA).
AI Is Strengthening Both Attackers and Defenders
Artificial intelligence is making that challenge more complicated.
Hassan described AI as a double-edged technology for cybersecurity. Security teams can use it to assess risks, identify suspicious activity and detect attacks earlier, while malicious actors can also use increasingly sophisticated tools to develop and execute attacks.
That creates a growing need for information sharing between organizations, experts and governments.
Hassan said the Arab Security Conference is seeking to strengthen an interconnected regional cybersecurity community capable of exchanging expertise and threat information while protecting shared interests.
Cyberattacks do not stop at national borders, making regional cooperation increasingly important as governments and businesses become more digitally interconnected.
350 Teams Enter Arab Security Cyber Wargames
The conference is also using practical competitions to identify and develop cybersecurity talent.
Ahmed Bahaa, Vice President of iSec, said this year’s Arab Security Cyber Wargames attracted 350 teams from around the world.
Following the qualification stages, just 10 teams advanced to the final competition, with the top three due to be recognized during the conference.
The competition adds a practical dimension to a conference agenda that otherwise includes policy discussions, workshops and technical sessions.
Cybersecurity Rules Need to Reach More Industries
Ahmed Bahaa also called for clearer cybersecurity regulatory frameworks across a wider range of economic sectors.
He pointed to existing frameworks in regulated industries, including banking and financial services, arguing that similar models could be expanded across other sectors to establish clearer requirements for data protection and cyber-risk management.
The issue is not limited to banks, telecom operators or major infrastructure companies.
Retailers, franchise businesses and other private companies can hold customer names, telephone numbers, addresses and other sensitive information, creating cybersecurity responsibilities even when technology is not their primary business.
Bahaa argued that protecting this information cannot depend entirely on voluntary decisions by individual organizations.
Clear regulatory requirements, compliance mechanisms and regular assessments could help establish a minimum level of protection across industries as the amount of data held by private companies continues to grow.
Digital Identity Raises the Stakes for Data Protection
Egypt’s move toward digital identity creates another important cybersecurity challenge.
Bahaa said the digital identity project is a necessary development that could have been introduced earlier, but its implementation also creates significant responsibility around securing citizens’ information.
As more services become connected to verified digital identities, the potential consequences of security failures increase, making protection of the underlying infrastructure and data critical.
The same principle applies to the wider digital economy: the more services, transactions and personal information move online, the less cybersecurity can remain confined to specialist IT teams.
Arab Security Conference Marks Its 10th Edition
This year’s conference is being held with the support of the Ministries of Communications and Information Technology, Finance and Industry, as well as NTRA, alongside cybersecurity technology partners.
Dr. Reham Bahaa said the tenth edition brings together Arab speakers and international experts, with specialized workshops addressing different areas of cybersecurity.
The event will also recognize executives from banks and government institutions for their contributions to cybersecurity development.
For Hassan, however, the milestone comes with a wider message for the next decade: cybersecurity has moved beyond buying security products after infrastructure has already been built.
As attacks become more frequent and AI makes the threat environment more complex, training, regulation, institutional responsibility and sustained investment are becoming as important as the security technology itself.














