Sanjiv Cherian moved from London to Dubai in November 2024. He argues the region has passed a structural turning point that most international vendors have not yet priced in.

For most of the last two decades, the cybersecurity market in the Gulf worked in a fairly predictable way. Technology was designed elsewhere. It was sold through regional partners. The higher-value advisory work was delivered by consultants flown in for the engagement, and the monitoring was frequently performed from a security operations centre several time zones away.
Sanjiv Cherian, who relocated from London to Dubai in November 2024 after nineteen years in the British capital, argues that model is now visibly breaking down, and that the reasons are structural rather than cyclical.
“Three things changed at once. Regulators started asking where the data physically sits and who holds the credentials. National strategies started measuring domestic capability, not just spend. And the operators themselves worked out that a service delivered from six thousand kilometres away has a response time problem that no service level agreement can fix.”
The regulatory driver is the most concrete. Requirements across the region increasingly touch on data residency, the location of monitoring operations and the vetting of personnel with privileged access to critical systems. For an operator of critical national infrastructure, the question of which jurisdiction holds administrative access to a control network has become a governance matter rather than a procurement detail.
“There was a period when nobody asked. That period is over. If you cannot answer where the analyst with access to my environment is physically sitting, and under whose law, you are no longer in the conversation for the serious work.”

The second driver is economic policy. Saudi Arabia’s national transformation programme and the United Arab Emirates’ successive national strategies have both attached explicit weight to domestic capability, local employment and knowledge transfer. Cherian argues this has changed the commercial question that operators ask suppliers.
“The question used to be what does it cost. Now it is what does it cost, and what capability stays here when you leave. Those are very different procurement conversations and a lot of international suppliers are still answering the first one.”
He is careful not to overstate the shift. Regional capability, he says, is uneven, and the shortage of experienced specialists in industrial and operational technology security is acute everywhere, not only in the Gulf. He argues that international expertise remains essential, but that the delivery model around it has to change.
“This is not a case for shutting the door. It is a case for changing the structure. Bring in the specialist, absolutely, but build the team here, certify it here, and make sure the knowledge does not get on the plane home. The organisations doing this well are the ones treating every external engagement as a transfer exercise.”

Cherian’s own move was a bet on this thesis. His firm holds CREST certification and ISO 27001 accreditation and operates across the United Arab Emirates, Saudi Arabia and the United Kingdom, delivering operational technology security, managed security operations and assurance work regionally rather than remotely.
He is direct about what the transition means for the incumbents.
“The reselling model had a very good run and it is closing. If your regional business consists of a logo, a distribution agreement and a quarterly visit, the regulatory direction is not going to be kind to you. The firms that will still be here in ten years are the ones building something that a regulator would recognise as local.”
Asked what would most accelerate the shift, he does not name a technology.
“Talent, and specifically industrial security talent. The frameworks exist, the capital exists, the political will exists. What does not exist in sufficient quantity is people who understand both a control system and a threat model. Whichever country in this region solves that first will set the standard for the rest.”

Sanjiv Cherian writes publicly on operational technology security and the enterprise use of artificial intelligence, publishing to an audience of more than 21,000 followers on LinkedIn and at sanjivcherian.com, where he sets out his work on the deliberate pairing of human judgement with machine capability. Sanjiv Cherian spoke on “Digital Transformation vs Cyber Threats in UAE Energy and Utilities” at the OT Security First MENA Event in Abu Dhabi in February, 2026 and has been twice quoted on the CISO Series Podcast for his thought leadership on Cyber security. The through-line is consistent across everything he publishes: technology sets the ceiling on what a security function can do, and people determine how much of that ceiling is ever reached.
AUTHOR BIO BLOCK: Sanjiv Cherian is a British cybersecurity executive based in Dubai, United Arab Emirates. He is Co-Founder and Chief Commercial Officer of Microminder Cyber Security, which delivers operational technology and industrial control systems security, managed security operations, penetration testing and cyber assurance services across the United Arab Emirates, Saudi Arabia and the United Kingdom. Born in Mumbai, he moved to the United Kingdom at twenty-one and spent two decades in London before relocating to Dubai in November 2024. He holds a Master of Business Administration from Liverpool John Moores University. He writes and speaks on operational technology security, critical national infrastructure protection, and the role of artificial intelligence in enterprise security. More at sanjivcherian.com






