As Qatar accelerates the digitisation of critical sectors such as energy, finance, healthcare, water, and transport, corporate spending on defensive cybersecurity tools is reaching record levels. 

However, a significant gap remains between installing security software and verifying if those controls can withstand a real-world attack, according to David de Paula Santos Silva, the founder and CEO of CyberX, an ethical hacking services firm headquartered at the Qatar Science and Technology Park (QSTP).  

“Organisations are often willing to invest significant amounts in defensive technology... The problem is that installing a security control does not prove that the control will work when somebody actively tries to bypass it,” Silva told Gulf Times in an exclusive interview.

Silva emphasised that operational technology environments within the energy, water, and transport sectors require special attention. He said these areas combine rapid digitalisation with critical safety requirements, making it difficult to take systems offline for routine maintenance or testing. 

While companies spend heavily on systems like firewalls, endpoint detection, monitoring platforms, and threat intelligence, Silva explained that these investments demand active validation. He noted that a sophisticated security stack could still fail to detect an attack, allow network segmentation to be bypassed, or reveal a broken incident response process during a simulation. 

“You can have an expensive security stack and still discover during a penetration test or red-team exercise that an attack was not detected, network segmentation could be bypassed, an endpoint was not properly monitored, or the response process did not work as expected,” he explained.

Instead of asking what security tools have been purchased, Silva noted that boards should ask when someone was last authorised to try and defeat those exact tools. Assuming a network is protected without independent testing is primarily a governance problem, he stressed. 

Silva compared the situation to installing a fire alarm: The green indicator light shows the device is turned on, but only actual smoke proves the system functions during an emergency. He pointed out that cybersecurity requires the exact same verification mindset, even if the testing produces uncomfortable answers for IT departments. 

According to Silva, a simulated incident exercise might reveal that an expensive security tool missed a specific technique, or that staff do not know who has the authority to isolate a compromised system late at night. 

“A red team is effectively an exam for the security investments you have already made. A penetration test can tell you whether vulnerabilities can be exploited,” stated Silva, adding that organisations need both defence and verification. 

While Qatar already has a substantial cybersecurity framework, Silva cautioned against relying solely on compliance standards. He recommended strong requirements around independent risk-based penetration testing, periodic red-team exercises, third-party risk assessments, and mandatory retesting after significant vulnerabilities are fixed. 

Incident response exercises are equally critical, said Silva, noting that an organisation might possess an excellent response document but discover during a drill that phone numbers are outdated or an important supplier cannot be reached outside business hours. 

He said, “Supply-chain exposure deserves particular attention because critical infrastructure increasingly depends on external software, cloud services, maintenance companies and technology providers.”

Silva added: “The regulator should not only be asking: ‘What security products do you have?’ It should also be asking: ‘Show me the last time somebody tested whether those controls could actually be bypassed, what they found and whether you fixed it’. That creates a very different security culture.”

Related Story