PARAMOUNT CEO ON THE CYBERSECURITY RISKS RESHAPING GCC BANKING
As GCC banks accelerate open banking and cloud adoption, the region’s threat landscape is evolving just as quickly. In this interview-led analysis, Premchand Kurup, CEO at Paramount, outlines the...
Table Of Content
- Three forces pushing cybersecurity up the regulatory agenda
- Why behaviour-based analytics is moving from ‘nice-to-have’ to critical
- What Paramount’s SOC is seeing in 2026 so far
- The most common threats: phishing, ransomware, API attacks, and cloud misconfigurations
- What bank leaders should prioritise now
- Why the GCC’s BFSI cybersecurity landscape is different
As GCC banks accelerate open banking and cloud adoption, the region’s threat landscape is evolving just as quickly. In this interview-led analysis, Premchand Kurup, CEO at Paramount, outlines the regulatory pressures, the rise of AI-enabled attacks, and why behaviour-based analytics is becoming essential for BFSI security teams.
Three forces pushing cybersecurity up the regulatory agenda
Kurup says GCC banking regulations are being shaped by a convergence of threats that have become harder to predict and easier to scale—especially with the emergence of AI. At the top of the list are targeted ransomware and data extortion campaigns against banks and fintechs, which have shifted from one-off events to a persistent, systemic risk.
The knock-on effect is tighter supervisory scrutiny. Kurup points to stricter expectations around incident reporting timelines, operational resilience testing, and recovery capabilities—controls that are increasingly embedded into central bank requirements and national cybersecurity frameworks, with more stringent requirements expected through 2026.
A second pressure point is the rapid expansion of open banking and digital transformation initiatives. API security, cloud exposure, and third‑party integrations are creating new attack surfaces—particularly where cloud environments are misconfigured or API authentication is weak. Regulators across the UAE, Saudi Arabia, and the wider GCC are responding by strengthening guidance on identity management, data protection, and third‑party risk management.
The third factor is AI’s dual-use impact. Financial institutions are adopting AI for credit assessment, KYC, and fraud detection, while attackers use AI to scale phishing, social engineering, and evasion. According to Kurup, this is pushing supervisors to treat cyber risk and model risk as connected disciplines—driving new expectations for AI governance, explainability, and monitoring in the financial sector.
Why behaviour-based analytics is moving from ‘nice-to-have’ to critical
While many security teams still rely heavily on static rules and known signatures, Kurup argues that behaviour-based analytics will become one of the Middle East’s most important cybersecurity capabilities over the next few years. Rule-based systems can be effective against traditional threats, but often miss modern attacks that blend into legitimate activity—using lateral movement, living-off-the-land techniques, and sophisticated social engineering.
Behaviour-driven analytics, by contrast, builds dynamic baselines for users, devices, applications, and APIs. By continuously monitoring access patterns, transaction behaviour, and system-to-system communication, it can surface anomalies that signal fraud or intrusion earlier—an advantage that becomes crucial as GCC banks scale cloud adoption, open banking frameworks, and AI use in operations. Kurup notes that many institutions are prioritising these capabilities alongside broader digital trust considerations raised in industry research such as PwC’s “2025 Global Digital Trust Insights – Middle East findings”.
Reflecting this shift, Paramount’s advisory and SOC services are increasingly encouraging a blended approach—combining behavioural analytics with traditional rules and threat intelligence—to improve detection speed and reduce false positives in complex Middle Eastern BFSI environments.
What Paramount’s SOC is seeing in 2026 so far
From the Paramount SOC’s perspective, volume and severity indicators are trending upward. Kurup says that over the last year Paramount issued more than 592 critical advisories—alerts with the potential to significantly halt business operations—and mitigated them. He adds that 2026 has started with nearly 100 advisories already issued, which he says signals a continuing increase in alert activity.
Beyond critical advisories, Kurup notes Paramount issued 318 regular advisories “this year”, compared to 2,208 last year. (For publication, SpacialWire editors may wish to confirm the exact reporting period referenced by “this year” in the interview notes.)
The most common threats: phishing, ransomware, API attacks, and cloud misconfigurations
During FY2024–2025, Kurup says the most frequently detected and addressed issues at Paramount’s SOC include phishing and credential theft leading to account takeover—often using highly localised lures that can be AI-generated. Teams also regularly respond to ransomware and data extortion, alongside attacks on digital banking platforms such as API and web application exploits and DDoS attempts. Cloud misconfigurations and excessive access permissions remain a persistent risk, commonly uncovered through continuous monitoring and threat hunting.
What bank leaders should prioritise now
Kurup’s message to C-suite leaders is to treat cyber resilience as a board-level business capability, not an IT-only function. He recommends embedding cyber risk into enterprise risk management and board reporting, and quantifying scenarios such as prolonged digital-channel outages, data extortion incidents, and systemic third-party failures in line with evolving GCC expectations. Independent maturity assessments can help leadership identify gaps and prioritise investments through 2026.
On execution, Kurup highlights zero trust across identities, devices, networks, and applications—especially in API-enabled and cloud-based banking. He also points to the need for strong SOC and incident response capabilities for 24/7 monitoring and rapid containment, plus documented playbooks that stand up to regulatory review. Just as importantly, he calls for rigorous third-party and supply chain risk management, including due diligence and continuous monitoring of fintech partners, cloud providers, and critical vendors. Finally, leadership-led simulations of ransomware, data leaks, and payment fraud scenarios can strengthen organisational readiness and demonstrate proactive resilience.
Why the GCC’s BFSI cybersecurity landscape is different
Kurup argues that GCC BFSI cybersecurity is uniquely complex because banks are navigating rapid digital transformation in a high-interest threat environment, while also meeting multi-layered regulatory requirements. Institutions often need to comply with national cybersecurity authorities, central banks, and—depending on the operating model—additional regulatory bodies, alongside strict data residency and sovereignty rules that influence cloud and cross-border platform design. Operationally, the region’s fast rollout of mobile, digital, and open banking services expands the attack surface through APIs, cloud services, and fintech partnerships—sometimes faster than ecosystem-wide security maturity. Kurup adds that the Gulf is heavily targeted by financially motivated cybercrime and disruptive attacks, making resilience a strategic priority. In response, Paramount says its approach emphasises region-specific security architectures aligned with local obligations, regional threat intelligence, and the realities of Middle Eastern banking operations



No Comment! Be the first one.