Cybersecurity defenses that operate as isolated functions can leave organizations with costly blind spots even as spending on security tools, personnel and monitoring increases, according to Tariq Alharbi, vice president of cybersecurity managed services at Saudi Information Technology Company (SITE). He observed that organizations often have security operations centers, incident response teams and threat intelligence capabilities that fail to operate as a single, integrated defense ecosystem, creating complexity that can undermine visibility and response.
The fragmented approach is becoming more costly as cyberattacks accelerate, Alharbi said, citing CrowdStrike’s 2026 Global Threat Report, which found attacks surged 89% in 2025 while average breakout time fell to 29 minutes, 295% faster than in 2024.
“This is largely because artificial intelligence (AI) has become a force multiplier, accelerating both adversary and defensive operations alike,” Alharbi wrote in a Tuesday World Economic Forum (WEF) story. “But attackers are moving particularly fast, using generative and agentic AI to scale phishing campaigns, accelerate malware development, automate reconnaissance and create highly convincing social engineering content that is increasingly difficult to distinguish from legitimate communications.”
He added that the resulting threat landscape is larger, faster and more interconnected than ever before. Fragmented security defences will struggle to keep up with adversaries operating within these coordinated cybercrime networks.
Alharbi recognized that organizations can invest heavily in people, platforms and monitoring dashboards, but still lack the coordinated visibility required to detect and respond to a real intrusion. In fact, he noted that this false sense of security arising from tool proliferation may be one of the most expensive assumptions in cybersecurity today.
Citing IBM’s 2025 Cost of a Data Breach Report, Alharbi said that it found breaches involving data spread across multiple environments cost an average of $5.05 million and took 276 days to identify and contain. Alharbi recommended maintaining a current inventory of assets and dependencies, classifying assets according to business importance, continuously assessing vulnerabilities and unifying detection, response and recovery functions.
“Breaches involving data spread across multiple environments cost an average of $5.05 million and take 276 days to identify and contain, the IBM report shows,” Alharbi detailed. “This window is long enough to compound operational disruption, deepen regulatory exposure and inflict lasting reputational damage on the organization.”
He pointed out that effective cybersecurity requires two disciplines – grounding the defense through complete asset visibility, classification, and continuous assessment, and sustaining it by treating the organization as a unified system. The first involves identifying assets, classifying by criticality, evaluating security posture, and remediating vulnerabilities before exploitation, while the second demands integrated threat intelligence, unified incident response across teams, and threat models that evolve as rapidly as adversaries do.
Organizations must know what assets they have, how critical each asset is to the business, and whether they are actually secure before implementing any defense strategy. This begins by building a complete, current inventory of assets and dependencies across the environment, since what cannot be seen cannot be defended.
Assets must then be classified to determine which ones underpin critical business services, as a payment gateway and a printer are not at the same risk level, and treating them as equivalent creates blind spots. The current architecture, vulnerability exposure, and patching configuration of each asset must be continuously evaluated against its importance, and given that the median time from vulnerability disclosure to active exploitation has collapsed to days, this cannot be a point-in-time exercise. Finally, identified gaps must be closed with solutions that will hold, rather than assuming a patch deployed represents a risk resolved.
Lasting resilience comes from treating the organization as one connected system instead of a patchwork of tools, processes, and teams. This requires extending intelligence beyond the perimeter by combining integrated visibility across the internal defense stack with participation in broader intelligence-sharing ecosystems, which enables organizations to identify cross-sector attack patterns before related activity reaches them rather than after.
It also demands unifying detection, response, and recovery functions so that SOC, incident response, and threat intelligence operate as a single connected system instead of three separate functions checking three different dashboards and working to three different timelines; fragmentation at this layer turns a contained incident into a prolonged breach. Finally, threat models must evolve continuously, as static defense models age out quickly against adversaries that can act in minutes, requiring organizations to keep pace with evolving threat complexity.
In conclusion, Alharbi wrote that building comprehensive detection, response and intelligence capabilities in-house requires sustained investment in talent, technology and round-the-clock operations.
“Organizations should assess whether they can build these capabilities internally or if they should rely on a trusted partner to close the gap,” he added. “Partnering with a trusted cybersecurity provider can transform security from a collection of standalone capabilities into an integrated, intelligence-led defence. This will strengthen resilience, accelerate threat detection and response, and reduce operational complexity. Organizations can then focus on their core business and strategic priorities.”
Alharbi’s post comes as industrial organizations are embracing AI for OT (operational technology) cybersecurity, although most deployments remain limited in scope and governance has yet to keep pace, according to July findings from a survey developed by Takepoint Research. Nozomi Networks and BlastWave. Based on 302 responses collected between April and July, the ‘State of AI in OT Cybersecurity 2026’ industry survey found that 87.7% of respondents are already using, evaluating, piloting, or planning AI for OT cybersecurity. However, only 7.9% reported deploying AI across multiple OT cybersecurity functions, indicating that enterprise-wide operational adoption remains in its early stages.


