Skip to main content
Sercxi Index · Q2 2026 - Final

Cybersecurity Displacement

GCC · Q2 2026 · Final Assessment

NCA ECC-2:2024 audits now examine who is operating the cybersecurity function - Saudization is the binding constraint. UAE PDPL and DESC layer additional obligations. Bahrain's Cyber Ready Initiative launched in May. FortiBleed exposed a region with heavy FortiGate deployment.

In Saudi Arabia, the audit asks who you hired - not just what you bought.

Method

Final Q2 read grounded in NCA ECC-2:2024 documentation, Saudi Compliance Institute analysis (Jun 2026), Palo Alto Unit 42 IR Report 2026, primary breach disclosures, and Bahrain CBB material. Directional points explicitly flagged.

7 Roles Assessed·🟢 5 Stable🟡 2 Transitioning
🟢
StableRole intact, demand holding
🟡
TransitioningScope shifting materially
🟠
ExposedMandate erosion underway
🔴
DisplacedRole being eliminated

Key Findings

KSA NCA ECC-2:2024 audits now examine who operates the cybersecurity function - Saudization is the binding leadership constraint.

UAE PDPL, CBUAE, ADGM, and DESC create a multi-framework overlay no single regional candidate fully covers.

Bahrain launched Cyber Ready Initiative (May 2026); CBB TRM Module compliance is driving CISO/GRC appointments in financial services.

vCISO model is growing in UAE fintech/mid-market but does not satisfy regulated banks and critical infrastructure.

Saudi-national CISO and Head of GRC candidates represent the acutest supply-demand imbalance in the GCC.

FortiBleed (Jun 2026) created post-incident CISO accountability moments at exposed GCC entities heavy in FortiGate.

Methodology

The Sercxi Displacement Index assesses senior leadership roles against three structural vectors. Each is scored 1–5. The combined profile produces a Displacement Rating.

Elimination Risk(1–5)

The probability that the role is structurally removed from organisational charts within 24 months - not through attrition, but through deliberate elimination driven by automation, managed services, or mandate consolidation.

Redefinition Pressure(1–5)

The degree to which the role's scope, accountability, and required competencies are shifting. A high score indicates the job description is being rewritten faster than most incumbents are adapting.

Creation Signal(1–5)

The strength of net-new demand for the role or its evolved successor. High creation signals indicate structural tailwinds - new regulatory mandates, emerging technology domains, or market gaps creating durable hiring pressure.

Scorecard Overview

RoleEliminationRedefinitionCreationRating
CISO
🟢Stable
Head of SecOps / SOC
🟢Stable
Head of GRC
🟢Stable
Head of AppSec / Product Security
🟡Transitioning
Head of AI Security
🟡Transitioning
Head of Identity
🟢Stable
Head of Cloud Security
🟢Stable

Role-by-Role Analysis

01

Chief Information Security Officer (CISO)

Elimination: 1/5·Redefinition: 3/5·Creation: 5/5
🟢Stable

KSA NCA ECC-2:2024 (updated July 2025) is the baseline cybersecurity standard across Saudi public entities and critical national infrastructure. Q2 2026 audit cycles are active.

NCA ECC audit examines who is operating the cybersecurity function - driving demand for Saudi-national cybersecurity leadership (Saudi Compliance Institute, Jun 2026). Saudization is the binding constraint.

UAE PDPL, CBUAE circulars, ADGM requirements, and DESC standards layer additional compliance obligations. The full-time CISO market rate is estimated at AED 350,000+ for mid-market firms (eShield IT, 2026); vCISO model growing rapidly in the startup and fintech segment.

02

Head of SecOps / SOC

Elimination: 1/5·Redefinition: 3/5·Creation: 4/5
🟢Stable

FortiBleed (22 Jun 2026) exposed GCC enterprises heavily dependent on FortiGate estate; regional SOC leadership demand is spiking.

DESC and NCA both mandate SOC function for critical entities. Palo Alto Networks Unit 42 2026 Global IR Report documents AI-compressed attack lifecycles - the fastest attacks quadrupled exfiltration speed in 2025.

GCC critical infrastructure - energy, banking - is a prioritised target in Unit 42's regional data.

03

Head of GRC

Elimination: 1/5·Redefinition: 3/5·Creation: 5/5
🟢Stable

Multi-framework overlay (NCA ECC, UAE PDPL, CBUAE, ADGM, CBB TRM in Bahrain) requires GRC leaders with cross-jurisdictional GCC fluency - a genuinely rare profile.

Demand is driven by audit cycles, not just strategic intent. The candidate who can credibly span UAE domestic regulation and EU-level frameworks (for entities with EU operations) is extremely rare.

Bahrain's Cyber Ready Initiative (May 2026) and CBB TRM Module add a third regulatory layer at scale.

04

Head of AppSec / Product Security

Elimination: 1/5·Redefinition: 2/5·Creation: 3/5
🟡Transitioning

GCC technology product build remains in early stages; demand is real but concentrated in UAE tech hubs (DIFC, Hub71).

Not yet at EMEA volume. Directional only - no published GCC AppSec vacancy data.

The role will mature once Vision 2030 product organisations begin shipping commercial-grade software at scale.

05

Head of AI Security

Elimination: 1/5·Redefinition: 1/5·Creation: 3/5
🟡Transitioning

UAE AI Strategy and Saudi AI ambitions create genuine demand; candidate supply is near-zero in-region.

Most GCC organisations are at vCISO/advisory stage rather than permanent Head of AI Security. The function is emerging, not yet structurally mandated.

Directional - the role will harden into a permanent hire once GCC AI Act-equivalent guidance is issued.

06

Head of Identity

Elimination: 1/5·Redefinition: 3/5·Creation: 4/5
🟢Stable

Zero Trust mandates under NCA ECC and DESC, combined with large-scale government digital identity programmes (UAE Pass, Saudi National ID integration), are driving Identity Security leadership appointments.

Banks, government, and critical infrastructure are the primary buyers.

Talent supply is thin; vendor displacement from global firms is helping at the margin.

07

Head of Cloud Security

Elimination: 1/5·Redefinition: 3/5·Creation: 4/5
🟢Stable

GCC cloud migration is accelerating (AWS/Azure/Google MEA region expansions); NCA ECC cloud security controls are mandatory for covered entities.

Regional cloud security talent pool is thin but growing via vendor displacement from global firms.

Saudization compliance increasingly constrains who can lead the function for state-adjacent entities.

The Sercxi Read

The GCC corridor is entering a maturation phase characterised by regulatory formalisation rather than the exploratory phase of 2020-2023. NCA ECC-2:2024, UAE PDPL, and the Bahrain Cyber Ready Initiative are not aspirational frameworks - they are audit-cycle realities in Q2 2026. The displacement dynamic is less about CISO burnout (which the IANS/Artico data captures globally) and more about structural underqualification: many entities that now require a formally-credentialed CISO have been operating with an IT Director or vCISO arrangement that will not survive the next NCA or CBUAE audit cycle.

The Saudization dimension is a first-order sourcing parameter, not a secondary checkbox. Saudi-national cybersecurity executives at CISO or Head of GRC level represent the acutest supply-demand imbalance in the entire GCC market. The pipeline from Saudi universities, KACST, and NEOM-adjacent programmes is growing but years from closing the gap. Sercxi's most valuable intervention is identifying Saudi nationals in international roles (London, Amsterdam, Singapore) who have the regulatory fluency and are recruitable back under the right commercial structure.

For UAE and Bahrain, the tactical opportunity is multi-framework GRC. The overlap of PDPL, CBUAE, ADGM, CBB TRM, and - for entities with EU operations - DORA and NIS2 has created demand for a profile that does not have an established talent pipeline.

The audit is not asking what your stack is. It is asking what your passport says.

Your Three Questions

Answer these honestly. No form. No follow-up unless you want one.

1.

Does Sercxi have a mapped pool of Saudi-national cybersecurity executives currently in EMEA or APAC roles who could be recruited into KSA CISO or Head of GRC mandates?

2.

For UAE fintech clients currently on vCISO arrangements - at what regulatory trigger point does Sercxi proactively surface a permanent appointment?

3.

Are GCC clients factoring DORA compliance into CISO briefs where they have EU financial services operations - and is Sercxi positioning this as a differentiating brief qualifier?

Each answer is a quota line - not a discretion line.

Initiate Confidential Briefing →

Save this report

Print-optimized layout for executive distribution.

Q3 2026 · September 2026

Q3 2026 - Post-Audit-Cycle Read

Post-Q3 NCA ECC audit-cycle read, UAE PDPL enforcement update, and updated Saudi-national candidate pool mapping.