This September, ahead of Cybersecurity Awareness Month, we spoke with Ashish Kamdar, Director in Risk Advisory Services at BDO Oman, who advises organisations on risk management, internal audit, corporate governance, IT risk and internal controls, about the cyber and operational risks organisations should be preparing for, the growing impact of AI-enabled threats and why strong governance, risk awareness and organisational resilience remain critical in an increasingly digital business environment.
Ashish Kamdar is a Director in Risk Advisory Services with over 21 years of experience in internal audit, risk management, investigations, IT audits and corporate governance. A Chartered Accountant and Certified Information Systems Auditor (CISA), he has delivered risk-based internal audits and advisory assignments. His expertise spans ERM and risk assessments, internal audit, IT general controls, corporate governance, investigations, ICFR reviews and anti-bribery and corruption audits, alongside SOX compliance audits and the development of process frameworks, training programmes and management reporting.
What cyber risks should Omani organisations prepare for by 2027?
One of the biggest risks is the growing sophistication of AI-enabled cyberattacks. We're already seeing how AI can make phishing, impersonation and social engineering far more convincing. Emails, voice calls and even video interactions can potentially be created to impersonate senior management, employees, customers or vendors. That makes the human element an even bigger risk, particularly for sectors such as banking, oil and gas, utilities, telecommunications and government entities.
“Organisations need to look beyond traditional controls. Greater focus is required on identity and access management, multi-factor authentication, privileged access, employee awareness and continuous monitoring of unusual activity. Regular cyber incident simulations should also become part of standard preparedness. Going into 2027, the key question shouldn't only be whether an organisation can prevent an attack, but how quickly it can identify, contain and recover from one when it happens,” – mentions Ashish Kamdar.
What's the biggest cybersecurity myth?
That cybersecurity is primarily the IT department's responsibility. Organisations may have firewalls, antivirus solutions and access controls in place, but cyber risk extends well beyond IT. Many incidents originate from simple human actions: clicking a malicious link, sharing credentials, approving an unusual request, using a weak password, or being fooled by someone impersonating a trusted contact.
“Cybersecurity needs to be treated as an organisation-wide responsibility. Management has to set the right tone from the top, employees need to understand the risks relevant to their roles and functions such as HR, Finance, Procurement and Operations need controls embedded in their own processes. A related misconception is assuming that having policies and systems in place means an organisation is adequately protected. What matters just as much is whether those controls actually work in practice and are regularly tested. Cybersecurity isn't just an IT issue, it's a business risk that needs continuous attention across the organisation,” – says Ashish Kamdar.
Where should organisations start with cyber resilience?
In my view, it's people. Organisations can invest heavily in tools and technology, but even the strongest systems can be undone by a simple human error. Phishing, credential theft, social engineering and increasingly sophisticated AI-based impersonation continue to target employees because they're often the easiest way in.
That has to go beyond annual awareness training. Employees should regularly be exposed to practical scenarios, phishing simulations and examples of emerging threats relevant to their roles, with particular attention to staff handling sensitive information, payments or system administration. Organisations also need to build a culture where employees feel comfortable reporting suspicious activity, or even their own mistakes, quickly and without hesitation. Well-informed, alert employees can often spot something unusual before a system does, which makes building that awareness one of the most practical starting points for improving resilience.
How is AI changing cybersecurity?
AI is changing the landscape in two very different ways. It's making cyberattacks more sophisticated, but it's also giving organisations better tools to identify and respond to them. From a risk perspective, AI has made it far easier for attackers to create convincing phishing emails, fake identities, voice clones and deepfake videos. What might once have been relatively easy for an employee to spot as suspicious can now look and sound extremely genuine and AI lets attackers automate activity and scale attacks well beyond what was possible before.
On the other hand, organisations can use AI to continuously monitor large volumes of activity, identify unusual patterns and detect potential threats much faster than traditional methods allow. So AI shouldn't be viewed only as a threat. The real challenge is how effectively organisations use AI themselves while putting the right controls around it. I expect cybersecurity will increasingly become a contest where both the attacker and the organisation are using AI and the better-prepared side will have the advantage.
Ashish Kamdar is a Director in Risk Advisory Services with over 21 years of experience in internal audit, risk management, investigations, IT audits and corporate governance. A Chartered Accountant and Certified Information Systems Auditor (CISA), he has delivered risk-based internal audits and advisory assignments. His expertise spans ERM and risk assessments, internal audit, IT general controls, corporate governance, investigations, ICFR reviews and anti-bribery and corruption audits, alongside SOX compliance audits and the development of process frameworks, training programmes and management reporting.
What cyber risks should Omani organisations prepare for by 2027?
One of the biggest risks is the growing sophistication of AI-enabled cyberattacks. We're already seeing how AI can make phishing, impersonation and social engineering far more convincing. Emails, voice calls and even video interactions can potentially be created to impersonate senior management, employees, customers or vendors. That makes the human element an even bigger risk, particularly for sectors such as banking, oil and gas, utilities, telecommunications and government entities.
“Organisations need to look beyond traditional controls. Greater focus is required on identity and access management, multi-factor authentication, privileged access, employee awareness and continuous monitoring of unusual activity. Regular cyber incident simulations should also become part of standard preparedness. Going into 2027, the key question shouldn't only be whether an organisation can prevent an attack, but how quickly it can identify, contain and recover from one when it happens,” – mentions Ashish Kamdar.
What's the biggest cybersecurity myth?
That cybersecurity is primarily the IT department's responsibility. Organisations may have firewalls, antivirus solutions and access controls in place, but cyber risk extends well beyond IT. Many incidents originate from simple human actions: clicking a malicious link, sharing credentials, approving an unusual request, using a weak password, or being fooled by someone impersonating a trusted contact.
“Cybersecurity needs to be treated as an organisation-wide responsibility. Management has to set the right tone from the top, employees need to understand the risks relevant to their roles and functions such as HR, Finance, Procurement and Operations need controls embedded in their own processes. A related misconception is assuming that having policies and systems in place means an organisation is adequately protected. What matters just as much is whether those controls actually work in practice and are regularly tested. Cybersecurity isn't just an IT issue, it's a business risk that needs continuous attention across the organisation,” – says Ashish Kamdar.
Where should organisations start with cyber resilience?
In my view, it's people. Organisations can invest heavily in tools and technology, but even the strongest systems can be undone by a simple human error. Phishing, credential theft, social engineering and increasingly sophisticated AI-based impersonation continue to target employees because they're often the easiest way in.
That has to go beyond annual awareness training. Employees should regularly be exposed to practical scenarios, phishing simulations and examples of emerging threats relevant to their roles, with particular attention to staff handling sensitive information, payments or system administration. Organisations also need to build a culture where employees feel comfortable reporting suspicious activity, or even their own mistakes, quickly and without hesitation. Well-informed, alert employees can often spot something unusual before a system does, which makes building that awareness one of the most practical starting points for improving resilience.
How is AI changing cybersecurity?
AI is changing the landscape in two very different ways. It's making cyberattacks more sophisticated, but it's also giving organisations better tools to identify and respond to them. From a risk perspective, AI has made it far easier for attackers to create convincing phishing emails, fake identities, voice clones and deepfake videos. What might once have been relatively easy for an employee to spot as suspicious can now look and sound extremely genuine and AI lets attackers automate activity and scale attacks well beyond what was possible before.
On the other hand, organisations can use AI to continuously monitor large volumes of activity, identify unusual patterns and detect potential threats much faster than traditional methods allow. So AI shouldn't be viewed only as a threat. The real challenge is how effectively organisations use AI themselves while putting the right controls around it. I expect cybersecurity will increasingly become a contest where both the attacker and the organisation are using AI and the better-prepared side will have the advantage.
