
In this exclusive interaction with The Catalyst, Ziad Nasr, General Manager, Acronis, Middle East, shares insights into the company’s growth strategy, the region’s Zero Trust adoption, and how resilience-driven security is shaping enterprise roadmaps.
You have led Acronis Middle East through a transformative journey marked by exponential growth. What were the key strategic decisions that enabled this success?
Our focus has been simplification, scale, and sovereignty. We have invested in local infrastructure to ensure data residency and performance and have also aligned our platform with global and regional compliance frameworks so partners can deliver security without added complexity. Another key focus has been to build a strong partner ecosystem, enabling MSPs to expand services like disaster recovery, without needing heavy in-house resources.
Zero Trust has become a buzzword in cybersecurity, how do you see it being implemented realistically in Middle Eastern enterprises?
Zero Trust is most effective when adopted gradually. In the Middle East, many enterprises are starting with identity and access controls, enforcing MFA, conditional access, and least privilege. From there, they extend into workload segmentation and continuous monitoring. MSPs are guiding customers through this journey using maturity models and platform-based services. For many organizations, it’s about reducing risk step by step without overextending budgets, while ensuring compliance with emerging regulatory frameworks.
Data protection and compliance are becoming top priorities. How does Acronis ensure its solutions align with regional regulatory frameworks?
Compliance is deeply tied to resilience. In March 2025, for example, the UAE saw a sharp spike in malware activity linked to new Comprehensive Economic Partnership Agreements (CEPAs), which expanded cross-border digital flows and introduced supply-chain risks. Our solutions map natively to frameworks like NIST and CIS, but we also support regional requirements. Features like immutable storage, secure patching, and detailed logging make it easier for enterprises to demonstrate compliance while keeping operations running even when threat levels rise.
Ransomware remains a top concern worldwide. How prepared are Middle Eastern enterprises, and what gaps do you see in their defence strategies?
The UAE recorded just 3 ransomware detections per 10,000 workloads in the first half of 2025, one of the lowest figures globally according to the Acronis Cyberthreats Report H1 2025. On the surface this is encouraging, but it doesn’t mean enterprises are not being targeted. These low rates often reflect stronger preventive defenses, with attacks being blocked before encryption attempts occur. The real gap is visibility into stealthier tactics like credential abuse and supply-chain compromises, which are harder to measure. Enterprises must continue investing in layered defenses, immutable backup, and geo-redundant disaster recovery to avoid a false sense of security.
Discuss the role of cyber resilience (not just prevention) shaping enterprise security roadmaps in the region?
Resilience has become the defining theme. In the UAE, 10.9% of all globally blocked malicious URLs in 2025 were recorded, a reminder that phishing and fraud campaigns remain constant. No preventive control is perfect, which is why resilience planning is critical. Our approach combines real-time prevention with recovery capabilities such as immutable backups, automated restoration, and cross-border disaster recovery. Enterprises are increasingly looking for security strategies that assume breaches will happen and focus on fast restoration of operations with minimal disruption.
How do international partnerships help strengthen the region’s cybersecurity posture?
International partnerships bring global capabilities into the local market without compromising sovereignty. Access to global threat intelligence and AI-powered defenses allows partners in the Middle East to anticipate and block advanced threats more effectively. At the same time, enablement programs and certifications raise the skills of local teams, ensuring service providers meet international standards while staying aligned with regional regulations. Finally, partnerships expand resilience: co-managed service models and geo-redundant disaster recovery options help enterprises maintain continuity even under regional disruptions. This combination of intelligence, skills, and resilience is what ultimately strengthens the region’s cybersecurity posture.
As the Middle East continues its rapid digital transformation, cybersecurity strategies are evolving from prevention-focused models to resilience-driven architectures. Organizations are recognizing that agility, compliance, and intelligent defense must work in tandem to counter increasingly sophisticated threats. With stronger partner ecosystems, local infrastructure, and global intelligence, enterprises are better equipped to protect critical assets while ensuring operational continuity. This shift toward integrated, adaptive security is setting the foundation for a more secure and resilient digital future across the region.
All Content Rights Reserved by The Catalyst.








