Presented byRegister now

Advertise with us

Waves&Tech

Mastercard's Cyber Resilience Center: One Year On in Saudi Arabia

Adam Jones on what the Riyadh center has revealed about the Kingdom's digital trust and security readiness.

Karim El-Sayed·26 Aug 2026·2 min read
Mastercard's Cyber Resilience Center: One Year On in Saudi Arabia

When Mastercard opened its Cyber Resilience Center in Riyadh in May 2025, the goal was to replace isolated security postures with a shared defense for Saudi Arabia's financial ecosystem. The center brings banks, regulators, and other players together to pool intelligence, train, and apply global standards to a payments landscape expanding under Vision 2030. One year on, Adam Jones, Mastercard's EVP and Division President for West Arabia, says the initiative has exposed both progress and a bottleneck.

What has changed

Digital growth in the Kingdom has attracted more threat activity. Jones says customers have shifted focus toward detection and monitoring, particularly for third-party connections. Twenty years ago, organizations operated largely alone. Today they sit inside hyperconnected ecosystems, where collaboration determines whether an alert becomes a response.

Mastercard's acquisition of Recorded Future in December 2024 strengthened the intelligence side. Customers get help at three levels: strategy, where leadership anticipates risks; technical operations, where exposed credentials, dark-web activity, and dangerous infrastructure are flagged; and governance, where intelligence drives priorities and decisions.

The center has seen results. Simulated attacks built from real intelligence show early indicators like identity misuse and unusual access patterns from third-party integrations. Teams that acted quickly blocked the attack before reaching critical systems. In live cases, Mastercard identified phishing campaigns through lookalike domains and malicious infrastructure, giving customers time to take down domains and update controls.

Where it stalls

The clearest gain over the past year is speed from alert to decision. Decisions that once required multiple loops between technical teams and management now happen earlier in the incident window, with legal and compliance brought in sooner. Exposure time drops, and containment is cleaner.

But crisis simulations keep revealing a problem: breakdowns at the decision and coordination layer, not the tooling layer. Technical teams often detect signals early. The hard part is aligning the right people quickly enough to decide on containment, communications, regulatory handling, and business impact. That is the gap the center exists to close.

Collaboration and AI

Public-private cooperation in the Kingdom is mature by regional standards. The regulatory framework is clear, and institutions know resilience is not optional. The opportunity is operational: faster sharing of indicators, quicker translation of intelligence into action, and stronger alignment between regulation, response, and third-party oversight.

Banks report incidents to the regulator under a defined rulebook, including immediate reporting for certain cases. Simulations show they are aware of the duty. The challenge is internal speed—assessing, validating, and escalating information fast enough.

Attackers are moving quickly with AI, especially in phishing, social engineering, and content generation. Mastercard's 2025 cybersecurity survey found rising concern about AI-generated scams, voice cloning, and deepfakes. Recorded Future's research points to infostealers, identity compromise, and early malware using AI after a breach. Defenders are adopting AI too, for analytics, prioritization, and automation. The center's model is meant to stay ahead of that shift.

Jones sees progress on both understanding and limiting attacks. Intelligence and telemetry are far better. So is containment, though stopping every attack remains unrealistic. Attackers only need to be right once. Defenders must be right every day across people, process, and technology. Saudi institutions are investing in identification, protection, detection, response, and recovery. The Cyber Resilience Center is there to push them from awareness to action.