One Year On: Adam Jones, EVP, Division President of West Arabia at Mastercard, On What The Cyber Resilience Center Has Revealed About Digital Trust In The Kingdom

“We launched the Cyber Resilience Center to support exactly that effort: helping institutions move from awareness to action, and from detection to resilience,” Adam Jones explains.

You're reading Entrepreneur Middle East, an international franchise of Entrepreneur Media.

Mastercard
Adam Jones is the EVP, Division President of West Arabia at Mastercard.

When Mastercard launched its Cyber Resilience Center in Riyadh in May 2025, it marked more than a new facility- it signaled a shift in how Saudi Arabia’s financial sector would approach digital security, moving from isolated defenses to a shared, collaborative front against cyber threats.

The center was built to bring banks, regulators, and other key players from the Kingdom’s financial ecosystem together under one roof, pooling intelligence, training, and global standards to safeguard a commerce and payments landscape that has been expanding at record pace under Vision 2030.

A year in, we sit down with Adam Jones, Executive Vice President, Division President of West Arabia, Mastercard, for a Q&A interview to find out what the center has revealed about how Saudi institutions respond under pressure, how the line between cybersecurity and fraud prevention is blurring, and what comes next as AI reshapes the region’s payments infrastructure.

One year after the launch of the Cyber Resilience Center, what has actually changed on the ground in Saudi Arabia’s cybersecurity landscape?

Saudi Arabia is experiencing rapid growth in the digital sector, which naturally draws increased cyber threat activity. Our interactions with customers have revealed a strong focus on detection and monitoring, particularly regarding third-party connections. This emphasis is understandable, as organizations are now significantly more interconnected compared to 20 years ago, when they largely operated independently. The current hyperconnected environment forms an ecosystem in which communication and collaboration are more critical than ever. This trend represents a major shift in the market. Additionally, the intelligence surrounding cyber threats has become a prominent topic, equipping industry leaders with relevant insights to remain informed about the prevailing cyber risks specific to the region and sector.

How does the threat intelligence and cyber insight produced by the Cyber Resilience Center help organizations prevent, detect, and respond to attacks more effectively?

With this information, organizations can gauge which threats are most likely to affect them. It’s like being aware of potential dangers in your neighborhood so you can better protect your home.

At Mastercard, we acquired Recorded Future in December 2024 to boost our capabilities across threat intelligence, AI-driven analytics, fraud prevention, identity management, and operational resilience. This move benefits customers on three fronts: at the strategic level, it helps leadership anticipate evolving risks; at the technical level, it highlights issues such as exposed credentials, activity on the dark web, dangerous infrastructure, and risks from third parties; and at the organizational level, it supports connecting intelligence with governance, setting priorities, and making response decisions.

Can you share an example where intelligence or preparedness work from the Cyber Resilience Center helped an organization anticipate a threat or strengthen its readiness before impact occurred?

In one of the scenarios we built based on real threat intelligence, early indicators, such as identity misuse and unusual access patterns from third-party integrations, were detected. In cases where teams acted quickly, the attack path was effectively cut before reaching critical systems.

Beyond simulations, our intelligence, especially through Recorded Future and broader strategic insights, supports customers on a daily basis in anticipating and stopping potential threats.

For example, we identified phishing campaigns targeting organizations by detecting lookalike domains and malicious infrastructure at an early stage. Using our intelligence, we provided advance warning before the campaigns scaled. This enabled security teams to take proactive actions, such as domain takedowns, customer notifications, and updating detection controls, ultimately disrupting the campaigns and reducing potential impact, while execution remained within each organization’s internal operations.

What we can validate through the Cyber Resilience Center is how effectively organizations respond in such scenarios. Through our cyber crisis simulations, we test whether early indicators actually lead to timely decisions and containment, which determines whether an attack is stopped or escalates. So, the Cyber Resilience Center contributes to prevention, detection, and response readiness. 

How does the Cyber Resilience Center define success in terms of improving customer readiness, decision-making, and resilience outcomes?

The Cyber Resilience Center is designed to strengthen the overall cyber posture of the ecosystem through targeted initiatives, including simulations, security assessments, and awareness programs. Executed in close collaboration with banks and leading institutions across the Kingdom, this approach ensures a coordinated and scalable impact rather than isolated interventions.

Collectively, these efforts enhance decision-making capabilities and foster a more resilient workforce that is less susceptible to social engineering attacks. Partnerships focused on improving third-party risk visibility are particularly instrumental in advancing a secure and resilient digital ecosystem. While some initiatives deliver immediate impact, others mature over time, progressively reinforcing the ecosystem’s foundational resilience.

What has improved over the past 12 months and by roughly how much?

What has improved most is the speed from alert to decision. That matters because during a live incident, delay gives an attacker more time for lateral movement, privilege escalation, persistence, and data staging. From what we observed in Saudi Arabia and across the region, the improvement is clearly material, even though it doesn’t lend itself to a single, uniform percentage across the market. 

The practical change is this: Decisions that previously took too many loops between technical teams and management are expected to happen earlier in the same incident window, with legal and compliance brought in sooner where needed. The benefits include reduced exposure time, cleaner containment, and less chance that a manageable event becomes a full crisis. 

RELATED: IBM’s Jonathan Adashek on Saudi Arabia’s AI Ambitions and the Rise of Digital Sovereignty

Once intelligence is shared, how do organizations typically operationalize it, and where does the Cyber Resilience Center help accelerate that process?

Responsibility sits with the institution – usually the security operations center (SOC), cyber defense, IT, fraud, risk, legal, compliance, and management, depending on the nature of the issue. What the Cyber Resilience Center is trying to address is the gap between “we know” and “we act”. That is exactly why its scope is broader than reports alone. Threat index reporting shows what is changing in the environment.

Threat-casting helps institutions think ahead. Knowledge-sharing raises awareness across technical and non-technical stakeholders. Crisis simulations test the real decision path. Third-party risk work enables organizations to identify exposures outside the perimeter. Risk assessments assist in prioritizing controls and remediation. When these pieces come together, intelligence is more likely to trigger action quickly enough. 

Where does the process typically break down — decision-making, coordination, or technical execution?

Most often, it breaks down at the decision and coordination layer, not at the tooling layer. In our cyber crisis simulation exercises we held for our customers in the Kingdom, the technical teams were often able to detect signals early. The bigger issue was whether the right people were aligned quickly enough to decide on containment, communications, regulatory handling, and business impact. 

This is precisely where the Cyber Resilience Center adds value to the Saudi market. It is not there only to talk about threats in theory. It is there to help institutions pressure-test their operating model, validate whether governance works under stress, improve third-party and ecosystem awareness, and make cyber intelligence usable at the executive and operational levels. That is how the market matures. 

In practice, how effective is collaboration between the public and private sectors?

In the Kingdom, collaboration is relatively mature by regional standards, especially in the financial sector. The regulatory framework is clear, the expectations are understood, and institutions know cyber resilience is not optional. The opportunity now is less about creating collaboration from zero and more about making it operational: faster sharing of relevant indicators, quicker translation of intelligence into action, and stronger alignment between regulation, operational response, third-party oversight, and sector-wide preparedness. That is also where a center like ours fits well: It helps convert strategic collaboration into practical readiness through reporting, threat-casting, exercises, and assessments. 

Are organizations still reluctant to share breach data, and what’s holding them back?

In the Saudi financial sector, banks do report cyber incidents and breaches to the regulator as per the cybersecurity framework and incident management rulebook, including immediate reporting for certain incidents. In our cyber crisis simulation exercises, we also saw that banks were very aware of this, and legal and compliance stakeholders were brought in where necessary. The more practical challenge is ensuring that institutions assess, validate, and escalate information fast enough internally so the reporting and response process is timely and effective. 

Are attackers moving faster than institutions in adopting AI, and what new types of threats are you seeing?

Attackers are moving fast with AI, especially in phishing, social engineering, and content generation. We are seeing more realistic lures, more scalable fraud attempts, and more pressure on identity as the main control plane. Our 2025 cybersecurity survey highlighted growing concern around AI-generated scams, voice cloning, and deepfakes, while Recorded Future’s research has also pointed to the expanding role of infostealers, identity compromise, and even early cases of malware using AI during post-compromise activity. At the same time, defenders are also adopting AI for analytics, prioritization, and automation. This is exactly why the Cyber Resilience Center matters: not just to identify current threats but to help institutions prepare for where threats are going next through threat intelligence, forward-looking threat-casting, knowledge-sharing, third-party monitoring, and resilience testing. The Cyber Resilience Center model is future-aware rather than static. 

Realistically, are we getting better at understanding cyber threats or actually stopping them?

Both, but in different ways. We are definitely getting better at understanding threats because intelligence, telemetry, and sector-wide awareness are improving. We are also getting better at limiting impact, even if it is unrealistic to claim we will stop every attack. 

The reality is that attackers only need to be right once, while defenders need to be right every day across people, process, and technology. That makes the defender’s job harder. Still, Saudi financial institutions, and the sector more broadly, are clearly investing in stronger identification, protection, detection, response, and recovery. 

We launched the Cyber Resilience Center to support exactly that effort: helping institutions move from awareness to action, and from detection to resilience. 

RELATED: The 100 NRIs – 2026: Prakriti Singh, Executive Vice President – Core Payments, Mastercard (EEMEA)

Mastercard
Adam Jones is the EVP, Division President of West Arabia at Mastercard.

When Mastercard launched its Cyber Resilience Center in Riyadh in May 2025, it marked more than a new facility- it signaled a shift in how Saudi Arabia’s financial sector would approach digital security, moving from isolated defenses to a shared, collaborative front against cyber threats.

The center was built to bring banks, regulators, and other key players from the Kingdom’s financial ecosystem together under one roof, pooling intelligence, training, and global standards to safeguard a commerce and payments landscape that has been expanding at record pace under Vision 2030.

A year in, we sit down with Adam Jones, Executive Vice President, Division President of West Arabia, Mastercard, for a Q&A interview to find out what the center has revealed about how Saudi institutions respond under pressure, how the line between cybersecurity and fraud prevention is blurring, and what comes next as AI reshapes the region’s payments infrastructure.

One year after the launch of the Cyber Resilience Center, what has actually changed on the ground in Saudi Arabia’s cybersecurity landscape?

Saudi Arabia is experiencing rapid growth in the digital sector, which naturally draws increased cyber threat activity. Our interactions with customers have revealed a strong focus on detection and monitoring, particularly regarding third-party connections. This emphasis is understandable, as organizations are now significantly more interconnected compared to 20 years ago, when they largely operated independently. The current hyperconnected environment forms an ecosystem in which communication and collaboration are more critical than ever. This trend represents a major shift in the market. Additionally, the intelligence surrounding cyber threats has become a prominent topic, equipping industry leaders with relevant insights to remain informed about the prevailing cyber risks specific to the region and sector.

Related Content