Posted inAnalysis

‘Cyber Resilience is now Business Resilience,’ says Mastercard’s Selin Bahadirli

Cyber threats are no longer an IT issue, they are a direct risk to growth, trust and economic continuity.

The rapid expansion of the digital economy is exposing organisations across Eastern Europe, the Middle East and Africa to a broader and more interconnected threat landscape. Mastercard’s inaugural Cyber Pulse Report found that the public sector, technology and finance account for 44% of targeted industries, with malware, ransomware and email-based social engineering among the most common attack methods.

Selin Bahadirli, executive vice president of Services for EEMEA at Mastercard, says businesses must move beyond viewing cybersecurity as a defensive function. As attacks become more targeted and disruptive, resilience increasingly depends on stronger operational preparedness, secure digital infrastructure and closer cooperation between governments, financial institutions and the private sector.


Selin Bahadirli, executive vice president of Services for EEMEA at Mastercard

Mastercard works with businesses, governments and financial institutions across the region to help strengthen cyber resilience. Based on Mastercard’s cybersecurity and intelligence expertise, what are the key trends and emerging threats organisations should be paying attention to today?

The inaugural edition of our Cyber Pulse Report reveals that the rapid expansion of the digital economy has created a vast, highly interconnected threat landscape across Eastern Europe, the Middle East and Africa.

Many organisations have moved quickly to adopt cloud, mobile and digital platforms. In many cases, security practices have not kept pace. The result is a growing attack surface, with familiar weaknesses, misconfigurations, exposed assets and application-level gaps still widespread.

The public sector, technology and finance account for 44% of all targeted industries. Attackers are drawn to these sectors because of their high concentration of monetisable data and critical role in national infrastructure.

Malware, ransomware and email-based social engineering dominate regional threat patterns, indicating that malicious actors favour scale and repeatability over sophistication. Two-thirds of targets are concentrated across three areas: business systems, physical infrastructure and customer information. Attackers aim to disrupt operations and commit fraud.

We are also seeing a clear shift away from high-volume attacks towards more targeted activity. Identity compromise, phishing, malware and lateral movement are being combined more effectively. Activity also tends to spike around geopolitical events, particularly in the early stages of a crisis.

To mitigate cyber risks, organisations must address systemic weaknesses. Application security and web encryption remain the most persistent vulnerabilities, making these entry points critical to business continuity and customer trust.

In a constantly evolving threat environment, every second counts. Proactive cyber intelligence is therefore essential, providing the real-time insights needed to maintain an agile line of defence.

The Cyber Pulse Report highlights a growing link between cyber resilience and economic continuity. How should business leaders rethink cybersecurity as a driver of business resilience and growth, rather than solely a risk management function?

We are no longer dealing with isolated IT challenges. Modern cyber risks threaten the entire commerce ecosystem. Organisations must therefore shift their mindset from perimeter defence to operational survivability. The benchmark of maturity is no longer only preventing an attack, but maintaining continuity during one.

Because a single vulnerability can disrupt entire supply chains, the fallout extends far beyond technical downtime. It threatens consumer trust, brand equity and macroeconomic stability. Secure networks are the bedrock of modern commerce, making robust cyber hygiene a fundamental business imperative.

Leaders must elevate cyber resilience from a technical workstream to a pillar of business resilience. This means addressing foundational vulnerabilities continuously rather than waiting for an audit, while conducting regular, multi-scenario crisis simulations so teams can respond instinctively under pressure.

Enterprises across the region are investing heavily in cybersecurity, but that does not always translate into better outcomes. Technology matters, but people, skills and operational discipline are equally important. Resources must be distributed across advanced systems, ongoing talent development and clear governance frameworks.

By embedding cybersecurity into organisational culture, enterprises do not just protect current assets; they create the foundation for long-term industry leadership.

As organisations continue to accelerate their digital transformation efforts, how can they strike the right balance between innovation, security and customer trust?

True business resilience lies in building a culture where security and innovation coexist. By integrating robust cyber health into their operations, organisations can create the trust needed to support secure growth.

When emerging technologies are introduced, their market viability depends on user confidence. Without that assurance, even groundbreaking digital solutions can fail to gain meaningful adoption. By viewing security as an enabling capability rather than a restrictive gatekeeper, organisations can turn ideas into widely adopted products and services.

This requires embedding security into the architecture of every new initiative from the outset. Businesses must establish continuous monitoring and adaptive protocols that shift the focus from reactive incident response to proactive threat mitigation. This allows them to scale digital offerings without exposing themselves to potentially catastrophic vulnerabilities.

A holistic approach to digital infrastructure also helps bridge the gap between technical teams and executive leadership. When risk mitigation is treated as a core business driver, compliance can become a competitive advantage rather than an administrative burden.

Organisations can then pursue ambitious digital strategies, explore transformative technologies and integrate third-party systems, knowing their operational framework is well protected.

Cyber threats are increasingly crossing sectors, industries and borders. How important is collaboration between the public and private sectors in strengthening cyber resilience, and what more can be done to improve intelligence-sharing and collective preparedness across the region?

No single organisation can face today’s cyber risks alone, which makes collaboration essential. At Mastercard, we are committed to serving as a trusted cybersecurity and threat intelligence partner. Since 2019, we have invested more than $12.6 billion in cybersecurity innovation.

Our global network of cyber resilience centres, spanning four continents, helps stakeholders understand, share and manage cyber risk together. These initiatives bring together the public and private sectors to strengthen defences, accelerate response times and serve as focal points for cybersecurity thought leadership.

Financial institutions, government entities and businesses can benefit from collective threat intelligence, learn from each other’s experience in managing incidents and continuously monitor their risk posture.

The centres also deepen collaboration among chief information security officers, senior business leaders and cybersecurity teams through dedicated C-suite briefings and events focused on securing the commerce and payments ecosystem. They help partners anticipate emerging threats and improve preparedness through continuous risk monitoring and scenario-based exercises.

The centres are designed to evolve over time, expanding their capabilities in line with changing market needs.

In the EEMEA region, our Cyber Resilience Center in Riyadh marked its first anniversary this May. We have also partnered with Azerbaijan’s Innovation and Digital Development Agency to strengthen the Azerbaijan Cybersecurity Center through a regional programme focused on resilience, skills development and cross-institutional collaboration.

We also recently launched our Africa Cybersecurity Center of Excellence as part of our continued investment in the continent’s digital future. Together with our partners, we are building long-term cyber resilience that supports secure growth for all.