Sept. 3, 2026 · Prof. Dr. Mohammed Abdur Rahman
At LEAP 2026 in Riyadh, Prof. Dr. Mohammed Abdur Rahman delivered a 20-minute live case study on the Cyber–Orbital Stage, asking one question: is the surface you defend the surface that actually exists?
For most enterprises the honest answer is no. The inventory might list 180 assets while the internet shows 234 — and the gap is where breaches begin: forgotten subdomains and dev servers, shadow AI APIs, AI SaaS with standing credentials, unreviewed vendor trust, and now the newest entry point of all, the organisation’s own AI applications.
1. Attack Surface Animation — from the tidy inventory to what an attacker really finds, and a five-hop breach chain that ends at the crown jewels.
2. Attack ↔ Defence Simulation — the same graph played twice. First as the attacker: recon, shadow API, leaked token, AI-agent pivot, customer data, with zero alerts. Then as the defender: discover outside-in, attribute, assess, prioritise and remediate — and the chain dies at hop one.
Why it matters for every enterprise deploying AI: an AI assistant is not a chatbot, it is an identity with tools. Give it a database connector, an MCP tool layer and an over-scoped token, and the attack surface extends all the way to the data it can reach. In the demo, the pivot that reached customer records was not a zero-day — it was an AI agent doing exactly what it was allowed to do, for the wrong principal. The first lesson: discover outside-in — start from the internet, not the CMDB.