Maman Ibrahim's avatarPerson

Maman Ibrahim

FounderGinkgo Resilience LTD

London, UK

Skills

Coaching
Information Security
Risk Management

About

Maman Ibrahim is a seasoned executive with more than 20 years of international experience in cyber and digital risk and assurance, spanning highly regulated industries such as pharmaceuticals, manufacturing and financial services. He has led cybersecurity governance, risk and compliance strategies at the global level, working with organizations to embed cyber resilience at the heart of their operations. Throughout his career, he has helped business and security leaders turn complex regulatory requirements into practical, value-driven strategies that enhance trust, strengthen operational resilience and accelerate secure digital transformation. A trusted advisor to boards and executive teams, Maman is known for his practical insight, leadership in building high-performing security cultures and passion for translating cyber risk into business opportunity.

Published content

Shadow AI Is Expanding Your Attack Surface; Here’s What to Do

expert panel

NIST emphasizes that effective AI risk management depends on organizations being able to govern, map, measure and manage how AI systems are used. However, following that guidance is becoming increasingly complicated.Artificial intelligence is moving into everyday business operations faster than many organizations’ security and governance processes can keep up. Employees and business teams can now build workflows around large language models, add AI copilots to existing tools, and connect agents to company systems without the kind of formal deployment process that traditionally gives security teams visibility into new technology. As AI moves from standalone experimentation into copilots, connected workflows and increasingly autonomous agents, security teams may have less visibility into where it’s being used, what data it can reach and what actions it’s authorized to take. The result is a widening gap between the AI environment an organization believes it is governing and the one actually taking shape across the business.It’s essential for security leaders to gain visibility into the web of AI systems being built across their organizations—and the ever-expanding attack surface that comes with it. Below, members of the Senior Executive Cybersecurity Think Tank—with expertise spanning enterprise cybersecurity strategy, breach prevention, risk management and cybersecurity leadership—explain how security leaders can get ahead of business-led AI deployments and recognize when unmanaged AI risk is already beginning to compound.

From Siloed Alerts to Unified Action: Moving Beyond Detection-Centric Cybersecurity

expert panel

An attacker who gains access through a stolen credential may quickly move across devices, cloud resources and network systems in search of valuable data or greater control. Each step can generate clues, but when those signals land in separate tools and queues, security teams may struggle to recognize the full attack before the damage spreads.This challenge is becoming harder to tackle as traditional boundaries between users, devices, applications and infrastructure continue to dissolve. NIST’s zero-trust guidance reflects that shift, moving security away from static, network-based perimeters and toward continuous decisions based on users, assets and resources. This same erosion of boundaries is what makes it harder to catch attackers who don’t need to break anything to move around. CISA’s guidance on identifying and mitigating “living off the land” techniques warns that attackers can abuse legitimate, trusted tools and processes to blend in with normal system activity, making isolated alerts harder to interpret without broader context.Yet many organizations still measure security effectiveness largely by how well they detect suspicious activity. Detection remains essential, but alerts alone don’t determine which risks matter most, coordinate action across environments, or help the business continue operating when defenses fail. That requires an approach that connects visibility with timely decisions, enforceable controls and plans for maintaining and restoring critical operations.Moving beyond a detection-centric model means reconsidering how security data, decisions and defenses work together across the enterprise. Below, members of the Senior Executive Cybersecurity Think Tank—with expertise in enterprise cybersecurity strategies, data breach prevention, risk management, threat detection and cybersecurity leadership—explain what a more unified, real-time approach to visibility, control and resilience should look like.

Vendor Breach Recovery: How to Know Whether Remediation Promises Are Real

expert panel

A vendor’s data breach doesn’t stay neatly contained within its own systems. Business clients may face exposed information, operational disruptions, regulatory scrutiny and difficult questions from their own stakeholders, even when their networks weren’t directly compromised. Third-party risk management is a growing issue for companies whose customers’ data resides in a growing web of applications and workflows.Once the initial crisis passes, vendors typically issue reassuring statements about investigations, remediation and stronger security. But communications crafted for customers and the media can’t establish whether the conditions that allowed the attack have truly been addressed. Telecommunications and media giant Comcast learned this the hard way in 2024 when a vendor initially said a breach hadn’t impacted Comcast’s customers—only to reverse course more than four months later.For organizations deciding whether to continue trusting a breached provider, the real question isn’t whether the vendor responded quickly or communicated effectively. It’s whether the vendor can demonstrate that it learned from the incident and has taken real, effective steps to reduce the risk of another one. Below, members of the Senior Executive Cybersecurity Think Tank—with expertise in enterprise cybersecurity strategy, data breach prevention and risk management—share what would convince them that a breached vendor will be a safer partner going forward.

Beyond Vendor Checklists: A Better Approach to Third-Party Cyber Risk

expert panel

Companies rarely operate wholly within their own digital walls anymore. Critical business functions now depend on cloud platforms, software components, contractors, service providers and sprawling networks of suppliers, with each trusted relationship creating another possible route into an organization. And the risk is growing: Verizon’s 2026 Data Breach Investigations Report found that breaches involving third parties had increased 60% from the previous year’s dataset, accounting for 48% of all breaches analyzed.For attackers, compromising a well-connected partner can be faster and more effective than challenging each target’s defenses directly. A 2025 GitHub Action supply chain compromise demonstrated how a tool embedded in development workflows could expose credentials and other sensitive information across downstream users. Yet many organizations still evaluate cyber risk from outside partners primarily through questionnaires and scheduled reviews—methods that document security practices but often fail to reveal how risks, access or dependencies have changed since the assessment was completed.Reducing third-party cyber risk now requires organizations to look beyond whether a vendor passed an assessment and consider how trusted relationships affect their security and resilience over time. Below, members of the Senior Executive Cybersecurity Think Tank—with expertise in enterprise cybersecurity strategy, data breach prevention and risk management—explain what effective third-party risk reduction looks like today and where (and why) companies must move beyond checklist-driven oversight.

2026 Cyber Risk: How Leaders Can Tackle Evolving Security Challenges

expert panel

Cybersecurity leaders have never had the luxury of moving slowly, but the second half of 2026 may test even the most mature security teams. AI is accelerating both sides of the fight: Attackers can find vulnerabilities, craft more convincing scams and move faster, while businesses (and employees) are racing to embed AI into products, workflows and everyday operations. That combination raises the stakes for every leader responsible for protecting data, systems, customers and trust.The challenge isn’t just technical. As cyber risk spreads across engineering, finance, operations, legal, HR, procurement and executive teams, the old model of security as a separate checkpoint no longer fits how businesses actually run. The organizations that handle this next phase successfully will need to rethink cybersecurity as a shared operating discipline, not a last-minute review, compliance exercise, or problem for one department or leader to solve alone.Members of the Senior Executive Cybersecurity Think Tank have deep expertise in enterprise cybersecurity strategies, risk management, threat detection and cybersecurity leadership. Below, a group of them discusses what they see as the biggest cybersecurity challenges for leaders in the second half of 2026 and how organizations move from reactive defense to enterprisewide resilience.

Critical Infrastructure Cybersecurity: How To Build Real Readiness

expert panel

Critical infrastructure is where cyber risk stops being abstract. When power grids, water systems, transportation networks, hospitals or financial systems are disrupted, the fallout isn’t limited to one company’s operations or balance sheet. It can affect public safety, economic stability and trust in the systems people rely on every day.That’s why a recent World Economic Forum survey should get leaders’ attention: 31% of global CEOs lack confidence that their country could respond effectively to a major cyberattack on critical infrastructure. But that lack of confidence may not reflect doubts about governments’ readiness alone. Many leaders may also be recognizing security gaps closer to home, from aging systems and complex vendor networks to crisis plans that haven’t been tested under real pressure. In a recent survey of senior leaders, 48% said the potential emergency they felt least prepared for was a cybersecurity crisis. Preparedness requires much more than policy statements, compliance checklists or well-intentioned plans stored in a shared drive. Leaders across industries and nations need a clearer understanding of how decisions will be made, who will act first and how organizations, sector partners and public agencies will coordinate when minutes matter.Members of the Senior Executive Cybersecurity Think Tank have deep expertise in enterprise cybersecurity strategies, risk management and modern security architecture. Below, seven of them share what’s driving leaders’ declining confidence in cyber resilience and what practical steps could strengthen preparedness at both organizational and national levels.

Company details

Ginkgo Resilience LTD

Industry

Information Technology & Services