Proactive IT-Security
Specialize in Information Security & data protection, Cybersecurity Experts, ISMS Audit, IT Consultancy
29/07/2026
A Real Cybersecurity Case Every Organization Should Learn From
π¨ Could This Happen to Your Organization?
Recently, I investigated a Business Email Compromise (BEC) incident during a cybersecurity engagement. While I can't disclose the identity of the organization involved, the lessons learned are valuable for every business.
The attack didn't rely on sophisticated malware or ransomware. Instead, it exploited everyday cyber hygiene weaknesses such as:
πΉ Reusing passwords
πΉ Saving passwords in web browsers
πΉ Using unsecured public Wi-Fi
πΉ Installing untrusted software or browser extensions
πΉ Granting excessive permissions to third-party applications
Once access was gained, the attacker quietly monitored email communications through hidden mailbox rules before sending fraudulent payment instructions, resulting in financial loss.
What can you do today?
β
Use a unique password for every account.
β
Enable Multi-Factor Authentication (MFA).
β
Never approve unexpected MFA requests.
β
Verify payment instructions through a second trusted communication channel.
β
Regularly review mailbox rules and connected applications.
One simple check you can perform today:
Check whether your email address has appeared in a known data breach using:
Have I Been Pwned
If your email appears, it does not necessarily mean your account has been compromised. However, if you have reused passwords, now is the right time to change them and review your account security.
Cybersecurity is no longer just an IT issueβit is a business continuity issue.
At PROACTIVE ITS, we help organizations strengthen their cyber resilience through cybersecurity assessments, security governance, Microsoft 365 security, cyber awareness, and security best practices.
π© Need assistance protecting your organization?
PROACTIVE ITS
π www.proactive-its.com
βοΈ [email protected]
π ASSESS | SECURE | OPTIMIZE
π¬ What do you believe is the most overlooked cybersecurity habit in organizations today? Share your thoughts in the comments.
.ITS
24/06/2026
Your biggest AI risk is not your technology. It is your people.
Not because they are careless β but because most organizations have never given them the right policies, training, or culture to use AI securely.
The numbers speak for themselves:
πΉ 57% of employees use personal ChatGPT, Gemini, or Copilot accounts for work β outside IT visibility
πΉ 33% admit feeding sensitive company data into unapproved AI tools
πΉ Only 37% of organizations have a formal AI policy β while 77% already run AI in their systems
Building an AI-aware culture requires three things:
β
Clear policies on approved AI tools
β
Ongoing training β not annual checkbox compliance
β
Defined accountability when something goes wrong
AI governance is not an IT project. It is a culture shift.
Is your organization investing in AI culture β or just AI technology?
π© Contact us: [email protected]
03/06/2026
Most organizations think they're assessing AI risk. They're not.
They review a compliance certificate, tick a few boxes, and call it done. That's wishful thinking.
The real blind spots?
πΉ Employees are already using ChatGPT, Copilot, and Gemini β without IT knowing
πΉ Your vendors are quietly embedding AI into your systems
πΉ AI-generated outputs are being trusted without validation
πΉ Nobody knows who is accountable when AI causes harm
And most organizations are applying yesterday's frameworks to tomorrow's risks.
ISO/IEC 42001, NIST AI RMF, and the EU AI Act are clear: AI governance is no longer optional.
Is your organization truly assessing AI risk β or assuming it?
π© Contact us: [email protected]
π¬ What's the biggest AI blind spot you're seeing?
.ITS
16/04/2026
Cybersecurity in Times of Conflict: 10 Steps to Stay Protected
Your defenses are only as strong as your weakest habit.
In times of conflict and instability, cyber threats don't pause β they get worse. Hackers take advantage of the chaos, the distraction, and the fear.
Whether you're an individual or a business owner, here are 10 simple steps to protect yourself right now:
For you personally:
1. π Turn on two-step verification on all your accounts
2. π Change your passwords β especially email, banking, and social media
3. π΅ Don't click on links from people or sources you don't know
4. πΆ Avoid public Wi-Fi β use a VPN when you can
5. πΎ Back up your photos, documents, and important files today
For your business:
6. π¨ Brief your team β make sure everyone knows the risks right now
7. π‘ Keep a closer eye on your systems and network activity
8. π£ Remind your staff that fake emails and scam messages are increasing
9. π Limit access to sensitive data β not everyone needs to see everything
10. β
Make sure your backups actually work β test them, don't assume
β οΈ A crisis is exactly when attackers strike. Don't wait until something goes wrong.
π© Want to know how protected your business really is?
Reach out to us at Proactive ITS: we're here to help.
[email protected] - 00961-3-917619
18/03/2026
AI Governance: Do You Have ItβOr Just AI Tools?
"We have AI governance!"
Really? Answer these 5 questions:
1οΈβ£ Who is accountable when your AI makes the wrong decision?
2οΈβ£ Can you explain how your AI reached its conclusion?
3οΈβ£ What decisions can your AI make without human approval?
4οΈβ£ How do you detect if your AI is developing bias?
5οΈβ£ What happens when your AI fails?
If you hesitated on even oneβyou have AI tools. Not AI governance.
After 25 years implementing governance frameworks across Lebanon, the GCC, and Africa, I keep seeing the same pattern: organizations rush to deploy AI while governance remains an afterthought.
The result? A growing gap between what AI can doβand what organizations are prepared to control.
AI governance isn't about slowing down innovation. It's about making sure innovation doesn't outpace accountability.
Whether you're working toward ISO 42001, NIST AI RMF, or building your own standards, the fundamentals don't change:
β
Named accountability β not "the AI team"
β
Defined decision boundaries β what AI can decide alone vs. what triggers human review
β
Explainability β "the AI flagged it" is not an answer
β
Continuous bias monitoring β AI systems drift as data evolves
β
AI-specific incident response β because when AI fails, a cyber playbook isn't enough
If you're building AI capability faster than governance maturity, you're not innovatingβyou're accumulating risk.
π Read the full analysis: https://www.linkedin.com/posts/mohammed-zahwe-6b8949183_aigovernance-artificialintelligence-cybersecurity-activity-7439668100846874624-KC6z?utm_source=share&utm_medium=member_desktop&rcm=ACoAACtjYKwBz_a6Rv6OLrap2m5gIkrXnRoPvBo
16/02/2026
Human-in-the-Loop: When Should AI Act Alone in Cybersecurity?
Last week, an AI security system blocked a "suspicious transaction"βit was the CEO authorizing an emergency payment to a critical vendor.
That's not a system failure. That's a supervision model decision.
The leadership question: When should AI act autonomously, and when must humans stay in control?
Three levels of AI oversight:
π΄ Human-in-the-Loop - AI recommends, human approves π‘ Human-on-the-Loop - AI acts, human monitors
π’ Autonomous - AI acts, human reviews later
The real risk isn't AI autonomy. It's undefined autonomy.
If you can't clearly state:
β’ When AI is allowed to decide
β’ When escalation is mandatory
β’ Who owns the outcome
β’ How intervention happens
Then you don't have AI governance. You have AI exposure.
AI-driven cybersecurity is about positioning human judgment exactly where it creates the most value.
Organizations that get this right will move faster than human teams and safer than purely automated systems.
Read our CEO Mohammed Zahwe's full analysis: https://www.linkedin.com/posts/mohammed-zahwe-6b8949183_cybersecurity-artificialintelligence-aigovernance-share-7429129163803967489-whLJ
26/01/2026
The Consultant's Paradox I spend my days advising clients on AI adoptionβwhile AI automates what consultants traditionally do. Research? AI does it faster.
Analysis? AI processes more data. Reports? AI generates them instantly.
So what's left for consultants? Judgment. Context.
Trust. Accountability. AI won't replace consultants.
But consultants who use AI will replace those who don't.
This shifts from information provider to wisdom broker.
Read the full analysis: https://www.linkedin.com/pulse/consultants-paradox-advising-technology-could-replace-mohammed-zahwe-ycnsf
Helping Lebanese and regional organizations navigate AI governance and digital transformation.
π§ [email protected]
π +961 3917619
25/12/2025
As 2025 comes to a close, we thank our clients and partners for a year built on trust, resilience, and secure digital foundations.
From cybersecurity to intelligent infrastructure, we look forward to engineering a safer, smarter 2026 together.
Wishing you a peaceful holiday season and a future-ready New Year.
Proactive ITS Team
.ITS
23/12/2025
AI Adoption Is Accelerating. AI Governance Is Not.
As 2025 closes, organizations across Lebanon and the region are rapidly adopting AIβfor customer service, fraud detection, document processing, and analytics.
But one critical question gets overlooked: When AI processes our data, where does sovereignty endβand dependency begin?
Critical governance questions remain:
β Who controls the algorithms making decisions about our data?
β Can we audit systems we don't architecturally control?
β What happens if geopolitical shifts restrict access to AI providers?
AI governance frameworks are emergingβISO/IEC 42001 for AI management systems, NIST AI RMF for risk management, and the EU AI Actβbut adoption lags deployment.
The 2026 question for boards: Do we clearly understand where our strategic autonomy ends, and our technology dependency begins?
AI sovereignty isn't about rejecting global tools. It's about making deliberate, informed choices about control, outsourcing, and risk.
Does your organization have an AI governance strategy for 2026? Proactive ITS helps Lebanese and regional organizations assess their AI readiness and build governance frameworks aligned with international standards.
Contact us to discuss your approach: [email protected]
Whats App 78 998 906
.ITS
11/12/2025
β οΈ Still Using WSUS for Patch Management? Time Is Running Out.
If your organization relies on Windows Server Update Services (WSUS) for patch management, here's what IT leaders need to know right now:
Microsoft has moved on to cloud-based, AI-driven solutions. While WSUS still works today, it's legacy technology on a sunset path.
THE NUMBERS DON'T LIE
π 60% of data breaches involve unpatched vulnerabilities
π° Average breach cost: $4.45 million
β° Organizations waiting for Microsoft's official announcement will face a resource crunch
WHAT MODERN AI-POWERED PATCH MANAGEMENT DELIVERS
β
Intelligent prioritization based on YOUR actual risk
β
Predictive analysis that flags compatibility issues BEFORE deployment
β
Optimized scheduling that minimizes business disruption
β
Automated compliance monitoring and reporting
β
70% reduction in manual IT effort
THE CRITICAL QUESTION
Will you transition on your termsβor under pressure when Microsoft pulls the plug?
Organizations planning their migration NOW will:
β Avoid the rush for consultants and solutions
β Retain institutional knowledge during transition
β Achieve better security outcomes
β Reduce operational costs
NEED HELP WITH YOUR TRANSITION?
Proactive ITS helps organizations across Lebanon, the GCC, and Africa modernize their patch management and cybersecurity infrastructure.
We offer complimentary IT infrastructure assessments to help you plan your roadmap.
π§ [email protected]
π www.proactive-its.com
π +961 3 917619
π Serving Lebanon | GCC | Africa
Drop a comment or message us to schedule your assessment.
Click here to claim your Sponsored Listing.
Website
Address
Sami ElSolh, Badaro, Alam
Beirut
1111111
Opening Hours
| Monday | 08:30 - 17:30 |
| Tuesday | 08:30 - 17:30 |
| Wednesday | 08:30 - 17:30 |
| Thursday | 08:30 - 17:30 |
| Friday | 08:30 - 17:30 |