ESET will demo AI-native upgrades to its PROTECT Platform at LEAP 2026 in Riyadh from 31 August to 3 September, pairing the technology with deeper Middle East channel support as Saudi organisations race to secure cloud and public-service rollouts.
The company has booked Hall 3 Booth F60 at RECC Malham. Visitors can see live demonstrations and meet the regional team led by Elias Tsapsidis, General Manager at ESET Middle East, Greece, Cyprus and Malta.
LEAP returns as the region’s concentrated tech stage
LEAP 2026 is the fifth edition of the event co-organised by the Ministry of Communications and Information Technology, the Saudi Federation for Cybersecurity, Programming and Drones, and Tahaluf. Official materials list more than 201,000 expected attendees, 1,800 global tech brands, 1,000 speakers, 600 startups and 1,900 investors.
The dates shifted earlier in the year after consultation with partners. Free general admission remains available until 30 August, sponsored by stc. The theme is “Into New Worlds,” with DeepFest running alongside as the AI track.
- 201,000+ projected attendance
- 1,800+ global tech brands
- 1,000+ speakers and 600+ startups
- RECC Malham venue in Riyadh Province
Those figures compress an entire regional buying cycle into four days. Procurement teams, investors and ministry delegates share the same halls, which is why product launches and partnership announcements tend to cluster here rather than across scattered roadshows.
- Until 30 August free general admission window, sponsored by stc
- 31 August doors open at RECC Malham for LEAP 2026
- 31 August to 3 September live demos, speaker sessions and DeepFest AI track
- 3 September final day for booth meetings and follow-up scheduling
On X, early posts already treat the gathering as the place where AI and data-centre investment announcements land. That scale explains why cybersecurity vendors treat the four days as more than a product booth. Full LEAP 2026 dates and Riyadh venue details sit on the organiser site.
Saudi cyber spending already tops SAR 15 billion
The timing lines up with hard numbers from the National Cybersecurity Authority. According to the NCA 2024 cybersecurity market size report, total spending on products and services reached SAR 15.2 billion in 2024, up 14 percent from the prior year. Government entities accounted for SAR 4.8 billion (32 percent). Private-sector entities spent SAR 10.3 billion (68 percent).
The same report puts the sector’s contribution to GDP at roughly SAR 18.5 billion, or 0.40 percent of total GDP and 0.71 percent of non-oil activity. Direct contributions from providers were SAR 9 billion; indirect effects added SAR 9.5 billion.
| Indicator | 2024 figure | Notes |
|---|---|---|
| Cybersecurity market size | SAR 15.2 billion | +14% year on year |
| Government spend share | SAR 4.8 billion (32%) | Public entities |
| Private spend share | SAR 10.3 billion (68%) | Includes CNI operators |
| Workforce | 21,700 specialists | +9%; women 32% |
| GDP contribution | SAR 18.5 billion | 0.40% of total GDP |
Private outlays already dwarf government budgets inside the same report. Critical national infrastructure operators in energy, finance and telecoms sit inside that larger private total, and they carry compliance duties that keep multi-year security programmes funded even when discretionary IT spend tightens.
A separate MarketsandMarkets assessment places the wider Middle East cybersecurity market at USD 16.75 billion in 2025, rising to USD 26.04 billion by 2030 at a 9.2 percent CAGR, with Saudi Arabia expected to hold the largest country share. Vision 2030 digital projects, cloud migration and Critical National Infrastructure protection drive the demand. The National Cybersecurity Authority official site also maintains the Essential Cybersecurity Controls that apply to government bodies and private operators of critical infrastructure.
| Market view | Figure | Context |
|---|---|---|
| Middle East market, 2025 | USD 16.75 billion | MarketsandMarkets baseline |
| Middle East market, 2030 | USD 26.04 billion | Projected endpoint |
| Regional CAGR | 9.2 percent | 2025 through 2030 |
| Saudi country position | Largest share | Inside the regional total |
That regional climb supplies the backdrop for every serious booth conversation in Riyadh. Vendors that can show both product depth and local delivery capacity arrive with a clearer path from demo to contract.
What ESET will put on the floor
At the booth ESET will highlight recent enhancements to the ESET PROTECT Platform. The company describes it as a cloud-first, AI-native system that combines next-generation prevention, detection and response with managed services.
Core pieces on display include advanced XDR through ESET Inspect, automated incident response, root-cause process trees, IOC search across more than 30 indicator types, and detection rules mapped to MITRE ATT&CK. Additional layers cover ESET LiveGuard for zero-day and unknown threats, cloud application protection for Microsoft 365 and Google Workspace, vulnerability and patch management, full-disk encryption and multi-factor authentication.
- AI-native prevention and behavioural detection across endpoints, servers and mobiles
- XDR with full process trees, IOC hunting and automated response actions
- Cloud workload and cloud-app protection plus mail security
- Vulnerability and patch management plus device and web control
- Optional MDR services and premium support tiers
The platform runs from a single console and supports both cloud and on-premises deployment. That dual option matters for ministries and CNI operators that still keep sensitive workloads inside their own facilities while shifting citizen-facing services to the cloud.
ESET notes more than two decades of machine-learning work and eleven global R&D centres feeding its LiveGrid reputation system. Full descriptions of the cloud-first AI-native XDR platform modules appear on the company’s business site. These capabilities sit inside the wider conversation on broader digital risk management shifts that organisations face as attack surfaces grow.
Live walkthroughs will stress how process trees and automated response cut the manual steps between alert and containment. For teams already stretched thin, fewer hand-offs per incident is the practical gain on offer.
LEAP is one of the most important technology platforms in the region, and for ESET it represents a powerful opportunity to engage directly with customers, partners and innovators shaping Saudi Arabia’s digital future. Our mission is to help organisations innovate confidently, and at LEAP 2026 we are proud to showcase AI-driven cybersecurity technologies that support the Kingdom’s ambitions for secure, sustainable digital growth.
Elias Tsapsidis, General Manager at ESET Middle East, Greece, Cyprus and Malta, said the lines above in the company’s announcement.
Channel enablement sits beside the product demos
Saudi Arabia remains a strategic growth market for ESET Middle East. The company says it is expanding technical enablement, sales support and joint go-to-market work with distributors and resellers. The stated goal is to give partners the expertise and resources needed to scale modern solutions so customers get stronger protection and faster access to new releases.
That partner-first framing matters because the NCA workforce figures show only 21,700 cybersecurity specialists nationwide in 2024, even after 9 percent growth. Women already make up 32 percent of the pool, higher than many global averages, yet absolute numbers remain tight relative to the scale of cloud and smart-city projects. Automation that reduces routine alert volume and partner teams that can deploy and tune platforms locally both stretch limited headcount further.
- Technical enablement so resellers can deploy and tune the platform without waiting on scarce in-house staff
- Sales support that keeps joint go-to-market plans aligned with Vision 2030 project timelines
- Faster access to new releases once partners hold current product knowledge
Without that local layer, even strong AI-native tooling risks sitting idle after purchase. With it, smaller security teams inherit a ready path from licence to live protection.
Who feels the pressure first
Government ministries and authorities modernising public services sit at the front of the queue. So do private operators of critical national infrastructure in energy, finance and telecoms that must meet NCA Essential Cybersecurity Controls. Large enterprises adopting multi-cloud setups also need unified visibility that older point tools struggle to deliver.
Smaller organisations and pure startups gain less immediate lift from enterprise XDR tiers, yet the channel push can still bring packaged offerings and managed services within reach. Regional competitors and global vendors already active in the Kingdom will watch how aggressively ESET equips its partners; any gain in local delivery capacity shifts share in a market still expanding at double-digit rates.
The 32 percent government and 68 percent private split in the NCA spend data maps cleanly onto those two pressure groups. Public bodies fund control compliance and citizen-service uptime. Private CNI operators fund the same controls plus continuous operations across energy, finance and telecom networks.
Automation meets a real headcount ceiling
The second-order effect is straightforward. Vision 2030 digital programmes expand the attack surface faster than universities and training pipelines can produce senior analysts. AI-assisted detection, automated response playbooks and clear root-cause views let smaller security teams cover more ground without proportional hiring. At the same time, trained resellers reduce the time between purchase and effective operation.
ESET’s combination of platform automation and channel investment is one vendor’s answer to that mismatch. Other suppliers will bring their own AI claims to the same halls. The practical test after LEAP will be whether Saudi customers and partners can turn demos into measured reductions in dwell time and mean-time-to-respond while staying inside NCA control frameworks. Parallel conversations about the Kingdom’s wider Saudi regional strategy and power reset keep cybersecurity as an enabling layer rather than a side project.
A workforce of 21,700 specialists, even after 9 percent growth, cannot shadow every new cloud workload by hand. Tools that collapse alert noise and partners that finish the install both act as force multipliers on that fixed pool.
Single Consoles Cut Friction Across Hybrid Estates
Many of the buyers walking Hall 3 already run mixed estates. Some workloads remain on-premises for data residency or control reasons. Others have moved to Microsoft 365, Google Workspace or public-cloud infrastructure. Point products that each need their own console multiply the work for the same limited analysts.
A cloud-first platform that still supports on-premises deployment, and that folds endpoint, server, mobile, mail and cloud-app protection into one view, reduces that friction. Root-cause process trees and IOC search across more than 30 indicator types then give the same team a shorter path from signal to decision.
Optional MDR and premium support tiers extend the model further for organisations that prefer to hand routine monitoring to a managed service while keeping policy ownership in-house. That mix matches the talent ceiling the NCA numbers describe without forcing a binary choice between full outsourcing and full self-run operations.
Demos Will Be Judged Against Control Frameworks
Live platform walkthroughs at Booth F60 will not be judged on feature checklists alone. Government bodies and CNI operators must map any new stack to the Essential Cybersecurity Controls maintained by the National Cybersecurity Authority. Detection rules aligned with MITRE ATT&CK, vulnerability and patch management, full-disk encryption and multi-factor authentication are the kinds of concrete controls those reviews examine.
Vendors that can show how automated response and LiveGuard unknown-threat handling operate inside those frameworks give buyers a clearer compliance story. Vendors that cannot will face longer proof-of-concept cycles after the event closes.
The four-day window is short. Follow-up that ties demo outcomes to control evidence and to the partner resources available inside the Kingdom will separate serious evaluations from booth traffic.
Booth F60 is open for the four days
ESET invites attendees to Hall 3 Booth F60 for live platform walkthroughs and conversations with Middle East specialists. The event runs 31 August through 3 September at RECC Malham. Registration details and speaker line-ups continue to update on the official LEAP site as the final fortnight begins.
For organisations already mid-migration to cloud or preparing new public-facing services, the week offers a concentrated chance to compare AI-native tooling against the concrete compliance and talent constraints they already face.
Teams that arrive with a short list of control gaps and headcount limits will leave with sharper questions for every vendor on the floor, including the one demonstrating at F60.
