As digital risk accelerates, organisations are searching for clarity, resilience and trustworthy systems. Mercan Yildirim, Founder and CEO of German Cyber-Systems, shares how early work in law enforcement and cyber forensics shaped her mission, why she believes culture is the true frontline of security and how the Middle East can lead a new era of resilient, sovereign cyber innovation.

It is quite unusual for a young woman to found a cybersecurity company. What motivated you to take this path?
I still remember one of the cases I worked on with the German Federal Police. It was a truck that had been stopped near the border and on the passenger seat lay a broken smartphone. The suspect had tried to destroy it, likely thinking the information on it was gone. The phone ran on GrapheneOS, which made accessing the data even more complicated. But the case was serious, potentially involving smuggling or drug trafficking, and we had to get inside that device. We collaborated with the BKA, who had the right tools to extract the data. Together, we managed to crack it.
That experience stayed with me. It showed me how vulnerable digital systems are and how important it is to handle them with care and skill. It also reminded me that we never solve anything alone. You need collaboration, and you need the humility to know when to ask others for their expertise.
Looking back, founding my own company was not something I planned from the start. I simply followed the problems that mattered to me. I was young, and yes, often the only woman in the room, especially in highly technical settings. But I believe deeply in the idea that when we surround ourselves with people who think with clarity, act with integrity and share a vision, we all grow. That is the mindset I try to carry every day. Not because I have all the answers, but because I care enough to keep asking better questions.
What do you see as the biggest cybersecurity vulnerability that companies in our region need to address right now?
The biggest vulnerability is still the human factor, not the technology. Many companies invest in expensive tools but overlook the behaviour and mindset of their teams. In regions experiencing rapid digital growth, that gap becomes even more visible. Phishing, credential theft and shadow IT remain common ways attackers gain access. What’s needed is a shift in culture.
Cybersecurity should be seen as a shared responsibility, embedded in daily routines, not as a one-time technical solution. True resilience begins with awareness, leadership and clarity at all levels of the organisation.
Why did you decide to expand your company to the UAE and the Middle East, and what makes this region special for you?
The UAE impressed me from the very beginning. There is a sense of forward momentum here, a focus on building instead of waiting. When I first came to the region, I met people who were not just talking about innovation, they were actively implementing it.
That energy, paired with a serious commitment to security and infrastructure, made it clear to me that this is a place where future-ready solutions are not only welcomed, but needed. It felt less like expansion and more like alignment. I saw the values of my company reflected in the region’s ambition and direction.
What is your vision for the future of cybersecurity and what role should business leaders play in it?
My vision is that cybersecurity becomes so embedded in our systems and thinking that it becomes invisible, like the brakes in a car. You trust they will work without thinking about them. That is the kind of trust we need in digital systems.
Leaders play a crucial role in shaping that future. They need to understand that cybersecurity is not about fear, but about clarity and long-term thinking. It is part of strategic leadership. The leaders who make the biggest impact will be the ones who see cybersecurity as cultural, not just technical. They will prioritise transparency, invest in ethical and explainable technology, and build teams that carry these values forward.
In Europe, debates around chat control and encrypted communication are heating up. From your perspective, how should the Middle East balance national security with privacy and secure communication for businesses and individuals?
The current debate in Europe around scanning encrypted messages highlights how complex the relationship between privacy and national security has become. The goal of protecting people, especially children, is critical. But the proposed methods risk undermining the trust people place in digital tools.
In the Middle East, I recognise and respect the emphasis on security and societal stability. At the same time, secure communication is vital for business confidence and long-term economic growth. Weakening encryption can open doors not only for authorities, but also for cybercriminals. The region has a unique opportunity to create a model that prioritises protection without sacrificing trust. By focusing on targeted investigations, modern digital forensics and building trusted national infrastructure, it can set an example for others to follow.
How can emerging technologies and new models of Artificial Intelligence reshape the way we think about resilience and sovereignty in cybersecurity?
Artificial Intelligence is already transforming how we detect and respond to threats, but the more important shift is about ownership. Who controls the infrastructure, the models and the data? Centralised AI, controlled by a few major companies, creates dependence and limits transparency. It becomes harder to know what drives decisions, how data is used and where vulnerabilities might exist.
That is why decentralised models like Bittensor are so promising. They distribute intelligence across a network, reduce single points of failure and encourage collaboration. For the Middle East, this presents a powerful opportunity to develop systems that reflect local values, languages and priorities.
Sovereignty in cybersecurity is not only about borders or compliance. It is about taking ownership of your digital future, building trusted systems and making sure that critical decisions are made with transparency and intention.


