Technology rarely gives people the luxury of standing still. As businesses move from traditional systems to cloud platforms, connected infrastructure and increasingly complex digital environments, the people responsible for keeping those systems secure have had to evolve just as quickly. Cybersecurity today is no longer limited to technical teams. It touches governance, risk, operations, business continuity and, perhaps most importantly, the people making decisions behind technology.
It is within this changing landscape that Dr. Yasmin Razack, Lead Assessor & Trainer at Gabriel Registrar | Specialist in Cybersecurity GRC & ISO standards, has built a career spanning more than 25 years across IT, aviation and fintech industries. She is a results-driven Cybersecurity GRC Specialist and Lead Assessor, with extensive experience establishing critical security infrastructure and driving compliance across major enterprises and government sectors. She has a proven track record in building high-availability defense frameworks from the ground up, including the foundational design of Emirates Airline’s Network Operations Center (NOC). She is a recognized industry expert, author, and PhD holder in Cybersecurity, skilled at translating complex regulatory mandates into actionable enterprise risk strategies. She combines rigorous technical auditing with global training capabilities to minimize organizational vulnerability, secure critical infrastructure, and foster robust security cultures.
What makes Yasmin’s journey particularly interesting is that cybersecurity was not where she initially intended to arrive. She began her career as a technical expert, drawn to the satisfaction of solving problems and fixing things. With time, however, her work moved towards processes, governance and risk. That shift changed how she viewed technology and opened a much wider understanding of what security really meant.
A significant turning point came when Emirates Airline sponsored her for an MBA. The opportunity helped her step into leadership and eventually establish a NOC for the airline from the ground up. Building the function, its processes and its people gave her a deeper appreciation of governance, risk and cybersecurity, while also showing her the lasting value of developing others.
A Lean Six Sigma project at Emirates Airline brought another important shift, eventually leading Yasmin towards a doctorate in cybersecurity assurance. Looking back, her career reflects less of a carefully planned route and more of a willingness to learn, take on unfamiliar challenges and recognize opportunities when they appear. That openness has shaped not only her professional journey, but also the way she approaches leadership, cybersecurity and the next generation of professionals entering the field.
A Complex Cybersecurity Landscape
The Arab region’s ambitious digital and smart-city projects are rapidly expanding its attack surface. Cloud, AI, IoT and connected critical infrastructure will bring new governance and security challenges.
Yasmin believes AI governance will be among the most pressing concerns. AI can strengthen organizations while also giving attackers new capabilities. Shadow AI and the use of public language models with corporate data can create serious exposure, making responsible AI use and stronger data protection essential.
Regulatory compliance will also become harder as organizations operate across jurisdictions and rely more heavily on vendors and digital partners. Alongside technology, people and skills will remain central to building resilience. Yasmin sees an opportunity for the UAE to take a leading role in creating a secure and trusted digital economy.
A Broader View of Risk and Leadership
Experience across aviation, banking, finance, education and IT has shaped Yasmin’s leadership philosophy around adaptability, evidence and risk.
Her experience with an airline employing more than 160 nationalities taught her that leadership cannot follow a single formula. Different industries and cultures bring different risks, regulations and expectations, requiring decisions that balance security with business and operational realities.
Her Lean Six Sigma background has further strengthened this approach. She believes lasting change comes when people are empowered to take ownership, supported by data, evidence and root-cause analysis, rather than assumptions.
Making Innovation Secure by Design
Yasmin believes security should be built into innovation rather than added afterwards. Her approach centers on four practical principles: secure guardrails instead of excessive gatekeeping, a clearly defined risk appetite, continuous compliance and a no-blame security culture.
Pre-approved infrastructure, change templates and embedded security controls allow teams to move quickly without abandoning safeguards. Risk-based controls ensure that low-risk initiatives are not unnecessarily restricted, while automated monitoring can identify issues faster than annual audits.
She also believes employees must feel comfortable reporting mistakes and vulnerabilities. A culture focused on learning and root causes is more effective than one built around blame.
Bridging Business and Technology
Her experience as a Change Management Head at Emirates Airline and Network International required Yasmin to connect two very different perspectives: executive concerns around business value and risk, and technical teams focused on architecture and security.
In aviation, cybersecurity had to support operational continuity, passenger safety, compliance and customer experience. In banking, decisions also had to consider customer trust, regulatory expectations and growth.
Her role was to create a common language that allowed business and technical teams to make decisions around risk, investment and resilience together.
Developing the Next Generation
Yasmin’s commitment to developing cybersecurity talent comes from seeing what young professionals can achieve when given responsibility and the right guidance.
At Emirates Airline, she coordinated mentorship for the Emirati internship programme and recruited five graduates into her NOC team. Additionally, she recruited five fresh graduates into her NOC team. Within a year, one of them developed the capability to manage critical mainframe operations traditionally handled by experienced staff.
Her work with MAHE University has continued that focus through initiatives exploring trainee security auditors and ISO lead auditor training for postgraduate students. She believes future cybersecurity professionals need more than technical knowledge. Curiosity, ethical judgment, adaptability, communication and business understanding will be equally important.
Governing the Risks of Emerging Technology
Yasmin expects AI to have the most immediate impact on governance, bringing new concerns around data provenance, model risk, privacy, third-party services and AI-enabled attacks.
She also urges organizations to prepare for the quantum era by building cryptographic inventories, identifying vulnerable systems and planning the transition to post-quantum cryptography.
Blockchain will bring opportunities around data integrity, digital identity and traceability, but also risks involving smart contracts, key management and accountability. Yasmin’s view is that emerging technologies should be governed according to their actual business and risk context.
Ultimately, she sees technology governance as inseparable from business continuity, regulatory responsibility, and customer trust.
The First Line of Defense is Already at Work
Yasmin believes a strong security culture begins when employees are treated as part of the defense, not as the weakest link. Cybersecurity should be everyone’s responsibility, supported by continuous and role-specific learning rather than annual training alone.
Procurement teams can learn about supply-chain risks, developers about secure coding, finance teams about payment fraud, and other employees about phishing and social engineering. Real incidents should become learning opportunities, supported by a no-blame culture that encourages early reporting.
She also advocates Cyber Champion networks, recognition for secure behaviour and practical metrics such as phishing click/reporting rates and repeat incidents, not just training completion as a metric. Nominating a Cyber Champion in every department will help in bridging cybersecurity and business teams and help reinforce good practices locally.
Security, in her view, should become part of onboarding, procurement, projects and supplier management. Leadership must ultimately set the tone by connecting security with customers, people, reputation and business continuity.
The Achievement That Matters Most
The achievement that gives Yasmin the greatest pride is the people she has helped develop. Several professionals she mentored have progressed into management and leadership roles across banking, telecommunications and IT.
She is also proud of establishing the NOC at Emirates Airline from the ground up, including its team, processes, policies and rosters, delivering a highly responsive, 24/7 monitoring capability that safeguarded enterprise operations. Beyond this, her doctoral research and co-authored book on blockchain applications provided aviation organizations with forward-looking blueprints for secure innovation, while her security posture assessments for major government and semi-government entities continue to provide leaders with actionable risk insights. She is also an advisory board member for the University of Fairfax, Virginia, USA.
Yet developing people remain the achievement closest to her.
Why She Kept Moving
Three principals have shaped Yasmin’s decisions throughout her career: adaptability, accountability and continuous improvement. She deliberately moved between departments roughly every three years to keep learning and avoid becoming tied to a single function or technology. During crises, she believes leaders must take responsibility and make difficult decisions.
Her Lean Six Sigma experience reinforced the importance of understanding root causes, using data and improving processes rather than simply reacting to problems. As technology changes, she continues to see learning, adaptability and people development as essential to effective leadership.
A Legacy Built Through People
Being recognized among the Arab World’s 20 Most Iconic Woman Leaders to Watch is an honour Yasmin values, but she measures leadership by the opportunities created for others. Her ambition is to help people move beyond self-doubt and understand that cybersecurity leadership is not limited to those with deep technical expertise. Curiosity, adaptability and the willingness to keep learning can be equally valuable.
She believes human capability should remain at the center of cybersecurity. Her guiding principle is simple: do not make yourself indispensable. Build people who can do what you do, share knowledge and give them room to grow.
If those people eventually become mentors and leaders themselves, Yasmin believes that will be the legacy worth leaving behind.