![]()
Sanjiv Cherian spent his first twenty-one years in India, nineteen years in London, and now runs consulting and commercial strategy for a leading cybersecurity firm from Dubai. He argues that the route matters more than the destination.
MUMBAI, IN / ACCESS Newswire / August 6, 2026 / There is a version of the technology executive biography that reads as a straight line. Sanjiv Cherian’s does not.

Born and raised in Mumbai, he left India at twenty-one for the United Kingdom, where he stayed for the better part of two decades, nineteen of those years in London. In November 2024 he moved again, this time to Dubai, where he is Co-Founder and Chief Commercial Officer of Microminder Cyber Security, a firm working across the United Arab Emirates, Saudi Arabia and the United Kingdom on the security of industrial and critical national infrastructure.
Three cities, three very different relationships with risk. He thinks that is the useful part of the story.
“Mumbai teaches you that systems fail constantly and people carry on anyway. London teaches you process, governance and the assumption that the system will hold. The Gulf is building at a speed neither of those cities has seen in fifty years. If you have only ever worked in one of those environments, you tend to think your assumptions about risk are universal. They are not.”
The move to Britain was not a move into cybersecurity. That came later, in an era when the discipline was still largely understood as an internal IT function, something bought with the network refresh and rarely discussed above the level of the IT director.
Sanjiv Cherian has now spent over 15 years in the sector, most of it in consulting, technology and advisory roles rather than purely technical ones, working with end-client organisations across critical national infrastructure (CNI) industries like energy, utilities, manufacturing, transport, financial services and government. His focus has settled on the part of the field that is hardest to sell and most consequential to get wrong: the security of operational technology and industrial control systems, the equipment that actually moves water, generates power, refines hydrocarbons and runs production lines.
That focus is not accidental. It reflects a view about where the real exposure sits.
“For twenty years the industry optimised for protecting information. Confidentiality first, integrity second, availability third. Then we connected the plant floor to the corporate network, and suddenly the thing at risk was not a database. It was a turbine. The order of priorities inverts completely and most security programmes have not caught up.”
He holds a Master of Business Administration from Liverpool John Moores University, a qualification he describes without much ceremony as the thing that taught him to stop presenting security as a technical problem.
“Nobody on a board has ever approved a budget because of a vulnerability count. They approve budgets because they understand what happens to production, to regulatory standing, or to the balance sheet if a control fails. The MBA did not make me a better engineer. It made me able to have the second conversation.”
The 2024 relocation to Dubai was considered a bet on where the work would be. The Gulf states have moved, in under a decade, from importing cybersecurity capability wholesale to building and regulating it domestically. Saudi Arabia’s National Cybersecurity Authority has issued binding controls that reach into operational technology environments specifically. The United Arab Emirates has layered national, emirate-level and sector-specific requirements across critical infrastructure operators. Very large industrial and energy programmes are being commissioned with security requirements written in from the design stage rather than retrofitted afterwards.
For a specialist in industrial security, that combination of scale, regulation and greenfield build is unusual.
“In a mature market you spend most of your time remediating decisions made twenty years ago. Here you get asked the question before the concrete is poured. That is a genuinely different job, and it is a better one.”
Sanjiv Cherian is also a persistent advocate for a less fashionable position on artificial intelligence in security: that it is a force multiplier for skilled teams and close to worthless without them. He has been consistent that automation should absorb the volume work in a security operations centre, correlation, enrichment, triage and summarisation, so that experienced analysts spend their time on the judgement calls that automation handles badly. He is equally clear that the same technologies are lowering the cost of attack, and that the governance question of who is accountable when an automated decision is wrong remains largely unanswered in most enterprises.
Asked what he would tell a board with a single sentence of their attention, he does not reach for the threat landscape.
“Ask your team one question. If someone got into the control network on a Friday night, how would we know, who would we call, and what would we be able to do about it before Monday? If the answer takes more than a minute, you already have your answer.”
Sanjiv Cherian writes publicly on operational technology security and the enterprise use of artificial intelligence, publishing to an audience of more than 21,000 followers on LinkedIn and at sanjivcherian.com, where he sets out his work on the deliberate pairing of human judgement with machine capability. Sanjiv Cherian spoke on “Digital Transformation vs Cyber Threats in UAE Energy and Utilities” at the OT Security First MENA Event in Abu Dhabi in February, 2026 and has been twice quoted on the CISO Series Podcast for his thought leadership on Cyber security. The through-line is consistent across everything he publishes: technology sets the ceiling on what a security function can do, and people determine how much of that ceiling is ever reached.
AUTHOR BIO BLOCK: Sanjiv Cherian is a British cybersecurity executive based in Dubai, United Arab Emirates. He is Co-Founder and Chief Commercial Officer of Microminder Cyber Security, which delivers operational technology and industrial control systems security, managed security operations, penetration testing and cyber assurance services across the United Arab Emirates, Saudi Arabia and the United Kingdom. Born in Mumbai, he moved to the United Kingdom at twenty-one and spent two decades in London before relocating to Dubai in November 2024. He holds a Master of Business Administration from Liverpool John Moores University. He writes and speaks on operational technology security, critical national infrastructure protection, and the role of artificial intelligence in enterprise security. More at sanjivcherian.com
Company Details
Company Name: Microminder Cyber Security
Contact Person: Sanjiv Cherian
Email: sanjiv.cherian@micromindercs.com
Website: https://sanjivcherian.com
SOURCE: Microminder Cyber Security
View the original press release on ACCESS Newswire