Currently — QuantumHandshake™ in late MVP, controlled institutional pilot targeted for 2026

Naushad.

I build the trust layer for systems that cannot afford to be wrong.

Two decades breaking into networks taught me exactly how they fail — now I design the cryptographic infrastructure that outlasts the quantum transition.

Founder & CTO, QuantumHandshake™CISO · Cryptographic EngineerAI/ML Engineer · Red Team

What I'm building

Trust infrastructure for the post-quantum era

Harvest Now, Decrypt Later turns tomorrow's cryptographic break into today's exposure. These are the two companies I founded to address it.

Founder & CTO

QuantumHandshake

Trust Before Transport™

The internet has encryption. It still lacks trust. QuantumHandshake decides whether a session can be trusted before anything is transmitted — not after the fact — and produces a structured Evidence Pack for every decision. The architecture began as iDIS in 2017 at the Wolverhampton Cyber Research Institute, and pivoted to NIST's ML-KEM and ML-DSA when FIPS 203, 204 and 205 were published on 13 August 2024. Independently reviewed by a university-led technical assessment; late MVP, with controlled institutional pilots targeted for 2026.

Trust Before Transport™Covalence StackBCQP™DCBA™NSQC™ML-KEM / ML-DSAEvidence Pack
quantumhandshake.com
Founder · Building since 2017

AiiDIS

Quantum Exposure Intelligence

AiiDIS began in 2017 as iDIS — IoE · Detect · Inspect · Secure — research into secure channel transmission and Red Team / Blue Team adversarial security at the Wolverhampton Cyber Research Institute, and as the reconnaissance tool I ran on live engagements. One script, one question at a time, grown across nine years into a plugin architecture spanning DNS, breach data, registries, social platforms and reputation feeds. Battle-tested on red team, black-box and internal engagements, wireless and network hygiene audits, and dark-web threat intelligence. Then I added the cryptographic layer and designed the HNDL Risk Score, so it now answers one question: what does the outside world see — and will its cryptography survive the post-quantum transition?

Since 2017WCRI researchHNDL Risk Score237 Modules12 DisciplinesPassive ReconEvidence-Labelled
aiidis.com
29yrsSince 1997
1,200+Developers supported
9yrsR&D since 2017
237AiiDIS modules

FILE / ORIGIN-1997 · TWO EXHIBITS · VERIFIED

Naushad at his desk in March 1997 — two beige CRT monitors, one showing a web page, an early laptop, a MIDI keyboard, and a camera date stamp reading 8 3'97.
8 3’97 My first official appointment, first web development team.
The cyber lab in 2026 — six screens across two tiers running a code editor, terminals and dashboards, a wall of instrumented boards and displays to the right, all under green lab lighting, with Naushad at the keyboard in headphones.
2026 The cyber lab, 2026. Same shape, better hardware.

Twenty-nine years on, the room has changed and the habit has not. More screens than anyone needs, a terminal open on every one of them, a rack humming in the corner and the same question on all of it: can you trust what is on the other end of this connection? The kit got faster. The work did not move.

Where it started

1994 → 1997 → now

The browser on that beige CRT and a post-quantum handshake are the same problem: can you trust what is on the other end of the connection? I have been working on that question for twenty-nine years.

My life in computing started in 1994. In March 1997 I took my first official appointment and formed my first web development team — building web directories, forums, blogs, e-commerce platforms, CMS, and both static and dynamic sites.

HTML, PHP, Python, JSP, ASP and C++, with Adobe Suite, Photoshop, Dreamweaver, Macromedia Flash and Fireworks. As webmaster I led the team through STLC, with code review at the centre of the process — security built into the foundation of every project rather than bolted on afterwards. That is where the interest in networking and infrastructure security began, and it never left.

  1. 1994The journey into computing begins.
  2. 1997First official appointment. First web development team formed.
  3. 1997–2000TISO — webmaster, security-first development, STLC and code review.
  4. 2017iDIS begins at the Wolverhampton Cyber Research Institute — and as my own reconnaissance tool. One script, one question.
  5. 2026QuantumHandshake™ — late MVP, institutional pilot. The same trust problem, three decades on.
The first web development team at a shared meal, late 1990s.
03
The team gathered around a table, late 1990s.
04
Naushad at a workstation in the late 1990s office.
05
Racks and cabling inside an early data centre.
06

Services

What I am engaged to do

Twenty years of breaking into networks, leading security operations and building the cryptography that has to outlast them. Engagements run UK-wide and remote, under NDA.

Penetration Testing

Internal, external, web, wireless and mobile testing that ends in a fix list, not a scanner dump.

Detail

Red Team Operations

Full adversary simulation: black-box, social engineering, physical and wireless, against a live defence.

Detail

Post-Quantum (PQC) Readiness

Cryptographic inventory, Harvest Now Decrypt Later exposure and a migration plan with dates on it.

Detail

AI and Machine Learning Security

Two directions: machine learning that catches what rules miss, and securing the AI systems themselves.

Detail

Private Cyber Investigations

Confidential digital forensics and investigation, run so the evidence survives scrutiny.

Detail

SOC and SIEM Build

Design, build and staff a security operations centre — or fix the SIEM that is drowning your analysts.

Detail

Incident Response and CSIRT Readiness

Containment when it is happening, and the playbooks that stop the next one becoming a crisis.

Detail

Threat Intelligence and Dark-Web Monitoring

What the criminal market already knows about your organisation, and what to do about it.

Detail

Attack Surface and OSINT Reconnaissance

Everything the outside world can see about you, assembled before an attacker assembles it.

Detail

Security Architecture Review

A design assessment that finds the flaw before it is built into production.

Detail

DDoS Resilience Engineering

Mitigation architecture and load testing for services that cannot be allowed to fall over.

Detail

Compliance and Audit

PCI-DSS, ISO 27001 and GDPR taken from gap analysis to signed-off evidence.

Detail

vCISO and Security Leadership

Board-level security leadership without carrying a full-time CISO on the payroll.

Detail

Security Awareness, Training and Speaking

Training built from real engagements, and keynotes that do not read from the vendor script.

Detail

Engagements

Where the work has been done

Red team, black-box, internal and external engagements, wireless and network hygiene audits, and dark-web threat intelligence — across defence, healthcare, law, infrastructure, logistics and motorsport. This is the field experience AiiDIS was sharpened on.

  • Smiths Detection
  • ATB Computing Services
  • G4S
  • Royal Mail
  • Aston Martin
  • Mercedes-AMG Petronas Motorsport
  • NHS
  • Amey
  • Gowling WLG
  • Brigade
  • ICE
  • APS Group
  • Actavo
  • Mace
  • HouseMark
  • Standard
  • Sitel
  • Taylor Wessing
  • BMI
  • Healogics
  • Dentsu
  • Bravura Solutions
  • Freshfields
  • MSD
  • LKQ
  • Trowers & Hamlins
  • BT
  • Ministry of Defence
  • Moonpig
  • NATO
  • Photobox Group
  • SigTech
  • FIFA

About

Two decades on the offensive side of security

A CISO with over 20 years of experience, I lead advanced threat detection, forensic investigations and cybersecurity innovation across blockchain and AI. As a national strategist in electronic revenue policy, my focus is on leveraging cryptography to drive cyber resilience and digital sovereignty.

I started building for the web in 1997 and moved into enterprise security leadership — red team operations, SOC leadership, security architecture, vulnerability assessment and digital forensics. That history is why QuantumHandshake exists: I have spent twenty years watching how trust actually fails in production, long before quantum computing made it urgent.

RedTeam Ethical Hacker

Red TeamAI/ML EngineeringCryptographic EngineeringSOC LeadSecurity ArchitectAI-Integrated IdentityVulnerability DetectiveNetwork ExaminerDigital Forensics

Research & tooling

Projects behind the practice

Ongoing research and the offensive-security tooling that informs it.

PhD research · 2018 — ongoing In research

CyBotic Predator

An ultimate signal-sniffing platform — one defence system across air, sea, network and IoT.

YouTube · loads on click

My second PhD research project. CyBotic is a signal-sniffing platform built around five core capabilities, drawing air, sea, network and IoT defence into a single orchestrated system.

There are two reasons I wanted to take this to PhD. I have a genuine passion for research in the signal-sniffing domain itself — hacking, plainly — and the understanding that comes with it. And I wanted to be intellectually challenged and guided by a world expert in the field. The question underneath it is simple: can I push far enough to build the ultimate cyber defence system, orchestrated end to end?

  • Air defence, including drone defence
  • Sea defence systems
  • Network and Wi-Fi defences
  • IDS and IPS
  • IoT operations and intelligence

cybotic.io The dedicated site is offline; the research continues.

Security platform Live

Ministry of Hack

Adversary-centric detection and proactive threat hunting.

A security ecosystem for IT infrastructure, built on cyber intelligence, deep analysis of attacks and incident response, with integrated risk management. The methodology is adversary-centric detection and proactive threat hunting: knowing how attackers think and act, and using that to find them and remove them.

Visit Ministry of Hack

Offensive tooling Held privately

Hail Mary Toolkit

Three attack modes across Wi-Fi, RFID and contactless.

A research toolkit with three modes. The first targets the WPA2 handshake — the key to the kingdom is tricking the four-way handshake, achieved by manipulating and replaying the cryptographic handshake messages. The second detects long-range RFID at over 100 metres. The third is a long-range scanner for contactless smart cards operating at 13.56 MHz.

  • WPA2 — four-way handshake manipulation and replay
  • RFID — long-range detection beyond 100 m
  • Contactless — 13.56 MHz smart-card scanning

Not published. Offensive tooling, held privately.

Threat intelligence Archived

Malware Detective

Hunting spyware, trojans, keyloggers and bots in real time.

A special-ops project: threat intelligence researchers hunting spyware, adware, trojans, keyloggers, bots, worms and hijackers in real time. The premise was that the landscape had already changed — we are no longer protecting against a piece of malicious code, we are defending against persistent adversaries.

malwaredetective.co.uk has been retired.

Track record

Two decades, abbreviated

From red-team operations and SOC leadership to NATO cyber defence and doctoral research.

2021

A Majority of Cyber Attacks Successfully Infiltrate Enterprise Environments Without Detection

The report summarizes the results of thousands of real attacks performed by experts from t

2020

InfoSec Events

THE SHIFTING CYBER THREAT LANDSCAPE

2020

Build a smart piSOC with MITRE ATT&CK Unified Security

The threat landscape keeps getting more complex. The trend toward cloud and hybrid environ

2019

Wisdom of Crowds Lon Nov2018

2018

Photobox Group Security Team

2018

AppSec Check list Mine Map

Application security encompasses measures taken to improve the security of an application

2018

GDPR Audit Checklist

The first steps towards GDPR compliance are understanding your obligations, what your curr

2018

PhD Project: CyBotic Predator

What is the Cybot, AKA CyBotic Predator : 2018

2017

Cyberlympic ‘Ethical Hacking’ World Championship

Hackers in the world competed in the Global CyberLympics final during Cyber Security Week

2017

Capture The Flag-HackTheBOX

Hack The Box is an online platform allowing you to test your penetration testing skills an

The full timeline

Contact

Start the conversation

Briefings on post-quantum readiness, HNDL exposure assessment, or security leadership engagements.