Track record

Career

10 roles from 2006 to now — security operations leadership, red team engineering, SOC and SIEM build, and the government years that stay under NDA. The 1997 starting point has its own section, and the full CV carries the certifications and platform detail.

The through-line

Apr 2019 — Present

Chief Technology Officer (CTO) & CISO

AcuityGroup LtdCurrent

Research lab and innovation hub — parent of Quantum Handshake Ltd (No. 17261924)

The through-line. The client engagements below ran alongside this, not instead of it — AcuityGroup is the lab where the R&D happens.

  • Chief Technology Officer (CTO) & CISO (Jun 2026 — Present)
  • CISO / Enterprise SOC Engineer (Mar 2020 — Jun 2026)
  • Interim CISO / Cyber Security Specialist (Apr 2019 — Mar 2020)
  • Digital Transformation Lead (Oct 2019 — Apr 2020)
  • Lead the technical vision, cyber security strategy and platform architecture behind the post-quantum digital trust ecosystem — QuantumHandshake™ and AiiDIS™, both incubated here from R&D begun in 2017
  • Own the complete security picture for the group: strategy and architecture through to daily SOC operations, incident response and threat intelligence
  • Built greenfield security operation centre service and on-boarding
  • 24x7 active monitoring, incident triage and handling
  • Drove SIEM engineering and fine tuning; SIEM detection analysis across the cyber kill chain
  • Designed strategic cyber security visualisation programmes and security architecture
  • Advanced persistent threat and insider threat monitoring, forensics and focused operations
  • Third-party technology assurance and advisory, ISAE 3402 (previously SAS 70)
  • Advanced IoT/IoE threat research with leading academics — detection, inspection and secure systems
  • Automated cyber assessment using bots for a new GDPR data protection certification scheme

Client engagements — run alongside

Nov 2023 — Aug 2024

Head of Cyber Security Engineering

SIG Technologies Limited

  • Designed and implemented security architectures, systems and networks; established 24/7 monitoring and response, recruiting and training the internal team
  • Developed and executed incident response plans for prompt breach handling
  • Ran security audits and vulnerability assessments to identify and mitigate weakness
  • Set up and managed security monitoring tooling for real-time threat detection
  • Developed and enforced security policy, ensuring compliance with industry standards
  • Performed penetration testing, code review and validation of security controls

Sep 2022 — Mar 2023

Cyber Security Specialist & Interim CISO

Cordial World

  • Responsible for global security operations centre resilience
  • Led incident response and built the incident playbooks
  • Ensured OT operations SIEM monitoring and fine tuning
  • Supported SOC engineers on alert sources and triage; escalation point for all technical issues
  • Worked with senior management to drive the crisis committee
  • Organised and conducted ethical hacks of the existing security architecture

Oct 2021 — Sep 2022

SOC Engineer / Cyber Security Specialist

Cyber DiligentiaContract

  • Investigated potential incidents, triaged and prioritised detections
  • Monitored client security infrastructure, identifying and reporting real-time attacks
  • Documented incidents in accordance with government policy and procedure
  • Set up and operated an investigator's lab, and processed computer crime scenes
  • Performed risk assessment and testing on live data processing activity
  • Provided on-the-job training to develop junior SOC team members

Nov 2020 — Oct 2021

Cyber Security Programme Manager

Shayype Ltd | Coltech GroupContract

  • Led enterprise infrastructure penetration testing to proactively identify weakness
  • Led web application source code review and network security architecture work
  • Presented results to technical and non-technical stakeholders and advised on remediation
  • Implemented Endpoint Detection & Response
  • Established cyber resilience and maturity assessment programmes — proactive threat hunting
  • Worked alongside development covering SDLC across applications and infrastructure

Jan 2020 — Jan 2021

vCISO, Technical Assistant to CEO and CTO

EURUSOG Ltd

Startup, short-term open contract

Jul 2013 — Apr 2019

Cyber Security Specialist — Red Team Engineer

Photobox Group Ltd

6 e-commerce brands, 22 factories, 8 technical teams, 1,200+ developers, 30+ SOC team members, 10 security champions, 12 countries

  • IT Security Specialist and Digital Transformation Lead (Jul 2013 — Jun 2015)
  • Penetration testing across 6 e-commerce brands and factories, with remediation management
  • Quarterly PCI-DSS penetration testing at level 1, level 2 and self-assessment
  • Built greenfield SOC operations in the UK and Europe, matured into world-class capability
  • Defined critical incident handling for phishing, DDoS, critical malware and complex triage
  • Regular auditing of Wi-Fi, wireless, LAN and external network leak signals
  • Signed off changes on IDPS, anti-spam, DNS firewall and content filtering
  • Chaired daily operations across security, DevOps, incident management and threat intelligence
  • Conducted regular cyber resilience programmes and red team attack scenarios

2011 — 2014

Cyber Intelligence Officer — Red Team Engineer

Government red team operationsUnder NDA

Period covers Royal Navy service and NATO-related work. Unit, rank and detail withheld.

  • Responsible for critical judgements about threats to national security
  • Red team specialist running reconnaissance assessment, identifying vulnerabilities and recommending corrective action
  • Planned and performed technical analysis and red team assessment on targeted intelligence

2010 — 2011

Red team operations lead

Government contractorUnder NDA

Period covers Royal Navy service and NATO-related work. Unit, rank and detail withheld.

  • Managed and assessed 17 team members plus 5 international operators
  • Scoped operations with stakeholders, defined objectives and developed a delivery approach that minimised operational risk
  • Accountable for plan execution, tracking, reporting and stakeholder management

2006 — 2014

Founder / Head of Information Security

AlWahy.com

Archived at the Wayback Machine

Field notes

What I was working on

29 short notes written alongside the roles above — platforms evaluated, techniques tested, events attended, 10 of them with video. Not job history; a record of where the attention went.

2021

A Majority of Cyber Attacks Successfully Infiltrate Enterprise Environments Without Detection

The report summarizes the results of thousands of real attacks performed by experts from the Mandiant Security. The tests consisted of real attacks, specific malicious behaviors, and actor-attributed techniques and tactics run in enterprise-level production environments representing 11 industries against 123 market-leading security technologies -- including network, email, endpoint, and cloud solutions. The report reveals that while organizations continue to invest significant budget dollars in security controls and assume that this means assets are fully protected, the reality is that a majority of the tested attacks successfully infiltrated the organizations’ production environments without their knowledge. READ MORE:  attacks-successfully-infiltrate 

2020

InfoSec Events — keynote speaking

THE SHIFTING CYBER THREAT LANDSCAPE

As hackers become more creative in their subversive techniques, businesses need to become more proactive in educating their workforce and stepping up their cyber incident response plans. Businesses should consult with their vendors, third-party suppliers and stakeholders in every business unit to ensure continuity, mitigate risk and verify that security measures are being employed and regularly updated.

Build a smart piSOC with MITRE ATT&CK Unified Security

The threat landscape keeps getting more complex. The trend toward cloud and hybrid environments complicate your cybersecurity posture. Many organisations building a cyberSOC may seem like an impossible task. With limited resources (time, staff, and budget), setting up an operations center supported by multiple security monitoring technologies and in real-time threat updates does seem complicated. Thankfully, I have step by step white-paper for you to start building your own DIY SOC in very cost effective way to implement and manage these different tools on an ongoing basis...Find full white-paper on: https://www.linkedin.com/pulse/build-smart-pisoc-mitre-attck-unified-security-naushad-hunter/ [embed]https://www.youtube.com/watch?v=gRFeu4-wiwc[/embed]

2019

YouTube · loads on click

Wisdom of Crowds Lon Nov2018

2018

Vimeo · loads on click

Photobox Group Security Team

AppSec Check list Mine Map

Application security encompasses measures taken to improve the security of an application often by finding, fixing and preventing security vulnerabilities. From the risk management strategic point of view, the mitigation of application security risks is not a one time exercise; rather it is an ongoing activity that requires paying close attention to emerging threats and planning ahead for the deployment of new security measures to mitigate these new threats. PDFChecklist mine map

GDPR Audit Checklist

The first steps towards GDPR compliance are understanding your obligations, what your current processes are and identifying any gaps. Undertaking a data protection audit is essential to achieving compliance. This checklist is intended to provide a starting point, rather than providing an exhaustive audit. Download full PDF here
YouTube · loads on click

PhD Project: CyBotic Predator

What is the Cybot, AKA CyBotic Predator : 2018

Here is my 2nd Ph.D research project, CyBotic is an Ultimate Signal Sniffing Predator, which has build in five core functionality's
      1. Air defence system including Drone defence
      2. Sea defence system
      3. Network & WiFi Defences
      4. IDS & IPS
      5. IoT Operations and Intelligence - IoT Innovation There are two reasons why I want to start a PhD on CyBotic Predator. I have a passion for research on signal sniffing domain itself  "i mean hacking", for developing understanding and knowledge. Also, I have a desire to be intellectually challenged and guided by a world expert in this field. My curiosity on this subject is simple can I able to push my limit to build the ultimate cyber defence system just like security orchestration. Visit dedicated site: https://cybotic.io 

2017

Cyberlympic ‘Ethical Hacking’ World Championship

Hackers in the world competed in the Global CyberLympics final during Cyber Security Week in The Hague. This is an international hacking competition aimed at improving the level of national cyber security and strengthening international cooperation. “The competition this year was at the highest level we’ve ever seen due to the relevance of the challenges such as credit card cloning and cryptocurrency mining. The whole event had such amazing energy since it was in the middle of Cyber Security Week here in The Hague. Read More: /cyberlympic/
Vimeo · loads on click

Capture The Flag-HackTheBOX

Hack The Box is an online platform allowing you to test your penetration testing skills and exchange ideas and methodologies with other members of similar interests. It contains several challenges that are constantly updated. Some of them simulating real world scenarios and some of them leaning more towards a CTF style of challenge.
Vimeo · loads on click

Call Offensive Security

Call Offsec they are the very best!..Information Security Training, Ethical Hacking Certifications, Virtual Labs and Penetration Testing Services from Offensive Security, the creators of Kali Linux.
Vimeo · loads on click

0day Exploit for Windows 10 RCE

2016

InfoSec Events

See more about the top security events I have attended. Conferences are important events in almost every industry, giving professionals the opportunity to learn about new developments, get valuable insights from leading experts, and network with other professionals. In few fields do conferences play as important a role as they do in information security. This ever-changing industry places high demands on professionals to stay abreast of the latest best practices, trends, and research findings that impact their day-to-day responsibilities and help them perform at their best. See more

NATO Cyber Defence

Cyber Defence Pledge

Cyber threats and attacks are becoming more common, sophisticated and damaging. The Alliance is faced with an evolving complex threat environment. State and non-state actors can use cyber attacks in the context of military operations. In recent events, cyber attacks have been part of hybrid warfare. Read More

Elastica CloudSOC platform

The Elastica CloudSOC platform enables companies to confidently leverage cloud applications and services while staying safe, secure and compliant. Leveraging advanced data science and machine learning, CloudSOC taps real-time user traffic, native SaaS APIs and other data sources to provide a single pane of glass for monitoring and controlling your SaaS apps.

Akamai Intelligent Platform

Akamai's content delivery network- CDN is one of the world's largest distributed computing platforms, Akamai's Network Operations Command Center (NOCC) is used for proactive monitoring and troubleshooting of all servers in the global Akamai network. The NOCC provides real time statistics of Akamai's web traffic. The traffic metrics update automatically and provide a view of the Internet traffic conditions on Akamai's servers and customer websites. akamai

YouTube · loads on click

Arbor DDoS Solutions!

The Evolution of DDoS Attacks Arbor solutions offer full protection and simplified network management on all interconnected environments. They provide a bigger and better overview, actionnable information and proven protection, ensuring that network threats are detected and neutralised. Availibility of the network is thus guaranteed.

2015

Metasploit

PUT YOUR DEFENSES TO THE TEST, OFFENSIVE SECURITY TEAMS

The Metasploit Project is a computer security project that provides information about security vulnerabilities and aids in penetration testing and IDS signature development. Knowing the adversary's moves helps you better prepare your defenses. Metasploit, backed by a community of 200,000 users and contributors, gives you that insight. It's the most impactful penetration testing solution on the planet. With it, uncover weaknesses in your defenses, focus on the highest risks, and improve your security outcomes.

Decoding Petya Ransomware

Seems I have a decoder for #Petya, but it works only if the system was not rebooted after the infection. Petya Ransomware eats your hard drives.

Petya ransomware eats your hard drives

p2

Ransomware is evolving — fast. The new versions of ransomware use strong asymmetrical encryption with long keys so that files cannot be decrypted without the key. The bad guys have started using TOR and payments in bitcoins for the sake of staying totally anonymous. And now there is Petya ransomware which in a certain sense encrypts the whole hard drive all at once instead of encrypting files one by one.

Source ↗

Fifty Shades of Grey Cyber Lab

It is an art to performing a pen-test. There are various penetration testing methods available. Pen-testing should be an integral part of product SDLC cycle, and You need an Integrated Penetration Testing Tools and a Lab, ReadMore: CyberLab

What Is Red Teaming?

Red Teaming is a process designed to detect network and system vulnerabilities and test security by taking a hacker-like approach to information security system/network/data access. This process is also called "RedTeam Operation -ethical hacking" since its ultimate purpose of the red teams is to enhance security system, either by specifying the adversary’s preferences and strategies or by simply acting as a "Devil’s Advocate". Red Team provides a more realistic picture of the security readiness than exercises.
YouTube · loads on click

Cyber Immune System

Darktrace Experience

Darktrace is a world leader in Enterprise Immune System technology for cyber security. Using new machine learning techniques based on the biological principles of the human immune system, Darktrace addresses the challenge of detecting previously unidentified cyber threats, irrespective of their origin.

NHS WannaCry Attack

I am proud to have co-authored this book. Wannacry Ransomware Crowd Source Intelligence, A free resource created by the global cyber community and This is not the end but rather just the beginning of life-impacting cyber attacks. To download this document and to keep abreast of such initiatives and continue receiving reports and guidance papers please Download here

RedTeam Travel Kit

Malware Detective

Special Ops Project: Threat intelligence researchers hunting various potential spyware, adware, trojans, keyloggers, bots, worms, and hijackers, in real time. The CyberSecurity landscape has changed. No longer are we protecting against a piece of malicious code - we are defending against persistent adversaries. Find out more about APT's or Advanced Persistent Threats. (malwaredetective.co.uk)

2014

Hail MaryToolkit

My Hail Mary toolkit have 3 type of attack mode Attack mode 1: Will able to break WPA2 encryption scheme. Key to the kingdom is to tricking the 4-way handshake, This is achieved by manipulating and replaying cryptographic handshake messages in a fundamental way. Attack mode 2: Detect Long-range RFID's over 100-120m. Attack mode 3: Long-range scanner for contactless smart card (Its embedded integrated circuits can store (and sometimes process) data and communicate with a terminal via 13.56-MHz)
YouTube · loads on click

CyberWar: How can they hurt us?

What damage can cyber attacks actually do? NATO Review asks the White House's former director of cyber infrastructure protection what we should be worried about - and how knowledge of cyber attacks' potential may be more limited than portrayed.
YouTube · loads on click

Photobox Group Hackathon 2018

We've just completed the 5th PhotoBox Group Hackathon! We first time demonstrated my CyBotic Project, AKA CyBotic Predator. I can't wait to kick off. The CyBot Predator idea thrived from the original RedTeam Hail Mary toolkit developed in 2014.

Ministry of Hack

M-O-H Security ecosystem provides comprehensive protection for your it infrastructure based on our unique cyber intelligence and deep analysis of attacks and incident response, along with integrated risk management which reinvent the way you manage risk. Our methodology based on adversary-centric detection and proactive threat hunting. We are military grade cyber threat hunters, with the years of experience in threat hunting.. We know how attackers think and act, and how to use tools to find them and kick them out.Visit: Ministry Of Hack