Consulting & Advisory
How I can help
Independent freelance consulting grounded in real, hands-on practice across cybersecurity, governance and data protection. Engagements are scoped to deliver measurable risk reduction — not slideware. Available remote, onsite or hybrid, from Kuwait. It’s backed by 6+ years across cybersecurity, GRC and financial-crime technology.
Governance, Risk & Compliance
GRC & ISMS
ISMS build-out (ISO 27000), risk assessments, security policy, vendor assurance and AI-governance frameworks that turn standards into day-to-day controls.
Offensive & Defensive
VAPT & Security Testing
Vulnerability assessment and penetration-testing concepts for web apps and cloud — OWASP-aligned reviews, remediation tracking and pragmatic hardening roadmaps.
People & Behaviour
Security Awareness Training
Tailored awareness programs and phishing simulations that measurably change behaviour — the same approach that cut click-through from 15% to 11%.
Privacy
Data Protection & Privacy
GDPR and Kuwait PDPL readiness — data-flow mapping, privacy impact assessments, consent and data-handling controls, retention rules and breach-response planning.
Web & Apps
Web Development
Fast, secure, modern websites and web apps — this site included. Design, build, deployment, hosting and maintenance, with security and SEO baked in from the start.
Advisory
Technology Consulting
Independent, practical guidance — assessments, roadmaps, vendor and technology selection, and hands-on delivery support across security, compliance and digital projects.
How I work
Discover · Design · Deliver
01
Discover
Understand the systems, data, regulatory drivers and the real risk you’re trying to reduce.
02
Design
Translate requirements into concrete rules, scenarios, controls or a training plan — sized to your context.
03
Deliver
Implement, test and hand over with documentation and metrics so the improvement is measurable and audit-ready.