Consulting & Advisory

How I can help

Independent freelance consulting grounded in real, hands-on practice across cybersecurity, governance and data protection. Engagements are scoped to deliver measurable risk reduction — not slideware. Available remote, onsite or hybrid, from Kuwait. It’s backed by 6+ years across cybersecurity, GRC and financial-crime technology.

Governance, Risk & Compliance

GRC & ISMS

ISMS build-out (ISO 27000), risk assessments, security policy, vendor assurance and AI-governance frameworks that turn standards into day-to-day controls.

Offensive & Defensive

VAPT & Security Testing

Vulnerability assessment and penetration-testing concepts for web apps and cloud — OWASP-aligned reviews, remediation tracking and pragmatic hardening roadmaps.

People & Behaviour

Security Awareness Training

Tailored awareness programs and phishing simulations that measurably change behaviour — the same approach that cut click-through from 15% to 11%.

Privacy

Data Protection & Privacy

GDPR and Kuwait PDPL readiness — data-flow mapping, privacy impact assessments, consent and data-handling controls, retention rules and breach-response planning.

Web & Apps

Web Development

Fast, secure, modern websites and web apps — this site included. Design, build, deployment, hosting and maintenance, with security and SEO baked in from the start.

Advisory

Technology Consulting

Independent, practical guidance — assessments, roadmaps, vendor and technology selection, and hands-on delivery support across security, compliance and digital projects.

How I work

Discover · Design · Deliver

01

Discover

Understand the systems, data, regulatory drivers and the real risk you’re trying to reduce.

02

Design

Translate requirements into concrete rules, scenarios, controls or a training plan — sized to your context.

03

Deliver

Implement, test and hand over with documentation and metrics so the improvement is measurable and audit-ready.

Let’s scope your challenge