about

Abdullah Bin
Zarshaid

ABZ
Abdullah Bin Zarshaid
Founder & Principal Consultant
CISSPCEHMSc

I am a hybrid cybersecurity leader: technical, compliance-driven, client-facing and business-aware. For a decade I have worked at the intersection of technical security, compliance, service delivery and business risk.

My work spans offensive security, AI and ML security, GRC, SOC leadership and incident response, delivered across international regulated industries including finance, healthcare, government, transport and technology.

I plan and oversee authorized security assessments across web, API, mobile, network and cloud, define scope and rules of engagement, validate findings, and turn them into executive and technical reports leadership can act on. On the governance side I lead ISO 27001, SOC 2, NIST and PCI DSS programs, risk registers, control mapping and audit preparation.

I also build teams. I have delivered security awareness and hands-on training to thousands of people, because most security fails when teams were never shown how attacks actually work.

track record

A decade of measurable impact.

0
TRANSFORMATION PROJECTS
~50%
FASTER DETECTION & RESPONSE
0
USERS TRAINED
0
MAJOR AUDIT FINDINGS

// what i bring

Depth across the whole stack

Offensive security

Manual-led penetration testing across web, API, mobile, network and cloud — mapped to OWASP WSTG, PTES and NIST SP 800-115.

Compliance & GRC

ISO 27001, SOC 2, PCI DSS and NIST CSF readiness — gap assessment, control mapping, evidence and audit coordination.

AI & LLM security

Testing AI-powered products against prompt injection, data leakage and excessive agency — the full OWASP LLM Top 10.

Security leadership

Virtual CISO advisory: risk registers, board reporting, security programme design and vendor assessments.

Incident response

Calm, evidenced handling when it matters — containment, scope assessment, and closure your board can act on.

Hands-on training

Security awareness and technical upskilling delivered to thousands — because teams defend best when they have seen the attack.

my approach

Why I work the way I do

Over a decade in cybersecurity, I saw the same pattern too often: organisations paying for "penetration tests" that were really just automated scans, delivered by juniors, wrapped in a long report nobody could act on. The findings were noise. The real risks stayed hidden.

ABZSECURE exists to be the opposite of that. When you engage me, you work directly with the person doing the testing — not a salesperson, not a rotating team of juniors. Every finding is proven with reproducible evidence. Every report is written to be used: one version your board can read, one your engineers can act on.

I hold CISSP and CEH certifications and an MSc in Computer Networks & Security. But credentials only matter if the work is real. That is why retests are included, evidence is always reproducible, and I would rather report five findings that matter than fifty that don't.

— Abdullah Bin Zarshaid, MSc, CEH