Home About IT Training Consultancy Research Scholarship Gallery Contact
IT Consultancy

Security work that ends with your team able to run it.

Audits, incident response, governance programmes and cloud hardening for banks, telecoms, fintechs and government agencies. Every engagement ends with a handover — dependency is a failure mode, not a business model.

180+
Organisations secured
90+
Enterprise audits
< 4 hrs
Retainer IR response
12 yrs
Average consultant experience
Services

Four ways we engage

Scoped, fixed-outcome work — or an ongoing retainer where you need continuity.

2–6 weeks · on-site + remote

Security Audit & Assessment

We map the estate, test it, and hand back a prioritised remediation plan your own engineers can execute. Findings are ranked by exploitability and business impact rather than raw CVSS, because a critical on an isolated test box matters less than a medium on your payment path.

What you receive
  • Executive summary written for a board, not for engineers
  • Technical findings with reproduction steps and evidence
  • Prioritised remediation roadmap with effort estimates
  • Free re-test of remediated findings within 90 days
Typically for
Organisations facing a regulatory deadline, a customer security review, or a board that has started asking questions.
Emergency callout or 12-month retainer

Incident Response & Retainer

Emergency engagements start within four hours for retainer clients. We contain first, investigate properly second, and give you a written account of what happened that will hold up with a regulator, an insurer or a customer. Retainer clients also get quarterly readiness exercises.

What you receive
  • Containment and eradication, executed with your team
  • Forensic timeline and root cause analysis
  • Regulator- and insurer-ready incident report
  • Post-incident hardening plan
Typically for
Anyone currently in an incident, and any organisation that would rather not negotiate terms mid-breach.
Led by Rajib Islam
6–16 weeks · programme

Governance, Policy & Compliance

We write the policies your organisation will actually follow, define the controls behind them, and build the evidence collection that makes audit season survivable. Where a certification is the goal, we run the gap assessment, the remediation and the readiness review.

What you receive
  • Full policy and standard set, tailored not templated
  • Control framework mapped to your chosen standard
  • Gap assessment and remediation plan
  • Audit readiness review before the external assessor arrives
Typically for
Banks, NBFIs, insurers and any organisation pursuing ISO 27001 or PCI-DSS.
3–10 weeks

Cloud Security & DevSecOps

Most cloud engagements begin with an organisation that moved fast and now cannot answer who can reach what. We rebuild the identity model on least privilege, fix the posture findings, instrument the delivery pipeline, and train your engineers to keep it that way.

What you receive
  • Cloud posture assessment across all accounts
  • Least-privilege IAM redesign
  • Hardened CI/CD pipeline with policy gates
  • Handover training for your engineering team
Typically for
Teams running production workloads on AWS, Azure, GCP or Kubernetes.
1–4 weeks per scope

Penetration Testing

Scoped testing against a defined target with a written rules-of-engagement document agreed in advance. You get reproduction steps for everything, a remediation call with your engineers, and a free re-test once fixes land.

What you receive
  • Rules of engagement and scope document
  • Findings report with full reproduction steps
  • Remediation walkthrough call
  • Re-test of fixed findings
Typically for
Annual compliance testing, pre-launch assurance, or customer-mandated assessment.
Led by Ahmed Khan
Ongoing · monthly retainer

Virtual CISO

A named senior consultant acts as your security lead — owning the roadmap, sitting in leadership meetings, managing vendors and handling regulator or customer questions. Typically two to six days a month.

What you receive
  • Security strategy and 12-month roadmap
  • Board and leadership reporting
  • Vendor and third-party risk management
  • Regulator and customer assurance support
Typically for
Growing organisations with real security obligations but no in-house leadership yet.
Book an appointment

A free scoping call, then a fixed proposal.

Thirty minutes on a call is usually enough for us to tell you whether we are the right people and roughly what the work would cost. No obligation and no sales sequence afterwards.

1

Scoping call

Thirty minutes. You describe the estate and the driver; we tell you what we would actually do.

2

Written proposal

Fixed scope, fixed fee, named consultants and a delivery date. Usually within three working days.

3

Delivery

On-site and remote as the work requires, with a weekly status note so nothing arrives as a surprise.

4

Handover and re-test

Your engineers are walked through every finding, and remediated items are re-tested free within 90 days.

In an active incident?

Do not fill in a form. Call the number below — we answer out of hours, and retainer clients get a responder on the line within four hours.

+880 1700 123 456

Everything else

Book a scoping call and we will put the right consultant on it rather than a salesperson.

Who does the work

The consultants on your engagement

You are told who is assigned before you sign anything. Each name opens a shareable profile.

AK Lead Trainer
Ahmed Khan
Lead Trainer — Network & Offensive Security
OSCP, CEH, CCNP Security
12 years · Penetration testing
View profile
FA Specialist Trainer
Fatima Ali
Specialist Trainer — Web & Cloud Security
GWAPT, AWS Security Specialty, CCSK
10 years · OWASP Top 10
View profile
RI Trainer
Rajib Islam
Trainer — Incident Response & Digital Forensics
GCIH, ECIH, GCFA
11 years · Incident response
View profile
SB Cloud Security Lead
Shahanaz Begum
Cloud Security Lead
CCSK, CKS, Azure Security Engineer
13 years · Kubernetes security
View profile
MH Principal Consultant
Mahbub Haider
Principal Security Consultant
CISSP, CISA, ISO 27001 Lead Implementer
15 years · Security audit
View profile
Clients

Organisations we have worked with

SB Sonali Bank Consultancy client
GP GrameenPhone Corporate training
BB BRAC Bank Audit & governance
RA Robi Axiata IR retainer
BK bKash Application security
CB City Bank Compliance programme
PT Pathao Cloud security
Client feedback

What clients said afterwards

Their audit team found a misconfigured storage bucket and two privilege-escalation paths our previous vendor missed entirely. The remediation plan was practical rather than theatre — our own engineers executed it in three weeks.

SK Shamima Karim CTO · Fintech Platform

We ran the incident response retainer for a year. Mean time to containment dropped from days to under four hours, and the quarterly exercises are the reason the team stayed sharp.

TI Tanvir Islam Head of IT · Telecom Group

The cloud engagement rebuilt our identity model from scratch. Six months on we can still answer who can reach what, which we could not before.

KN Kazi Nazmul Infrastructure Lead · Insurance Group
No obligation

Start with a thirty-minute scoping call.

Describe the estate and the driver. We will tell you what we would do, what it would cost, and whether you actually need us.

Speak to the CEO