Skip to content
L&M Cybersecurity

About us

Built by practitioners who got tired of the report.

L&M was founded on a simple frustration: too much of this industry ends at the finding. We stay until it is fixed.

L&M Cybersecurity started in 2017 with two consultants, one client and a conviction that the standard consulting model was broken. Reports were being delivered, invoices paid, and the same vulnerabilities were still there twelve months later at the next test.

What we changed

We made remediation part of the engagement rather than an upsell. Our engineers sit with your engineers, in your repositories and your consoles, until the finding is closed and the retest passes. That single decision reshaped everything about how we hire and how we price.

Where we are now

Today we are a team of 60 across offensive security, detection engineering, cloud, GRC and incident response, working with organisations across finance, healthcare, industry and government in the Middle East, Europe and North Africa. Our SOC runs continuously and our incident response hotline is answered by a responder, not a switchboard.

What we will not do

We do not sell products we also assess. We do not staff engagements with juniors under a senior name. And we will tell you when you do not need the thing you asked us to quote for — which costs us revenue and buys us clients who stay for years.

By the numbers

0

Consultants

0+

Engagements

0

Monitored estates

0 yrs

Operating

Accreditations

  • ISO 27001:2022 certified
  • SOC 2 Type II attested
  • CREST member company
  • PCI DSS Qualified Security Assessor
  • Cyber Essentials Plus assessor

How we operate

Four commitments we can be held to.

These are in our contracts, not just on this page.

Independence

We hold no product resale agreements. Our recommendation is never a commission.

Accountability

Named consultants, named owners, dates in writing. You always know who has the ball.

Transferable capability

We build your team up. If we make ourselves less necessary each year, we did it right.

Honest severity

A medium is a medium. We do not inflate findings to justify the invoice.

Leadership

The people accountable for the work.

All four still bill client hours. That is deliberate.

LA

Lina Awad

Co-founder & Managing Director

Former head of security assurance at a regional banking group. Runs our GRC and advisory practice.

MH

Marwan Haddad

Co-founder & Technical Director

Twenty years in offensive security. Still leads two red team engagements a year.

SN

Sara Nasser

Head of Detection & Response

Built our SOC from the first analyst. Obsessive about time-to-acknowledge.

OT

Omar Tarek

Head of Cloud Security

Ex-platform engineer. Believes findings without guardrails are just homework.

Next step

Come and see whether we are as advertised.

Ask for references from clients in your sector. We will connect you directly — no curated case study.