About us
Built by practitioners who got tired of the report.
L&M was founded on a simple frustration: too much of this industry ends at the finding. We stay until it is fixed.
L&M Cybersecurity started in 2017 with two consultants, one client and a conviction that the standard consulting model was broken. Reports were being delivered, invoices paid, and the same vulnerabilities were still there twelve months later at the next test.
What we changed
We made remediation part of the engagement rather than an upsell. Our engineers sit with your engineers, in your repositories and your consoles, until the finding is closed and the retest passes. That single decision reshaped everything about how we hire and how we price.
Where we are now
Today we are a team of 60 across offensive security, detection engineering, cloud, GRC and incident response, working with organisations across finance, healthcare, industry and government in the Middle East, Europe and North Africa. Our SOC runs continuously and our incident response hotline is answered by a responder, not a switchboard.
What we will not do
We do not sell products we also assess. We do not staff engagements with juniors under a senior name. And we will tell you when you do not need the thing you asked us to quote for — which costs us revenue and buys us clients who stay for years.
By the numbers
0
Consultants
0+
Engagements
0
Monitored estates
0 yrs
Operating
Accreditations
- ISO 27001:2022 certified
- SOC 2 Type II attested
- CREST member company
- PCI DSS Qualified Security Assessor
- Cyber Essentials Plus assessor
How we operate
Four commitments we can be held to.
These are in our contracts, not just on this page.
Independence
We hold no product resale agreements. Our recommendation is never a commission.
Accountability
Named consultants, named owners, dates in writing. You always know who has the ball.
Transferable capability
We build your team up. If we make ourselves less necessary each year, we did it right.
Honest severity
A medium is a medium. We do not inflate findings to justify the invoice.
Leadership
The people accountable for the work.
All four still bill client hours. That is deliberate.
Lina Awad
Co-founder & Managing Director
Former head of security assurance at a regional banking group. Runs our GRC and advisory practice.
Marwan Haddad
Co-founder & Technical Director
Twenty years in offensive security. Still leads two red team engagements a year.
Sara Nasser
Head of Detection & Response
Built our SOC from the first analyst. Obsessive about time-to-acknowledge.
Omar Tarek
Head of Cloud Security
Ex-platform engineer. Believes findings without guardrails are just homework.
Next step
Come and see whether we are as advertised.
Ask for references from clients in your sector. We will connect you directly — no curated case study.