Akbar M A — Founder & CEO of Cyronix Dev & Security
25.2048° N, 55.2708° E · DUBAI_HQ · ACTIVE
Founder & CEO — Cyronix Dev & Security
Cybersecurity. Engineering. Systems. Building what comes next.

Akbar M A

Founder & CEO of Cyronix Dev & Security. Architecting resilient digital infrastructure and defending enterprise assets through advanced penetration testing and security-first engineering.

I build what I can defend, and I defend what others have built.
CEH v11 (EC-Council) PayTM Bug Bounty Hall of Fame Kerala Cyber Dome Contributor Dubai, UAE
Scroll to enter narrative
01 / Identity

Who Is Akbar M A?

Executive Summary

Akbar M A is the Founder & CEO of Cyronix Dev & Security, a security-first architect and cybersecurity researcher with a proven track record of building and defending enterprise-grade digital assets. Based in Dubai, UAE, he combines hands-on penetration testing with full-stack engineering to eliminate security vulnerabilities from line zero. His philosophy: "Security by Design" — bridging the gap between creation and protection to deliver infrastructures resilient from line zero.

What I Build

Enterprise web systems, automated vulnerability auditors, real-time threat visualizers, and resilient network topographies hardened from line zero.

What I Care About

Security by Design, defense-in-depth, zero-trust network segmentation, and digital sovereignty under UAE NESA information assurance standards.

How I Work

Offensive research informing defensive architecture. Building software that assumes breach from inception and defending enterprise environments against real-world adversaries.

02 / Story

The Story

From curiosity to defense: the evolution of a cybersecurity architect.

v0.1 ARCHIVED

INCEPTION & CURIOSITY

Kerala, India

System initialized. Core curiosity modules loaded. Early fascination with computing hardware and operating systems — disassembling machines to understand failure modes and how low-level components interact.

v1.0 LEGACY

OPERATIONAL DISCIPLINE

Hospitality & Client Ops · Kerala

Operating in high-pressure environments. Developed acute situational awareness, calm problem-solving under heavy operational load, and clear client-facing communication.

v2.0 MILESTONE

CYBER DEFENSE INIT

RedTeam Hacker Academy · 2022

Formalized offensive and defensive cybersecurity foundations. Completed the Advanced Diploma in Cyber Defence and earned the EC-Council Certified Ethical Hacker (CEH v11) credential.

v2.5 MILESTONE

OFFENSIVE RESEARCH & DISCLOSURES

Offenso & Cyber Dome · 2023–2024

Conducted 50+ manual penetration tests across enterprise web apps. Supported law enforcement digital forensics and achieved official PayTM Bug Bounty Hall of Fame recognition for responsible vulnerability disclosure.

v3.0 MILESTONE

ENTERPRISE HARDENING

BSBG · Dubai, UAE · 2024–2026

Managed IT & enterprise cybersecurity posture at an international architecture firm. Windows Server administration, endpoint defense, and corporate infrastructure hardening in Dubai.

v4.0 ◉ LIVE

CYRONIX DEV & SECURITY

Founder & CEO · Dubai, UAE · Current

Founded Cyronix Dev & Security. Directing enterprise offensive security (VAPT), security header audit systems, and OWASP-compliant zero-trust digital platform engineering globally.

03 / Expertise

Capability Arsenal

Real-world offensive, defensive, and engineering disciplines tested in production environments.

Web Application Penetration Testing

Offensive Security

Comprehensive manual and automated assessments mapping the OWASP Top 10 — uncovering IDOR, broken authorization, SQL injection, and API flaws before malicious threat actors exploit them.

Primary Tooling Burp Suite Pro, OWASP ZAP, SQLmap
Production Deployment Cyronix VAPT, 50+ Enterprise Audits
Standards Compliance OWASP ASVS, UAE NESA IA
04 / Projects

Featured Work & Dossiers

Documented security architectures, public tools, and network defense simulations.

Flagship Architecture & Public Tool

Cyronix Security Auditor

Automated HTTP Security Headers & TLS Configuration Scanner · Deployed Live Worldwide

01 / The Problem

Vulnerable Headers & Weak TLS Exposing Enterprise Web Platforms

Modern web applications routinely expose critical security gaps through missing Content Security Policy (CSP), absent HTTP Strict Transport Security (HSTS), missing clickjacking defenses (X-Frame-Options), and deprecated TLS ciphers — leaving client sessions vulnerable to cross-site scripting and man-in-the-middle attacks.

PENTEST 2024
Vulnerability Assessment Preview

Vulnerability Assessment Report

Comprehensive audit documenting discovered CVEs, attack vectors, and step-by-step remediation across enterprise web infrastructure.

Web AppCVE AnalysisOWASP
View Security Dossier
Impact Scope:

Evaluated production web application hosting confidential client accounts for OWASP Top 10 vulnerabilities.

Technical Breakdown:

Identified Broken Object-Level Authorization (BOLA/IDOR) in customer profile endpoints and stored script injection in account settings.

Remediation:

Enforced server-side session authorization validation, input sanitization routines, and defense-in-depth CSP policies.

SECURE DEV 2024
Secure E-Commerce Platform

Secure E-Commerce Platform

Full-stack storefront built security-first — JWT auth, input sanitisation, CSRF protection, and hardened against OWASP Top 10 throughout.

Next.jsJWT AuthOWASP-Hardened
View Security Dossier
Impact Scope:

Engineered an e-commerce platform architected to prevent inventory fraud, checkout tampering, and credential stuffing.

Technical Breakdown:

Eliminated client-trusted price states with strict server validation. Implemented HttpOnly Secure SameSite cookies and cryptographically signed tokens.

Remediation:

Zero-trust API architecture, database parameterization preventing SQL injection, and granular rate-limiting on authentication routes.

SECURE DEV 2023
Banking Dashboard UI

Banking Dashboard UI

React financial dashboard with XSS prevention, strict Content Security Policy headers, and full OWASP Top 10 hardening baked in.

ReactCSPXSS Prevention
View Security Dossier
Impact Scope:

Financial ledger and transaction telemetry view protected against supply-chain and client-side code execution.

Technical Breakdown:

Hardened against DOM-XSS and iframe embedding attacks (clickjacking) using X-Frame-Options DENY and restrictive CSP directives.

Remediation:

Enforced strict DOM sanitization, eliminated unsafe-eval/unsafe-inline scripts, and restricted subresource origins.

OSINT 2024
Automated OSINT Framework

Automated OSINT Framework

Python toolchain that aggregates open-source intelligence — domain pivoting, email enumeration, and passive fingerprinting in one pipeline.

PythonOSINTAutomation
View Security Dossier
Impact Scope:

Reduces pre-engagement reconnaissance overhead by automating passive asset mapping and attack surface discovery.

Technical Breakdown:

Aggregates certificate transparency logs (crt.sh), DNS records, Shodan intelligence, and Google dorking queries into structured JSON.

Remediation:

Enables proactive vulnerability discovery, catching exposed staging subdomains and leaked credentials before threat actors capitalize.

DEFENSIVE 2023
Firewall Audit Log Analyzer

Firewall Audit Log Analyzer

Bash script that parses raw firewall logs, flags anomalous traffic patterns, and generates structured CSV reports for IR teams.

BashLog AnalysisIncident Response
View Security Dossier
Impact Scope:

High-throughput log analysis pipeline processing gigabytes of raw syslogs to identify active intrusions.

Technical Breakdown:

Detects port-knocking sequences, brute-force SSH attempts, and irregular egress beacons using regex and frequency analysis.

Remediation:

Generates dynamic blocklists formatted for iptables/pfSense and dispatches instant webhook notifications for SOC escalation.

NETWORK INFRA 2023
Cisco Packet Tracer Network and Red Team Simulation

Enterprise Network & Red Team Sim

Corporate multi-subnet topology configured in Cisco Packet Tracer with VLAN segmentation, switchport security, and red team vulnerability testing.

Packet TracerVLANs & ACLsRed Team Testing
View Security Dossier
Impact Scope:

Enterprise campus network simulation testing switchport hardening and defense against internal rogue devices.

Technical Breakdown:

Simulated rogue DHCP attacks, ARP cache poisoning, and unauthorized VLAN hopping across unhardened access switches.

Remediation:

Configured DHCP Snooping, Dynamic ARP Inspection (DAI), and Port-Security with sticky MAC addresses and shutdown violation mode.

05 / Recognitions

Hall of Fame & Disclosures

Verifiable security research credentials spanning responsible vulnerability disclosures, law enforcement cyber intelligence, international defense symposiums, and UAE regulatory compliance.

Law Enforcement Official Support

Kerala Police Cyber Dome

Cyber Intelligence · Volunteer Research

Provided technical intelligence, open-source intelligence (OSINT) recon methodologies, and digital forensics expertise to support law enforcement cyber divisions in tracking malicious threats.

OSINT Intel Digital Forensics Law Enforcement
Commended Contributor
Global Conference Goa, India

Seasides InfoSec Conference

Security Research Delegate · Goa

Offensive security researcher and delegate at the renowned Seasides Information Security Conference in Goa, participating in red team exploitation workshops, hardware villages, and CTFs.

Red Teaming Hardware Villages Research Delegate
Delegate Verified
UAE Authority Dubai, UAE

NESA & Dubai Cyber Strategy

Regional Framework Alignment · UAE

Deep familiarity with UAE National Electronic Security Authority (NESA) Information Assurance Standards and Dubai Cyber Security Strategy, architecting defense compliant with UAE regulations.

UAE NESA IA Dubai Cyber Strategy Enterprise Compliance
Regional Authority
06 / The Lab

The Lab & Arsenal

Real-time posture telemetry, interactive diagnostic console, and verified offensive & defensive tools.

Security Posture 100 / 100 Grade A+ Hardened
HTTP Strict Transport HSTS Active max-age=63072000
Content Security CSP Strict Zero Unsafe Inlines
RFC 9116 Disclosure Verified .well-known/security.txt
Execute in Console [T]:
Burp SuiteOffensive
Web app proxy & active scanner
MetasploitOffensive
Exploit framework & payload delivery
SQLmapOffensive
Automated SQL injection & takeover
HydraOffensive
Online brute-force credential cracker
John the RipperOffensive
Offline password hash cracker
NiktoOffensive
Web server misconfiguration scanner
OWASP ZAPDefensive
DAST scanner & security testing proxy
NessusDefensive
Enterprise vulnerability assessment
pfSenseDefensive
Firewall & network perimeter control
WiresharkDefensive
Deep packet inspection & analysis
NmapRecon
Network discovery & port scanning
MaltegoOSINT
Link analysis & threat intelligence
ShodanOSINT
IoT & exposed services discovery
Recon-ngRecon
Automated web reconnaissance framework
Kali LinuxPlatform
Primary penetration testing OS
Parrot OSPlatform
Privacy-focused security distro
Windows ServerPlatform
AD, Group Policy & hardening
PythonScripting
Automation, OSINT tooling & exploits
BashScripting
Shell automation & log parsing
Git / GitHubDev
Version control & code collaboration
07 / Cyronix

Cyronix Dev & Security

Bridging the gap between creation and protection — an enterprise cybersecurity consultancy.

"We secure what you build — and build what is already secure."

www.cyronixsecurity.com

Offensive Security & VAPT

Rigorous manual penetration testing across enterprise web platforms, APIs, and network perimeters to eradicate high-risk exploit paths.

Web PentestAPI VAPTOWASP ASVS

Defensive Hardening & NESA

Infrastructure hardening aligned with UAE NESA standards, Dubai Cyber Security Strategy, zero-trust network segmentation, and firewall rules.

UAE NESA IAZero-TrustpfSense / AD

Secure Web Engineering

Full-stack Next.js and React digital applications engineered with security from line zero, including strict CSP, JWT rotation, and XSS defense.

Next.js / ReactStrict CSPSecure APIs

Threat Research & Tools

Free, accessible security tooling engineered to advance public cyber awareness, including the Cyronix Security Auditor and Live Threat Map.

Security AuditorThreat MapPublic Tools
08 / Experience

Work Experience

Current Positions
Past Experience
BSBG 2024 – 2026

IT / Cybersecurity Professional

BSBG — Brewer Smith Brewer Group · Dubai, UAE

  • Overseeing IT operations ensuring seamless, secure technical performance within a high-level corporate architecture environment.
  • Managing network security posture, endpoint protection, and infrastructure hardening across the organisation.
Windows Server Enterprise Arch Network Sec
Offenso 03/2023 – 06/2024

Cyber Security Researcher

Offenso Hackers' Academy · Cochin

  • 50+ manual pentests — OWASP Top 10 across enterprise web apps.
  • Network analysis, firewall config & Google Dorking recon.
Kali Linux Burp Suite Nmap OSINT
Cyber Dome 01/2023 – 06/2023

Cyber Security Volunteer

Kerala Police Cyber Dome · Remote

  • Cybersecurity intelligence & technical support to law enforcement cyber divisions.
  • OSINT gathering and digital forensics for cybercrime investigations.
Python OSINT Forensics
I Mate 12/2020 – 12/2022

Hardware/Software Technician

I Mate Solutions · Kothamangalam

  • Diagnosed & resolved hardware, software, and network issues — significantly reducing downtime.
  • OS deployments & system assemblies — contributed to 25% revenue growth.
Hardware Networking OS Deploy
Indus Nexa 01/2022 – 12/2022

Relationship Manager / IT Ops

Indus Nexa Pvt Ltd. · Cochin

  • Directed daily operations & client relations with high customer satisfaction.
  • Primary IT contact — troubleshooting systems and network issues autonomously.
IT Operations Client Mgmt Networking
09 / Services

Cyronix Services

Cyronix_Services.log

[ ACTIVE ] Full-Stack Web Development (Next.js / React)
[ ACTIVE ] Vulnerability Assessments for SMBs
[ ACTIVE ] Secure WordPress / CMS Hardening
[ MONITOR ] E-Commerce Security Integration (VAPT)

Secure by Design

Applications built and penetration-tested from line zero. JWT auth, CSRF protection, WAF integration, and OWASP hardening baked in.

Next.js Node.js OWASP-First

Security Audits

1-on-1 vulnerability consulting and VAPT for businesses. Detailed reports with remediation roadmaps.

Book a Session
10 / Credentials

Certifications

Certified Ethical Hacker

EC-Council

Cybersecurity Penetration Testing
Verify Credentials

TryHackMe

Level: Expert

Top 30% Global Active CTF Player
View THM Profile

Advanced Diploma In Cyber Defence

RedTeam Hacker Academy

Comprehensive training in ethical hacking, incident response, and cybersecurity fundamentals.

arcX

Threat Intelligence

arcX Foundation Level

Security Expert

Offenso Academy

LinkedIn

GRC Foundations

LinkedIn Learning

HackTheBox

HackTheBox

Active Profile

Google Ads Search

Google Certified

Linguistic Capabilities

Multilingual Communication

English · Professional Malayalam · Native Hindi · Working Tamil · Working
11 / Client Trust

Client Trust

"Cyronix conducted a thorough penetration test of our web infrastructure and uncovered critical vulnerabilities before launch. Their detailed report and remediation guidance was invaluable to our team."

RM
Ravi Menon CTO · FinTech Startup, Dubai
★★★★★

"The secure e-commerce platform Akbar built for us has withstood multiple automated attack attempts. The OWASP-hardened architecture gives us real confidence in our security posture every day."

SA
Sara Al-Rashid Founder · E-Commerce Brand, UAE
★★★★★

"Professional, thorough, and security-obsessed. Cyronix identified 12 vulnerabilities in our legacy system that three other auditors had missed. Highly recommended for serious security engagements."

KJ
Khalid Jassim IT Director · Architecture Firm, Dubai
★★★★★

* Testimonials represent genuine client feedback. Names may be anonymised on request.

12 / Knowledge Base

Frequently Asked

Who is Akbar M A (Akbar M.A.)?

Akbar M A (also written as Akbar M.A. or Akbar MA) is a CEH-certified cybersecurity researcher based in Dubai, UAE, and the Founder & CEO of Cyronix Dev & Security. He specialises in penetration testing, vulnerability assessment (VAPT), OSINT, and security-first web development.

What does Cyronix Dev & Security do?

Cyronix Dev & Security is a Dubai-based cybersecurity and secure web development company. Services include penetration testing, VAPT, security audits, incident response support, and OWASP-hardened web application development.

Is there a free tool to check a website's security headers?

Yes — Cyronix's Security Auditor is a free live tool that scans any domain's HTTP security headers and TLS configuration and grades it against OWASP best practice.

Where can I see live global cyber-threat activity?

Cyronix runs a Live Threat Map that visualises real-time global attack activity across regions.

Does Cyronix work with clients outside Dubai/UAE?

Yes. While Cyronix is based in Dubai and familiar with regional frameworks, engagements are delivered remotely for clients globally — penetration testing, VAPT, and secure development work is scoped and reported the same way regardless of location.

What certifications does Akbar M A hold?

Certified Ethical Hacker (CEH v11), with additional practical training including threat intelligence (arcX), GRC foundations, and hands-on offensive security work verified on TryHackMe and Hack The Box.

What cybersecurity services does Akbar M A provide in Dubai and the UAE?

Operating from Dubai, Akbar M A and Cyronix Dev & Security provide web application penetration testing, vulnerability assessment (VAPT), security audits, infrastructure hardening, and OWASP-compliant development aligned with UAE NESA standards.

13 / The Conversation

Let's Build Something Secure

Whether you're exploring a technology idea, security project, software system, or collaboration — start a conversation.

Operating from Dubai, UAE through Cyronix Dev & Security. Available for penetration testing engagements, security audits, and enterprise consulting.

akbarmayakkat11@gmail.com
+971-506167230
+91-7356067042
Dubai, UAE
Available for freelance & full-time roles

Send a Message

THE STORY DOESN'T END HERE
AKBAR M A

Cybersecurity. Engineering. Systems. Building what comes next.