Every system looks safe from the surface.
I test what is underneath. Penetration testing, red teaming and AI security for banks, ministries and digital platforms across Asia. One senior tester, from the first call to the closure letter.
Most pentests look safe from the surface, too.
A scanner export, reformatted.
Four hundred informational items and a new cover page. The business-logic flaws that actually lose money never appear in it.
The tester you met is not the one testing.
Whoever is free that week, often a junior with senior “review”.
Criticals wait for the final report.
Found on day two, reported in week four. Your exposure lasts as long as their template does.
Do you really know what can be reached from the internet?
Portals, wallets, APIs, admin panels and the AI features added last quarter. I find the path to your customer records before someone else does.
I scoped and sold agency pentests for years. I know exactly where they leak.
Four steps, from briefing to closure letter.
Testing runs on UAT or staging. A critical reaches you the day it is found, not at the end.
Thirty minutes. What the system does, what would hurt most if it broke, and what must never be touched.
NDA, authorisation and rules of engagement, already filled in. You sign, we fix the dates.
By hand, on UAT. A status note every day. A critical reaches you the same day, with a mitigation.
Report within three days, then a walkthrough. You fix, I retest free and sign the closure letter.
Pricing. Fixed per engagement, quoted in writing within two working days of the briefing. No hourly surprises. Retest and walkthrough included.
Book the briefingFive findings from real engagements.
In the format you would receive them. Each one was reported, fixed by the client and retested by me. Names removed under NDA.
Full database access through SQL injection
- Component
- Search endpoint, customer-facing portal
- Impact
- Customer credentials, phone numbers and admin records extracted. Write access demonstrated on a single test record, to show how far it actually reached rather than report a “vulnerable parameter” and leave the client guessing what it meant.
- Remediation
- Parameterised queries throughout the endpoint, and a least-privilege database role that cannot write to privileged tables.
Remote code execution on a public government platform
- Component
- File handling, citizen-facing service
- Impact
- Full control of the host serving the public. Any data passing through the service was readable, and the platform could have been used to attack the citizens using it.
- Remediation
- Reported the same day with an emergency mitigation the team could apply immediately, days ahead of the full report.
Payment deposits approved outside the intended flow
- Component
- Deposit approval workflow
- Impact
- Deposits could be approved with no trace in the merchant portal. Direct financial loss, and no audit trail to reconstruct it afterwards.
- Remediation
- Server-side state enforcement across the approval sequence, and an audit record written before the approval is committed.
Private keys exposed by a public-facing service
- Component
- Public-facing service metadata
- Impact
- Recoverable by an unauthenticated user. Enough to impersonate the system and decrypt data it had protected, so the damage reached past the service itself.
- Remediation
- Keys rotated, the exposing response removed, and the storage location moved out of anything the service can serve.
Normal user escalated to Super Administrator
- Component
- Two API endpoints, chained
- Impact
- Full platform control, starting from an account anyone on the internet could create.
- Remediation
- Server-side authorisation checks on both endpoints, and role assignment removed from anything a client can influence.
Three deliverables, all in the fixed price.
Findings, with proof
Manual testing of your logic, your roles and your workflows. Every finding comes with a working proof of concept, not a theory.
Not a scanner export with 400 informational items.
A report for two readers
Page one for the board. The rest for your engineers: CVSS, steps to reproduce, evidence and the fix.
Not a 90-page PDF nobody reads.
A closure letter for your auditor
You fix. I retest, free. Then I sign a closure letter you can file with NBC, ISO 27001 or PCI DSS.
Not “retest available at additional cost”.
Twenty-five scopes, one accountable tester.
Each one written against a published standard: OWASP ASVS and MASVS, PTES, NIST SP 800-115, MITRE ATT&CK and ATLAS.
Applications
- Web applicationPortal, admin panel, e-commerce
- Mobile appiOS & Android
- APIREST, GraphQL, partner integrations
- AI / LLM featureChatbot, RAG search, agents
- Smart contract auditSolidity, Move, Rust
Infrastructure
- External networkEverything the internet can reach
- Internal network & ADOffice network, Active Directory
- CloudAWS / Azure / GCP
- KubernetesCluster and workloads
- Vulnerability assessmentWhole estate, triaged by hand
- Attack-surface monitoringContinuous, alerts on change
- Blockchain platformNodes, custody, exchange
- IT infrastructure auditAgainst NBC, ISO 27001, CIS
Configuration & code
- Source code reviewManual, with the developers
- Host configurationServers against a CIS baseline
- Firewall configurationRule base and segmentation
- Cloud configurationAWS accounts against CIS Benchmarks
- System hardeningPlan, apply, verify
People & programme
- Phishing & awarenessCampaign plus the session after
- Red teamWould you survive a real attack?
- Compliance pentestNBC, ISO 27001, PCI DSS
- Executive briefings & tabletopsDecisions rehearsed, not improvised
- Purple teamDetections written in the room
- Vulnerability managementFindings tracked to closure
- Incident response retainerSigned before you need it
One tester. The name on the report is the person who did the work.
Six years attacking systems with permission. Core banking and mobile wallets at national-payment scale. Ministry platforms in live production. Gaming and e-commerce, where a logic flaw is a direct financial loss.
I led testers and priced engagements at a regional firm, so I know where agencies cut corners. I lecture at ITC, coached a national-CTF runner-up team, and have briefed close to a thousand officials. Phnom Penh based, working in Khmer and English. Mehsao (មេសោ) is Khmer for master key.
- Since 2026Cybersecurity Lecturer · Institute of Technology of Cambodia
- Since 2025Senior Penetration Tester · Loma
- 2025–26Penetration Tester Lead · MISTI: public-service systems in production
- 2022–25Security Engineer & PreSales Lead · Veilron: engagements across Asia
- 2021–22Cyber Risk Advisory · Deloitte: Bakong wallet, core banking & paygate code review
Team certifications
Tell me what worries you.
Test plan and fixed price in two working days. I reply within one working day, and the redacted sample report is yours either way.