About Mahmoud Lotfy
Mahmoud Lotfy is a cybersecurity consultant and independent security researcher based in Cairo, Egypt. He works with organisations across the Gulf Cooperation Council region on cyber risk assessment, threat intelligence, governance, and security strategy.
Mahmoud began his career as a SOC analyst at TalkTalk, defending UK critical national infrastructure, where he spent two years on the frontline of security operations, developing expertise in security monitoring, alert triage, and threat detection. He then moved into consulting at SecurityHQ, working across more than seven clients simultaneously on incident response, forensic analysis in Arabic and English, threat modelling, and governance frameworks including ISO 27001, PCI DSS, SAMA CSF and NCA.
He is building Excera, a research project into human risk intelligence for the agentic enterprise. Excera is a working prototype that generates a personal, voice-first threat briefing in Arabic and English for every employee, scoped to what they can authorise: moving money, granting access, and approving AI agent actions.
Mahmoud hosts Tencast, an Arabic-language podcast featuring founders, builders, and operators across the Gulf. The podcast focuses on long-form conversations about building businesses in the region, with guests ranging from fintech founders to luxury brand creators and architects.
He holds a BSc (Honours) in Computer Networks and Cybersecurity from Northumbria University. His undergraduate dissertation examined spear phishing vulnerability, specifically whether demonstrating a live attack changes how people respond to future phishing attempts. The research found that single-intervention training, even when realistic, does not fully close the vulnerability gap, and that combining demonstration with repeated exposure and roleplay techniques produces better outcomes.
Mahmoud publishes long-form articles on cybersecurity, risk, and the Gulf market in his writing, covering AI trust and security, threat intelligence, insider threat, the human layer of security, and the cybersecurity compliance landscape across the GCC.