Zaid Ahmad seated at a university event

KUALA LUMPUR, MALAYSIA

Cybersecurity,
through a human lens.

I’m Zaid Ahmad, a penetration tester and PhD researcher. I test the systems people rely on, and study why phishing keeps reaching the people behind them.

About

Penetration testing, phishing research, and teaching at APU.

I lead vulnerability assessment and penetration testing at APU’s Forensics & Cybersecurity Research Centre. My work spans web applications, cloud environments, enterprise systems, and operational technology, with a background in digital forensics and security auditing.

Alongside that work, I’m pursuing a PhD in Cybersecurity at Asia Pacific University. I study repeated phishing victimization: how everyday behaviour, psychology, and the way people use their devices can affect their susceptibility to attacks.

I started asking this question after watching the same colleagues fall for near-identical phishing attempts more than once: not from carelessness, but from something more predictable in how attention and habit work under pressure. That gap between what security training assumes and how people actually behave is what my research tries to close.

I also design and teach cybersecurity modules. Moving between assessments, research, and the classroom gives me different ways to examine the same questions about security.

Current role
Lead Penetration Tester, APU FSeC
Research focus
Phishing victimization & cyberpsychology
Teaching
Ethical hacking · Mobile forensics · VAPT
Based in
Kuala Lumpur, Malaysia

Research & Publications

Published work on cybersecurity, human behaviour, and learning.

Understanding Repeated Phishing Victimization Through Psychological Factors and Routine Digital Behavior

Research into the psychological factors and everyday digital behaviours associated with repeated phishing victimization.

View paper on IEEE Xplore (opens in a new tab)

Mitigating Social Engineering Attacks: Psychological, Financial Impact, and a Conceptual Framework for Cybersecurity Awareness

A co-authored examination of social engineering and a conceptual framework for cybersecurity awareness. Published in the Annual Review of Cybertherapy and Telemedicine, starting on page 90.

Read the journal issue (opens in a new tab)

Famous Cyber Attacks in the History of Cyber Security

An early research paper examining well-known cyberattacks, including WannaCry, the Estonia attacks, and the Sony Pictures breach, as material for security education.

Read full paper (opens in a new tab)

Links open the publisher’s page. IEEE full-text access may require an institutional subscription.

Questions behind the work

The themes connecting my research and security practice.

Human behaviour

Why does phishing happen again?

My PhD research examines the psychological, behavioural, demographic, and device-related factors behind repeated phishing victimization, with the aim of developing preventive strategies.

Security practice

What happens after an assessment?

My role covers the full assessment lifecycle, including reporting findings to stakeholders and working with teams on remediation. That context informs the way I teach technical security.

Work With Me

Security assessments, consultation, and training for teams, businesses, and individuals.

Penetration Testing & Security Assessments

Web, cloud, enterprise, and OT security assessments from scoping through remediation. Recent engagements include application-layer testing (SQL injection, authentication bypass, LFI, IDOR) and full digital forensic investigations.

Enquire about an assessment (opens your email app)

Consultations

Advisory sessions for businesses and individuals: security posture reviews, incident guidance, and phishing/human-factor risk assessment grounded in active research, not generic checklists.

Book a consultation (opens your email app)

Training & Workshops

Cybersecurity awareness and technical training for students and non-technical teams. Past sessions include cybersecurity awareness workshops (SMK Taman Desa), digital forensics training (TechXperience), and security leadership training (GreenPhyto Singapore).

Enquire about training (opens your email app)

Experience

From security operations and digital forensics to research and teaching.

Lead Penetration Tester

APU Forensics & Cybersecurity Research Centre · January 2024–present

I lead a team through assessment scoping, testing, and remediation planning across web applications, enterprise systems, and cloud environments.

Research Associate

Asia Pacific University · Jul 2024–Present

Research on phishing victimization, cyber awareness, and preventive strategies. Co-authored work published in IEEE and the Annual Review of Cybertherapy and Telemedicine.

Module Instructor, Cybersecurity

Asia Pacific University · Aug 2024–Present

Design and deliver cybersecurity modules to master’s and undergraduate students.

Career Path Program Manager

Virtually Testing Foundation · May 2022–April 2023

I progressed from security engineering into program coordination and management, helping organise training, onboarding, and security work for an international cohort of interns.

Get in touch

For research collaborations, speaking opportunities, or a conversation about technical security and human behaviour, you can reach me by email or on LinkedIn.