Zaid Ahmad speaking into a microphone at an event

KUALA LUMPUR, MALAYSIA

Cybersecurity,
through a human lens.

I’m Zaid Ahmad, a penetration tester and PhD researcher. I test the systems people rely on, and study why phishing keeps reaching the people behind them.

About

Penetration testing, phishing research, and teaching at APU.

I lead vulnerability assessment and penetration testing at APU’s Forensics & Cybersecurity Research Centre. My work spans web applications, cloud environments, enterprise systems, and operational technology, with a background in digital forensics and security auditing.

Alongside that work, I’m pursuing a PhD in Cybersecurity at Asia Pacific University. I study repeated phishing victimization: how everyday behaviour, psychology, and the way people use their devices can affect their susceptibility to attacks.

While many of the projects around me focused on building or improving IT systems, I found myself drawn to the people using them. I wanted to understand how psychology, habits, and everyday decisions shape our responses to security risks, especially the human factors that technical work can overlook. That curiosity led me to phishing research: a way to study why people respond to deceptive messages and how a better understanding of behaviour can inform prevention.

I also design and teach cybersecurity modules. Moving between assessments, research, and the classroom gives me different ways to examine the same questions about security.

Current role
Lead Penetration Tester, APU FSeC
Research focus
Phishing victimization & cyberpsychology
Teaching
Ethical hacking · Mobile forensics · VAPT
Based in
Kuala Lumpur, Malaysia

Research & Publications

Published work on cybersecurity, human behaviour, and learning.

Understanding Repeated Phishing Victimization Through Psychological Factors and Routine Digital Behavior

Research into the psychological factors and everyday digital behaviours associated with repeated phishing victimization.

View paper on IEEE Xplore (opens in a new tab)

Mitigating Social Engineering Attacks: Psychological, Financial Impact, and a Conceptual Framework for Cybersecurity Awareness

A co-authored examination of social engineering and a conceptual framework for cybersecurity awareness. Published in the Annual Review of Cybertherapy and Telemedicine, starting on page 90.

Read the journal issue (opens in a new tab)

Famous Cyber Attacks in the History of Cyber Security

An early research paper examining well-known cyberattacks, including WannaCry, the Estonia attacks, and the Sony Pictures breach, as material for security education.

Read full paper (opens in a new tab)

Links open the publisher’s page. IEEE full-text access may require an institutional subscription.

Questions behind the work

The themes connecting my research and security practice.

Human behaviour

Why does phishing happen again?

My PhD research examines the psychological, behavioural, demographic, and device-related factors behind repeated phishing victimization, with the aim of developing preventive strategies.

Security practice

What happens after an assessment?

My role covers the full assessment lifecycle, including reporting findings to stakeholders and working with teams on remediation. That context informs the way I teach technical security.

Work With Me

Security assessments, consultation, and training for teams, businesses, and individuals.

Penetration Testing & Security Assessments

Web, cloud, enterprise, and OT security assessments from scoping through remediation. Recent engagements include application-layer testing (SQL injection, authentication bypass, LFI, IDOR) and full digital forensic investigations.

Enquire about an assessment

Consultations

Advisory sessions for businesses and individuals: security posture reviews, incident guidance, and phishing/human-factor risk assessment grounded in active research, not generic checklists.

Book a consultation

Training & Workshops

Cybersecurity awareness and technical training for students and non-technical teams. Past sessions include cybersecurity awareness workshops (SMK Taman Desa), digital forensics training (TechXperience), and security leadership training (GreenPhyto Singapore).

Enquire about training

Case study

From Security Findings to Verified Fixes

Following website findings through a retest: what changed, what remained open, and why verification matters.

Read the case study

Case study

Reviewing Cloud Administrative Access

Reviewing the access paths around a cloud security control and turning configuration evidence into remediation priorities.

Read the case study

Experience

From security operations and digital forensics to research and teaching.

Lead Penetration Tester

APU Forensics & Cybersecurity Research Centre · January 2024–present

I lead a team through assessment scoping, testing, and remediation planning across web applications, enterprise systems, and cloud environments.

Research Associate

Asia Pacific University · Jul 2024–Present

Research on phishing victimization, cyber awareness, and preventive strategies. Co-authored work published in IEEE and the Annual Review of Cybertherapy and Telemedicine.

Module Instructor, Cybersecurity

Asia Pacific University · Aug 2024–Present

Design and deliver cybersecurity modules to master’s and undergraduate students.

Career Path Program Manager

Virtually Testing Foundation · May 2022–April 2023

I progressed from security engineering into program coordination and management, helping organise training, onboarding, and security work for an international cohort of interns.

Get in touch

For research collaborations, speaking opportunities, or a conversation about technical security and human behaviour, you can reach me by email or on LinkedIn.