Malik Haroon Ahmad & Co. offers a robust portfolio of cybersecurity services, leveraging certified experts (CISSP, CISA, CEH) and partnerships like OpenText-Microfocus. Our solutions include SOC operations, SIEM implementation, penetration testing, PCI-DSS compliance, ISO 27001 implementation, IT audits, application reviews, strategic planning, and threat hunting. We align with global standards (ISO 27001, NIST CSF, OWASP, MITRE ATT&CK) to deliver comprehensive security tailored to your needs, ensuring resilience against evolving threats.
Security Operations Center (SOC)
Our SOC provides 24/7 monitoring and response to cyber threats, leveraging expertise from certified professionals (CISA, CISSP) and advanced tools like SIEM. Operates in line with NIST CSF and ISO 27001 frameworks to ensure comprehensive threat management and risk mitigation.
SIEM Implementation
Partnering with OpenText-Microfocus, we implement Security Information and Event Management (SIEM) systems to centralize and automate security monitoring. Delivered by certified professionals (CISA, CEH), these solutions align with ISO 27001 and SOC 2 standards for enhanced security posture and incident response.
Penetration Testing
Certified Ethical Hackers (CEH) and Offensive Security Certified Professionals (OSCP) conduct simulated attacks to identify vulnerabilities in networks, applications, and infrastructure. Our testing adheres to OWASP Top 10 and PCI-DSS requirements, providing actionable insights to strengthen security.
PCI-DSS Compliance
Our team of Qualified Security Assessors (QSAs) ensures your organization meets PCI-DSS standards for secure payment data handling. Services include gap analysis, remediation support, and compliance certification, aligning with global payment security mandates.
ISO 27001 Implementation and Compliance
Our ISO 27001-certified auditors and consultants design, implement, and maintain Information Security Management Systems (ISMS). The process includes risk assessments, control implementation, and certification readiness, ensuring robust protection of information assets.
IT Audit
Certified Information Systems Auditors (CISA) evaluate IT systems, policies, and controls for compliance with COBIT, ISO 27001, and other international standards. Our audits uncover inefficiencies and risks, providing actionable recommendations to optimize IT governance.
Application Security Review
Detailed assessments of application security by certified professionals (CISM, CEH) ensure compliance with OWASP standards and other best practices. We identify vulnerabilities in software development and deployment to safeguard applications against evolving threats.
Information Strategic Planning
Strategic planning services align your cybersecurity initiatives with organizational goals, leveraging expertise from CISSP-certified professionals. Our methodology incorporates NIST CSF and ISO 27005 to create resilient, future-ready security frameworks.
Threat Hunting
Proactively detect and neutralize advanced threats using expertise from certified Threat Intelligence Analysts (CTIA) and advanced analytics tools. This service aligns with MITRE ATT&CK and ISO 27032 frameworks to uncover hidden risks and ensure system integrity.
Malik Haroon Ahmad is a Fellow Chartered Accountant (FCA) and the founding Managing Partner of MHA & Co. He brings over 28 years of distinguished professional experience, including senior managerial roles at Ernst & Young (EY), where he served multinational and large corporate clients across complex, high-value engagements. His extensive career spans risk management and governance advisory, statutory and external audit, and corporate taxation, with notable expertise in advising entities operating in strategic sectors. Haroon has led landmark mandates for clients associated with CPEC infrastructure and energy projects as well as the Reko Diq mining programme, bringing deep sectoral insight to project risk, regulatory compliance, and financial governance for large-scale resource and infrastructure ventures. His practice philosophy centers on delivering technical excellence with commercial pragmatism, enabling clients to navigate regulatory complexity while building sound governance frameworks. Under his leadership, MHA has grown into a QCR-rated firm affiliated with the UC&CS global network, serving clients ranging from family enterprises to multinational corporations across Pakistan and international markets.