A small, senior cybersecurity practice — built for organizations that need real expertise, not consulting theater.
Why Qhalent exists
The cybersecurity consulting market is well-served at the top — large firms with thousands of consultants — and well-served at the bottom — generalists who'll attempt any work for the right price. The middle is the problem. Organizations that need senior expertise, applied thoughtfully, at sensible rates, often can't find a firm that's small enough to care and serious enough to deliver.
We started Qhalent to be that firm. Senior practitioners, taking on a small number of engagements at a time, doing work we'd be proud to have audited. Compliance certifications, security advisory, and assurance — done with operational substance, not paperwork performance.
The partners
Muhammad Khan
Muhammad has spent two decades in IT and cybersecurity. His career began working with leading telecommunications operators as a consultant. He later joined a European telecommunications company with global presence, where he led architectural projects across multiple markets. He then moved to a global investment bank, before joining an Australian consulting firm.
For seven years, he led cybersecurity consulting and managed security services at the Australian firm, working with enterprise clients across the Asia Pacific region on risk assessments, security maturity reviews, compliance gap assessments (ISO 27001, PCI DSS, NZISM), security operations, and cloud security architecture.
His current focus is on cybersecurity for critical infrastructure and regulated environments — supply chain cyber risk assessments, vulnerability management programmes, cloud security governance, and security vendor due diligence.
Credentials: CISSP, CCSP, and CISM, with additional certifications across cloud security (Microsoft Azure, AWS, Google Cloud) and security operations.
Based: Between the UAE and Pakistan.
Service Reach: Asia Pacific, Middle East, and Africa.
Hamid Khan
Hamid has spent over fifteen years in IT and cybersecurity, with deep expertise in governance, risk, and compliance. His career began in systems and data center engineering — managing IT systems for major technology and telecom outlets.
Over the past decade he moved fully into cybersecurity, leading security operations centers, building enterprise risk management frameworks, and running governance and compliance programs for large technology organizations across Pakistan. His work has spanned SOC leadership, ISO 27001 audit preparation and certification, security policy development, incident response, vendor risk management, and organization-wide security awareness programs.
Specializations: GRC, security operations, ISO 27001 implementation and audit readiness, enterprise risk management, security awareness, and incident response.
Based: Lahore, Pakistan.
Arslan
Arslan brings over twelve years in software engineering, solution architecture, and cloud infrastructure, leading technical teams across SaaS, healthcare, fintech, and enterprise platforms. His career spans hands-on development through engineering leadership — architecting and scaling high-growth systems, including a large-scale fintech platform serving over a million registered users.
More recently his focus has been secure platform engineering and cloud operations: defining architecture standards, managing AWS infrastructure, DevOps, and scalability, and leading delivery of enterprise software — including a next-generation firewall and SIEM platform and a healthcare learning application. He pairs deep full-stack engineering (Node.js, Next.js, React, cloud-native architectures) with a security-first approach to system design.
Specializations: software engineering, solution architecture, cloud infrastructure (AWS), DevOps, secure platform development, and full-stack delivery.
Ali Iqbal
Ali leads project delivery at Qhalent Cyber LLP, ensuring that client engagements run on time, on scope, and to the standards the firm commits to.
His background combines project management discipline with the operational mindset required to coordinate complex multi-stakeholder engagements. He brings the kind of execution focus that's essential when the firm is committing to compressed timelines and specific deliverables.
Based: Islamabad, Pakistan.
What we believe
Compliance should reduce risk, not perform it.
The most expensive compliance work is the kind that produces documents nobody reads and controls nobody runs. We design programmes the way we'd want them designed if we had to operate them — because we have, and because we will.
Senior expertise should be accessible.
Senior security practitioners are not a luxury good. We work at rates that make serious expertise viable for organizations that genuinely need it — without subsidizing layers of overhead.
Honesty in scope beats expansion of scope.
We turn down work we're not the right fit for. We tell clients when a control doesn't need implementing as written, when a problem doesn't need solving with our service, when their existing team is already doing the work. Long-term trust beats short-term billing.
Small is a choice.
We work with a small number of clients at a time, by design. Scale dilutes the relationship and the work. We'd rather do fewer engagements with the people whose problems we can solve than more engagements at the cost of either care or substance.
Where we work
Qhalent Cyber LLP is registered and headquartered in Islamabad, Pakistan. We work with clients globally — primarily across the UAE, GCC, UK, EU, and North America — delivering remotely with on-site engagement where needed.
Our partners hold UAE residency and travel to client engagements on request. We work in English and Urdu.
For partnerships, media, or speaking inquiries
info@qhalent.comFor security disclosures
security@qhalent.comWant to work with us?
Start with a 30-minute conversation. We'll figure out together whether we're the right fit.