Most people have sat through a
security talk. Few remember one.
Real research, real attacks and real fraud cases, turned into stories a room actually carries out of the building. Keynotes, panels, workshops and executive briefings.

Md Shariar Shanaz Shuvon
Founder & CEO, AwareXone · Ethical hacker, researcher and trainer
Based in Malaysia, working across Kuala Lumpur, Cyberjaya, Selangor and nationwide. The research is offensive - disclosures to NASA, Google, Meta, Amazon and Sony - but the talks are about the part that keeps working regardless of how good the technology gets: how a person decides under pressure, and what an attacker borrows instead of breaking.
Sessions are story-driven rather than a slide deck read out loud. The measure of a good one is not applause. It is someone on the way out saying they need to go and check something.
Bring me into the room
Keynotes
Opening or closing a conference with one idea the room repeats afterwards.
Conference talks
A single real attack, taken apart slowly, in thirty to forty-five minutes.
Panel discussions
Fraud, AI-enabled scams and human risk, with room to actually disagree.
Corporate awareness sessions
For staff who are tired of being told to be careful online.
University talks
For students deciding whether security is something they could do.
Security community events
Meetups, chapters and CTF crowds. Technical, informal, fast.
Executive briefings
Short and direct, about decisions and authority rather than tooling.
Interactive workshops
Half the room ends up arguing about a message on the screen. That is the point.

4th Annual Asia Anti-Fraud Leaders' Summit & Masterclass
A room of fraud investigators, bank risk teams and compliance leads. People who see the aftermath of this every day and are not easily impressed by a security talk. The three days covered AI-enabled scams, the psychology of fraud, cross-border money movement and the gaps attackers rely on.
When the disclosures hit, they noticed
Coverage across Bangladesh, Malaysia, Qatar and Vietnam of the NASA and Sony disclosures, and of AwareXone itself.

The same talk twice is a wasted afternoon
Executives and developers do not need the same session. Neither do employees and security researchers. Every session gets built around who is actually in the room.
What a convincing message costs the company, and who can authorise their way around a control.
The five seconds before you click, and explicit permission to slow down and ask.
Support flows, password resets, and the helpful reply that hands over an account.
How attacks actually start, and how to get into this field for real.
- Social engineering
- AI-powered scams
- Deepfakes & voice cloning
- Scam psychology
- Human risk
- OSINT
- Security awareness
- Bug bounty
- Red team thinking
Got a room full of people who need to hear this?
Conferences, panels, university events, corporate awareness days and executive briefings. Tell us about the room and we will tell you honestly whether it is a fit.