Fresh Start,
Serious Security
We're a cybersecurity startup building the partner we wish existed when we were on the other side — one that leads with honesty, does the actual work, and doesn't charge enterprise prices for startup-sized problems.
Why We Started
We started Underwings because we kept seeing the same problem — businesses buying security tools they didn't need, or getting generic advice that didn't fit their actual risks. The gap between what's sold and what actually protects is wide.
So we're building something different. A small, focused team of certified security professionals who lead with understanding before recommending. We don't push products — we solve problems. Whether it's a penetration test, ISO 27001 implementation, or the right security software, we start by listening.
We're just getting started, operating from the UAE, and working with businesses that want security done right — practical, affordable, and built around real risks, not vendor hype.
Mission & Vision
What we do today, and where we're taking UAE cybersecurity over the next three years.
Honest, practitioner-led cybersecurity for UAE businesses that deserve better than vendor hype.
We exist to close the gap between what's sold and what actually protects. Every engagement — pen test, ISO 27001 implementation, cloud review — is delivered by named, certified practitioners who scope transparently, quote in 48 hours, and prove their work with reproducible evidence.
- Published pricing — no enterprise-sales opacity
- Named OSCP, CPTS, ISO 27001 LA practitioners on every engagement
- Free retest of critical & high findings within 30 days
- Security that reduces real risk, not checkbox theater
By 2028, the UAE's most trusted full-stack cybersecurity partner — from pen testing to SOC, built on reputation, not ad spend.
We're building a three-year phased capability — offensive security and GRC today, managed services and red-team exercises in 2027, and full SOC / DFIR / CTI in 2028 — all delivered from the UAE by a team that stays named on every report.
- 2026Offensive Security, Cloud, Network, GRC, Training — the four operating pillars
- 2027Vendor risk, managed vuln management, red-team exercises, MDR bridge
- 2028SOC-as-a-Service, DFIR, Cyber Threat Intelligence, OT / ICS security
How We Work
Four principles that shape every engagement, every recommendation, every quote we send.
Honest Advice
We recommend what fits your needs, not what has the highest margin. If you don't need something, we'll tell you.
Practical Security
Security that works in the real world. We focus on risk reduction, not checkbox compliance or security theater.
Long-Term Partnership
We're not here for one-time sales. We build relationships and support our clients through their security evolution.
Regional Presence
Operating from the UAE, we understand the compliance landscape, business culture, and threat environment across the region.
The Team Behind Underwings
A small, focused team of certified professionals who do the actual work — no layers, no handoffs.
Cybersecurity consultant leading Underwings' mission to deliver honest, effective security solutions. Specializes in penetration testing, compliance strategy, and cloud security architecture.
Offensive security specialist focused on uncovering real-world vulnerabilities across networks, web applications, and infrastructure. Proven track record on HackTheBox.
Seasoned IT networking professional with deep expertise in enterprise network design, security, and cloud infrastructure. Brings 14 years of hands-on experience to Underwings' networking and infrastructure consulting.
Leads company operations and technology strategy at Underwings, bringing deep full-stack engineering roots to how the business is built and run — from product delivery to quality assurance across every client engagement.
Drives client acquisition and partnership growth across the UAE market. Works closely with prospects to understand their security needs and match them with the right Underwings services.
Manages Underwings' digital presence — from SEO and content strategy to social media and campaign execution. Focused on building brand awareness and generating qualified leads in the cybersecurity space.
Hiring in 2027 — red-team lead, SOC analyst, GRC consultant. See open roles →
Want to Work With Us?
We're always happy to chat — no pressure, no hard sell. Reach out and we'll respond within 24 hours.