German & Egyptian · PhD, Cloud Security · Technical University of Darmstadt

Ahmed Taha

I take regulated companies from security gap to audit-ready — and build the function that keeps them there. Gulf & EU.

Senior Security Manager & Acting CISO Unifonic — security strategy, governance and incident response for a regional CPaaS platform

Professor, Computer Science & Cyber Security IU Internationale Hochschule, Germany — course design, teaching, and supervision of bachelor and master theses

Available for advisory & consulting · Gulf & EU

Ahmed Taha
Practice13 yrs
Doctorate2018
Citations475 h-index 11
Funded projects5

How I help

Advisory & consulting · Gulf & EU

Cloud compliance readiness

Take an organisation to audit-ready against the frameworks that actually apply — NCA (ECC & CCC), SAMA CSF and PDPL in the Gulf; GDPR and NIS2 in the EU — mapped onto ISO 2700x and NIST so one control set answers all of them. Gap assessment, control mapping, and the roadmap to certification.

NCA · SAMA · PDPL · ISO 2700x · NIST · SOC 2 · GDPR · NIS2

Virtual CISO & program build

Stand up or mature a security function the way I built Unifonic's from the ground up — governance, enterprise risk, incident response, and the team behind it. Delivered as a fractional CISO or a fixed-term engagement.

vCISO · GRC · risk · incident response · board reporting

Cloud security architecture & review

Assess and harden production estates across AWS, Azure, GCP and OCI — exposure, identity, egress and the control stack (SIEM, IAM, WAF, DLP, Zero Trust), grounded in a decade of research on quantitative cloud-security assessment.

AWS · Azure · GCP · OCI · threat modelling · Zero Trust

AI security & AI governance

Put controls around the AI you are already shipping. Threat modelling for LLM and agentic systems — prompt injection, tool abuse, data leakage and model supply chain — mapped onto the EU AI Act, ISO/IEC 42001 and the NIST AI RMF, with the conflicts between those rulebooks resolved rather than ignored. This is the subject of my current research.

EU AI Act · ISO 42001 · NIST AI RMF · SDAIA · OWASP LLM Top 10

Courses, academies & enablement

I design and deliver cyber security curricula for a living — as a professor at IU Internationale Hochschule and previously as a co-lecturer at TU Darmstadt. The same work for your organisation: a corporate security academy, a role-based training track for engineers, or an executive and board-level briefing. Built to your stack, delivered on-site or remotely, in English, Arabic or German.

curriculum design · corporate academy · secure development · board briefings

Digital transformation & secure modernisation

Large modernisation programmes fail at the seams — identity, data residency, legacy integration and the governance nobody owns. I lead that work end to end on national-scale and enterprise digitalisation programmes: target architecture, cloud and data foundations, the security and compliance layer, and the local capability needed to run it after handover.

target architecture · cloud migration · data residency · capability build

Signature work

The parts that are hard to find anywhere else

TU Darmstadt · EU H2020 · SAP Germany · 2013 — present

Cloud security measured, then actually delivered

My doctorate and five EU-funded projects produced a quantitative way to rank and compare providers' security — AHP-based assessment and machine-verifiable security SLAs. I then spent three years at SAP in Germany doing the cloud digitalisation itself: enterprise multi-cloud design, the controls underneath it, and the SOC 2 and GDPR audits that followed.

  • 475citations
  • 5EU-funded projects
  • SAPenterprise cloud delivery

Gulf + EU · 2023 — present

Two rulebooks, one control set

NCA, SAMA, PDPL and the CST CRF on one side; GDPR and NIS2 on the other — with ISO 2700x and NIST as the common library underneath. I run both regimes from that one control set rather than two parallel programmes, and hold the certifications sitting under it.

  • 100%CST CRF
  • 2regimes, one library
  • ISO 2700xNIST · CSA STAR · SOC 2

Published 2026

A framework for resolving AI compliance conflicts

The EU AI Act, ISO/IEC 42001 and the NIST AI RMF contradict each other in practice. My 2026 paper sets out how to decide when they collide — and I turn that into working controls for LLM and agentic systems.

  • 3regimes reconciled
  • 2026new paper
  • LLM+ agentic scope

Fraunhofer SIT · TU Darmstadt · 2012 — 2013

Security that ships inside the device

An open smartphone-based car immobiliser and secure offline Bitcoin payments over NFC — cryptographic protocol work on real hardware, years before either problem became fashionable.

  • 79citations, ACM CODASPY
  • NFChardware-level
  • Key2Shareopen framework

Practice

Security leadership, architecture and governance

  1. Aug 2023 —
    Present

    Senior Security Manager & Acting Chief Information Security Officer

    Unifonic · Egypt

    Direct the organisation's security strategy and enterprise risk and governance programme, lead the incident response team, and own adherence to ISO 27001, CSA STAR, SOC 2 and the Saudi regulatory set — PDPL, SAMA and NCA. Evaluate and operate the control stack: SIEM, IAM, WAF, DLP and Zero Trust architecture. Report cybersecurity posture and strategic risk to the board.

    • Reduced security risk by 76% across 2025 and 2026 through advanced threat detection and prevention.
    • Achieved 100% compliance with the CST Cybersecurity Framework (CRF).
    • Built the company's first dedicated security team from the ground up, with defined career paths and mentorship.
  2. May 2023 —
    Jul 2023

    Cyber Security Senior Manager

    PwC ETIC · Egypt

    Advised clients on cybersecurity strategy and posture, managed and mentored a team of analysts, engineers and consultants, and defined the KPIs used to measure whether the controls were working.

  3. Jan 2022 —
    Apr 2023

    Senior Security Consultant & GRC Specialist

    RSA · Egypt

    Architecture and strategy across on-premise and SaaS estates — NGAV, firewall-as-a-service, EDR, vulnerability management, IAM, SIEM and secure cloud implementation. Led GRC initiatives and control implementation against PCI-DSS, PCI-3DS, ISO 27001/2 and NIST 800-53, and built the business unit's cloud security strategy and maturity plan.

  4. Sep 2018 —
    Dec 2021

    Senior Security Architect & IT Business Services Senior Consultant

    SAP · Germany

    Worked on enterprise cloud digitalisation programmes — designed and implemented cloud security solutions for clients across multi-cloud environments, ran security risk assessments and the resulting controls, and supported internal and external audit for SOC 2 and GDPR. Engaged the full stakeholder spectrum — customers, prospects, partners and SAP development teams — on security.

Teaching & research

Running in parallel with practice since 2012

  1. Apr 2022 —
    Present

    Professor

    IU Internationale Hochschule GmbH · Germany

    • Design and teach computer science and cyber security courses.
    • Supervise bachelor and master graduation projects.
  2. Aug 2013 —
    Apr 2018

    Security Researcher

    DEEDS security research group, TU Darmstadt · Germany

    Co-lecturer for Security and the Cloud — The Issues and Metrics with Prof. Neeraj Suri. Doctoral research on quantitative trust assessment in the cloud, alongside work on decentralised runtime monitoring over Ethereum smart contracts, encrypted security SLA verification, and an open-source Security-as-a-Service and Monitoring-as-a-Service framework built on CSA STAR data.

  3. Apr 2012 —
    Jul 2013

    Security Researcher

    Center for Advanced Security Research Darmstadt (CASED) · TU Darmstadt

    Secure, time-efficient offline bitcoin payments over NFC, and an open smartphone-based car immobiliser architecture with the security framework underneath it.

Standards & regulation

Two rulebooks at once

Operating a platform from Saudi Arabia means satisfying both the international frameworks that enterprise buyers and auditors expect, and the national mandates the regulators actually enforce. Most security leaders know one set well. I run both.

Saudi mandates enforced locally

NCA ECC & CCC
National Cybersecurity Authority — the Essential Cybersecurity Controls baseline, plus the Cloud Cybersecurity Controls that govern how regulated workloads may sit with a cloud provider.
CST CRF
Communications, Space & Technology Commission — the Cybersecurity Regulatory Framework binding licensed ICT and communications providers. Took an organisation to 100% compliance.
SAMA CSF
Saudi Central Bank — the Cyber Security Framework required of banks, insurers and payment firms, and therefore of anyone serving them.
PDPL
Personal Data Protection Law — the Kingdom's data protection regime: lawful basis, data subject rights, residency and cross-border transfer conditions.

International frameworks what buyers audit

ISO/IEC 27001/2
Certified information security management system and the control guidance underneath it.
SOC 2
Trust Services Criteria attestation — the report enterprise customers ask for before they sign.
CSA STAR
Cloud Controls Matrix and the STAR registry — also the dataset behind my doctoral research on cloud trust.
PCI-DSS & PCI-3DS
Cardholder data protection, and the 3-D Secure environment requirements on top of it.
NIST 800-53
Control catalogue used as the common library when frameworks have to be mapped to one another.
GDPR
EU data protection, from the SAP and audit-support years onward.

Technical competencies

What I work with day to day

Cloud
AWS · Microsoft Azure · Google Cloud · Oracle Cloud Infrastructure
Security tooling
CrowdStrike · Orca · Wiz · Prisma Cloud · Qualys · Devocean · Mesh Security · SentinelOne · Archer · SolutionManager · Sysdig · Semgrep · Snyk
AI security
LLM and agentic-system threat modelling, prompt-injection and tool-abuse controls, model supply chain, AI governance under the EU AI Act, ISO/IEC 42001 and the NIST AI RMF
Governance
Enterprise risk assessment, GRC programme management, board-level reporting, security awareness and team building
Teaching
Curriculum design, lecturing and thesis supervision at bachelor and master level · Arabic, English and German

Research record

Google Scholar · 475 citations · h-index 11 · i10-index 13

Selected publications 6 of 20 · most-cited

  1. 2015 J. Luna, A. Taha, R. Trapero, N. Suri. Quantitative Reasoning about Cloud Security Using Service Level Agreements. IEEE Transactions on Cloud Computing 5(3). 102 cited
  2. 2013 C. Busold, A. Taha, C. Wachsmann, A. Dmitrienko, et al.. Smart Keys for Cyber-Cars: Secure Smartphone-based NFC-enabled Car Immobilizer. Proc. 3rd ACM CODASPY. 79 cited
  3. 2014 A. Taha, R. Trapero, J. Luna, N. Suri. AHP-Based Quantitative Approach for Assessing and Comparing Cloud Security. Proc. 13th IEEE TrustCom. 66 cited
  4. 2016 J. Modic, R. Trapero, A. Taha, J. Luna, M. Stopar, N. Suri. Novel Efficient Techniques for Real-Time Cloud Security Assessment. Computers & Security 62. 41 cited
  5. 2017 R. Trapero, J. Modic, M. Stopar, A. Taha, N. Suri. A Novel Approach to Manage Cloud Security SLA Incidents. Future Generation Computer Systems 72. 40 cited
  6. 2026 A. Taha. A Framework for Resolving AI Compliance Conflicts. new
View full profile on Google Scholar →

Funded research projects

Speaking

  • Black Hat MEA — RiyadhNov 2024
  • Falling Walls — BerlinDec 2021
  • AsiaCCS — Xi'anMay 2016

Doctorate

  • PhD, Cloud Security — TU Darmstadt2013–2018
  • Thesis: Quantitative Trust Assessment in the Cloud