Studying security is not the same as doing it.

1:1 mentorship into pentest, VAPT and red team work. Beginner or halfway there, the plan starts with a diagnosis of where you actually are.

Free, and nothing gets booked or charged. Or ask on WhatsApp first.

9+years in practice
1,600+instruction hours
10countries
20+organisations trained
  1. We talkA call. I tell you honestly whether I can help.
  2. I diagnoseA short intake: what you know, what you have tried, where you stopped.
  3. We workYour plan, live sessions, marked assignments, interview prep.

Starting points

Find your starting point

People arrive here from very different places and need very different plans. Open the one that sounds like you.

New to cybersecurity, starting from zero
Missing
A starting point, and a way to tell useful material from noise.
We start with
Networks, Linux and how the web really works, in the order you actually need them.
Ready means
You work a target end to end on your own, without being walked through it.
Coming from IT, support or development
Missing
Security fundamentals, and a lab habit you actually keep.
We start with
Foundations, a weekly lab, and notes an engineer could follow.
Ready means
You find a real vulnerability on an unfamiliar target and explain why it matters.
Certified, but never tested anything live
Missing
Hands. The vocabulary is there; the target is not a walkthrough.
We start with
Live targets under time pressure, starting inside your depth.
Ready means
You work an unfamiliar target to a finding with nothing open in the next tab.
Moving from SOC or GRC into offensive work
Missing
The offensive method. It does not transfer from defensive work.
We start with
The method for the domain you are entering, and nothing you already carry.
Ready means
You run the core workflow end to end and hold your own in its interviews.
Intermediate, stuck below professional
Missing
Depth, and delivery. You find things; the write-up does not carry them.
We start with
Advanced technique, plus report writing trained as its own skill.
Ready means
You produce a report a client signs off without rework.

People are frequently not in the row they assume. The intake is what settles it.

Method

Diagnose first. Then mentor.

The same sequence an engagement follows: scope what is there before deciding what to do about it.

Intake

A structured questionnaire, before anything is planned or priced.

Your plan

Written from the intake, not pulled off a shelf. Duration and cost become knowable here.

Live 1:1 sessions

Direct time with me, not a batch of thirty. You bring what you are stuck on.

Accountability

Assignments with real deadlines, which I read and mark.

Interview prep

Resume, portfolio and interview practice for the role you are targeting.

Fit

Who this is for

Worth being direct before either of us spends time on an intake.

This is for you if

  • You want to work in security and cannot do the job yet, whether that is from scratch or from halfway.
  • You can attend live sessions on IST hours.
  • You want a plan built around where you are, not an eight-week outline.

This is not for you if

  • You want a certificate. EC-Council, CompTIA, etc. are not included.
  • You want a watch-along course. There is work between sessions.
  • You need a fixed price before you begin. Pricing follows the intake.

Background

Who you would be working with

Mentorship is a small part of my week. The rest is the work I would be teaching you to do.

Certifications held

CEH Master certification CPENT certification LPT Master certification CHFI certification Certified EC-Council Instructor ISC2 Certified in Cybersecurity WAHS certification

Questions

Questions people ask first

Including the two everyone wants answered before anything else.

Who is this for?

Anyone who wants to work in cybersecurity and cannot do the job yet. That covers people starting from nothing, students, people who finished a bootcamp or institute program, and working professionals moving over from IT, SOC or GRC. The one hard requirement is that you can attend live sessions on IST hours.

How long does it take, and what does it cost?

Both are set after I read your intake. Someone moving between security domains often needs about a month, someone coming from general IT needs considerably longer, and someone starting from nothing needs longer still. If you need a fixed number before any conversation, this is genuinely not the right program.

Do I need an IT background to start?

No. Some people arrive with years of IT behind them, some arrive with nothing but the decision to change careers. The intake tells me which, and the plan starts wherever that is. Starting from zero means a longer road, not a closed one.

Does this include certification?

No. EC-Council, CompTIA, etc. are not included. If a specific job requires one, we can plan for it separately. What this builds is the practical capability those programs often do not.

How is the plan decided?

Diagnosis before curriculum. The intake establishes what you know, what you have tried, where you stopped, and what "job-ready" means for the role you are targeting. The plan is written from that.

What is ShopEasy?

A hands-on API security lab I built and maintain: the same e-commerce app in a vulnerable and a fixed version, covering BOLA, JWT flaws, broken authentication and debug data leaks. Free and public: see the lab, or browse the rest at labs.sarathg.me.

What happens between sessions?

Assignments with real deadlines, which I read and mark. This is the piece most programs skip, and the reason most people who enroll elsewhere never finish.

How do I start?

Book a call, or send the questionnaire if you would rather start in writing. Both routes end at the same place, and pricing is shared once I have read your intake. Quick question first? WhatsApp is fastest.

Start with a conversation.

Either route ends in the same place: a plan built around your actual starting point.

Or ask a question on WhatsApp first.