ShadowSec Lab

Practice

A small lab. Senior operators. No theatre.

ShadowSec Lab opened in 2019 because too many “security tests” were scans with a letterhead. We kept the firm small so principals still read scopes, sit in kickoffs, and write the executive letter.

We work with fintech, health, SaaS, and investment firms that need evidence for boards, buyers, and engineers. We decline work that is unlawful, theatrical, or better solved with a scanner.

ShadowSec Lab lobby

2019

Practice founded in London

5 principals

Named on every statement of work

12 countries

Remote testing under local counsel where needed

The people who do the work

Full team →
Amara Okonkwo

Amara Okonkwo

Managing Principal

Kenji Sato

Kenji Sato

Principal, Offensive Security

Lucía Herrera

Lucía Herrera

Lead, Application Security

Marcus Hale

Marcus Hale

Lead, Incident Response

Priya Mehta

Priya Mehta

Principal, Cloud Security

Next step

Tell us what you need answered.

A 30-minute scoping call is enough to know whether a pentest, a cloud review, or a retainer is the right buy. We will say if it is not.