A consulting practice built around real threats, not checklists.
Lion Sec is an independent cybersecurity consulting practice. It works with technology companies that carry real security responsibility and have little or no internal security capacity — and it answers their questions in the order those questions actually matter.
Make security accessible for everyone.
Serious security work — threat modeling, attack path analysis, incident command — has mostly been available to organizations large enough to employ a security team. Everyone else is offered checklists, tooling and the assumption that generic advice transfers.
It usually does not. A company of forty people with one cloud account, a Kubernetes cluster and a small engineering team has a specific threat model, and it deserves the same quality of analysis as a company of four thousand. Lion Sec exists to make that analysis available at that scale: the same rigor, in a form a small team can actually act on.
Real Security First
Most security advice is written for an average company. Yours is not average: it has a particular architecture, a particular business model, particular data and a particular set of people who would find it worth attacking.
Real Security First means every recommendation begins with a threat that is realistic for your organization, and every priority is derived from the risk that threat creates. The reasoning runs in one direction and each step has to earn the next one.
- 01 Relevant threats Who would attack you, and why it would be worth their effort.
- 02 Actual risk What those attacks would reach, and what that would cost.
- 03 Security decisions Which controls and design changes remove that risk.
- 04 Prioritized actions What gets done first, second and third.
What that changes in the work
- Findings are written as attack scenarios and attack paths, not as isolated observations.
- Every recommendation names the scenario or gap it addresses.
- Priorities follow risk reduction and implementation effort rather than framework order.
- Evidence, confidence levels and assumptions are stated, including what remains unknown.
- Recommendations that cannot be traced to a realistic threat do not get written.
Standards still matter
This is not an argument against frameworks. ISO 27001, SOC 2, NIST 800-53 and CIS Controls are useful, and Lion Sec works with them regularly.
The difference is the order of reasoning. A framework is a good vocabulary and a poor starting point: it tells you what controls exist, not which of them would have stopped the attack that is realistic against your company this quarter. The threat model decides the order; the framework describes the result.
Lev Mordvinkov
Cybersecurity Professional and Security Incident Commander
Professional profile on LinkedInLion Sec was founded by Lev Mordvinkov, a cybersecurity professional whose work spans security engineering, threat modeling, infrastructure security, and incident response in fintech and crypto environments.
He has led the response to real security incidents, including sophisticated attacks involving activity attributed to established APT groups; assessed cloud, Kubernetes, CI/CD, and infrastructure-as-code environments for realistic attack paths; and built security controls, detection capabilities, vulnerability management processes, and incident response practices around the risks identified.
That experience shaped Lion Sec’s Real Security First approach: understand how a company can realistically be attacked, identify what makes those attacks possible, and prioritize security work based on meaningful risk reduction rather than generic checklists.
Lion Sec packages this approach into focused engagements for growing technology companies that need security expertise and clear direction without building a dedicated security function first.
What every engagement has in common
The method is the same regardless of which question you start with. It is designed so that the output survives contact with an engineering backlog.
Fixed scope, agreed before the start
Every engagement has a defined scope, a defined duration and a defined set of deliverables. Nothing expands quietly.
No access to your production environment
All three engagements work from documentation, interviews and externally available information. Nothing is scanned, probed or exploited.
Findings carry their evidence
Each conclusion states what it is based on and how confident it is. Your statements are recorded as statements, with the validation they still need.
Two audiences, one analysis
An executive summary written for people who approve budgets, and a technical report written for the engineers who implement the work.
Recommendations are traceable
Every recommendation names the attack scenario or response gap it addresses. If it cannot be traced to one, it does not belong in the report.
The engagement ends with a plan
A 90-day roadmap ordered by risk reduction against implementation effort, with owners and expected effect — not a list of observations.
Bring a real problem to the first call.
The most useful introductory calls start with something concrete: an architecture you are unsure about, an incident that went badly, or a security budget you have to justify.