
The State of Cybersecurity in Lebanon, To where?
Back then when I heard about Cybersecurity, I was in High School. To be honest, I heard that a person in my region was a professional in hacking. I was curious to know: what is cybersecurity and what is hacking? But to be honest, I was fully focused on Mathematics, Physics, and becoming a successful...
- Author
- Hassan AL ACHEK
- Published
- JUL 8, 2026
- Reading time
- 9 MIN
- Views
- 133 views
Introduction:
Back then when I heard about Cybersecurity, I was in High School. To be honest, I heard that a person in my region was a professional in hacking. I was curious to know: what is cybersecurity and what is hacking? But to be honest, I was fully focused on Mathematics, Physics, and becoming a successful mechanical engineer to work later on with Airplane mechanics 😆.
So I just ignored that. And also at this phase, I did not have a personal laptop, nor a personal phone.
Back then we did not have those "academies," nor cybersecurity training in Lebanon (it might have existed but I did not know about it), but I can confidently say "Lebanese" cybersecurity resources were so limited. But today, we are full of cybersecurity ads, reels on Instagram... dozens of academies, dozens of cybersecurity "influencers" experts (experts in influencing tbh).
So I decided to share this post with you at the end of the year, to share my honest opinion, my point of view of the cybersecurity state in Lebanon, what we are doing wrong, where we will land due to the "Transforming cybersecurity in Lebanon" lie, and the exploitation of Lebanese emotional state we live in every day.
The state of cybersecurity now in Lebanon:
Our government doesn't have an actual cybersecurity plan, and all that talk on TV mentioning cybersecurity is just to mention it. That's it, as it's a fancy word so who shouldn't mention it guysss.
But let's put our feet on the ground. When it comes to cybersecurity, our government is below zero in the real application of cybersecurity. I don't need to mention all the cybersecurity attacks we suffered from just last year. I don't even need to mention how many unmentioned, unpublished cybersecurity attacks happened silently, were remediated silently, and happened again and again (even after responding to the incident, you can imagine the expertise of people who worked on those incidents ;) let's put a hundred lines under expertise).
Almost all universities in Lebanon have vulnerabilities on their systems (Infra level, Application Level, ...). I don't want to enter into a discussion related to that, but yeah, the reality is a bit shocking when a university charging students thousands of dollars still can't upgrade an application they use or patch a known vulnerability. So yeah, and what pisses me off is that they sometimes teach cybersecurity. Oh yeah, "the trainer doesn't need to play."
So yeah, I did not mention those startups, medium, and large-size companies who treat security like an option, an audit done by a Big 4 (I don't want to talk about Big 4 especially in cyber because I don't want to end up being sentenced by law :) so I will keep my opinion to myself). And even some of them rush to integrate AI into their applications and buzz the world (oh goddd) with the word AI, and guess what :) they hardcode the API key of OpenAI into their application frontend, yeah, and also rely on client-side for validation (Btw thank you guys for the free tokens <3).
Also I don't want to exclude local cybersecurity companies who are selling clients AV/EDRs/IDS/SIEM like brokers and that's it. Yeah man, if you have all of these you are secure trust me bro (yeah yeah like a broker). Also those who offer Pentesting services after watching a TCM training, launching Responder and yeah trust us bro, your self-signed certificate gonna f* your company up by hackers!! And yeah your CSP missing header gonna let hackers ransomware your company, and guess what the apache version exposed gonna give attackers root access into your servers!!
We are fu*ed up, and that's not the problem of Lebanon only. Even outside Lebanon, I see a lot of those companies who do "pentest" as a service (Or I don't know, we call it LAAS I will let you guess what it means ;)).
How I see the state of Lebanon with all these academies rising for cybersecurity training?
You might think cybersecurity will be better in Lebanon, and that cybersecurity in Lebanon will change, and those dramatic words.
But nah. Let's say why?
Okay so basically we are seeing a rise in cybersecurity training academies, that normally means we will see a rise in cybersecurity skills right?
But yeah no, basically most of those academies are recycling free content/paid content from international companies. Yeah I know that teaching and the way of explanation differ but trust me they also copy this :)
So Basically, they are doing what has been done and will be done every time: let's recycle something on Lebanon, exploit people, get money and yeah repeat.
Almost all of these academies are selling more than helping the community. But what do you mean by that? Basically they do an event just to sell you a new product (yeah not to let you learn new things, because the new things are just recycled shit). They are organizing CTFs just for you to pay the prize price and yeah, you will enjoy a piece of paper with dozens of zeros on it (after that you get a free entry into their courses that cost dozens. Yeah they remind me of how the Lebanese government is trying to solve the problem of depositors who lost their money due to the economic/bank disaster that happened in Lebanon). And by the way guys, CTFs usually are free to participate. You get sponsors or you got the money and you organize a CTF to help people, not to exfiltrate their pockets (yeah you see I use exfiltrate like exfiltration in cybersecurity :P ). So yeah recycled training, copied content, fake investment into the community but yet "They will change the cybersecurity in Lebanon," so yeah.
Let's be clear, I am not against organizing events, but recycling the same topic over and over again that has zero real impact on the progress of cybersecurity in Lebanon, just to flex and sell a new training, is bad (yeah I will choose bad as a word for now :) ).
Also those academies are basically selling you outdated content. Why? Because the recycled, milked contents are outdated from the foreigner sources who are also outdated and here just to sell.
Most of them try to convince beginners/students/professionals from different careers that, for example, web security is the highly demanded field in cyber, that making money from bug bounty will be a few clicks away after solving some labs from PortSwigger (With all respect to PortSwigger and the amazing people behind it). Ignoring all the other fields will basically create a lot of laborers for a desert (and yeah you understood it right). They are creating a generation of people who think not being able to find a bug in a web application is the end of their careers in cybersecurity (yeah man we don't need GRC, SOC analyst, network pentester, cloud security engineers... we only need bug bounty hunters who spray and pray for an XSS! And trying to flex with unaccepted security vulns (if we can call them security vulns) with fake severity yeah man no one will check behind us...).
Additionally, they are selling you dreams, like landing your first 6-figure job, landing your first six-figure bounty, remote positions, the dream that the market is waiting for you king (no they are not)... and much more of dreams... (I will discuss the state of the cybersecurity market in Lebanon and the world in general in a separate blog inshallah).
But for now, I don't want to be understood as attacking those academies and "experts". I am just here saying my honest point of view, my honest feedback on their behaviors. I don't care if someone will believe it or not, I am trying to keep the community of the domain I liked and I adore!! the most safe from what will end up being if they will do what they are doing now. Think of it as an invitation to those academies to stop and reflect what the fu* they are doing?! Maybe they will change their mind and return to reality and treat the community better!
What should we do to have a better future in cybersecurity for Lebanon?
Instead of turning this domain into a money milking domain (as what has been done into other fields, I don't want to spend the next year in prison :) so I will shut my mouth), we should find a way to advance the community, the people who trust us, our government.
Okay but how?
First of all, we should stop just milking the community.
We should start thinking, planning, and giving (yeah I know it's hard but we should).
We should start building not just copying (recycling 99% of the times).
We should say the reality and stop selling dreams. Yeah cybersecurity is very important, very demanding domain but not like what they are trying to sell you. It's also a hard domain, what you learn today might be outdated in the same day. What you should learn is not techniques and steps. Someone in cybersecurity should not be an architect with no engineering skills (me3marje mtl ma mnsami bi lbnen). They should be an engineer in mind (not literally an engineer) but you should have a mentality which recycled/surface level/technologies, techniques, step-based courses (who let you feel like cybersecurity is a piece of cake just to confront you to buy a new course) can't teach you that.
And much more, so I will keep it to a different blog post.
Ending:
This will be a series of blogs. I really care about the cybersecurity community in Lebanon. I understand the need to make money, but I can't understand the exploitation process of the community under the umbrella of "Transforming cybersecurity in Lebanon."
I want the best for the people/the community. I like, back when I started into this field, people were exaggerating their index upload on an outdated fu* up website forgotten in the cave of the internet on new TV channels, exploiting people who don't know the technical is so easy, but this is a very bad game to play and a very sad situation to see the community for the domain I loved the most fall on it...