Senior Lecturer in Cyber Security · Cardiff University

DrAmir Javed

I study how cybercriminals exploit people and machines, and build machine-learning defences that catch attacks early: from phishing and malware on social media to intrusions in connected vehicles, IoT and industrial systems.

Portrait of Amir Javed
CISSP · ISC2 CC · FHEA · PhD
  • 43Publications
  • 23Journal articles
  • 4Doctorates completed
  • 40+BSc & MSc projects
  • 10,000+Hackathon students
01About

From the trading floor to AI-driven defence

I am a CISSP-certified Senior Lecturer in the School of Computational and Mathematical Sciences at Cardiff University, where I direct the MSc Cyber Security and MSc Cyber Security & Technology programmes. I hold a PhD in cyber security and an MSc in Information Security and Privacy from Cardiff, and ISC2's Certified in Cybersecurity credential.

Before academia I spent eight years in the Global Markets Group at ICICI Bank, advising corporate clients on foreign-exchange risk and derivatives. That experience still shapes how I think about cyber risk: practical, quantified and tied to business impact. Today I apply frameworks such as NIST, ISO 27001, OCTAVE and MITRE ATT&CK alongside machine learning to detect, predict and quantify attacks.

My research has involved work with GCHQ, Airbus, PwC and Thales, and funded collaborations in India, New Zealand and the USA. I co-founded Kesintel, Highly Commended for New Product of the Year at the FinTech Awards Wales 2025, and support start-ups and SMEs as a Domain Knowledge Expert at the Wales Cyber Innovation Hub, including advising Alacrity on an AI-powered threat-hunting dashboard for intelligence agencies.

Since 2019 I have supervised more than 40 BSc and MSc projects and moderated over 40 more, which keeps my expertise broad: from phishing psychology and malicious websites to CAN bus attacks on cars, industrial control systems, reverse engineering and security operations.

02News

Recent news

  • 2026
    GroupCongratulations to Dr Muzun Althunayyan, Dr Fatimah Aloraini and Dr Turki Al Lelah on completing their PhDs, and to Loic Lorente Lemoine on his MPhil. Meet the group
  • 2026
    PaperOur survey on continuous compliance auditing for IoT security is out in Computers & Security, and a survey of learning-based intrusion detection for in-vehicle networks in Computer Networks.
  • Nov 2025
    ConferencePapers at the 29th CISSE Colloquium in Seattle, on LLMs for vulnerability analysis in teaching, and at IEEE FLLM in Vienna, on RAG for security log analysis.
  • Sep 2025
    AwardKesintel was Highly Commended for New Product of the Year at the FinTech Awards Wales 2025. Full results
  • Jul 2025
    ConferencePresented the Great AppSec Hackathon model for closing the cyber skills gap at ICCS 2025, Singapore.
  • Jan 2025
    TalkVisited IIT Kanpur to speak on advancing cyber security research and collaboration with Cardiff University. IIT Kanpur news
  • Aug 2024
    PressMore than 10,000 students took on the Great AppSec Hackathon, run with the Data Security Council of India. Cardiff University news
  • 2024
    CredentialBecame a CISSP and earned ISC2's Certified in Cybersecurity.
  • Jan 2024
    TalkSeminar at the Indian Institute of Science, Bengaluru, on international collaboration in cyber security, supported by the Global Wales–IISc partnership fund. IISc event
  • Feb 2021
    PressOur analysis of 275,000 tweets showed that tweets expressing fear were 114% more likely to be retweeted, helping malicious links spread. Cardiff University news
03Impact

Impact and recognition

Amir Javed holding the Highly Commended award for New Product of the Year, on stage with three colleagues at the FinTech Awards Wales 2025
Award · 2025Kesintel: Highly Commended, New Product of the Year at the FinTech Awards Wales 2025, sponsored by Deloitte. Kesintel is a company I co-founded.
Partnership · DSCI

The Great AppSec Hackathon

I led Cardiff University's sponsorship of this global application-security hackathon, run by the Data Security Council of India (DSCI) in partnership with Cardiff and The Hague Centre for Strategic Studies. The 2024 edition drew more than 10,000 students to a 24-hour capture-the-flag, with JPMC, Securein, TCPWave and the Telangana State Cybersecurity Bureau recruiting interns from it.

Read the story →

In the press

Tweets of fear spread malware

Our study of 275,000 tweets found fear-laden posts were 114% more likely to be retweeted, a tactic cybercriminals use to spread malicious links.

Read the story →

International

Building links with India

Invited talks at IISc Bengaluru and IIT Kanpur on research collaboration, alongside funded projects in India, New Zealand and the USA.

04Research

Research themes

Three connected questions: how attacks spread, how to detect them early, and how to make that detection trustworthy.

05Expertise

Knowledge and skills

Threat detection with AI

  • Network & IoT IDS
  • Vehicle / CAN bus IDS
  • Malware detection
  • Malicious websites
  • Phishing & SMS phishing
  • Deepfakes
  • Adversarial ML
  • Explainable ML
  • LLMs & RAG
  • Security of AI
  • Federated learning
  • Deep neural networks
  • Python, C/C++, Java

Offensive security

  • Penetration testing
  • Ethical hacking labs
  • Android reverse engineering
  • Rust reverse engineering
  • QR code analysis
  • Keyloggers
  • Rootkit detection (VMI)
  • Honeypots
  • OSINT
  • Threat hunting
  • Malware analysis
  • Forensic imaging
  • Footprinting & scanning

Cyber-physical & OT

  • CAN bus & telematics
  • Replay attacks
  • Car hijacking
  • ICS hardware-in-the-loop
  • Smart grid risk
  • EV charging
  • Power-line attacks
  • SANS OT training
  • OT incident response

Risk & governance

  • NIST CSF
  • ISO 27001
  • OCTAVE
  • MITRE ATT&CK
  • SOC playbooks
  • Cyber risk quantification
  • SME risk tools
  • SOC design
  • Secure SDLC
  • Residual-risk reporting
  • IDS evaluation
  • Compliance auditing

Human factors

  • Phishing susceptibility
  • Eye tracking
  • Emotion & persuasion
  • Social engineering
  • Hate speech
  • Risk perception
  • Training effectiveness

Security education

  • Gamification
  • Escape rooms
  • CTFs & cyber ranges
  • DSCI AppSec Hackathon (10,000+)
  • GenAI challenges
  • GenAI in assessment
06Publications

Selected publications

  1. C&S
    Beyond the automation gap: a survey on continuous compliance audit for IoT security Briliyant, O., Javed, A. and Cherdantseva, Y. Computers and Security 168, 104953, 2026
  2. COMNET
    A survey of learning-based intrusion detection systems for in-vehicle networks Althunayyan, M., Javed, A. and Rana, O. Computer Networks 277, 112031, 2026
  3. VEHCOM
    A robust multi-stage intrusion detection system for in-vehicle network security using hierarchical federated learning Althunayyan, M., Javed, A. and Rana, O. Vehicular Communications 49, 100837, 2024
  4. SPE
    Security analytics for real-time forecasting of cyberattacks Javed, A. et al. Software: Practice and Experience 52(3), 788–804, 2022
  5. ACM TWEB
    Emotions behind drive-by download propagation on Twitter Javed, A. et al. ACM Transactions on the Web 14(4), 16, 2020
  6. BJC
    Hate in the machine: anti-Black and anti-Muslim social media posts as predictors of offline racially and religiously aggravated crime Williams, M. L. et al. British Journal of Criminology 60(1), 93–117, 2020
  7. IPM
    Prediction of drive-by download attacks on Twitter Javed, A., Burnap, P. and Rana, O. Information Processing and Management 56(3), 1133–1145, 2019

All 43 publications →  ·  Google Scholar

07Group

Research group

Current PhD researchers

  • Obrina BriliyantContinuous, AI-assisted compliance auditing for IoT security
  • Arunima ChaudharyGenerative AI in cyber security education
  • Nima ValizadehForecasting vehicle emissions trajectories using data-driven approaches
  • Jenny HighfieldOperational technology security incident response

Alumni

  • Dr Muzun AlthunayyanPhDIntrusion detection for in-vehicle networks
  • Dr Fatimah AlorainiPhDAdversarial attacks on IDS in connected and autonomous vehicles
  • Dr Turki Al LelahPhDAbuse of legitimate cloud services for command-and-control
  • Loic Lorente LemoineMPhilAdaptive machine learning in edge IDS for vehicular systems

Theses, projects and how to apply →

08Teaching

Teaching

  • Programme Director, MSc Cyber Security and MSc Cyber Security & Technology
  • Module lead, CMT116 Cyber Security and Risk Management
  • Module support, CMT217

I make security education hands-on: game-based workshops, escape rooms, capture-the-flag challenges and the safe use of generative AI in the classroom. With DSCI I co-developed the Great AppSec Hackathon, a global web-application CTF that has engaged around 10,000 students.

09Consulting

Consulting and speaking

I work with organisations on security risk, threat detection and cyber skills, drawing on research, CISSP practice and eight years in banking.

Advisory

Cyber risk assessment against NIST, ISO 27001 and OCTAVE, SOC design, and evaluation of AI security tools. Recent work: advising Alacrity on an AI threat-hunting dashboard for intelligence agencies.

Talks and keynotes

Security of AI for leaders, the dark side of AI and today's threat landscape, vehicle and EV security, OT security, phishing and human factors. Recent audiences in Kuwait, India, Saudi Arabia, the USA, Latin America and the UK.

Training and hackathons

Gamified security training, escape rooms and large-scale hackathons, including the DSCI Great AppSec Hackathon with more than 10,000 students.

10Speaking

Talks, workshops and service

Selected talks and workshops

  • Security of AI: leadership sessionDelivered a leadership session on securing AI, Kuwait. Post
  • The dark side of AI: the current cyber threat landscapeInstructor for a two-day workshop at the National Police Academy (NPA), India.
  • Guest lecture on AI security, Butler UniversityGuest lecture on the security of AI systems.
  • Guest lecture, Indian School of Business (ISB)Guest lecture on cyber security. Post
  • Electric and vehicular securityPresented at IIT Delhi. Post
  • SANS workshop on OT securityOrganised a SANS workshop on operational technology security. Post
  • Summer workshop, Princess Nourah bint Abdulrahman UniversityRan a summer cyber security workshop for students from Saudi Arabia.
  • Short course on AI for Latin America, CardiffDelivered a short course on AI at Cardiff University for participants from Latin America.
  • Collaboration seminars, IISc Bengaluru and IIT KanpurBuilding joint research in cyber security. IISc · IIT Kanpur

Editorial and community

  • Guest Editor, Frontiers special issueFederated and privacy-preserving learning for next-generation intrusion and phishing detection.
  • Guest Editor, Sustainability special issueFederated and Distributed Intelligence for Sustainable Edge–Cloud Ecosystems.
  • Partner, ICCSInternational Conference on Cyber Security, Privacy in Communication Networks. Post · Post
  • Great AppSec HackathonCardiff University lead for the global hackathon run by the Data Security Council of India (DSCI).
  • Domain Knowledge Expert, Wales Cyber Innovation HubSupporting cyber security start-ups and SMEs.

Project spotlight

  • eMindGuardProject updates: 1 · 2 · 3 · 4 · 5
11Contact

Get in touch

For consulting, speaking or PhD enquiries, email [email protected].

Abacws, Room 4.08 · Senghennydd Road · Cathays · Cardiff CF24 4AG