Lagoda Security georgy@lagodasec.com

Georgy
Lagoda

Independent Cybersecurity Researcher & Security Engineer

Cryptographic Security · Vulnerability Research · Low-Level Systems Security

Cryptographic state field, decorative

Most security failures are not failures of design. They appear in the implementation — in how a primitive was written, how a compiler transformed it, how a processor executed it. This practice works at that level.

Expertise

  • CRYPTOGRAPHY

    Primitives, protocols, implementations

    Cryptographic Security

    Security analysis of cryptographic implementations, primitives, protocols, and implementation-level behavior.

  • VULNERABILITY

    Authorized assessment and validation

    Vulnerability Research

    Authorized vulnerability assessment, technical investigation, reproduction, and controlled validation.

  • SYSTEMS

    Binary, kernel, instruction set

    Low-Level Systems Security

    Security analysis at software, binary, operating-system, instruction-set, and processor architecture levels.

  • HARDWARE

    Processor behavior and boundaries

    Hardware & CPU Security

    Research into processor behavior, hardware/software boundaries, implementation-level security properties, and mitigations.

  • ENGINEERING

    Architecture, review, advisory

    Security Engineering

    Architecture review, security design, implementation analysis, and technical security advisory.

Research

Research field, decorative

Current research spans cryptographic implementation security and processor-level security — low-level implementation analysis, software/hardware security boundaries, and the validation of security mitigations. Selected work is conducted in direct technical collaboration with processor technology partners and is subject to NDA.

  • Cryptographic implementation security
  • Processor-level behavior
  • Optimization and security trade-offs
  • Low-level code analysis
  • Instruction-level behavior
  • Validation of security mitigations

Selected research and client engagements are subject to confidentiality obligations.

Professional Background

  1. Present

    Independent practice — Lagoda Security

    Cryptographic security, vulnerability research, and processor-level security research, alongside technical advisory work on cryptographic hardware and processor-platform security engineering within a regulated research environment.

  2. 2016–2026

    Executive and advisory roles — Technology and digital-transformation organizations

    Product strategy, market development, and public-sector technology programs.

  3. 2012–2019

    CISO (Chief Information Security Officer), then CEO — SEC Consult

    Vulnerability research, application and infrastructure security assessments, and security-methodology development at an Austrian-headquartered international cybersecurity company; leadership of technical security teams across international engagements.

  4. 2011–2012

    Information Security Expert — Chronopay

    Source-code security review and compliance-driven remediation for an international payment system, including PCI DSS / OWASP / WASC-aligned work and real-time integrity monitoring.

  5. 2007–2012

    Software Developer — Microsoft Lab, Lomonosov Moscow State University

    Scientific and mathematical software engineering — the systems foundation for the security work that followed.

International Experience

Cybersecurity experience spanning projects across 11 countries, including engagements across banking and financial services, automotive, insurance, payment systems, and public-sector infrastructure.

Extensive security assessment experience across the EU & APAC banking sector.

Much of this experience was carried out through SEC Consult's international project teams; individual client relationships remain confidential.

Academic Background

Currently conducting dissertation research in cryptography, with a focus on cryptographic implementation security, optimization, and processor-level implementation characteristics.

Lomonosov Moscow State University, Faculty of Computational Mathematics and Cybernetics.

  • cryptography
  • implementation security
  • processor architecture

Authorized Research Principle

Security research and intrusive testing are conducted only within explicitly authorized contractual scopes, with defined Rules of Engagement and, where applicable, Permission to Attack documentation specifying the systems and methods that may be tested.

Contact

Start a Conversation

Georgy Lagoda

Independent Cybersecurity Researcher & Security Engineer

Lagoda Security

georgy@lagodasec.com

+1 747 374 3911 — Phone / WhatsApp

lagodasec.com