Home OffSec
  • Pricing
Titan Shield Wins Client Trust and New Business with a Fully Certified Cybersecurity Team | OffSec
Case Studies

/

Titan Shield

Titan Shield Wins Client Trust and New Business with a Fully Certified Cybersecurity Team

"When we respond to an RFP or RFQ, we can show that our team holds 29 OffSec certifications. Other companies may present a couple of engineers with individual certifications. We can present a fully certified team, including our sales team."

  • Industry

    Cybersecurity Services

  • Size

    11-50 employees

  • HQ

    Palestine

Overview: Challenges

  • Build client trust and credibility as a newly established cybersecurity company competing for client engagements

  • Develop a largely early-career team with the breadth of practical skills to support web application, API, Active Directory, legacy system, threat hunting, incident response, and SOC engagements

  • Gain greater visibility and control over employee development by moving beyond individual, self-directed training

Overview: Solutions

  • Implement a 12-month Learn Enterprise program supporting nine core team learners across eight certification tracks, with seven additional seats extended to clients and partners for joint training on OffSec labs (16 activated seats in total)

  • Build practical offensive and defensive capabilities across web assessment, penetration testing, incident response, threat hunting, SOC analysis, CyberCore, Kali Linux, and wireless security

  • Guide learner development through custom learning paths and weekly or biweekly progress and experience reviews

Overview: Benefits

  • Strengthened client trust and competitive differentiation by demonstrating certified capability across the team

  • Built a broader bench of certified practitioners to support client engagements and the company's continued growth

  • Applied newly developed defensive skills in a client environment to detect and help prevent DCSync activity that existing security products had missed

  • Increased confidence and momentum among early-career

The challenges

Titan Shield was established in 2024 and needed to earn client trust without a long company history behind it. Sami T.J. Elsheikh, Co-Founder & CTO/CISO, with more than 25 years of information security experience, explained that prospective clients evaluate two things when considering a new cybersecurity provider: the company's age and the credentials of its team. Because Titan Shield was new, it focused on building a team with practical, externally validated skills.

Titan Shield entered the market with more than 20 years of collective team experience and a track record protecting sensitive systems across the region. Its specialists conduct penetration testing, manage 24/7 Security Operations Centers, and respond to sophisticated cyber incidents. The challenge was translating that experience into credentials that prospective clients could immediately recognize.

“When a new company tries to acquire clients, there are two major checkpoints: your team and your age. If you are a new company, you need credentials.” - Sami T.J. Elshiekh, Titan Shield

Most of Titan Shield's engineers were recent university graduates, while a few had three or four years of experience. The company wanted to prepare them for work across web application and API penetration testing, Active Directory, and legacy system penetration testing, then extend the team's coverage into incident response, threat hunting, and SOC analysis.

Titan Shield also needed to manage that development as one company-wide program. Sami said separate individual subscriptions would not provide a consolidated dashboard, reporting, or oversight across learner accounts. He wanted to track progress across the team and give each learner a focused path through the content.

"Titan Shield is now recognized as a leading information security firm in Palestine. Our OffSec credentials have helped us acquire new clients and gain their trust."

The solutions

Titan Shield launched a 12-month Learn Enterprise engagement in July 2025. Nine core team members activated their accounts across eight certification tracks spanning offensive and defensive security. To strengthen its ecosystem, the company also extended seven seats to select clients and partners for promotional engagements and joint training using OffSec labs, bringing total activated seats to 16.

“The most important thing to invest in is the personnel and the capacity building. We asked the board for the budget to build our team’s capability before we started working with any client.” - Sami T.J. Elshiekh, Titan Shield

Build capability before client deployment

Titan Shield began with the skills required for its core services. Learners worked across eight certification tracks covering web assessment, incident response, threat hunting, penetration testing, SOC analysis, foundational cybersecurity, Kali Linux, and wireless security.

The final certification results covered both offensive and defensive disciplines. Learners earned credentials in web assessment and penetration testing as well as incident response, threat hunting, and SOC analysis. Titan Shield also enrolled members of its nontechnical sales team in OffSec training, and Sami reported that they earned OSWA certifications.

“You cannot protect what you don’t understand. To understand an attack and protect your client from it, you have to understand that attack.” - Sami T.J. Elshiekh, Titan Shield

Turn broad access into focused progression

During the first month, learners were moving between different courses. Titan Shield's OffSec contact identified the pattern and raised it with Sami.

The teams responded by rebuilding the training as custom learning paths. Titan Shield then reviewed team progress and the learner experience with OffSec weekly or biweekly.

“Our team was jumping between materials. We rebuilt all of the paths as custom paths and focused the training. We then reviewed the team’s progress and experience weekly or biweekly with our account manager.” - Sami T.J. Elshiekh, Titan Shield

Validate skills through practical exams and labs

Titan Shield chose OffSec because its exams required learners to demonstrate skills in realistic environments. Across the 12-month program, learners made 37 exam attempts and passed 29!

“The main driver was the quality and the type of exam OffSec offers. It is not a true-or-false exam. It is a real-world scenario where the learner has to complete penetration testing or threat hunting to pass.” - Sami T.J. Elshiekh, Titan Shield

The team earned credentials across eight tracks:

Three of the OSCP-certified engineers also hold the OSCP+ credential, bringing the team's total OffSec credentials to 29.

All nine core team members earned at least one OffSec certification. The team achieved a 100% pass rate on the TH-200, SOC-200, and OSCC tracks.

Certifications were only one measure of progress. Ten of the activated learners، including client training seats، earned 68 hands-on skill pins across practical areas including incident detection and identification, web application testing tools, server-side request forgery, XML external entity attacks, enumeration, insecure direct object references, and incident response case management.

Learners also earned 39 domain and milestone badges. These included Level 10 and Level 20 milestones achieved by 10 activated learners each, five OWASP Top 10 badges, five Incident Responder Essentials badges, two GRC for Cybersecurity badges, two MITRE ATT&CK: Lateral Movement badges, two Threat Hunting Essentials badges, and one Digital Forensics Foundations badge.

The benefits

Titan Shield reports four business and workforce outcomes from the program:

  • Stronger client trust
  • Greater differentiation in RFPs and RFQs
  • New detection capabilities applied in a client environment
  • Increased confidence among early-career engineers

Turn team credentials into client trust and new business

Titan Shield could not rely on decades of company history when competing for work. It now uses its team's OffSec credentials to demonstrate capability to prospective clients.

Sami said the certified team has helped Titan Shield acquire new clients and gain their trust. In RFP and RFQ responses, the company can present credentials held across nine employees, including members of its sales team, rather than relying on one or two certified specialists.

“When we respond to an RFP or RFQ, we can show that our team holds 25 OffSec certifications. Other companies may present a couple of engineers with individual certifications. We can present a fully certified team, including our sales team.” - Sami T.J. Elshiekh, Titan Shield

Build the first fully OffSec-certified team in Palestine

Titan Shield's certified team now includes Palestine's first OSDA-certified professional and multiple OSWA-certified specialists. Those credentials support work spanning advanced penetration testing, 24/7 SOC operations, and incident response for environments protecting millions in digital assets.

Sami connected the company's longer-term training plan to its commitment to develop what he described as the best information security professional-services team in the MENA region.

“We have a long-term training and capacity-building strategy. The first year was focused on the 200 level. Next year, we are aiming for the 300 level.” - Sami T.J. Elshiekh, Titan Shield

Turn OSDA training into detections for a client environment

One team member, Abdullah Bakr, entered the program with professional experience in SOC leadership, incident response, threat hunting, and incident triage. OSDA deepened his understanding of Active Directory attacks and the artifacts analysts can use to investigate and detect them.

He applied that knowledge when Titan Shield encountered a DCSync attack in a client environment. According to Abdullah, the security products deployed in the environment had not detected the activity. He used the attack artifacts covered in OSDA to create custom detection rules. The team then ran an attack simulation against the environment to test those rules. The simulation produced both detections and preventions for the attack technique.

“Based on my understanding of the DCSync attack and its artifacts from the OSDA material, I created custom detection rules. We ran a simulation against the environment and achieved both detection and prevention.” - Abdullah Bakr, Titan Shield

Build confidence and momentum among early-career engineers

Another team member, Batoul Alnahawi, joined Titan Shield as a recent university graduate without prior experience taking a cybersecurity certification exam. Sami recalled that she was initially shy and that most of her confidence came from what she had learned at university.

Sami said Batoul's confidence and motivation changed after her first certification. With encouragement from the company and continued practice solving machines, she went on to earn three certifications during the program.

“After earning three certifications, the exams were not easier, but it became easier to take them on.” - Batool Alnahawi, Titan Shield

Why OffSec?

Sami's experience with OffSec dated back to BackTrack Linux before its rebirth as Kali Linux, but he said that history was not the main reason for the decision. He identified the quality and format of OffSec exams as the primary drivers because learners had to perform penetration testing, threat hunting, or other practical tasks in realistic scenarios rather than answer true-or-false questions.

Sami chose Learn Enterprise over separate Learn One subscriptions because it provided reporting, a dashboard, oversight across the accounts, and support from an OffSec account manager.

Sami chose Learn Enterprise over separate Learn One subscriptions because it provided reporting, a dashboard, oversight across the accounts, and support from an OffSec account manager. “Do not rely on individual accounts. Rely on enterprise-level management where you can follow up, track, and see every step of your team’s progress.” - Sami T.J. Elshiekh, Titan Shield

Over the 12-month engagement, Titan Shield built a fully OffSec-certified team that strengthened its credibility and gave prospective clients clear evidence of its cybersecurity capabilities.