Cape Town, South Africa — 33.9°S

Lèo Liebenberg

Cybersecurity engineer · Creator of Vikelus

Attackers don't break in. They walk in — through software you already have, using a hole that's been public for weeks.

I build the thing that finds it first.

Lèo Liebenberg speaking on stage to a seated audience.

The short version

Security that survives an audit, not just a slide.

I'm a cybersecurity engineer at F1 IT Solutions in Cape Town. I keep growing businesses secure — and I built the platform that proves they are.

Role
Cybersecurity engineer, F1 IT Solutions
Built
Vikelus — created, built, co-founded
Studying
BSc Cybersecurity & Networking, Eduvos
Based
Cape Town, South Africa
Writes
Plain English. No fear-mongering.

My idea, my build, my code

Vikelus

Protection, proven.

We don't wait for your devices to get breached. We watch them so they don't.

Every morning Vikelus pulls what the world learned overnight — CISA's list of the holes attackers are actively exploiting, the new critical CVEs, and the exploit-probability scores that say which ones actually matter.

Then it does the part nobody wants to do by hand: it checks the real installed version of every application on every machine we manage. Not per company. Per machine.

If something is genuinely exposed, it stages the fix. Two engineers sign off before anything touches a server. Every step lands in a ticket, and the client gets a report that proves what was checked, what was affected, and what was closed.

A dashboard that says “protected” and can't show you why is just a nicer way of hoping.

n8n · SuperOps · Cloudflare · Telegram · Anthropic

The Vikelus dashboard: live posture, severity mix and top vendors across the monitored fleet.

How Vikelus works

How I work

Four rules I don't bend.

Never fake a finding

Scores go on reports that clients hand to their insurer. If a finding is closed, it's because the machine was actually fixed — and the version proves it. Nothing gets marked done to make a dashboard look good.

Version-verified, or it doesn't count

“You're patched” is a claim. “This laptop runs build 141.0.7390.55, and the exploit needs anything below .54” is evidence. Only one of those survives an audit.

Two people, then the server

Nothing significant gets patched on one person's say-so. Two engineers approve. It's slower. It's also why nothing has gone sideways.

Plain English, or it isn't communication

If a business owner can't repeat back what's at risk and what you're doing about it, you haven't explained it. You've just performed.

On stage

The hard part isn't the exploit. It's the explaining.

Most security advice is written to sound impressive to other security people. That's useless to the person who actually has to decide whether to spend the money.

So I do the opposite. No jargon, no scare tactics, no acronym soup — just what's actually at risk, what it would cost you, and what to do about it on Monday.

The F1 IT Solutions team — Lèo Liebenberg with colleagues Reza and Christiaan.

The long version

How I ended up building it.

A technical engineer in Cape Town, a BSc that isn't finished yet, and a problem nobody wanted to do by hand.

Read the story

Straight answers

Asked often enough to write down.

Who created Vikelus?
I did. The idea was mine and so was the build — I designed the architecture, wrote the platform end to end, and I run it in production. I'm also a co-founder and co-owner, alongside co-founder Reza Marvasti, who leads growth and the partner network.
What is Vikelus?
A version-verified vulnerability-management platform. It matches every installed application on every managed device against CISA KEV, NVD and EPSS, verifies the real installed version per machine, stages patches behind two-person approval, and produces client- and insurer-ready proof reports.
Why build it instead of buying one?
The tools on the market were expensive — priced for enterprises with a security team — and unreliable: they'd flag machines patched a week ago and report at company level when the only question that matters is which machine. So I built one that proves itself.

Contact

Let's talk.

A second opinion on your security, a look at Vikelus, or just to connect.

[email protected]

Based
Cape Town — GMT+2