About me
Blog
Europe/Berlin
--:--:--

Your software is running. But is it actually safe?

I go through your systems, find security gaps — and, if you like, close them myself right away.

What I find in most systems

Typical weak spots I keep running into during a security check of your software. If your devices in the field could be exposed too, it pays to also look at Security for devices & firmware at the same time:
Access & interfacesLogin and interfaces are too easy to trick, passwords or access data are left exposed, and anyone can knock as often as they like.
Inputs & program codeWhatever someone types into the system can be misused to cause damage, because those inputs are not checked properly.
The technology behind itDefault factory passwords, access rights that are far too broad, missing encryption, and hardly any record of who did what.

How the security check works

Four steps, with concrete results at the end — no ticking boxes for show. Everything is checked against recognized security standards.
1. Define the scope & assess the risksFirst we agree together which systems and data will be checked. Then I think through where attackers would most likely strike. The result: a written scope and a sorted list of the most likely attacks — that list decides where I look most closely.
2. Review the program codeI read the most important parts of the code by hand and also run special checking tools over it. Focus: how inputs are checked, how login works, encryption, and how errors are handled. Depth over surface-level breadth.
3. Actively test the systemI test the interfaces live, try to cross their limits, and deliberately check whether the weak spots found earlier can really be exploited. Every finding is documented so you can follow it — no showboating.
4. Report & optional fixingEvery weak spot gets a rating of how serious it is, step-by-step instructions to reproduce it, and a concrete suggested fix. On request I fix the gaps myself and check again afterwards — testing and repair from one hand, no back-and-forth between tester and developer.

Packages

Health CheckA quick first assessment of how safe your software is right now.
Timeline: 3–5 daysfrom €1,500
Security AuditA thorough check of the program code and the technology behind it — against a recognized security standard.
Timeline: 1–2 weeksfrom €3,200
Hardening & remediationI fix the gaps myself instead of just reporting them — right after the check or on their own.
Timeline: Day rate / bundleon request

The standards I check against

A security check only counts if it can be measured against recognized standards — otherwise it is just a personal opinion.
OWASP Top 10 & ASVSRecognized checklists for the most common security gaps in web and interfaces. There is a minimum level for normal operations and a stricter level for sensitive areas like healthcare or finance.
NIS2 & ISO 27001Provides the evidence you need for legal security requirements or a certification — with documentation that stays understandable years later.
Made for the cloudWhether your systems run on Azure or AWS, I check them against each provider's official security recommendations. The setup and configuration are part of the check too — not just the program code.

Real example: Azure security audit (mechanical engineering NRW)

Security check of the desktop app (running in the Azure cloud)Hardening of a desktop application for strictly regulated environments. The whole system behind the interface was checked: the cloud setup, the login, the database access, and the connection between the app and the technology behind it — with an eye on the legal security requirements.Approach: first work out where attackers would strike, then review the program code by hand and with tools, then test the critical spots live.Outcome: 32 rated findings — 6 especially critical and 12 serious, mainly around inputs, login and sessions. I fixed all the critical gaps myself as part of the package price. On top of that I built over 70 automatic tests that permanently make sure the gaps don't come back.

What you can count on

10+ years of experienceDevices, software, cloud — every level
Check + fixNot just a report — I repair it myself
Recognized standardsChecked against current standards
Fast turnaroundFirst assessment in 3–5 days
ROLAND Rechtsschutz-Versicherungs-AG: “The collaboration with David Büngener was a real asset to our project. Communication, reliability and the quality of the results were consistently at expert level. We recommend David Büngener without reservation in the field of software testing.” (translated from the German original)
You'll find more references and my background on the About page.

FAQ — Security Check

Smart devices or firmware involved too?

Thanks to my experience with devices, I also help secure hardware and meet the security requirements for connected systems.
Security check for devices & systems

Ready to have your software checked?

30-minute intro call — free, no obligation, and directly with the person who would carry out the check.