Introduction
How I work
My principles
What I'm working on right now
Dive deeper
David Büngener
Security expert with 10 years of experience: I find security weaknesses and fix them myself — from software down into the devices. Solutions that stay.I'm a security expert with 10 years of experience in highly sensitive IT systems. My specialty: finding security weaknesses and fixing them myself — from the software down deep into the devices. Unlike consultants who only test and disappear, I leave behind solutions that stay with you.
How I work
I don't come to test and then disappear. Every audit ends with a finding that names a fix — and on request I implement that fix myself. No auditor-vs-developer ping-pong: I fix critical findings myself and re-test afterwards.Every review runs methodically against recognized benchmarks, not against an opinion: OWASP ASVS for web and API, IEC 62443 for OT and industry, and evidence that holds up in a NIS2 review.And I'm fast where speed matters: a health check is done in 3–5 days, a full audit report in 1–2 weeks. Because I know every layer — from the firmware through the API to cloud configuration — the whole review comes from a single hand.
The process in four steps
1 · Scoping & threat modelI define the systems, repositories and data flows in scope. Based on architecture and deployment topology I model threats with STRIDE — outcome: a written scope and a prioritized list of attack scenarios driving the depth of testing.
2 · Static code reviewManual secure-code review of the critical paths plus SAST tooling (Semgrep, CodeQL, project-specific linters). Focus: input validation, auth, cryptography, error and log handling. Depth over breadth.
3 · Dynamic testingAPI testing with Burp Suite and custom fuzzing scripts, configuration and rate-limit checks, abuse-case validation. The scenarios prioritized in the threat model are verified exploitatively — reproducible findings, no theater.
4 · Reporting & optional remediationEvery finding carries a CVSS rating, reproduction steps, impact and a code-level fix. Optionally I take over remediation myself and deliver a re-test of the fixed findings — audit and implementation from a single hand.
My principles
What I'm working on right now
[TBD — please fill in]