About me
Blog
Europe/Berlin
--:--:--
Introduction
How I work
My principles
What I'm working on right now
Dive deeper
Europe/Berlin
German
English
Schedule a call

David Büngener

Security expert with 10 years of experience: I find security weaknesses and fix them myself — from software down into the devices. Solutions that stay.
I'm a security expert with 10 years of experience in highly sensitive IT systems. My specialty: finding security weaknesses and fixing them myself — from the software down deep into the devices. Unlike consultants who only test and disappear, I leave behind solutions that stay with you.
10+
Years embedded & backend
In critical infrastructures
238/238
Tests passing in an auth system
Hardening of a login with 2FA
~4,100
Automated tests across the stack
deduplicated across 466 test files
15
Security feeds in the daily digest
Automatically scored & summarised

How I work

I don't come to test and then disappear. Every audit ends with a finding that names a fix — and on request I implement that fix myself. No auditor-vs-developer ping-pong: I fix critical findings myself and re-test afterwards.Every review runs methodically against recognized benchmarks, not against an opinion: OWASP ASVS for web and API, IEC 62443 for OT and industry, and evidence that holds up in a NIS2 review.And I'm fast where speed matters: a health check is done in 3–5 days, a full audit report in 1–2 weeks. Because I know every layer — from the firmware through the API to cloud configuration — the whole review comes from a single hand.

The process in four steps

1 · Scoping & threat modelI define the systems, repositories and data flows in scope. Based on architecture and deployment topology I model threats with STRIDE — outcome: a written scope and a prioritized list of attack scenarios driving the depth of testing.
2 · Static code reviewManual secure-code review of the critical paths plus SAST tooling (Semgrep, CodeQL, project-specific linters). Focus: input validation, auth, cryptography, error and log handling. Depth over breadth.
3 · Dynamic testingAPI testing with Burp Suite and custom fuzzing scripts, configuration and rate-limit checks, abuse-case validation. The scenarios prioritized in the threat model are verified exploitatively — reproducible findings, no theater.
4 · Reporting & optional remediationEvery finding carries a CVSS rating, reproduction steps, impact and a code-level fix. Optionally I take over remediation myself and deliver a re-test of the fixed findings — audit and implementation from a single hand.

My principles

Audit + fix from one hand

No auditor-vs-developer ping-pong — I fix critical findings myself and re-test afterwards.

Measured against standards

OWASP ASVS, IEC 62443, NIS2 — the whole review against recognised benchmarks, not an opinion.

Fast first value

Health check in 3–5 days, a full audit report in 1–2 weeks.

From chip to cloud

Every layer from one hand — from firmware through the API to cloud configuration.
The collaboration with David Büngener was a real asset to our project. Communication, reliability and the quality of the results were consistently at expert level. We recommend David Büngener without reservation in the field of software testing.
ROLAND Rechtsschutz-Versicherungs-AG
Reference letter as PDF

What I'm working on right now

[TBD — please fill in]

Dive deeper

Projects — /work

[TBD — please fill in]

My foundation — /foundation

[TBD — please fill in]

Ready to have your systems audited?

Free 30-minute intro call — directly with the person who would run the audit.