// security

Know where you're vulnerable
before an attacker finds out.

Targeted security tests give you a clear picture of your digital environment, with concrete and achievable improvements as the result.

I test as if I were the attacker myself - realistic, methodical, and with a clear report as the result.

Web Application Pentesting

Thorough audit of web applications following OWASP methodology: SQL injection, XSS, broken access control (IDOR), authentication bypass, SSRF, path traversal and file upload vulnerabilities. Result: a clear report with findings, risk assessment and concrete remediation steps.

API Security Testing

Testing REST and other APIs against the OWASP API Security Top 10 - from endpoint recon and parameter pollution to JWT implementation flaws (algorithm confusion, weak signing).

Network Pentesting

Internal and external network audits: identifying misconfigurations, layer 2 vulnerabilities and attack paths within your network infrastructure.

Bug Bounty & Vulnerability Research

Active contribution to responsible disclosure programs. My experience as a bug bounty hunter (Intigriti) translates directly into sharper, more realistic pentests.

Not every organization needs a full pentest - sometimes it starts with insight.

Security Audit / Risk Assessment

Evaluation of your current security posture based on the CIA triad (confidentiality, integrity, availability), with attention to GDPR compliance.

NIS2 / CyFun® Guidance

Practical support in mapping out NIS2 obligations and the CyFun® framework - translated into achievable steps for SMEs, without unnecessary complexity.

Hardening & Configuration Review

Review of firewalls, IDS/IPS configurations and endpoint security, with concrete recommendations to reduce the attack surface.

  • Organizations that want to know if their systems can withstand a real attack
  • Companies that need to comply with NIS2 or start a CyFun® track
  • Teams that need an independent security audit before an audit or certification
Discuss security

Want to know where you're vulnerable?

A pentest or security audit doesn't have to start complicated - a conversation is enough to define scope and approach.

Request a pentest