About

I'm Gerben. I do security research. I have built software for a long time.

Most of the bugs worth finding sit where a developer made a reasonable decision under time pressure. I made those decisions myself for years.

Background

I work as an Offensive Security Consultant at FreshMinds. Before that, Principal Security Consultant at YieldDD, consultancy work at Sogeti and Betabit, and a stretch at a blockchain start-up working on decentralised systems and cryptography.

Alongside that, years as a software architect and developer, reading systems I did not build and reporting on them. Technical due diligence included.

What I actually do

  • Penetration testing: web, API, mobile, cloud, external perimeter, OT.
  • Red teaming: objective-based adversary simulation, assumed breach and purple team.
  • Reverse engineering and low-level analysis: firmware, binaries, protocols.
  • Secure code review: application source and smart contracts.
  • Vulnerability research, threat modelling and security architecture review.
  • Training: teaching development teams to find this class of bug themselves.

Why independent

A practice of one cannot be staffed down or handed to whoever is on the bench. I take a few engagements at a time, and I'm not the right call if you need twelve testers next Monday.

How I work

I automate what can be automated, AI tooling included. Nothing reaches a client that I have not read myself, and I am answerable for every word of it.

The site itself

No JavaScript, no cookies, no analytics, no third-party requests, no fonts from someone else's CDN. The privacy page has the detail, and there is a disclosure policy and a security.txt.

Reachable at helloREMOVE@handsonzero.com.