About
I'm Gerben. I do security research. I have built software for a long time.
Most of the bugs worth finding sit where a developer made a reasonable decision under time pressure. I made those decisions myself for years.
Background
I work as an Offensive Security Consultant at FreshMinds. Before that, Principal Security Consultant at YieldDD, consultancy work at Sogeti and Betabit, and a stretch at a blockchain start-up working on decentralised systems and cryptography.
Alongside that, years as a software architect and developer, reading systems I did not build and reporting on them. Technical due diligence included.
What I actually do
- Penetration testing: web, API, mobile, cloud, external perimeter, OT.
- Red teaming: objective-based adversary simulation, assumed breach and purple team.
- Reverse engineering and low-level analysis: firmware, binaries, protocols.
- Secure code review: application source and smart contracts.
- Vulnerability research, threat modelling and security architecture review.
- Training: teaching development teams to find this class of bug themselves.
Why independent
A practice of one cannot be staffed down or handed to whoever is on the bench. I take a few engagements at a time, and I'm not the right call if you need twelve testers next Monday.
How I work
I automate what can be automated, AI tooling included. Nothing reaches a client that I have not read myself, and I am answerable for every word of it.
The site itself
No JavaScript, no cookies, no analytics, no third-party requests, no fonts from someone else's CDN. The privacy page has the detail, and there is a disclosure policy and a security.txt.
Reachable at helloREMOVE@handsonzero.com.