Services Methodology Development About Games Contact
DE/EN
Get in touch
🛡️ Principal Security Engineer · responsible disclosure
Scan active · 1 finding

I find the gaps in your systems — before anyone else does.

Penetration testing, security audits, and consulting for organizations that take IT security seriously. Because nothing matters more to people and organizations than the security of their data.

Manual testing, not just automated scans
Pricing on request
DACH region — remote & on-site
API DB Auth CI/CD VPN Web App · CVE open CORE
$4.44M
average global cost of a data breach (2025)
241
days on average to identify and contain a breach
01
test is often all it takes to find the gap an attacker would otherwise find first
Source: IBM Cost of a Data Breach Report 2025
Services

What I check for you.

From a single web service to your entire infrastructure — every review ends with a clear, understandable report, no jargon.

01
WEB & APP

Penetration Testing

Targeted, manual attack simulation on web applications, APIs, and networks — with an attacker's mindset, working on behalf of your security.

What exactly gets tested
  • Authentication & session management
  • Input validation (e.g. injection vulnerabilities)
  • Access controls & authorization logic
  • API endpoints for misconfiguration
02
INFRASTRUCTURE

Vulnerability Assessment

Systematic review of servers, networks, and configurations for known and overlooked vulnerabilities.

What exactly gets tested
  • Open ports & exposed services
  • Outdated software & protocol versions
  • Misconfigurations (firewalls, permissions)
  • Known CVEs in the stack in use
03
PROCESS

Security Audits

Assessment of your existing security measures, processes, and policies against common best practices.

What exactly gets tested
  • Existing security policies & processes
  • Backup & disaster recovery plans
  • Access & permission management
  • Alignment with recognized standards (e.g. BSI baseline protection)
04
ADVISORY

Security Consulting

Individual guidance on hardening measures, risk prioritization, and long-term security strategy.

Methodology

How an engagement runs with me.

Structured, transparent, with clear communication at every stage.

01

Scoping & Goal Definition

Together we define what gets tested, which systems are in focus, and what rules apply.

02

Reconnaissance & Enumeration

Mapping the attack surface — open services, technologies, possible entry points.

03

Exploitation

Controlled exploitation of identified vulnerabilities to demonstrate real-world impact.

04

Reporting

A clear report with risk ratings, evidence, and concrete remediation guidance.

05

Retest

After remediation, I verify whether the vulnerabilities have actually been closed.

Impact

Your attack surface — before and after.

Every unchecked vulnerability is an open door. A test reveals what only an attacker would have seen before — and closes it.

● Before the Assessment

unpatched open port weak password admin exposed 3 open findings

● After the Assessment

all findings fixed & verified
Principles

What you can rely on.

Confidentiality

All findings are discussed exclusively with you. An NDA is available on request.

Responsible Disclosure

Vulnerabilities are never published or shared — only reported and documented.

Plain Language, Not Jargon

Reports that even non-technical decision-makers can understand and act on.

See report structure →
Legal basis in detail — incl. § 202a StGB →
Additional Service

Frontend & Backend Development

Alongside security work, I also take on classic web development — from the website to the system behind it. Especially useful in combination: built securely from the start.

FRONTEND

Websites and web interfaces — modern, performant, responsive.

Learn more →
BACKEND

Server-side logic, APIs, and infrastructure — built clean and maintainable.

Learn more →
FAQ

Before you reach out.

What exactly is a penetration test?

A controlled, simulated attack on your systems aimed at finding vulnerabilities before real attackers do. Unlike an automated scan, this is done manually and with intent.

Is this legal for my company?

Yes — as long as the test is based on a written agreement (scope & authorization). That's exactly what gets defined together during the scoping phase, before anything is tested.

Will my systems be damaged?

The approach is controlled and coordinated with you. Critical tests (e.g. on production systems) are discussed in advance and can be shifted to test environments.

What does a test cost?

The price depends on scope and target systems — hence "pricing on request". After an initial conversation, you'll receive a tailored quote. What determines the price →

What if I don't have a security concept yet?

No problem — many clients start exactly there. An initial vulnerability assessment or consulting session lays the groundwork for everything else.

Contact

Ready for an honest assessment of your security posture?

Tell me briefly about your project — I'll get back to you with a tailored quote.

Open contact form → admin@christian-noack.com · Response typically within 2 business days