Product Security for B2B software companies
Know where your product security is weak.
I help B2B software teams identify where their Product Security capability is breaking down, fix the important gaps, and establish engineering controls that keep them fixed.
Book a Product Security Readiness Assessment1 week · No pentest report
Security work needs engineering depth
More security findings aren't necessarily the answer.
You may already have pentest reports, scanners, security tickets and engineering controls. The harder questions are:
- Do we know which security properties actually matter?
- Are findings turning into verified fixes?
- Are important vulnerabilities prevented from recurring?
- Can we defend our product-security decisions to an enterprise customer?
The Product Security Readiness Assessment shows you where the system is weak and what actually needs fixing next.
Product Security Readiness Assessment
Find out where your Product Security capability is actually breaking down.
Over one week, we examine your current capability across three areas:
- Security Architecture
- Do you know what must remain secure and where your critical trust boundaries are?
- Security Engineering
- Can your team consistently turn security risks and findings into effective engineering changes?
- Continuous Assurance
- Can you prove important controls and fixes continue working as the product changes?
You leave with:
A map of your current Product Security capability, the 3 to 5 most important systemic gaps, and a prioritised recommendation for what, if anything, you should invest in next.
Book a Readiness AssessmentBuild the Product Security capability you're missing
- 1
Security Architecture
- Security Requirements
- Define the security properties the product actually depends on.
- Threat & Trust Model
- Make trust boundaries, attack paths and security assumptions explicit.
- 2
Security Engineering
- Remediation System
- Turn vulnerabilities and weaknesses into engineering work that gets properly resolved.
- Security Controls in Engineering
- Build the right security controls into code, CI/CD and engineering workflows.
- 3
Continuous Assurance
- Verification Strategy
- Establish how critical controls and fixes are independently verified.
- Security Regression & Evidence
- Keep critical security properties tested and produce evidence that survives product changes.
You don't necessarily need all three. The Readiness Assessment determines where intervention actually makes sense.
"Søren quickly grasped the technical and business context of our project and added value from day one. His strong engineering background and structured thinking made collaboration seamless."
René Passmann
CEO, HAV Media
Søren Johanson
Product Security Engineer
I'm a software engineer specialising in Product and Application Security. I've worked on software supporting up to 50 million users and operate at the intersection of security architecture, software engineering and delivery.
Rather than producing another security report, I help engineering teams understand what needs to remain secure, turn identified risks into verified fixes, and build the controls that keep those fixes working.