Remigius Stalder first met our security expert Christian Schneider in 2018 on the occasion of his talk on security in IT and the cloud at the JavaLand conference. The presentation was so interesting that Remi wanted to get to know Christian immediately afterwards. Because these topics are becoming ever more important and Remi Stalder wanted to introduce the highest security standards for our Vanillaplan software as quickly as possible.
Christian Schneider is a proven security expert and trainer with years of experience in IT security and hacker attacks on IT systems. In 1997 he began his successful career as a freelance software developer and in 2005 shifted his focus to IT security. As a trainer he leads training courses in computer security at customers' premises or online. He enjoys building all kinds of security aspects into the development process for developers of IT projects from the outset. But even more than merely lecturing on security topics, Christian regularly gives open training sessions in front of an audience at important national and international conferences.
His mission is: better to include security during the development of software and to foster security as a culture within the team than to do so after the fact. His aspiration and his philosophy are to find simple solutions to complex problems and to share that knowledge.
One important measure for security in IT and the cloud is, for example, an «application pen test». Here Christian turns into a white-hat hacker and, using specialised security testing programs, carries out real attacks on the system from outside. A log is kept in which all the gaps found are recorded. Afterwards the results are discussed with the developers and Christian shows step by step how to close the security gaps.
Recently Christian has developed a standalone tool called «threagile» for the agile modelling of threat scenarios, which is attracting lively interest. An analysis with this tool is the basis for dealing with security risks on the basis of a detailed report that prioritises them according to the severity of their impact.
Since 2018 our Vanillaplan application has been tested regularly by Christian Schneider. First an individual threat scenario is set up. Then the architecture of the software is examined and finally the penetration test takes place. A log is produced for every test and the evaluations are discussed in detail. This also creates a learning effect and our developers are made aware of weak points, so that they can avoid the most important security gaps while they are programming.
At this point, a warm thank you for the good collaboration and the support.
To Christian Schneider's website
Agile Threat Modeling

In recent days the press has been reporting massive security problems at some large software companies. Not so at Vanillaplan. Because we do everything necessary for our customers so that our software is and stays as secure as possible. This includes our regular security checks by a proven external security expert. You can read in this report who that is and what exactly he does. And incidentally: why not ask your own software provider what they do for your security. Enjoy reading on…


