About Me
I'm Mattias Festin, a senior developer, architect, and AppSec specialist at Decerno, working from Kalix in the very north of Sweden. I spend my days at the intersection of application security, AI, and modern systems development, helping teams build software that is secure, sustainable, and still standing when the threat landscape shifts under it.
The through-line in my work: security is not a feature you bolt on at the end, it's a property of quality. Research puts the cost of fixing a vulnerability found late at up to 640 times that of one caught at design time. I'd rather help you check the foundation than repaint the cracks.
What I do
- Application security: technical reviews of code, architecture, and build pipelines, threat modeling, OWASP SAMM maturity work, SBOMs and supply-chain tracking, penetration testing and automated scanning.
- AI: practical use of LLMs, embeddings, and retrieval in real systems, including what breaks when you upgrade the models. (I write about that in my embedding drift series.)
- Systems development and architecture: building and modernizing custom systems, from legacy rescue missions to greenfield design.
Talks and webinars
- Sketch & Build, speaker two years running. Latest talk: "Use the AppSec: när hoten förändras snabbare än koden", a practical look for developers at how modern attacks work, how organized and automated the attacker side has become, and how to protect what you build when AI keeps raising the tempo.
- Webinars: I have presented several recorded webinars on security for Decerno, including "Säkerhetsgranskning", on security reviews in practice, from analysis to action, "Vem är hackern?", on who is behind modern cyberattacks and how to defend against them, and "När AI möter applikationssäkerhet", on how generative AI changes the way we build systems and opens new doors for attackers.
Writing
Besides this blog, I write about security for Decerno:
- Teknisk granskning: undvik dyra misstag och stärk er säkerhet, on why security reviews pay for themselves, whether you do them early or late.
- Säkerhet är kvalité, on SAMM, SBOMs, technical reviews, and static analysis as everyday quality work.
Find me
- GitHub: MattiasFestin
- LinkedIn: mattias-festin
- X: @mattiasfestin
This site
Best viewed in 800×600 at 256 colors.