Online Optimisers · Sebastian Tagwercher
← Back to orb
Profile · 2026-05-21

Where you are today, what you have, what you do not.

Sebastian Tagwercher, web application security consultancy. Friend-tier lead. Snapshot of the position, the plan he wrote, and the gaps this package closes.

Sebastian is transitioning from corporate tax accounting plus a master's in Information Systems into offensive web application security as a solo consultant. He met Donal at a Chiang Mai co-working space on 2026-05-20 and emailed his curriculum plus business plan the next morning, with an open invitation to critique.

This is a friend-tier, no-charge advisory engagement. Output lives in knowledge/leads/sebastian-tagwercher/ and at tagwercher-orb.pages.dev. Nothing moves into knowledge/clients/. No commercial expectation either way.

The position in one line
Master's thesis in LLM cybersecurity plus accounting plus business admin. Unusually well-positioned for the AI/LLM security niche selling to SMB SaaS founders. Almost no credible practitioners in this lane.

Snapshot

FieldValue
NameSebastian Tagwercher
LocationChiang Mai, Thailand
OriginGerman-speaking (Proton Mail signature in German, native German market)
Business nameTagwercher (solo consultancy)
Domaintagwercher.io (business plan) / tagwercher.com (curriculum). INCONSISTENT, ask which is owned.
Operating entity[INSERT: legal entity, jurisdiction]
Tax residency[INSERT: tax residency for invoicing]
Currency for invoicing[INSERT: USD / EUR / preference]
Plan startMay 2026 (now)
Current MRR$0
Target MRR (Mo. 7 to 12)$4K to $8K
Budget over next 6 mo~$950
Runway12+ months from savings + stock portfolio buffer
Time-to-first-paid (his plan)Week 20 to 26
LanguagesGerman (native), English (fluent), [INSERT: others?]
TechFeb 2026 MacBook Pro, Burp Suite Community installed, Firefox with proxy configured
Open to recommendationsYes. Asked Donal "feel free to reach out with suggestions".

Background

Master's degree in Information Systems with thesis on LLM cybersecurity. Bachelor's degree in Business Administration. Multiple years of corporate tax accounting experience.

Currently transitioning into offensive web application security as a solo consultant. Has built a comprehensive 26-week self-study curriculum (29 pages, well-structured) and a 1-page business plan. Both delivered to Donal 2026-05-21.

The combination of LLM thesis + accounting + business admin makes him unusually well-positioned for the AI/LLM security niche selling to SMB SaaS founders, who need someone who can speak both engineering and P&L. Almost no credible practitioners in this lane.

What he has articulated (in the plan he sent)

Offer stack (4 tiers, his order)

OfferPriceScope
Web App Pen-Test$3.5K to $12K5 to 15 day full assessment
Productized Audit$1.5K to $3.5KFixed-scope, 3 to 5 days, prioritized report
AI/LLM Security Review$3.5KOWASP LLM Top 10 assessment + remediation
Monthly Retainer$1.5K to $4K/moOngoing security advisor (goal by Mo. 9)

Revenue prioritization (his order): Productized audits first, then Pen-test contracts, then Bug bounty.

Go-to-market (his plan)

Target buyer: SMB SaaS founders (5 to 50 employees) with web apps handling user data or payments. Fintech/tax-adjacent and AI-powered products prioritized.

Geography: US, EU, German-speaking. Served remotely from Chiang Mai (~25% client cost-of-living = geographic arbitrage).

26-week milestones

What he has NOT articulated (the gaps we close)

  1. The AI/LLM Security Review is treated as offer #3 but is actually his strongest wedge. It is the only one of his four offers he can deliver TODAY (his thesis is the methodology). Productized audits and pen-tests require Phase 2 to 4 skill build. He has buried his unfair advantage at position 3 of 4. This is the package's central insight.
  2. No revenue path before Week 20. His plan assumes he must complete PortSwigger + PNPT before invoicing. False. OWASP LLM Top 10 reviews need none of those. He can be billable Week 4.
  3. Free-finding methodology is a one-liner, not a system. Plan says "lead with a free finding" but no template, no script, no scope, no qualification gate. This is the highest-leverage commercial system he needs.
  4. No sample report. His plan says "sample report by Week 20". A sanitized sample report can be written Week 1 from his thesis + a fake target. Single most important sales asset.
  5. LinkedIn rhythm undefined. "Weekly write-ups" with no calendar, no post types, no hook structure.
  6. No contracts pack. SOW / MSA / NDA / payment terms / liability disclaimers all undrafted. He needs these before the first paid engagement, not at Week 22.
  7. Domain inconsistency (tagwercher.io vs tagwercher.com) and no decision on portfolio site stack.
  8. No partner / co-founder. Solo. Different from Jacques. Lower coordination cost, but also no division of labor between sales and delivery.
  9. No cyber liability insurance. Plan mentions it from Month 5 onward (~$60/mo). Should ideally be in place BEFORE first paid engagement, not after.
  10. No pricing-ladder logic. Fixed ranges given, no triggers for raising prices. Geographic arbitrage is a one-way street if he prices for Chiang Mai cost-of-living. He should price for US/EU client value.

Tech readiness (today, from his curriculum doc)

SystemStatus
MacBook Pro (Feb 2026)Ready
Burp Suite CommunityInstalled
Firefox + FoxyProxy + dev toolsSet up
Kali VMNot yet (VMware Fusion or UTM recommended in his plan)
Native macOS tools (nmap, ffuf, sqlmap, nuclei)Not yet
Python tooling (requests, BeautifulSoup, async)Not yet
TryHackMe Premium / HackTheBox VIPPlanned ($84 + $96 for 6 months)
PortSwigger Web Security AcademyFree, planned heavy use Wk 5 to 10
PNPT certificationPlanned Wk 18 to 20 ($499)
Domain + email + websitePlanned Wk 1 ($60/yr)
Cyber liability insurancePlanned from Month ~5 (~$60/mo via Hiscox/Embroker)
Mullvad VPNPlanned ($5/mo)

Self-assessed skill position (from his curriculum)

"Your starting position is unusually strong for someone breaking into offensive security."

His framing of strengths

His framing of gaps (implicit in curriculum)

Commercial realities

What he asked for

Email of 2026-05-21:

"I enjoyed very much talking to you yesterday, you seem like an experienced guy who knows what he's doing. Attached you can find the curriculum I'm working through (I'm still very much at the beginning) and also a business plan I drafted. Feel free to reach out with any suggestions for improvements/adaptions."

Open invitation to critique + suggest improvements. Friend-tier, no commercial expectation. Donal's intent: ship a high-leverage package as a co-working-community goodwill investment.

How this package frames the engagement

This is NOT a paid engagement. Donal is NOT delivering pen-testing or AI security work FOR Sebastian. The package is:

  1. A critique + sharpening of the plan he wrote (council methodology)
  2. A revenue-compression argument (Week 4 vs Week 20) with the supporting offer + ops kit to make it real
  3. A starter operational kit (sales scripts, LinkedIn rhythm, sample report, contracts) so he doesn't build from zero
  4. A deployed portfolio surface at tagwercher-orb.pages.dev he can share when introducing himself

Open questions to ask Sebastian

Q1
Which domain do you own?
tagwercher.io or tagwercher.com (or both). Resolve the branding inconsistency before any outreach.
Q2
Legal entity / jurisdiction for invoicing?
German Einzelunternehmen, Thai BOI, US LLC, or other.
Q3
Any paid security work yet?
Even informal. Affects how Tier 1 launch pricing is anchored.
Q4
Open to leading with AI/LLM?
Treat web app pen-test as the Phase-2 upsell.
Q5
LinkedIn URL?
Needed to wire the 90-day engine + headline rewrite.
Q6
Existing warm contacts?
Anyone running or working at SMB SaaS. Highest-converting outreach channel.