Event History
August 31, 2009
Virtual Forge at SAP TechEd 2009 Vienna
As in the past, the Virtual Forge Team will attend SAP TechEd in Vienna from 27th to 29th October 2009 this year again.

After the successful premiere of CodeProfiler at SAP TechEd 2008 in Las Vegas and Berlin, Virtual Forge is now glad to present our scanner in Vienna with more than 12 months of field experience. We will show the tool in action and present stories from successful roll-out projects. is the most efficient solution to assure security and compliance at code level for your custom developed SAP code.

Meet us at the TechEd in Vienna and get a personal impression about how Virtual Forge's services and solutions will improve security of your company assets.

Click here to visit the SAP TechEd Homepage
Click here to visit the Homepage
July 12, 2009
Virtual Forge at DSAG congress
Virtual Forge will hold a lecture at this year's congress of DSAG, the German SAP Users' Group. The presentation will cover the topic "SAP Penetration Tests - Praktische Erfahrungen und Nutzen für den Kunden" (SAP penetration tests - empirical experience and customer benefit).

The congress will take place on September 30 and October 1, 2009, at the Messe und Congress Centrum in Bremen, Germany.

Find more information about DSAG's yearly congress on the DSAG Web site (in German language)
January 31, 2009
ISSECO Certified Professional for Secure Software Engineering - Preparation Workshop
The 1st official training course for secure development. The course prepares you for a certification by iSQI. We will offer the training together with the former CSO of SAP, Prof. Dr. Sachar Paulus.

The 3 day course takes place in Heidelberg on March 11 - 13, 2009 and in Brandenburg on July 1 - 3.

Read more
January 31, 2009
Virtual Forge offers secure ABAP programming workshop
This basic course explains why ABAP programs are at risk, provides hands-on examples and teaches best coding practices for developing secure ABAP.

This 2 day course takes place in Heidelberg on April 28 - 29, 2009.

Read more
October 7, 2008
Virtual Forge at SAP TechED '08 in Berlin
As in former years, Virtual Forge is represented at the SAP TechEd Europe in Berlin. This year, you can find us at booth no. 2.21 in the exhibition hall.
Together with partner akquinet, CTO Andreas Wiegenstein and CEO Dr. Markus Schumacher will show our new product to you. is the first static ABAP code analysis tool. It greatly helps you to improve ABAP programs regarding security, compliance and performance issues in a fast-paced and user-friendly way.
Additionallly, Virtual Forge will present its Hacking Challenge again in the SDN Clubhouse. Participants run the chance of winning an iPod.

Today, SAP publishes a press release on in the TechEd Newsroom.

The SAP TechEd '08 Europe takes place at ICC in Berlin on October 14 - 16, 2008.

Click here to read SAP TechEd Press Release
Click here to visit the SAP TechEd Homepage
Click here to visit the Homepage
September 10, 2008
Virtual Forge at SAP TechED '08 in Las Vegas
As in former years, Virtual Forge is represented at the SAP TechEd USA in Las Vegas. This year, you can find us at booth no. 97 in the exhibition hall.
CTO Andreas Wiegenstein and our partner Eric Kang from Adventier will show our new product to you. is the first static ABAP code analysis tool. It greatly helps you to improve ABAP programs regarding security, compliance and performance issues in a fast-paced and user-friendly way.

Today, SAP published a press release on in the TechEd Newsroom.

The SAP TechEd '08 USA takes place at Venetian Hotel in Las Vegas on September 8 - 12, 2008.

Click here to read SAP TechEd Press Release
Click here to visit the SAP TechEd Homepage
Click here to visit the Homepage
April 15, 2008
Dr. Markus Schumacher Speaks at SQC Conference
As in 2007, Markus Schumacher is again invited to hold a lecture at the "Software & Systems Quality Conference" (SQC).

He will talk about "Software Security Metrics 101 - Why & How?". Dr. Schumacher will explain the meaning and importance of application security on the software level as an essential additional layer for secure business applications besides well-known practices like authorization checks, firewalls, etc.

The conference takes place in Dusseldorf, Germany, from April 16 - 18 2008.
For more information, please visit the SQC homepage.
September 5, 2007
CTO Andreas Wiegenstein to Present for Association of German Internet Enterprises eco
eco, the Association of German Internet Enterprises (Verband der deutschen Internetwirtschaft e.V.), has invited Virtual Forge CTO Andreas Wiegenstein to speak at a workshop of its security task force. His presentation, titled "Web-Anwendungen - versteckte Hintertüren zu Ihren Geschäftsgeheimnissen" ("Web Applications - The Secret Back Door to Your Business Secrets"), will use cross-site scripting attacks as an example to illustrate the dangers of Internet applications. At the same time, Wiegenstein’s presentation will demonstrate possibilities and limitations of preventive security measures.

The workshop takes place in Frankfurt/Main, Germany, on September 26, 2007.
For more information, visit eco directly.
August 2, 2007
Dr. Markus Schumacher Speaks at DSAG Congress
The German-Speaking SAP User Group (DSAG) invited Virtual Forge's CEO to hold a lecture at the yearly congress in November.

Dr. Markus Schumacher will talk about "Application Security - A New Challenge for SAP Customers?", showing the security requirements and solutions for the highly sensitive area of Human Capital Management.

The event will take place in Frankfurt/Main, Germany, from November 5 - 7 2007.
For more information, please visit the DSAG homepage.
May 24, 2007
Virtual Forge in Australia
Sebastian Schinzel, Security Consultant of Virtual Forge, speaks at the SAP specific conference "Mastering SAP Technologies" in Melbourne on June, 5th. His presentation will focus on "Application Security Threats and Countermeasures".
Conference homepage
March 29, 2007
Business Breakfast in Ludwigshafen, April 18 2007, 9:00 am - 1:00 pm
Virtual Forge an its partner SHE are inviting to a business breakfast focusing on SAP security.

Dr. Wilfried Schmitz, CTO of SHE, will give an introduction and Virtual Forge's CEO Dr. Markus Schumacher will hold the final lecture speaking about "Security Processes for SAP Customers' Applications".
Additionally, Klaus Schimmer of SAP Corporate Security will give an overview of the goals and visions of the SAP Global Security Alliance - Virtual Forge joined this network of SAP security related companies last year.
The event is free. It takes place at the premises of SHE, Ludwigshafen.

For further information and registration, please check the flyer.
March 26, 2007
Dr. Markus Schumacher speaks at ROOTS Conference in Bergen, Norway
In his session "Security Patterns Applied - Volume II", Virtual Forge's CEO will continue his last year's security pattern tutorial.
Additionally, he will hold a hands-on session called "Hacker's Corner" where participants can learn about software issues on the basis of Virtual Forge's training environment. Furthermore, they can participate in a hacking challenge and try to break into a prepared Web Shop.

The ROOTS Conference will take place in Bergen, Norway, on April 25 to 27 2007.
For detailed information, please check the ROOTS homepage.
March 26, 2007
Dr. Markus Schumacher at CeBIT
Virtual Forge's CEO spoke at the Security Forum organized by IT journal PC Professionell.
Together with other international experts, he contributed to the special exhibition "CeBIT Security World".

CeBIT took place in Hannover, Germany, on March 15 to 21 2007.
More information at the CeBIT Security World homepage

March 26, 2007
Virtual Forge presents results of Web Application Scanner Benchmark in Berlin
Virtual Forge's CEO Dr. Markus Schumacher held a session on "Security of Web Applications" in which he spoke about typical problems and best practices to find, solve and avoid them.

The conference took place in Berlin, Germany, on March 12 to 13 2007.
For more information on the congress, please visit the conference homepage or read the brochure.
October 16, 2006
SAP TechEd '06 Amsterdam, October 18 - 20
At the European SAP TechEd '06 in Amsterdam, Virtual Forge will present its Hacking Challenge again.

On Friday 20th, Andreas Wiegenstein will perform a demonstration where he shows all the issues and hands over another brand new video iPod to the winner of the competition.

Visit the SAP TechEd Amsterdam website for more information.
September 25, 2006
SECOBAP'07: Markus Schumacher member of program committee
The First International Workshop on Security Technologies for Next Generation Collaborative Business Applications (SECOBAP'07) will take place in Istanbul, Turkey on April 16-20, 2007 in connection with the 23rd International Conference on Data Engineering (ICDE'07).

The workshop will provide a forum for presenting novel research results in collaborative business processes security. It will deal with topics like secure business processes, security policy management, web services security and related subjects.

Both papers on original research and position papers are welcome. Submission time ends on November 13, 2006.

Click here for further information
September 20, 2006
Information Security Conference in Krems on October 4th
After the kick-off of the Enterprise SOA Taskforce at the SAP TechEd in Las Vegas, Markus Schumacher will talk about "Secure Enterprise SOA - known and new challenges" at the 4th Information Security Conference in Krems, Austria.

More information at the University of Krems

September 10, 2006
Virtual Forge presents portfolio of Application Security and Global Risk & Compliance
Visit us at TechEd ´06 in Las Vegas (September 12th to 14th, 2006). Together with our partner SecurIntegration we willl show you how to secure your SAP NetWeaver® installations and application as well as how to reach compliance.
Visit our exciting live security competition and training in the Security Lounge at the SDN Clubhouse and win a brand-new iPod! Additionally, interesting demos of solutions for strong authentication in SAP NetWeaver® applications like the SAP Enterprise Portal are waiting for you at booth 67 in the ballroom of the Venetian Congress Center on level 2.

Visit the lecture of our CTO Andreas Wiegenstein, a frequent TechEd speaker. This year he will talk about "Top Five Application Security Threats and Contermeasures", and demonstrate how easily hackers can bypass security solutions like firewalls, reverse proxies and others if the developers have not done their homework. The lecture will be of approximately one hour length. Please check the official TechEd '06 site for up-to-date information.

Venetian Conference Centre
3355 Las Vegas Blvd South
Las Vegas, NV 89109.

Read our Press Release for further information.
May 18, 2006
CAST Forum, Darmstadt, Germany
Workshop on web service security: Gert Kremser of Virtual Forge talks about "Threat Modeling for Service-Oriented Architectures".
April 25-28, 2006
ROOTS, Bergen, Norway
At the Recent Object-Oriented Trends (ROOTS) conference, CEO Dr. Markus Schumacher gives a short introduction to Security Patterns and a three-hour tutorial on "Security Patterns: from Threat Models to Pattern Mining". Together with Sverre Huseby, author of "Innocent Code", he also offers an interactive Hacker Workshop.
January 22-26, 2006
OOP, Munich, Germany
At the OOP in Munich, CEO Dr. Markus Schumacher gives a 90-minute tutorial about "Understanding Security with Patterns". The Virtual Forge team also offers a security competition "Hacker Battleground".

OOP 2006
September 16, October 7, October 16, 2005
Survival for Programmers, Munich, Darmstadt, Magdeburg 2005
CTO Andreas Wiegenstein presents "live web hacking" in his tutorial "Ladendiebstahl leicht gemacht" together with Uwe Baumann of Microsoft at a series of workshops organized by "Deutschland sicher im Netz". The presentations take place at the universities of Magdeburg, Munich and Darmstadt.

Using the example of a typical Web shop, Wiegenstein and Baumann show how an attacker breaks into such an application and what damage he could do if the application is vulnerable. They demonstrate that security tools like firewalls are useless against application-level attacks. They conclude that it is important to consider security at the application-level and to harden the software itself against attacks.

"Deutschland sicher im Netz" is an initiative under the patronage of the Federal Ministry of Economics and Technology. Companies like SAP, Microsoft and many others work together to increase the awareness in Germany of the risks connected to the Internet and how they can be prevented.
November 7, 2005
SAP TechEd, Boston 2005
The title and topic of his lecture: "Web Applications - Security Risk #1"

According to a Gartner study, 70% of all attacks on networks take place in the application layer. Hence the importance of application security has increased dramatically in the past few years. In earlier times almost all attacks were against the network and system layer. Today you are no longer secure behind firewalls, virus scanners and anti-Trojan software. The security of Web-based applications has become an indispensable part of any effective security strategy and must have a high priority in every risk mitigation strategy.

Andreas Wiegenstein will teach "best practices" for secure Web programming in his lecture "Web Applications - Security Risk # 1" at Teched 2005 in Boston. In addition he will present how security of applications can be significantly improved by established test procedures and consequent "lessons learned" sessions. Understanding application security is a key success factor in order to implement effective countermeasures and to your assets and competitive advantages.