Skip to content
steelabs

Insights

Application security

OWASP-led assessment work from the practitioner side — what a structured review actually covers, where access-control bugs hide, and the difference between a scanner report and a finding somebody reproduced.

Where we stand

A scanner produces a list. An assessment produces findings somebody reproduced, with the reasoning for the severity shown, which is a different artefact with a different cost and a different value. We would rather hand over twelve demonstrated issues than three hundred lines of tool output that a developer has to triage before they can act.

The findings that matter are usually about authorisation rather than about injection. Products spanning several roles have far more role pairs than anyone wrote acceptance criteria for, and the damaging bug is one account reaching another account’s data through a path nobody enumerated. That work is manual, and it is where most of the value sits.

We are direct about what we are not. An OWASP-based assessment is not a certified penetration test by an accredited body, and we are not a notified body under any European regulation. Where procurement requires either, we say so early rather than at the report stage, because discovering it late is expensive for everyone.

Remediation sessions matter more than the report. Findings explained while the reproduction is still on screen get fixed correctly the first time; findings handed over cold produce a round of clarification and, often, a fix that addresses the symptom.

Articles on Application security

Contact

Have a project in mind?

Tell us what you are building — or what keeps breaking. You will get a considered reply from an engineer, not an autoresponder.