Insights & Research

Engineering secure digital systems

Practical security research, engineering notes and technical perspectives from the people building and securing the software organisations depend on.

Featured research

Application security
Featured

OWASP Top 10 for Business Applications

What these risks actually look like inside point-of-sale systems, APIs and payment integrations — and the first check to run on each one.

  • Application Security
  • 8 min read
Read the article

The ten risk categories

  • A01
  • A02
  • A03
  • A04
  • A05
  • A06
  • A07
  • A08
  • A09
  • A10

The ten risk categories, in the order OWASP lists them. Each is assessed against the request path below.

Request path we assess

  1. Untrusted input
  2. Server-side validation
  3. Authorised business logic
  4. Audited data store

Published research

Archived with a DOI
Research paper

Implementation and Analysis of IoT Attack Vector on Windows Systems

A study of how an IoT attack vector reaches and affects Windows systems — the implementation, the analysis and the resulting security implications.

DOI 10.5281/zenodo.14886141

View publication

Attack path studied

  1. IoT device
  2. Network exposure
  3. Windows system
  4. Attack vector
  5. Security impact

Have a system worth reviewing?

We assess web applications, APIs and business integrations against the same practical risks we write about — and report the specific checks to make first.

Request a security assessment