Skip to content

New guideModernizing a legacy system without stopping the business

Security

Application security checklist for business software

The controls that prevent the most common breaches in web and mobile applications.

Author
Eryon Engineering
Published
Updated
Reading time
1 min
Secure administrative dashboard with role-based navigation

Key takeaways

  • Access control failures are the most common and most damaging issue.
  • Secrets, configuration and dependencies need as much care as code.
  • Log security events so incidents can be investigated.
  • Review security before launch and after major changes.

Most breaches in business software come from ordinary gaps, not exotic attacks. A practical application security checklist for teams building and running web and mobile systems.

Access control first

Broken access control — users reaching data or actions they shouldn't — is the most frequent serious flaw in business applications. Check permissions on the server for every request, scope data by organisation and role, and test the negative cases: what a user must not be able to do.

Authentication and sessions

Where possible, integrate single sign-on so accounts are managed centrally and removed when people leave.

  • Offer multi-factor authentication, and require it for administrators.
  • Store passwords with a modern hashing algorithm.
  • Expire sessions and revoke tokens on logout and password change.
  • Protect login and reset endpoints with rate limiting.

Input handling and data protection

Validate input at the boundary, use parameterised queries, and encode output to prevent injection and cross-site scripting. Encrypt data in transit and at rest, and collect only what the business actually needs — data you don't hold can't leak.

Configuration, secrets and dependencies

Many incidents start with a forgotten test endpoint, a public storage bucket or an outdated library rather than a flaw in the main code.

  • Keep secrets in a managed secret store, never in code.
  • Set secure HTTP headers and disable unused features.
  • Scan dependencies automatically and patch promptly.
  • Restrict cloud permissions to the minimum each service needs.

Logging, monitoring and review

Record security-relevant events — logins, permission changes, exports, administrative actions — and alert on unusual patterns. Review security before each major launch and after significant architectural changes, using the OWASP Top 10 as a baseline.

Related serviceApplication SecuritySecure architecture, access control and hardening for business systems.

Enjoyed this? Get the next one by email.

One email a month. Unsubscribe any time.

Have a productworth building?

Let's turn the idea into a system your business can actually use.