Key takeaways
- Access control failures are the most common and most damaging issue.
- Secrets, configuration and dependencies need as much care as code.
- Log security events so incidents can be investigated.
- Review security before launch and after major changes.
Most breaches in business software come from ordinary gaps, not exotic attacks. A practical application security checklist for teams building and running web and mobile systems.
Access control first
Broken access control — users reaching data or actions they shouldn't — is the most frequent serious flaw in business applications. Check permissions on the server for every request, scope data by organisation and role, and test the negative cases: what a user must not be able to do.
Authentication and sessions
Where possible, integrate single sign-on so accounts are managed centrally and removed when people leave.
- Offer multi-factor authentication, and require it for administrators.
- Store passwords with a modern hashing algorithm.
- Expire sessions and revoke tokens on logout and password change.
- Protect login and reset endpoints with rate limiting.
Input handling and data protection
Validate input at the boundary, use parameterised queries, and encode output to prevent injection and cross-site scripting. Encrypt data in transit and at rest, and collect only what the business actually needs — data you don't hold can't leak.
Configuration, secrets and dependencies
Many incidents start with a forgotten test endpoint, a public storage bucket or an outdated library rather than a flaw in the main code.
- Keep secrets in a managed secret store, never in code.
- Set secure HTTP headers and disable unused features.
- Scan dependencies automatically and patch promptly.
- Restrict cloud permissions to the minimum each service needs.
Logging, monitoring and review
Record security-relevant events — logins, permission changes, exports, administrative actions — and alert on unusual patterns. Review security before each major launch and after significant architectural changes, using the OWASP Top 10 as a baseline.
Enjoyed this? Get the next one by email.

