We assess web applications combining automated and manual testing to discover OWASP Top 10 vulnerabilities and beyond, including business logic analysis, authentication, and authorization flows.
What's included
- Grey-box and black-box assessment of internet-facing and internal web applications, portals, and their supporting REST and GraphQL APIs, exercised both unauthenticated and as each user role to expose privilege boundaries.
- Full coverage of the OWASP Top 10 and the OWASP API Security Top 10, including injection, broken access control, server-side request forgery, insecure deserialization, and security misconfiguration.
- Business-logic and workflow abuse testing: authorization bypass, insecure direct object references, price and quantity tampering, manipulation of multi-step transactions, and race conditions that automated scanners cannot detect.
- Authentication, session management, and federation review covering password and MFA flows, JWT, OAuth2 and OIDC handling, session fixation, and token lifecycle.
- Optional secure code review, manual and SAST-assisted, of high-risk modules to trace vulnerabilities to their root cause in source and confirm the fix.
- Server, framework, and dependency configuration review, including exposed components, outdated libraries with known CVEs, and hardening gaps.
Methodology & standards
1. Scoping and threat modeling: define in-scope hosts, roles, and data flows, and agree rules of engagement, test windows, and a safe path for testing production or staging.
2. Reconnaissance and automated discovery: map the attack surface and run authenticated DAST and dependency scanning to establish a baseline, aligned to the OWASP Web Security Testing Guide (WSTG).
3. Manual exploitation verified against the OWASP ASVS: confirm each finding by hand, chain vulnerabilities, and assess real business impact, removing the false positives that tooling alone produces.
4. Risk rating and evidence capture: score every issue with CVSS v3.1 and document reproducible proof-of-concept steps.
5. Reporting, developer remediation guidance, and a complimentary retest to confirm fixes and close the loop.
Deliverables
- Executive summary that translates technical risk into business and regulatory impact for the board and audit committee.
- Detailed technical report: each finding with its CVSS score, affected endpoints, reproduction steps, evidence, and prioritized remediation.
- Developer-ready remediation guidance mapped to OWASP ASVS requirements and secure-coding fixes.
- Risk register and remediation tracker to manage closure across development sprints.
- Formal retest report confirming which findings are resolved, suitable for auditors and regulators.
- Attestation letter summarizing scope, methodology, and outcome for SAMA, NCA, or partner due diligence.
Regulatory controls it satisfies
Typical timeline
A typical web application assessment runs one to three weeks depending on the number of applications, roles, and API endpoints in scope, followed by a complimentary retest once your team has remediated.
Common questions
Do you test in production or a staging environment?
Either. We prefer a production-like staging environment to eliminate operational risk, but we can safely test production under agreed rules of engagement, rate limits, and monitoring windows.
What do you need from us to start?
In-scope URLs and API documentation, test accounts for each user role, and a technical point of contact. For the optional code review we also need read access to the relevant repositories.
From the same practice