We in Basefarm focus on secure operations of mission critical applications where security is naturally of great importance. To help our customers get the best solution we give advice on how to incorporate security already in the development phase, long before applications are launched.
We believe that there are no contradiction between fast development and high security. In cooperation with Detectify, we provide a thorough security check to reveal code vulnerabilities before they are discovered by hackers.
Detectify provides an online security scanner that automatically tests your web applications for 700+ vulnerabilities. The scanner is an easy to use tool for CSOs, CISOs, CIOs, CTOs, security engineers and developers also using devops.
Detectify was born from the simple idea that the internet was broken. The company’s founders, a team of top-ranked security experts, are on a mission to fix it.
“Security is not an afterthought, it should be considered from the first line of code. The best way to improve your security is to integrate it into your development process,” says Fredrik Nordberg Almroth, Detectify co-founder and security researcher.
As to systems already up and running, Almroth points out that understanding your web application’s security status is crucial. “The only vulnerabilities you can fix are those you are aware of. Working proactively with security and running scans on a regular basis will help you get secure and learn to write safer code,” he says.
These 7 steps can improve your security of your web appliations. Some of them might sound simple. That makes them feasible, which is good.
1. Prepare and do internal security chats.
Talk about security in a way that everyone in the organization understands. For non-IT colleagues, point out how good security can keep you ahead of competitors, increase customer loyalty and avoid negative PR induced by hackers. For the IT team show how security can be practically integrated into developer routines including sprints and agile work.
2. Have recurring reviews of security tools needs.
Go over your entire IT infrastructure and re-consider what kinds of facilities and services you need and how these fits internal processes.
3. Implement a web application security monitoring service.
Use during the development process and on a continuous basis when the application is up and running.
4. Plan and prioritize.
Map out your priorities before you run a security test. You will probably prioritize an e-commerce website that processes payments rather than your online store’s blog.
5. Interpret the results.
Detectify provides you with a threat score between 1 and 10 based on the standardized vulnerability scoring system CVSS. A high score signals an urgent need for fixing. Your findings will be divided into several parts colored green, yellow and red out of severity. Don’t get too nervous: go ahead and fix what you can and consult a Basefarm expert.
6. Make security a routine and not a one-off affair.
Security can easily be something “extra” which can be hard to prioritize. Turn your next web application development project into a security lighthouse project and establish a security culture for future and existing projects also.
7. Share with those who need to know.
Share results and best practices with your security team so the results won’t be wasted, and keep your findings away from those who do not need to know.
We look forward to a more secure world where web applications are protected and prepared for hacker attacks.