Security Insights

Application Security

Thinking on cybersecurity, compliance, and managed defence - from the CyberCheck team.

Web Application Firewalls: What They Catch and What They Miss

Insecure Direct Object References: A Common but Overlooked Flaw

Web application firewalls provide a valuable layer of defense for web applications, but organizations sometimes deploy them with an overly optimistic understanding of what they protect against, leading to genuine, real gaps in overall security posture when a WAF is treated as a comprehensive solution rather than one specific, valuable layer within a broader defense … Read more

Secrets Sprawl: Finding Hardcoded Credentials Before Attackers Do

Security Awareness Training That Employees Do Not Tune Out

Hardcoded credentials – API keys, passwords, and tokens embedded directly in source code rather than properly managed through a dedicated secrets management system – remain a persistent, common security finding despite being a well-understood risk for years. Understanding why this keeps happening, and how to address it systematically, matters for any organization with a real, … Read more

OWASP Top 10 Explained for Non-Security Teams

CSRF Attacks Explained: Why They Still Work in 2026

The OWASP Top 10 gets referenced constantly in security conversations, but for developers and product teams outside dedicated security roles, the list often reads like a wall of jargon – injection, broken access control, cryptographic failures – without much sense of what these categories mean for the code they write every day. Here is a … Read more

API Security: What Most Companies Get Wrong

API Discovery: Why You Probably Have More APIs Than You Think

APIs have quietly become the primary way most modern applications communicate, both internally between services and externally with partners and customers. That shift has made API security a critical concern, yet a surprising number of organizations still treat API security as an afterthought relative to the more traditional web application security practices they have had … Read more

Why a Correctly Configured Security Header Can Still Silently Stop Working

API Discovery: Why You Probably Have More APIs Than You Think

A security review of a genuinely well-maintained web application finds that its Content Security Policy header, present and correctly configured for years, has actually been silently non-functional for the past several months – a routine infrastructure change quietly stripped the header before it ever reached real browsers, and nobody noticed, because nobody had actually been … Read more