Recent history tells us that security breaches in result of successful web application attacks are among the top breaches in history. With this, millions of records of personal (and long-lived) identifiable information are exposed on the Internet and sold on the black market. The root cause of these successful attacks is vulnerabilities or security issues found in web applications. These vulnerabilities are inadvertently introduced in the code of web applications by their developers. Given the impact that such breaches have on society in general, proper and efficient security testing is paramount to increase the security of applications, the internet, and the society.
Current security testing methodologies, such as penetration testing, need to be challenged. Agile (iterative and incremental) software development methodologies have become popular and trendy, leading to more frequent releases. However, this is not compatible with penetration testing, because of the time and costs involved.
On the other hand, smaller companies don’t have the resources to hire a penetration testing service or to have an internal security team, leaving out proper security testing from their roadmap.
The solution relies on a) something more affordable and b) something that doesn’t require a lot of time from technical teams and that allows developers to be more independent when it comes to security testing. And these are Probely’s DNA.
The objectives for this SME Instrument project were to conduct a feasibility study for the aforementioned product and to study the viability of the business.