SecLab
The risk map and an AppSec mindsetchallengeDifficulty 3/535 min

Challenge: triage eight real findings

Objective: After this lesson you can take a pentest report and order the fixes yourself, with reasoning that survives a tech lead.

A01:2025A02:2025A10:2025SSDF RV
Step 1 of 5 · read3 min

The goal, with no guidance

This is a challenge: goal only. There are no hand-holding steps, and that is deliberate — this is where you prove you can do on your own what the previous three lessons taught.

The situation. You are the only backend developer on a small B2B SaaS product: customers are companies, each company has several users, the data is invoices and contracts. A pentest just came back with eight findings. You have one week, no help, and your tech lead will ask "why this one before that one".

What to produce. For each finding, answer four questions:

  1. Which Top 10:2025 category?
  2. Which layer — application code, config/infrastructure, process, or a business decision?
  3. Who fixes it?
  4. What position in the order, and why?

The fourth question is the only one that counts. The first three are classification; the fourth is judgement, and judgement is the part you cannot look up.

Read the primary source
View path

Comments

Join the discussion
Sign up to comment

Commenting needs an account with at least one completed lesson. That condition is what keeps this thread worth reading: every point belongs to someone who can be asked back, and reputation accrues over time.

Sign upSign in

You can still read every comment below without an account. Signing in brings you back to this exact spot, not to the top of the page.

Loading comments…