Training

OWASP Mobile Top 10: recognising security risks in apps

Your team develops mobile apps and needs to recognise their most common security risks. The workshop works through the OWASP Mobile Top 10 with technical examples and countermeasures.

Two mornings as an interactive webinar, for teams that develop, operate or test mobile apps.

Free of charge and without obligation.

  • OWASP Corporate Member · Silver Sponsor
  • Trainers are penetration testers
An open brass compass lying in a hand in front of a world map and sticky notes
OWASP Mobile Top 10: secure apps from the start.

Your situation

Your team develops mobile apps and needs to know where their security risks lie?

An app runs on devices you do not control. It stores data locally, communicates with a back end and can be taken apart and analysed by anyone who downloads it. This is why different risks apply to Android and iOS apps than to web applications – and apps in healthcare or finance often face additional testing requirements from clients or certifications.

The OWASP Mobile Top 10 summarises the most common risks of mobile applications. The workshop works through them with technical examples and countermeasures and ends with what development teams can take away: tips for developers and the procedure of an app penetration test. The APIs behind the app are covered in the OWASP API Security Top 10 workshop.

It is designed and delivered by the penetration tester responsible for mobile app security at secuvera. It is aimed at developers and DevOps, technically experienced product owners, product and project owners, and IT administration with knowledge of mobile apps and web technologies.

Services & results

App security based on the OWASP Mobile Top 10

Your team recognises the risks of the current OWASP Mobile Top 10 in Android and iOS apps, including the back end and APIs – each with a technical example and countermeasures. In addition, there are tips for developers and the procedure of an app penetration test, taught by the penetration tester responsible for mobile app security at secuvera. The training is available in German or English.

From the question of why an app is more than just an app, through the Mobile Top 10, to the procedure of an app penetration test. Two mornings, each from 9:00 to 12:30.

Context: OWASP and incidents involving apps

Overview of OWASP and selected projects for mobile security, then examples from public reporting in which apps were the vulnerability.

“Just an app?”

An app rarely stands alone: it comes with a back end, APIs and the device it runs on. This part shows the resulting attack surface and why a security review must not stop at the boundary of the app.

The OWASP Mobile Top 10 with technical examples

Each risk in the current version of the OWASP Mobile Top 10 with a technical example and the appropriate countermeasures. We cover Android and iOS equally.

Tips for developers and how app penetration tests work

To finish, the trainers summarise the tips for developers and show how an app penetration test works. It is based on our own testing practice: we test Android and iOS apps in line with the OWASP Mobile Application Security Testing Guide (MASTG).

Result

Your team knows the Mobile Top 10 risks, has tips for developers to hand and knows what is tested in an app pentest.

Our expertise

The trainer and author of the concept is Ruben Konrad, penetration tester and member of secuvera's Product Security team. In the pentest team, he is responsible for mobile app security and tests mobile apps, web applications and systems. In Product Security, he advises and evaluates under Common Criteria and IEC 62443.

We carry out app analyses for Android and iOS in line with the OWASP Mobile Application Security Testing Guide (MASTG). Our Common Criteria evaluation facility has specialised experts for smartphones, mobile systems and Android-based systems, among others. As an evaluation facility for BSI TR-03161, we also evaluate health applications. What the workshop says about app penetration tests comes from this practice.

Getting started

Format and schedule

Two mornings, remote

From 9:00 to 12:30 on each of two days, as an interactive webinar via Zoom – or via your platform, such as Webex or Teams. On site on request; in that case you provide the room and presentation equipment. Instead of a script, you receive slides to follow along and show notes for each session, and a certificate of attendance on request.

Up to 15 participants

You decide the number. For didactic reasons, we recommend up to 15 participants; with more than 20, the results suffer.

Plan OWASP training
Over-the-shoulder view of a map with sticky notes and navigation instruments
Know the mobile risks before your app sets sail.

secuvera is the training provider

The training is offered by secuvera and teaches OWASP methods. It is not a training course of the OWASP® Foundation.

Questions about the App Security workshop

Do we need the basic module first?

Not necessarily. The module builds on the basic module on web application security/OWASP Top 10, but can also be booked without it, depending on your level of knowledge.

How is the training structured?

Over two mornings from 9:00 to 12:30 as an interactive webinar: theory, joint technical demonstrations, polls and discussion. 95% of participants prefer this format to a full training day. Zoom is the standard; Webex, Teams or your own platform also work, and on request the training takes place on site.

How many people can take part?

You decide. We recommend up to 15 participants; with more than 20, the results suffer. The price applies per session, regardless of the number of participants.

Is the training adapted to our applications?

No. The modules are standard training courses that we continue to develop across all sessions. If you wish, send us a list of your internal requirements in advance, such as development guidelines – the titles are sufficient.

How does the workshop relate to an app penetration test?

The last part shows how an app pentest works. The workshop does not replace the test itself. If you want your app tested, that is a separate penetration test; we test Android and iOS apps in line with the OWASP MASTG.

How can we support you with the OWASP Mobile Top 10?