Context: OWASP and incidents involving apps
Overview of OWASP and selected projects for mobile security, then examples from public reporting in which apps were the vulnerability.
Training
Your team develops mobile apps and needs to recognise their most common security risks. The workshop works through the OWASP Mobile Top 10 with technical examples and countermeasures.
Two mornings as an interactive webinar, for teams that develop, operate or test mobile apps.
Free of charge and without obligation.

Your situation
An app runs on devices you do not control. It stores data locally, communicates with a back end and can be taken apart and analysed by anyone who downloads it. This is why different risks apply to Android and iOS apps than to web applications – and apps in healthcare or finance often face additional testing requirements from clients or certifications.
The OWASP Mobile Top 10 summarises the most common risks of mobile applications. The workshop works through them with technical examples and countermeasures and ends with what development teams can take away: tips for developers and the procedure of an app penetration test. The APIs behind the app are covered in the OWASP API Security Top 10 workshop.
It is designed and delivered by the penetration tester responsible for mobile app security at secuvera. It is aimed at developers and DevOps, technically experienced product owners, product and project owners, and IT administration with knowledge of mobile apps and web technologies.
Services & results
Your team recognises the risks of the current OWASP Mobile Top 10 in Android and iOS apps, including the back end and APIs – each with a technical example and countermeasures. In addition, there are tips for developers and the procedure of an app penetration test, taught by the penetration tester responsible for mobile app security at secuvera. The training is available in German or English.
From the question of why an app is more than just an app, through the Mobile Top 10, to the procedure of an app penetration test. Two mornings, each from 9:00 to 12:30.
Overview of OWASP and selected projects for mobile security, then examples from public reporting in which apps were the vulnerability.
An app rarely stands alone: it comes with a back end, APIs and the device it runs on. This part shows the resulting attack surface and why a security review must not stop at the boundary of the app.
Each risk in the current version of the OWASP Mobile Top 10 with a technical example and the appropriate countermeasures. We cover Android and iOS equally.
To finish, the trainers summarise the tips for developers and show how an app penetration test works. It is based on our own testing practice: we test Android and iOS apps in line with the OWASP Mobile Application Security Testing Guide (MASTG).
Result
Your team knows the Mobile Top 10 risks, has tips for developers to hand and knows what is tested in an app pentest.
The trainer and author of the concept is Ruben Konrad, penetration tester and member of secuvera's Product Security team. In the pentest team, he is responsible for mobile app security and tests mobile apps, web applications and systems. In Product Security, he advises and evaluates under Common Criteria and IEC 62443.
We carry out app analyses for Android and iOS in line with the OWASP Mobile Application Security Testing Guide (MASTG). Our Common Criteria evaluation facility has specialised experts for smartphones, mobile systems and Android-based systems, among others. As an evaluation facility for BSI TR-03161, we also evaluate health applications. What the workshop says about app penetration tests comes from this practice.
Getting started
From 9:00 to 12:30 on each of two days, as an interactive webinar via Zoom – or via your platform, such as Webex or Teams. On site on request; in that case you provide the room and presentation equipment. Instead of a script, you receive slides to follow along and show notes for each session, and a certificate of attendance on request.
You decide the number. For didactic reasons, we recommend up to 15 participants; with more than 20, the results suffer.

The training is offered by secuvera and teaches OWASP methods. It is not a training course of the OWASP® Foundation.
Not necessarily. The module builds on the basic module on web application security/OWASP Top 10, but can also be booked without it, depending on your level of knowledge.
Over two mornings from 9:00 to 12:30 as an interactive webinar: theory, joint technical demonstrations, polls and discussion. 95% of participants prefer this format to a full training day. Zoom is the standard; Webex, Teams or your own platform also work, and on request the training takes place on site.
You decide. We recommend up to 15 participants; with more than 20, the results suffer. The price applies per session, regardless of the number of participants.
No. The modules are standard training courses that we continue to develop across all sessions. If you wish, send us a list of your internal requirements in advance, such as development guidelines – the titles are sufficient.
The last part shows how an app pentest works. The workshop does not replace the test itself. If you want your app tested, that is a separate penetration test; we test Android and iOS apps in line with the OWASP MASTG.