Training

OWASP Top 10: training on security risks in web applications

Your team develops or operates web applications and needs to recognise the most common security risks before someone exploits them. The training works through the OWASP Top 10 using real-world examples – with interactive demonstrations instead of slides.

Two mornings as an interactive webinar, for development, product and project owners, business departments and IT administration. The basic module is expressly suitable for participants with less technical background as well.

Free of charge and without obligation.

  • OWASP Corporate Member · Silver Sponsor
  • Trainers are penetration testers
A navigation instrument being explained in a joint discussion
OWASP Top 10: recognising and avoiding security risks in web applications.

Your situation

Your team needs to know the OWASP Top 10 – including those who do not write code themselves?

A penetration test report lists findings such as Injection or Broken Access Control, and only part of the team understands what they mean. A client or your development guideline refers to the OWASP Top 10. Or product owners, business departments and IT administration are expected to have a say in security requirements without developing themselves.

The OWASP Top 10 is the best-known list of the most common security risks in web applications. It is not a standard to be met, but a common language for development, product ownership and operations.

The basic module of our OWASP training concept is expressly intended for participants with less technical background as well. The trainers are secuvera penetration testers; they show the risks through live demonstrations and examples from practice. If you want to go deeper, you can then book one of the advanced modules: Advanced, API Security, Mobile Apps or secure software development with OWASP SAMM.

Services & results

Basic module: the OWASP Top 10:2025 in two mornings

Your team understands every risk in the OWASP Top 10:2025 through real incidents and live demonstrations, such as Broken Access Control, Software Supply Chain Failures and Injection – expressly including people who do not write code themselves, such as product owners, business departments and IT administration. The trainers are secuvera penetration testers; Tobias Glemser leads the OWASP German Chapter. The training is available in German or English.

Two mornings from 9:00 to 12:30 as an interactive webinar – according to feedback from 95% of participants, better than a full training day. Theory alternates with live demonstrations, polls and discussion.

Understanding OWASP

Who the Open Worldwide Application Security Project is, how the Top 10 are compiled and which other OWASP projects are useful for development and testing. The background comes first-hand: trainer Tobias Glemser leads the OWASP German Chapter.

Real incidents

Well-known security incidents from public reporting, traced back to the Top 10 risks. This makes it clear that the subject is real vulnerabilities, not textbook cases.

The ten risks with live demonstrations

We explain each risk in the OWASP Top 10:2025 – including Broken Access Control, Software Supply Chain Failures, Injection and Mishandling of Exceptional Conditions – and demonstrate it interactively wherever possible. The examples come from our own web application penetration tests.

Result

Your team can name the ten risks and recognise them in its own applications and pentest reports.

Testing tools and methods from penetration testing

Which tools and methods are used in a web application penetration test, what automated scanners find and where manual testing remains necessary. We test web applications ourselves in line with the OWASP Web Security Testing Guide and the technically testable parts of the OWASP Top 10.

Result

Your team can judge what a scan achieves and what a manual penetration test additionally covers.

Principles for countermeasures

Not recipes for each risk, but the principles behind them: where a check belongs, why input validation alone is not enough and how protective measures can be transferred to your own applications. The trainers record questions from your session in show notes with references.

Result

Your team derives protective measures itself; the show notes serve as a reference.

Our expertise

The OWASP training courses are delivered by secuvera penetration testers who test web applications, APIs and apps themselves. The basic module is delivered by Tobias Glemser: managing director of secuvera, BSI-certified penetration tester, technical lead for penetration testing and chapter lead of the OWASP German Chapter. He has published security advisories on vulnerabilities he found in web applications and IoT devices, writes for c’t and iX among others, and speaks at events such as OWASP AppSec Germany, DevSec, secIT and it-sa.

secuvera is an OWASP Corporate Member and has been carrying out penetration tests since 2000 – we test web applications in line with the OWASP Web Security Testing Guide and the technically testable parts of the OWASP Top 10.

To date, we have held a three-digit number of training sessions for a four-digit number of participants; the overall rating is better than 1.3 on the German school grading scale (1 = best). Organisations that have booked the training include OTTO, Hapag Lloyd, Lufthansa Systems, TU Dresden, Bundesdruckerei, Verband der Ersatzkassen and Check24 – many as a regular part of their staff development.

Getting started

Format and schedule

Two mornings, remote

From 9:00 to 12:30 on each of two days, as an interactive webinar via Zoom – or via your platform, such as Webex or Teams. On site on request; in that case you provide the room and presentation equipment. Instead of a script, you receive slides to follow along and show notes for each session, and a certificate of attendance on request.

Up to 15 participants

You decide the number. For didactic reasons, we recommend up to 15 participants; with more than 20, the results suffer.

Individual places via heise conferences

For individuals, there are open dates with our partner heise conferences. From around six participants, a dedicated training session for your team is more cost-effective.

Building on it

If you want to go further, you can then choose from the advanced modules: Advanced, API security, app security or secure software development with OWASP SAMM.

Plan OWASP training
Over-the-shoulder view of a map with sticky notes and navigation instruments
Learning objectives aligned with your team's prior knowledge.

secuvera is the training provider

The training is offered by secuvera and teaches OWASP methods. It is not a training course of the OWASP® Foundation.

Questions about the OWASP Top 10 training

How is the training structured?

Over two mornings from 9:00 to 12:30 as an interactive webinar: theory, joint technical demonstrations, polls and discussion. 95% of participants prefer this format to a full training day. Zoom is the standard; Webex, Teams or your own platform also work, and on request the training takes place on site.

How many people can take part?

You decide. We recommend up to 15 participants; with more than 20, the results suffer. The price applies per session, regardless of the number of participants.

Is the training adapted to our applications?

No. The modules are standard training courses that we continue to develop across all sessions. If you wish, send us a list of your internal requirements in advance, such as development guidelines – the titles are sufficient. The training is not a test of your application – that is what a penetration test is for.

Is this a certification?

No. The training teaches OWASP methods and does not end with an exam.

How does this relate to a penetration test?

The training explains what a test finds and why. Many teams book it before their first penetration test so that they can read the report afterwards.

Articles on this topic (in German)

All 42 articles on the topic (in German)

How can we support you with the OWASP Top 10?