Skip to content
AspirecoStart
All answers

Cybersecurity

What should a first security review of a business app cover?

The short answer

Start with who can get in and what they can reach: authentication, authorisation, session handling and tenancy boundaries. Then secrets, dependencies, how the app is deployed, and whether backups have ever been restored. The output should be ranked findings you can act on, not a generic checklist.

Updated

Access first

Authentication, authorisation, session handling and tenancy boundaries — and whether access is modelled in the data and enforced on the server, or merely hidden in the interface. Hiding a button is not access control.

Secrets

Keys and passwords belong in a managed store, not in code or config files, with rotation that someone actually performs.

What the app pulls in

A dependency and supply-chain audit: what you ship, what it pulls in, and what is unmaintained. More in what a supply-chain audit covers.

How it runs

Hardened deployments — least-privilege service accounts, private networking, verified TLS — and backups that have actually been restored, with a written plan for the day something is breached. More in why an untested backup does not count.

What you get

A written dossier with ranked findings, yours to keep whether or not you hire us. Reviews of systems we did not build usually start with the free audit, because the risk often sits somewhere other than where it was expected.

Asked next

How often should a business app get a security review?

After any significant change, and on a schedule otherwise. Under retained capacity, dependency, access and infrastructure reviews happen on a schedule rather than when someone remembers.

Is a security review worth it for a small business?

It is cheapest while a system is being designed and most expensive to retrofit, which is why it is built into every programme rather than sold as an extra.