Cybersecurity

OWASP Top 10: Each Vulnerability Explained Like a Human

OWASP web security vulnerabilities

Every time we're called in to investigate a web security incident, it traces back to something on this list. Sometimes two things. Rarely anything more exotic.

Training Isn't Optional

Technical controls are half the battle. The other half is human behaviour. Running simulated phishing campaigns quarterly, walking through real recent incidents with your team, and making it easy to report suspicious messages without punishment — those things are measurably effective.

The training has to be short, relevant, and repeated. A 45-minute annual compliance video doesn't change behaviour. A 10-minute monthly check-in with a real example does.

If You Are Hit: The First Hours Matter

The first hours of a security incident are decisive. Disconnect affected systems from the network but don't power them off (forensics depends on memory). Take a snapshot. Notify your incident response partner if you have one, or call immediately if you don't. Reset all credentials assuming full compromise. Notify regulators within the required window, which in India can be as short as six hours for CERT-In.

Do not pay a ransom without professional advice. Ransoms fund future attacks and, more practically, often don't deliver working decryption. The legal and insurance implications of payment are also getting more complicated each year.

What Actually Works at an SMB Budget

A reasonable baseline for a small to mid-sized business: Cloudflare's free tier in front of web properties, MFA enforced everywhere via a password manager, endpoint protection from Microsoft or CrowdStrike, tested off-site backups, and a written incident response plan. Total annual cost for a 50-person business is usually under Rs 5 lakh, often well under.

That investment dramatically reduces your exposure to automated attacks, which are roughly 90% of what you'll actually face. Targeted nation-state attacks are a separate problem and usually not your problem.

Compliance vs Actual Security

There's a quiet tension in this field between compliance and security. Compliance is what the auditor checks. Security is what actually stops attackers. They overlap meaningfully but they're not the same thing, and treating them as identical leads to the worst of both worlds.

The pattern we see at well-run security programmes: treat compliance as a baseline that gets done competently and without drama, then spend the real attention on actual risk reduction. The compliance paperwork matters because it has to happen. The substance of what's underneath matters because attackers don't care about your audit report. Related read: our post on website cybersecurity basics covers the flip side of this.

The Anatomy of a Typical Breach

Most breaches we're called in to investigate follow a depressingly predictable pattern. Someone gets a phishing email, clicks a link, enters their credentials. The attacker logs into an account that didn't have MFA, finds a file share or database, exfiltrates data, encrypts or extorts. Six to eight weeks of silent access, on average, before anyone notices.

The controls that would have stopped this at any step are not complicated. MFA on every account. Phishing training twice a year. Monitoring on sensitive systems. A backup that's actually tested. None of these are enterprise-grade investments.

Why This Isn't Someone Else's Problem

The number of times we've seen businesses assume cybersecurity is for bigger companies is, frankly, embarrassing. The math doesn't work that way. Attackers scan every IPv4 address on the internet, find something exploitable, and automate their way in. Your size doesn't protect you.

What protects you is a baseline of controls that automated attacks can't easily bypass. None of those controls are expensive or exotic. They're just work that doesn't feel urgent until the day it is.

The Human Element, Honestly

Technical controls solve a big chunk of the problem. The rest is people. Employees click links, reuse passwords, share credentials in Slack, leave laptops in cars, and occasionally try to help attackers who've called pretending to be the CEO. Every one of these has been the root cause of a breach we've seen.

Training helps but it has a ceiling. The most effective controls combine training with architecture: MFA makes stolen passwords less dangerous, EDR catches malicious activity regardless of how it got in, segmentation limits what a single compromised account can reach. Design the system to survive human mistakes, because the mistakes will happen.

The Threat Landscape in 2026

The threat landscape has shifted in specific ways worth naming. Ransomware has become more targeted and more patient — attackers dwelling for weeks inside networks before encrypting, specifically to maximise damage and negotiating leverage. AI-assisted phishing has raised the floor of attack quality substantially; the obviously-broken English phishing emails of five years ago are largely gone.

On the defence side, tooling has also improved. Modern EDR products genuinely catch more than they used to. Managed SOC services are accessible at price points SMBs can afford. The gap between what's achievable in security and what most businesses implement has widened, which is frustrating because the tools to close it exist.

The regulatory environment has also tightened meaningfully. DPDP enforcement in India is becoming real. The EU's NIS2 and DORA regulations are producing compliance demands that flow down to vendors. Being serious about security is increasingly a market access requirement, not just a risk reduction investment.

Misconceptions That Keep Businesses Vulnerable

One: 'we're too small to be a target'. Demonstrably false. Automated attackers don't care about your size — they scan everyone. Ignoring security because you're small is exactly the reasoning attackers count on.

Two: 'we haven't been hacked, so our current security must be working'. Possibly. Or you've been hacked and just don't know yet. The average time between breach and detection is months. Absence of evidence isn't evidence of absence in this domain.

Three: 'security is too expensive'. Compared to what it costs to recover from a serious incident, it's cheap. Basic security controls for a 50-person business cost less than a single ransomware recovery effort.

A Close Call We Witnessed

A mid-sized client in the manufacturing sector almost got hit by a ransomware incident in late 2025. The initial access was a targeted phishing email to their finance head that mimicked a genuine vendor. Credentials got harvested. The attackers spent about three weeks mapping internal systems quietly before anyone noticed.

What saved them was a thing they'd grumbled about installing six months earlier: a proper EDR solution on every endpoint, with a managed SOC watching alerts. The anomalous behaviour — unusual PowerShell execution from the finance head's machine at 2am — triggered a response within an hour. Containment happened before encryption started.

The investment that "seemed expensive" six months before paid for itself a hundred times over that one night. We talk about this story in every security audit discussion now. The controls that feel optional in peacetime are the only thing standing between you and a very bad quarter.

The Short Checklist

If you take nothing else from this post, take this checklist. It's what we'd hand to someone just starting out in this area. None of it is revolutionary. All of it is worth doing. The compound effect of consistently doing these things, even without any other clever moves, is meaningful over a year or two. We'd rather see a team do the checklist competently than chase the latest trend while skipping the fundamentals.

  1. Turn on MFA for every account, no exceptions. Including the CEO.
  2. Run phishing simulations quarterly. Don't punish failures. Coach them.
  3. Test your backups by actually restoring something at least twice a year.
  4. Keep a written incident response plan. Review it annually.
  5. Monitor privileged accounts more closely than regular ones.
  6. Know your legal notification obligations (CERT-In, DPDP, sector regulators) before you need them.
  7. Run tabletop exercises for incident response annually. The plan you've never rehearsed probably won't work.
  8. Keep an asset inventory up to date. Assets you don't know about are assets you can't protect.
  9. Rotate high-privilege credentials quarterly. Long-lived admin credentials are a risk.
  10. Audit user access quarterly. People change roles; old access rarely gets revoked automatically.

None of this is rocket science. It's the accumulation of small good decisions, made consistently, over time. The teams that win at this aren't the ones with the cleverest tactics. They're the ones that keep showing up, doing the fundamentals, and improving a bit each quarter. That's the whole secret, and it's also why so few actually do it. The temptation to chase the novel and the exciting is real. The discipline to keep doing the boring work that actually produces results is rare. If you've read this far, you probably have the temperament to be one of the ones who makes this work. Start with one thing from the checklist above, ship it this week, and build from there.

Closing thought: everything we've written here comes out of actual client work, not theory. If you try something based on this post and it doesn't work the way we described, that's a useful data point — both for you and for us. We'd be curious to hear what happened, either way.

Frequently Asked Questions

Do I really need to worry about all 10 OWASP vulnerabilities?

Yes, though not equally urgently. A01 (Broken Access Control), A02 (Cryptographic Failures), A03 (Injection), and A07 (Authentication Failures) cover most real-world incidents we've investigated. Get those four right and you're well ahead of most sites. The others matter but aren't where most breaches start.

Is OWASP Top 10 enough, or do I need more?

OWASP Top 10 is a baseline. For specific contexts — SaaS apps, mobile, APIs, cloud — there are more detailed OWASP projects (ASVS, API Security Top 10, Mobile Top 10) that apply additional requirements. Start with the Top 10, then layer on the relevant specialised standard for your application type.

How often should I audit my app against OWASP Top 10?

A structured audit at least annually for applications handling sensitive data. A lighter review after every major release. Continuous checking through SAST/DAST tools in CI catches many issues automatically. The annual audit is for things automated tools miss — business logic flaws, authorisation issues, complex chains.

Can automated tools find OWASP vulnerabilities?

Automated tools (Burp Suite, OWASP ZAP, Semgrep) catch roughly 30-40% of vulnerabilities. The rest require human judgement — understanding business logic, chaining small issues into bigger ones, finding authorisation flaws that look like features. Combine automated tools with periodic professional review for real coverage.

Need help with your project?

Orange Essence Technologies builds e-commerce, software, mobile apps and AI solutions for clients across India and around the world. If any of this is relevant to what you're working on, we'd love to chat.

Get in touch →