Web & API security
Broken Access Control: Why IDOR and BOLA Top Every List
Why broken access control is the number one web risk in OWASP data, how IDOR and BOLA flaws lead to real breaches, why scanners miss them, and how to fix them.
· 6 min read
// Web App Pentest
An authenticated test of your web application against the OWASP Top 10 and the business-logic flaws scanners never find.
Automated scanners are good at spotting missing headers and outdated libraries. They are bad at noticing that one customer can read another customer’s invoices, that a discount code can be applied twice, or that a “viewer” role can call an admin-only endpoint.
A web application penetration test puts an experienced attacker in front of your app, logged in as each of your user roles, to find the flaws that actually lead to breaches, then shows your developers exactly how to fix them.
Read the full testing methodology.
// Process
A short call to agree targets, test type, dates and rules of engagement. You get a quote for that scope, then written authorization is signed before any testing starts.
Hands-on, tool-assisted testing aligned to OWASP and PTES, with every finding verified. Anything critical is reported to you immediately, not saved for the report.
A clear report: executive summary, then every finding with severity, evidence, reproduction steps and a specific fix. Followed by a readout call.
Once fixes are in, we verify each one and issue an updated report and an attestation letter you can share with customers and auditors.
// FAQ
Either. Staging is preferred when it mirrors production closely. When testing production, we agree testing windows with you, avoid destructive actions, and use dedicated test accounts so real customer data isn’t touched.
Yes. Ideally two accounts per user role (so access between users can be tested), plus any seed data needed to exercise the main features. Unauthenticated-only testing is possible, but finds far less.
Grey-box by default: authenticated access plus a short walkthrough of the app. That gives the best coverage for the budget. Source code review can be added for critical areas.
That’s one of its main uses. The report plus a letter of attestation covers the standard “have you had an independent penetration test in the last 12 months?” question.
// Further reading
Web & API security
Why broken access control is the number one web risk in OWASP data, how IDOR and BOLA flaws lead to real breaches, why scanners miss them, and how to fix them.
· 6 min read
Penetration testing
A section-by-section guide to pentest reports (executive summary, scope, severity ratings, findings and retests) and how to turn one into a fix plan.
· 5 min read
Penetration testing
What penetration tests cost in 2026 by test type, how quotes are built from days and day rates, what drives the price, and how to spot a scan sold as a pentest.
· 5 min read
// Also available
Testing of REST and GraphQL APIs for broken object-level authorization, auth flaws, mass assignment and data over-exposure.
External testing of everything you expose to the internet, and internal testing of what an attacker could reach once inside.
A fast, affordable baseline: automated scanning across your estate with every result validated, so you get a list of real issues, not 400 pages of noise.