How to decide if you need security testing for your software?

How to decide if you need security testing for your software?

Do you hate nightmares? If you do, then please continue reading it as you are possibly one of the target audience for security testing services. Typically, many start-ups or organisations do not test their software for security. Most of the times organisations are only bothered about functional aspects, while; usability & accessibility are used as add-ons (UK, Europe and US customers probably care about a11y).  Long ago, there were very few hackers in 90s however, nowadays we have handful of them who always want to breach the security for whatsoever reasons. Irrespective of any reason, as an organisation it is important to safeguard the sensitive data.

I recommend to have mix of tool-assisted and brain-assisted ethical hackers who are always in hunt for security vulnerabilities. It is important to accept the fact that, there cannot be fool-proof secured applications, but better tested applications where testers make a better effort in building a firewall against the hacks from unethical hackers.

Here is a questionnaire for you to decide if you need security testing services,

  • Can you afford to lose your customers?
  • Can you afford to lose to your competitors?
  • Can you afford to have down-time?
  • Can you afford to have bad reputation via social media?
  • Can you afford to get sued?
  • Can you afford to pay hefty amount for hosting for non genuine usage? (Cash overflow attack)
  • Can you afford to go out of business based on critical vulnerabilities?
  • Can you afford to face the questions by media?
  • Can you afford to face lawsuit?
  • Can you afford to have negative propaganda about your company / brand?
  • Can you afford to compromise with the privacy of your customers data?

If the majority answers were "NO", then you are eligible to get your software tested for security.

Now, I also understand that there could be budget constraints and you may not be able to hire cool security testers for testing your software; but I also believe that there are software testing firms (Example: Test Insane. I can quote only about my start-up because I do not know the rate cards of other software testing firms) who can understand your context and help you to get your software tested for security in the budget you may have. It's always the discussions that help to do better.

And before I put an end to this article, I want to say “If you care about having a happy & peaceful world, it's important to take care of security of your software. Remember, everything is connected and we can contribute to the peace through software by making them secure in good enough manner”.

What do you think?


要查看或添加评论,请登录

Santhosh Tuppad的更多文章

  • My QA Mentor’s Initial Days

    My QA Mentor’s Initial Days

    I made a choice to join QA Mentor as a Director of Security Testing Practice and it was a very smooth conversation…

    4 条评论
  • E4: Social Engineering - My Forte!

    E4: Social Engineering - My Forte!

    In simple terms, social engineering is hacking someone’s thoughts and making them act like how you want them to by…

  • E2: The internet and irc bug.

    E2: The internet and irc bug.

    The internet My high-school friends come to my home in Tumkur and they say this, “Let’s go to the internet café. And I…

    1 条评论
  • E1: The Beginning - Fear, Stealing and Lying.

    E1: The Beginning - Fear, Stealing and Lying.

    Like we don’t really understand the beginning of this universe, I did not understand how everything started in the…

  • DIY: Learn security testing — Quick TIPS!

    DIY: Learn security testing — Quick TIPS!

    Software is Code. You write code and it behaves based on how you write the code.

    3 条评论
  • We need more smart technical software testers

    We need more smart technical software testers

    Speaking about Software Testing craft, I have always been into technical side of testing and understanding the software…

    16 条评论
  • Are you really productive for 8 hours?

    Are you really productive for 8 hours?

    I have been working as a Software Tester for 6 years now and have had various experiences in various organizations…

    10 条评论
  • How (bad) bug reports can increase project cost?

    How (bad) bug reports can increase project cost?

    In my 6+ years of experience as a Software Tester, I have come across large number of bug reports which I have read for…

    8 条评论
  • Stop calling yourself a Test Lab if you are not experimenting

    Stop calling yourself a Test Lab if you are not experimenting

    Nowadays, it's very stylish and jazzy to call your start-up testing services as "Test Lab" as it looks cool to the…

    3 条评论
  • Security Testing is not about running the tools alone

    Security Testing is not about running the tools alone

    If things were so easy that tools would do the brainy work, humans should have done something else. Now, tools are what…

    5 条评论

社区洞察

其他会员也浏览了