Best Practices for Secure Software Development (Web, API, Mobile)

This foundational training course provides a comprehensive introduction to application security and offers a cohesive, in-depth approach to ensuring the long-term security of your applications. These may include web applications, APIs, mobile apps, fat clients, embedded systems, backend services, and/or infrastructure components—we tailor the course to your specific system landscape.
This training provides answers to the following questions
- What security threats do modern software systems face?
- How is the threat landscape changing in the age of AI and agentic coding?
- Why is it necessary for security to be integrated throughout the entire software development process?
- How do I get started with secure software development?
- Where can I find help for self-help?
Headline 3
Text 3
Description
The seminar draws on the seminal work of the OWASP (Open Worldwide Application Security Project) , which are considered to set the standard in the field. The content goes far beyond the widely recognized OWASP Top 10 standard. Particular emphasis is placed on the practicality and feasibility of the measures described.
Approaches to programming, software, and system architecture are presented as generic patterns that can be easily adapted to the participant’s own environment. This enables participants to develop secure software, analyze and evaluate existing applications for fundamental security vulnerabilities, and derive appropriate countermeasures.
Exercises
We use our convenient mobile training environment. Participants identify the vulnerabilities by completing specific exercises and then discuss them as a group. By using their own laptops, participants work in their familiar work environment.
Course content
Course contents at a glance
Fundamentals
- AI-SDLC: Security in the AI-Driven Development Process
- HTTP Fundamentals
- Identification/Authentication/Authorization, Access Control
- Sessions, Cookies, DOM Storage, JWT
- SOP, CORS
- Security Headers (CSP, HSTS, etc.)
- Cryptography (Fundamentals, SSL/TLS, Certificates, etc.)
- SOAP, JSON
Attacks
- XSS (reflected, stored, DOM-based)
- Injection (Command Injection, SQL, LDAP, XML, Code, Prompt Injection, …)
- Object Deserialization, JWT Parsing, XML External Entity Includes
- Web-specific: CSRF, clickjacking, JSONP hijacking, CORS misconfiguration
- Logical/Semantic Attacks, Phishing
- Unique Features Enabled by AI Integration (Prompt Injection, Jails)
- Special Features of Agentic Coding (Attack Assessment)
- AI-powered attacks (social engineering, automated exploits)
Defense
- Network Separation, Firewalls, WAFs
- Input Validation, Output Encoding
- Anti-Automation
- Programming Best Practices
- LLMs for Improving Code Quality and Security Reviews
- Use of AI Tools for Attack Detection
This training is aimed at companies and organizations. It is individually tailored to your requirements and the team's prior knowledge and can be carried out in-house or online. This training can be economical from as few as three participants.
Target Group
- Architects
- Software developers
- Project managers
Duration and format
- 2 to 5 days, individually tailored
- On-site or online training
- Working environment: NinjaDVA
Prerequisites
None
Our trainers
Our promise: from practice, for practice & always up to date. That's why all our trainers are active experts with many years of experience in the subject area they teach.
Your Benefit
Our training courses not only impart knowledge, they also change mindsets. Your developers will learn to identify security vulnerabilities early on and avoid them in a targeted manner. The result: more robust applications, more confidence - and a clear advantage in everyday project work.
All trainers are actively working Security Consultants. They contribute their experience with everyday problems, which often conflict with security requirements, and thus contribute to a pragmatic, realistic approach to security.
- Practical methods instead of theory to avoid typical security gaps in web applications and mobile apps.
- Content according to the latest standards by actively working, experienced Security Consultants.
- Secure coding for long-term maintainability and quality of the source code.
- Increased security awareness in the team prevents pitfalls at an early stage.
- Protection against liability risks & damage to reputation.





