Generated by All in One SEO v4.8.9, this is an llms.txt file, used by LLMs to index the site. # Forward Security Forward Security ## Sitemaps - [XML Sitemap](https://forwardsecurity.com/sitemap.xml): Contains all public & indexable URLs for this website. ## Posts - [Top 10 Gen AI Vulnerabilities You Should Know About](https://forwardsecurity.com/top-10-gen-ai-vulnerabilities-you-should-know-about/) - Generative AI opens new possibilities in applications – and new security pitfalls. As a developer integrating Large Language Model (LLM) APIs or GenAI into your app, it’s crucial to be aware of emerging vulnerabilities unique to these systems. Below we outline ten key vulnerability categories (LLM01 through LLM10), explaining what each one is, why it - [The Evolution of Crypto Exchange Breaches (2011–2025) ](https://forwardsecurity.com/the-evolution-of-crypto-exchange-breaches-2011-2025/) - Cryptocurrency exchanges have come a long way since Bitcoin first emerged in 2009. While these platforms have made digital asset trading more accessible, they have also become prime targets for cybercriminals. Over the years, hackers have exploited vulnerabilities, leading to billions of dollars in losses and shaking public trust in crypto security. From early security - [Forward Security Recognized in BC InfoSec / CyberSec Export Capabilities Directory](https://forwardsecurity.com/forward-security-recognized-in-bc-infosec-cybersec-export-capabilities-directory/) - We're excited to announce our recognition in the BC Information Security and Cybersecurity Capabilities Export Directory! This directory showcases the rich and dynamic cybersecurity landscape in British Columbia, demonstrating the innovation and expertise of B.C.-based companies. We are honoured to be recognized in British Columbia's cybersecurity industry alongside such outstanding organizations. A downloadable PDF file - [Farshad on the Application Security Weekly Podcast: Lessons That The XZ Utils Backdoor Spells Out](https://forwardsecurity.com/farshad-on-the-application-security-weekly-podcast-lessons-that-the-xz-utils-backdoor-spells-out/) - Farshad Abasi was invited once again to speak on the Application Security Weekly Podcast, hosted by Mike Shema! In this episode, they talk about solutions and themes regarding the recent XZ Utils backdoor attack, as well as current AppSec affairs. Tune in to the episode below, and subscribe to show your support for the ASW - [Agile, DevOps, and the Threat Modeling Disconnect: Bridging the Gap with Developer Insights ](https://forwardsecurity.com/agile-devops-and-the-threat-modeling-disconnect-bridging-the-gap-with-developer-insights/) - In 2008, my journey into application security and threat modeling began when I joined HSBC's Global Software Development Centre as a Software Security Engineer. With a clear mission to integrate security within the application development lifecycle, I ventured into an arena where the dynamics of software development were rapidly evolving. As time passed, the transition - [Farshad on the Application Security Weekly Podcast: Creating the Secure Pipeline Verification Standard](https://forwardsecurity.com/farshad-on-the-application-security-weekly-podcast-creating-the-secure-pipeline-verification-standard/) - Farshad Abasi recently appeared on the Application Security Weekly Podcast where he discussed the innovative Secure Pipeline Verification Standard he's pioneering with OWASP. Farshad delves into the intricacies of pitching new projects, aligning them with existing standards like ASVS, and ensuring practical guidance for developers. Tune in to learn about how his experience in #appsec - [Threat Modeling & Risk Assessment for Developers](https://forwardsecurity.com/threat-modeling-risk-assessment-for-developers/) - Threat modeling and risk assessment is a structured approach that enables an organization to identify, quantify, and address the threats to a system based on risk to the business. It involves understanding the system from an attacker's perspective, which can significantly enchance the security measures. The primary goal of threat modeling is to provide the - [Farshad Discusses CI/CD Pipelines & Emerging Threats at Developer Week 2024](https://forwardsecurity.com/farshad-speaks-at-developer-week-2024-about-ci-cd-pipelines-and-emerging-threats/) - As modern software development practices evolve, CI/CD pipelines have emerged as a potent, yet under-secured frontier. This has resulted in a shift in focus from attackers, who are exploiting the traditionally overlooked vulnerabilities in the development pipelines. In this presentation, Farshad dove into the top CI/CD security risks as identified by OWASP. He looked at - [Forward Security Receives Clutch 2023 Awards](https://forwardsecurity.com/forward-security-receives-clutch-2023-awards/) - Forward Security Inc. is a winner for Clutch’s 2023 Cybersecurity and Penetration Testing Awards! We’re honoured to be recognized for our dedication to top-notch cybersecurity solutions. Clutch awards recognize companies based on their performance, client feedback, and overall reputation within their respective industries. The awards aim to highlight top-performing companies in specific categories or niches, - [Next-Level AppSec: Transforming Secure Development using Automation Platforms](https://forwardsecurity.com/next-level-appsec-transforming-secure-development-using-automation-platforms/) - As the rate of application adoption accelerates globally, teams are expected to produce software faster, and often under tight budget and timelines. This provides an increased level of opportunity for attackers to use application as an attack vector. According to the 2023 Verizon Data Breach Investigation Report, attackers leveraged applications in 80% of incidents and - [Application Attacks on the Rise](https://forwardsecurity.com/application-attacks-on-the-rise/) - One alarming trend in the fintech industry is the sharp increase in application attacks. According to recent reports, 64% of financial institutions (FIs) have seen a rise in application attacks, including Class Loader manipulation and Expression Language Injection. These types of attacks exploit vulnerabilities in application class loaders and web application frameworks like Spring Boot, - [Why Security Design Reviews are More Effective than Pentesting](https://forwardsecurity.com/why-security-design-reviews-are-more-effective-than-pentesting/) - Many companies rely on pentesting to achieve compliance and strengthen their security posture. However, pentesting alone cannot identify all of your application’s potential security issues. Instead, it's recommended to include Security Design and Security Code Reviews as part of an 4-stage Application Security Risk Assessment, which includes: Security Design Review Threat Modelling Code Review Pentesting - [The Power of Threat Modeling for Application Security](https://forwardsecurity.com/the-power-of-threat-modeling-for-application-security/) - Threat modeling stands as the cornerstone of modern application security, offering a strategic approach that empowers companies to safeguard their digital assets against evolving cyber threats. At its core, threat modeling involves a meticulous examination of an application's architecture and design to identify vulnerabilities, assess risks, and proactively fortify its defenses against potential exploits. This - [Reduce Cybersecurity Risks for Remote or Hybrid Work Environments](https://forwardsecurity.com/reduce-cybersecurity-risks-for-remote-or-hybrid-work-environments/) - The shift to remote work has significantly impacted security threats, as organizations' digital footprints expand and expose them to new vulnerabilities. In this post, we will discuss the security challenges that have arisen with remote and hybrid work environments and provide recommendations for strengthening security posture. The Cybersecurity Landscape in a Post-Pandemic World Since the - [AutoGQL: The Ultimate GraphQL Plugin for Burp's Active Scanner](https://forwardsecurity.com/autogql-the-ultimate-graphql-plugin-for-burps-active-scanner/) - Have you ever stared at a GraphQL request, wishing Burp's Active Scanner just 'got' where to put its payloads? Well, I did and now we have AutoGQL. Burp Suite is the ubiquitous tool for penetration testers looking for a way in through the website. It acts as a middleman (aka proxy) between the browser and - [Unveiling New Additions to ASVS: Advancing the Frontier of Application Security](https://forwardsecurity.com/unveiling-new-additions-to-asvs-advancing-the-frontier-of-application-security/) - Today, we delve into the ongoing development of the Application Security Verification Standard (ASVS). If you’re new to ASVS, it serves as a foundational guideline for evaluating the technical security measures of applications. The ultimate goal? To rigorously safeguard the confidentiality , availability and integrity of platforms. I’m excited to share that, in our ongoing - [Rethinking Application Security: Why Penetration Testing Alone Doesn’t Cut It](https://forwardsecurity.com/rethinking-application-security-why-penetration-testing-alone-doesnt-cut-it/) - In our increasingly digital world, applications are the engines driving businesses, powering critical operations and service delivery. However, these applications can also serve as gateways for data breaches if they harbor security vulnerabilities. While various methods exist to uncover these flaws, it's essential to understand that not all testing approaches yield equal results. Vulnerability Assessment - [Penetration Testing Execution Standards (PTES)](https://forwardsecurity.com/penetration-testing-execution-standards-ptes-forward-security/) - It’s all too common for AppSec companies to claim they offer vulnerability assessments when in fact they are just doing pentests. They likely use some automated scanner like Burp or Nexus, run a scan, and present the client with a vulnerability report. However, this is not our approach we take at Forward Security. Our vulnerability - [The Crucial Role of Threat Modeling in Application Security](https://forwardsecurity.com/the-importance-of-threat-modelling-in-application-security/) - Threat modeling is a proactive approach aimed at identifying potential threat scenarios specific to your application. Following threat modeling is penetration testing (often referred to as pentesting). This step involves validating each identified threat scenario to determine the actual risks they pose to your business. In simpler terms, while threat modeling focuses on identifying all - [The Importance of Zero Trust in Cybersecurity](https://forwardsecurity.com/the-importance-of-zero-trust-in-cybersecurity/) - What Does Zero Trust Mean in Cybersecurity? Zero trust is a security model in cybersecurity that operates on the assumption that all network traffic, regardless of its origin, is untrusted and requires verification before access is granted. This means every user and device must be authenticated and authorized before accessing resources, whether they are within - [Cross-Site Scripting - An eXceSSive Discussion about XSS](https://forwardsecurity.com/an-excessive-discussion-about-xss/) - Cross-site scripting (XSS) is a security concern that has persisted for over two decades in the world of application security. For newcomers to this field, XSS is often one of the first vulnerabilities they encounter due to its prevalence in web applications and it's relatively straightforward nature. In this article, we delve into the origins - [The Challenge with Using Multiple Security Scanners](https://forwardsecurity.com/the-challenge-with-using-multiple-security-scanners/) - Development and security teams rely on automated scanners such as SAST, SCA, DAST, and others to scan applications for bugs and security issues during development and operation. Alongside these automated scanners, teams also conduct manual activities like threat modeling, vulnerability assessments, and penetration testing. We strongly recommend using more than one high-quality tool that produces - [How to Minimize False Positives in Automated Application Security Scans](https://forwardsecurity.com/how-to-minimize-false-positives-in-automated-application-security-scans/) - Every time a software development team introduces new code into their Software Development Life Cycle (SDLC), it potentially opens up a security vulnerability. Manual penetration testing can be time-consuming and costly, leading many organizations to deploy automated scanners such as Static Application Security Testing (SAST), Software Composition Analysis (SCA), and Dynamic Application Security Testing (DAST) - [Forward Security Celebrates 5 Years 🎂](https://forwardsecurity.com/celebrating-5-years/) - October is special to us at Forward Security for two reasons: a) it’s Cybersecurity Month b) it’s our birthday! I must say, I have never worked harder in my career. The past 5 years have not been without ups and downs, especially with the recent economic conditions. But what makes it all worthwhile is the - [The Three Pillars of Implementing DevSecOps](https://forwardsecurity.com/the-three-pillars-of-implementing-devsecops/) - With application-related attacks on the rise, it’s never been more critical to ensure that security is baked into the fabric of your software development and operation practices. Furthermore, addressing issues early in the lifecycle of an application can result in significant cost savings of up to thirty times as compared to addressing those issues after the application is - [What is Threat Modeling? (and Why is it Important for Applications?)](https://forwardsecurity.com/what-is-threat-modeling-and-why-is-it-important-for-applications/) - What is threat modeling and why is it important? A threat is something that has a negative impact on an asset. In the context of information security, particularly about application security, the main aspect of concern is data. The process of threat modeling systematically identifies all the different attack steps that could realize in an - [How to Get the Most Value from Your Security Tools](https://forwardsecurity.com/how-to-get-the-most-value-from-your-security-tools/) - There are several big problems with automated security scanning tools. In this post, we’ll discuss some of the major problems with the tools and what you can do to overcome them. Too Many False Positives Perhaps the biggest challenge with automated security scanning tools is that they produce too many false positives, which is when - [Forward Security and Scrut Automation Join Forces to Enhance Cybersecurity Solutions ](https://forwardsecurity.com/forward-security-scrut-automation-partnership/) - Vancouver – Forward Security Inc. is proud to announce a strategic partnership with Scrut Automation, a prominent automation technology provider. This collaboration aims to deliver comprehensive cybersecurity solutions that protect businesses from evolving cyber threats. “We are excited about our partnership with Scrut Automation,” said Farshad Abasi, Founder & CSO of Forward Security. “By combining - [Eureka DevSecOps Platform Installation Guide](https://forwardsecurity.com/eureka-devsecops-platform-installation-guide/) - NOTE: As a prerequisite, please ensure the person completing these details are an Admin of the subscription. 1. Navigate to the Marketplace Offer 2. Select Eureka from the list of plans 3. Click create 4. In the project details section select the subscription and recourse group you would like the managed application to be deployed - [Eureka DevSecOps Platform User Manual](https://forwardsecurity.com/eureka-devsecops-platform-user-manual/) - 1. If you wish to create another project click the Eureka Icon/ Home button 2. Click the Create New Project and fill in the details as needed 3. You can now use the Project Select dropdown to switch between your current view 4. Next you can start your CI/CD setup steps click the Project Settings - [Forward Security Accepted into the Microsoft for Startups Founders Hub](https://forwardsecurity.com/forward-security-accepted-into-the-microsoft-for-startups-founders-hub/) - Forward Security Inc., a North-American company with offices in Vancouver, Toronto, and Austin, TX specializing in application & cloud security consulting, is proud to announce our acceptance into the Microsoft for Startups Founders Hub. “We have been building the Eureka DevSecOps Platform on Azure, and released it recently in the Azure Marketplace,” said Farshad Abasi, - [Forward Security Announced as #2023TIA Finalists!](https://forwardsecurity.com/forward-security-announced-as-2023tia-finalists/) - [Forward Security Win Most Promising Canada Tech Services Company 2022](https://forwardsecurity.com/forward-security-are-recognized-winners-of-the-most-promising-canada-tech-services-company-2022-by-cioreview/) - Forward Security are delighted to be recognized as the winners of the Most Promising Canada Tech Services Company 2022 by CIOReview. We are passionate about building long-lasting relationships with our partners and clients, while continuing to invest in our team’s knowledge and skill set. We wish to thank everyone who has supported us in our mission to - [Forward Security Receives $150,000 of NRC IRAP Funding to Further Develop its Eureka DevSecOps Platform](https://forwardsecurity.com/forward-security-receives-150000-of-nrc-irap-funding-to-further-develop-its-eureka-next-generation-devsecops-platform/) - Forward Security Inc., a North American company with offices in Vancouver, Toronto, and Austin, TX, specializing in application & cloud security products and services, is proud to announce that it has received funding through the National Research Council of Canada Industrial Research Assistance Program (NRC IRAP). Forward Security have been awarded $150,000 to support research - [Forward Security Awarded the Canadian Workplace Culture Certification](https://forwardsecurity.com/forward-security-awarded-the-canadian-workplace-culture-certification/) - Forward Security is Canadian Workplace Culture Certified and are officially recognized as a Canadian Workplace Culture Leader. The overall score received placed Forward Security in the 88th percentile with a score of 83 against the national average of 62. The organization had great scores across most workplace attributes, with very strong scores seen in Career - [US Executive Order 14028 Impact on Application & Cloud Security](https://forwardsecurity.com/bidens-executive-order-impact-on-application-cloud-security/) - This article is Part 1 of a two-part series – Part 2: Simplifying NIST’s Guidance for US Executive Order 14028: New Standards for Software Verification The United States’ cybersecurity executive order takes important steps to bringing awareness to security for organizations when developing software. With 52% of breaches caused by malicious attacks against applications in - [Simplifying NIST’s Guidance for US Executive Order 14028: New Standards for Software Verification](https://forwardsecurity.com/simplifying-nists-guidance-for-us-executive-order-14028-new-standards-for-software-verification/) - This article is Part 2 of a two-part series – Part 1: US Executive Order 14028 Impact on Application & Cloud Security Cyberattacks are becoming more frequent, targeted, and complex with the sophistication of cybercriminals, techniques, and technologies. The rapid acceleration of software and digital adoption in all areas, particularly since the start of the - [Securing Modern API and Microservices-Based Apps by Design – Part 1](https://forwardsecurity.com/securing-modern-api-and-microservices-based-apps-by-design-pt1/) - Combine existing security concepts and best practices together and design more secure distributed applications. Introduction A common approach to modernizing applications is to use APIs and decompose them into smaller units that typically live in containers. These approaches involve many concepts and technologies that are not always well understood, leading to poor application security postures. In addition, solution architects and developers who are creating the applications often lack the knowledge to - [Securing Modern API and Microservices-Based Apps by Design – Part 2](https://forwardsecurity.com/securing-modern-api-and-microservices-based-apps-by-design-pt2/) - Combine existing security concepts and best practices together and design more secure distributed applications. Introduction Part 1 of this two-part series discussed what services and microservices are, the role of APIs and API gateways in modern application architectures, the importance of user-level security context, and end-to-end (E2E) trust. Now part 2 covers authorization (authZ) and different ways of handing it across microservices, what authentication (authN) and authZ protocols to use, what to do when an API is invoked by applications and services outside its trust boundary, - [Why ASVS Is The Gold Standard For Application Security](https://forwardsecurity.com/why-asvs-is-the-gold-standard-for-application-security/) - According to Contrast Security’s 2020 Application Security Observation Report, 96% of web apps have at least one vulnerability, and 26% of those are serious. The continued proliferation of application vulnerabilities confirms that development teams are not certain about their application’s security requirements, and security teams are not performing consistent and comprehensive assessments. Enter OWASP’s Application - [Security Implications of AI-assisted Coding](https://forwardsecurity.com/securityimplicationsofaiassistedcoding/) - [Forward Security is now an AWS Select Consulting Partner](https://forwardsecurity.com/forward-security-is-now-an-aws-partner/) - Forward Security Inc., a North American company with offices in Vancouver, Toronto and Austin, TX specializing in application & cloud security consulting, is proud to announce that it has earned the Select tier Consulting Partner designation from Amazon Web Services (AWS) through the AWS Partner Network (APN) program. “We are very excited to be recognized as a Select tier Consulting Partner - [SAST, SCA, DAST, IAST, RASP: What They Are and How You Can Automate Application Security](https://forwardsecurity.com/sast-sca-dast-iast-rasp-what-they-are-and-how-you-can-automate-application-security/) - Application security is an ongoing challenge throughout the entire software development life cycle (SDLC). Today, more and more development teams are shifting to Agile and DevOps SDLCs to rapidly build application to meet the rising demands from the business and consumers with little or no attention to security. In addition, open-source components are used to - [Application Security for Busy Tech Execs](https://forwardsecurity.com/application-security-for-busy-tech-execs/) - We have created this series to help busy technology executives like you navigate through the cloudy and often poorly understood field of application security and array of options out there. In this series we will discuss some of the key pillars of application security in 1-2 min video capsules to save you time and help make the best decision. - [Embedding Security Into Software During Development ](https://forwardsecurity.com/embedding-security-into-software-during-development/) - Security has traditionally been focused at the infrastructure level, particularly at the edge of the network where traffic flows across trusted and untrusted network segments. This is accomplished by using various tools such as network or application specific firewalls (e.g. web application firewalls, or email gateways) that would analyze traffic and look for malicious payloads. - [Blockchain and Its Impact on Information Security’s CIA-Triad](https://forwardsecurity.com/blockchain-and-its-impact-on-information-securitys-cia-triad/) - What is the CIA Triad? Before we get into the details of how blockchain can improve information security, let’s talk about the CIA triad. No, not the government agency, but the one related to Confidentiality, Integrity, and Availability. Confidentiality, Integrity and Availability are the key attributes when it comes to information security and determining the - [Top 3 Security Challenges Devs Encounter When Building Secure Apps](https://forwardsecurity.com/top-3-security-challenges-devs-encounter-when-building-secure-apps/) - There are a lot of tools (or categories of tools), that developers need to incorporate into their DevOps environment. Anyone in the AppSec field knows automation tools such as static application security testing (SAST), dynamic security testing (DAST), and Software Composition Analysis (SCA) have a lot of challenges. In this post, we discuss three of - [What is DevSecOps and How to Transform Your Agile / DevOps Team?](https://forwardsecurity.com/what-is-devsecops-and-how-to-transform-your-agile-devops-team/) - These days, everyone is talking about DevSecOps, and you might be wondering what it’s all about. How we evolved to DevSecOps Security was not really a part of software development until the early 2000s when Microsoft started the Trustworthy Computing Initiative. They came up with a concept of security DLC where you integrate different security - [Dev Teams Don’t Need Fulltime AppSec Members, They Need Security Champions](https://forwardsecurity.com/dev-teams-dont-need-fulltime-appsec-members-they-need-security-champions/) - In this post, we’ll explore whether you need dedicated application security team members in your development team and what the concept of security champions is all about. Where are all the application security professionals? There’s a shortage of application security professionals. According to James Wickett, Senior Security Engineer at Verica, he cites a ratio of - [What is Pentesting? (and What to Look for When Choosing a Service Provider)](https://forwardsecurity.com/what-is-pentesting-and-what-to-look-for-when-choosing-a-service-provider/) - You’ve probably heard of the term pentesting and wondered what it means. You've probably even had a pentest done and was not quite sure what it was.In this post, we're going to tell you what pentesting means and what to look for when choosing a service provider.How is Pentesting Different from Vulnerability Assessment?Pentesting is not - [Does Your Application Need Security Requirements?](https://forwardsecurity.com/does-your-application-need-security-requirements/) - How do I make my application more secure? Where do I get security requirements from? Why do I need security requirements? If you have an application, these are some of the questions you may have. What are security requirements? Security requirements describe what is expected of a system and how it should function. Security requirements - [The Importance of a Risk Based Approach in Security Assessments](https://forwardsecurity.com/risk-based-approach/) - Suppose you run a security scan on your application, and it produces a report with a list of one hundred security issues. Where would you start? What issue(s) would you tackle first? You need a way to prioritize the list and to know which issues are high risk, which are low risk, and which ones - [Case Study: Eureka DevSecOps Platform](https://forwardsecurity.com/case-study-eureka-devsecops-platform/) - The Background Our client in the data analytics sector had implemented DevOps automation and CI/CD pipelines but without any security in the mix. This is quite common as some organizations often focus their resources heavily on product development, especially in early stages of growth with security being an afterthought. Normally, organizations should have SAST and - [Orchestrating & Correlating Your Security Scanners](https://forwardsecurity.com/orchestrating-correlating-your-security-scanners/) - If you’re using multiple automated security tools such as SAST, DAST, and SCA, and not correlating the results, then you could be missing some critical vulnerabilities that put your business at risk. The Eureka DevSecOps Platform enables you to aggregate issues from automated and manual processes into a single view, normalize the results, and correlate - [10 Ways Eureka DevSecOps Platform Delivers Value](https://forwardsecurity.com/10-ways-eureka-devsecops-platform-delivers-value/) - Eureka DevSecOps Platform can help you get the most value from your tools, better identify real security issues, and reduce your business risk. Here are 10 ways Eureka DevSecOps Platform delivers value. 1. Eureka centrally configures and orchestrates your scanners This allows you easily manage multiple security tools in one central hub, reducing time and - [How to Overcome Common Challenges with SDLC](https://forwardsecurity.com/common-challenges-with-sdlc/) - Does this sound familiar? Less than 1,000 staff Small (or zero) security team other than CISO Have DevOps, but no DevSecOps Need annual pentests to prove compliance, but wondering if that’s enough Common Challenges with Secure SDLC Full-time application and cloud security staff are difficult to find and retain, and may not even be necessary - [10 Reasons to Make the Switch to Forward Security](https://forwardsecurity.com/10-reasons-to-make-the-switch-to-forward-security/) - Many of our clients (and prospective clients) are large firms in the fintech, health tech, and eCommerce sector who have existing relationships with well-established security providers with hundreds of staff. Although we are smaller and our brand name is less established, there are still plenty of reasons to make the switch from your current security - [Navigating IoT Innovations and Their Impact on Canadian Businesses ](https://forwardsecurity.com/navigating-iot-innovations-and-their-impact-on-canadian-businesses/) - The following is an excerpt from an interview from our Founder & CSO, Farshad Abasi and the Canadian Chamber of Commerce. Click here to read the full interview. As the Internet of Things (IoT) has become the Internet of Everything, IoT innovation is having a significant impact on the cybersecurity landscape for Canadian companies. As - [Penetration Testing: How Often Should You Test?](https://forwardsecurity.com/penetration-testing-how-often-should-you-test/) - How often should I do penetration testing? It’s a question that comes up regularly. The short answer is: it depends. The frequency of pentesting depends on the organization’s specific needs and risk profile, but in general, we recommend performing at least one comprehensive pentest annually. Additionally, we recommend performing regular, targeted pentests, also known as ## Pages - [Home Page](https://forwardsecurity.com/) - Your Code Security ExpertsApplication Security | DevSecOps | Cloud SecurityLeading Cybersecurity AheadIn an increasingly complex and interconnected world, organizations are under more pressure than ever to protect themselves and their customers against the threats of cybercrime. We aim to take the complexity out of software security for your organization with a best-practice approach, in order - [Cyrus User Guide](https://forwardsecurity.com/cyrus-user-guide/) - Introducing Cyrus for Jira — comprehensive security guidance, right where your team works Cyrus embeds the OWASP ASVS into every user-story discussion, automatically surfacing the controls you may have overlooked and letting you push them straight into the ticket. Here’s a soup-to-nuts walkthrough so anyone on your team can be up and running in minutes—completely - [Cyrus SLA](https://forwardsecurity.com/cyrus-sla/) - Service Level Agreement (SLA) Effective Date: June 24, 2025 This Service Level Agreement ("SLA") outlines the service levels, support, and responsibilities related to the use of Cyrus, a Jira application developed and maintained by Forward Security Inc. ("Forward Security"). 1. Scope This SLA applies to customers using the Cyrus Jira application via the Atlassian Marketplace. - [Cyrus Terms of Service](https://forwardsecurity.com/cyrus-terms-of-service/) - 1. Acceptance of Terms By installing, accessing, or using the Cyrus Jira application (“App”) you (“Customer”) agree to be bound by these Terms of Service (“Terms”). If you do not accept the Terms, you may not use the App. 2. Beta Status Pre-release software. The App is provided as a Beta/preview offering and may contain - [Careers & Mentorship](https://forwardsecurity.com/careers-mentorship/) - Join the A-Team at Forward Security Career Opportunities Looking to take your career in cybersecurity to the next level? Explore our open full-time positions. Learn More Mentorship Positions Looking to break into the world of cybersecurity? Find out more about our mentorship opportunities. Learn MoreCareersWe are passionate software and IT professionals who love security and - [Contact Us](https://forwardsecurity.com/contact-us/) - Ready to move forward? We offer a complimentary, no-strings attached consultation to build our understanding of your specific security needs and discuss solutions. Consultations can be scheduled in-person (Vancouver & Toronto Area) or via video conference. Name First Company NameEmail PhoneMessageCAPTCHA Δ Trusted By: and many more! We are headquartered in beautiful Vancouver, Canada with - [Cloud Security Services](https://forwardsecurity.com/cloud-security/) - We’re specialists in: Cloud security is a shared responsibilityFor businesses making the transition to the cloud, security is vital. Our Cloud Security experts can help you build security into your cloud infrastructure, providing the peace of mind your organization needs to push forward. Assessments performed in-house by a team of cloud security experts Many security - [Library](https://forwardsecurity.com/library/) - AllUncategorized3Application Security42Cloud Security14DevSecOps20News11Support2 Top 10 Gen AI Vulnerabilities You Should Know AboutGenerative AI opens new possibilities in applications – and new security pitfalls. As a developer integrating Large Language Model (LLM)… The Evolution of Crypto Exchange Breaches (2011–2025) Cryptocurrency exchanges have come a long way since Bitcoin first emerged in 2009. While these platforms have made - [About Us](https://forwardsecurity.com/about-us/) - “At FWDSEC (Forward Security) we are all about doing application, cloud, and information security better. Our team tackles security using a systematic approach, leveraging standards based and repeatable processes. We are incredibly passionate about delivering the best security solutions, and are driven to help our clients achieve the highest level of security to enable business - [Events](https://forwardsecurity.com/events-calendar/) - February 21st, 2024 @ 4:00 p.m. PSTDeveloperWeekJoin us at DeveloperWeek 2024 February 21st, 2024 @ 4:00 p.m. PST [In-Person] February 27th 1:00 p.m. PST [Virtual] Join us at DeveloperWeek 2024 in Oakland California, where Farshad Abasi…About This Event Mar 13th, 2024 @ 05:00 PMFireside Chat Discussing AI Vs. AppSec FundamentalsIn an era heralded by technological - [Security Training](https://forwardsecurity.com/security-training/) - Security knowledge to help your team make better decisionsHumans are the end-users and builders of computer systems, and they can often be the weakest link. Our expert instructors can teach your team how to apply the right security at the right time and place. Explore Our Course OfferingsApplication Threat ModellingBuilding Secure Web Applications by DesignBuilding - [Partners](https://forwardsecurity.com/our-partners/) - Cloud Service ProvidersTechnology PartnersIndustry Associations - [Eureka DevSecOps Solution](https://forwardsecurity.com/eureka-devsecops-solution/) - The technology, people, and processes your DevOps team needs to achieve security at speedWhether you’re building a new application from the ground up or driving the growth of an existing product, embedding security into your DevOps process is an essential way to save your team time and cost, while setting your organization up for long - [Application Security Services](https://forwardsecurity.com/application-security/) - Let your team focus on innovation while we help reduce your business riskBusinesses are increasingly relying on applications in order to succeed in this digitally enabled world. Meanwhile, development teams are under increasing pressure to launch new products and features on tight timelines, which can leave costly vulnerabilities for your organization. Attackers are shifting their - [Eureka Scanners](https://forwardsecurity.com/eureka-scanners/) - Scanners11CI/CD3Issue Tracking2 SnykSCA FindSecBugsSAST Bundle AuditSCA SecurityCheckerSCA VeracodeSAST MergeBaseSCA SemgrepSAST BrakemanSAST BanditSAST SonarQubeSAST OWASP ZAPDAST Scanners SnykSCA Snyk SYNK’s powerful security intelligence easily discovers open-source dependencies and vulnerabilities in an automated manner. Currently, we support the following packet managers and build tools: Nuget, Paket, N/A, Hex, Go Modules, Dep, Govendor, Gradle, Maven, NPM, Yam, Composer, - [Leveraging DevSecOps to Integrate Security and Compliance into CI/CD Pipelines](https://forwardsecurity.com/leveraging-devsecops-to-integrate-security-and-compliance/) - Securing Modern API- and Microservices-Based Apps by DesignThis white paper brings together the joint knowledge and expertise of Forward Security & Scrut Automation. Download Free White PaperWhat’s in the White Paper?This whitepaper explores the concept of DevSecOps and its significance in building resilient, secure, and compliant software delivery pipelines. It delves into the strategies, best - [Eureka Landing Page v2](https://forwardsecurity.com/v2-get-eureka/) - Accelerate Your DevSecOps DevOps is changing rapidly. With the help of AI technology, Dev teams are producing code faster than ever before. This has drastically increased the need for automated scanners such as SAST, DAST, and SCA. If you have security automation tools, you need Eureka DevSecOps Platform. Book a Demo Take Your DevOps to - [Eureka Landing Page v5](https://forwardsecurity.com/v5-get-eureka/) - Have Your Own Moment You may not run through through the streets of Sicily like Archimedes, but have can have your own ‘Eureka!’ moment. If you use multiple automated scanners such as SAST, DAST, and SCA, then you need the Eureka DevSecOps Platform. Reduce Time – having a central and normalized view of all your - [Eureka Landing Page v4](https://forwardsecurity.com/v4-get-eureka/) - Reduce. Increase. Secure. Reduce Time – having a central and normalized view of all your issues in one report results in making quicker and better decisions. Cost – optimize staffing resources and prevent wasteful spending on low-threat issues. Issues – avoid false-positive fatigue by minimizing the number of issues your developers have to deal with. - [Eureka Landing Page v3](https://forwardsecurity.com/v3-get-eureka/) - Build Secure Apps The Eureka DevSecOps Platform allows you to build more secure apps by centrally orchestrating all your open-source and commercial security scanners, correlating the results into one report, and managing your application security threats and risks. Take your DevOps to DevSecOps. Book a Demo A DevSecOps Platform for Secure Applications Add Security into - [Eureka Landing Page v1](https://forwardsecurity.com/v1-get-eureka/) - Connect, Manage, and Maintain Your Open-Source and Commercial Scanners See all scanners TAKE A TOUR ReduceIncreaseSecureReduce Time – having a central and normalized view of all your issues in one report results in making quicker and better decisions. Cost – optimize staffing resources and prevent wasteful spending on low-threat issues. Issues – avoid false-positive fatigue - [The AppSec Insiders Podcast](https://forwardsecurity.com/the-appsec-insiders-podcast/) - Listen to The AppSec Insiders Podcast – New Episodes every two weeks!The AppSec Insiders Podcast is a fun and engaging conversation around application and cloud security. Each week, our hosts bring you their fresh perspective of what’s happening in the world of cybersecurity. Subscribe and Listen to The AppSec Insiders PodcastMeet The AppSec InsidersIman SharafaldinApplication - [Why Choose Forward Security](https://forwardsecurity.com/why-choose-forward-security/) - Why Choose Forward SecurityEnhance your security postureWith attacks on the rise and attackers continuously evolving, so too should your testing approach. Our team of experts replicate real-world threats to find weaknesses in your security. Where we focusFintech & FinservHealth TecheCommerce We Understand your Industry When founding Forward Security, we carefully selected domains where we have - [DevSecOps Maturity Assessment](https://forwardsecurity.com/devsecops-maturity-assessment/) - DevSecOps Maturity AssessmentBegin Your AssessmentWant to know how mature your DevSecOps is? Take the assessment. Through this assessment, you will learn how to assess your DevSecOps practices, identify focus areas for improvement, and recognize the importance of evolving your DevSecOps maturity. Optimize Your DevSecOpsDevSecOps is a software development approach that focuses on integrating security into - [Healthcare Industry](https://forwardsecurity.com/healthcare-industry/) - Application Security | DevSecOps | Cloud SecurityForward Security Recognized in BC InfoSec / CyberSec Export Capabilities Directory Improve the Health of your Patients and Application Systems Due to the sensitive nature of health-related data, companies working in this space are required to adhere to more rigorous levels of security practices such as those outlined by - [Financial Industry](https://forwardsecurity.com/finance/) - Application Security | DevSecOps | Cloud SecurityForward Security Recognized in BC InfoSec / CyberSec Export Capabilities DirectorySee Introductory Offers Leverage our expertise in financial security We partner with financial services and financial technology companies to ensure their applications and cloud systems are built and operated securely. Our risk-based approach takes the unique context of your - [IoT Security Risk Assessment](https://forwardsecurity.com/iot-security-risk-assessment/) - Our team of experts have specialized experience with IoT device security. We work with IoT device manufacturers to ensure your devices do not pose a security risk. Our Four-Stage IoT Risk AssessmentWe use a four-stage process, which follow OWASP’s Application Security Verification Standard (ASVS). This includes a security design and code review to deliver a - [Blockchain & Smart Contract Security Services](https://forwardsecurity.com/blockchain-smartcontract-security/) - Audit Your Smart Contracts to Avoid BreachesAs blockchain and smart contracts conquer the technology industry, security is vital to ensure long term success. Our blockchain security experts provide design and risk assessment services to help you build security into your smart contracts, providing the peace of mind your organization needs to push forward. Our Services:Smart - [Security Design Review & Threat Modelling](https://forwardsecurity.com/security-design-review-threat-modelling/) - Security Design Review & Threat ModellingBook your Free ConsultationSecure your application from the startSecurity design reviews have no dependency on the application being built or run in an environment. They can also be applied early in the SDLC and provide significant cost savings due to avoidance of costly fixes later on in the application life-cycle. - [Code Security & Vulnerable Dependency Analysis](https://forwardsecurity.com/code-security-vulnerable-dependency-analysis/) - Code Security & Vulnerable Dependency AnalysisIdentify security weaknesses and vulnerabilities in the source code earlyCode security and vulnerable dependency analysis is the process of manually checking the source code of an application for security issues. Since many significant application security issues are extremely difficult to discover with other forms of analysis, such as penetration testing, - [Penetration Testing for Application and Cloud](https://forwardsecurity.com/penetration-testing-for-application-and-cloud/) - Penetration Testing for Application and CloudBook your Free ConsultationEnhance your security postureWith attacks on the rise and attackers continously evolving, so too should your testing approach. Our team of experts replicate real-world threats to find weaknesses in your security. Mobile(iOS | Android) Web(SPA, traditional, PWA) API(REST, GraphQL) DesktopThe 3 Types of PentestingBlack box is when - [Application Security Risk Assessment](https://forwardsecurity.com/appsec-risk-assessment/) - Secure any type of mobile, web, API, or desktop application Our team of AppSec experts have experience across a wide range of programming languages and technologies to help you confidently secure any type of application. Go Beyond PentestingPentesting is a commonly used approach to test the security vulnerability of software applications, but it doesn’t give - [eCommerce Security](https://forwardsecurity.com/ecommerce-security/) - Application Security | DevSecOps | Cloud SecurityeCommerce SecurityEnsure your customers’ eCommerce transactions are secureHelp earn your customers’ trust by making your eCommerce platform more secure and reach your compliance goals. We partner with online retailers to ensure their applications and cloud systems are built and operated securely. Get Started with Two Introductory OffersSee Introductory OffersLeveraging - [Securing Modern API- and Microservices-Based Apps by Design](https://forwardsecurity.com/securing-modern-api-and-microservices-based-apps-by-design/) - Securing Modern API- and Microservices-Based Apps by DesignModernizing applications involves many concepts and technologies that are not always well understood, leading to poor application security postures. In addition, solution architects and developers who create the applications often lack the knowledge and expertise to select and apply the required security controls. Download Free White PaperCombine Existing - [Case Studies](https://forwardsecurity.com/case-studies/) - Case StudiesLeverage our global expertise to enhance your security postureHaving worked for large enterprises gives us a broad view of the challenges and solutions within your industry and allows us to apply best-in-class practices for any size organization. With experience ranging from global enterprises down to regional institutions, we can right-size the approach as needed. - [Homepage temp](https://forwardsecurity.com/homepage-new-temp/) - Your Code Security ExpertsServicesApplication Security | DevSecOps | Cloud SecurityPlatformEureka!Trusted By: Leading Cybersecurity AheadIn an increasingly complex and interconnected world, organizations are under more pressure than ever to protect themselves and their customers against the threats of cybercrime. We aim to take the complexity out of software security for your organization with a best-practice approach, - [Home Page-old](https://forwardsecurity.com/home-page-old/) - Your Code Security ExpertsApplication Security | DevSecOps | Cloud SecurityBook Your Free ConsultationTrusted By: Leading Cybersecurity AheadIn an increasingly complex and interconnected world, organizations are under more pressure than ever to protect themselves and their customers against the threats of cybercrime. We aim to take the complexity out of software security for your organization with - [Book Free Consultation v2](https://forwardsecurity.com/book-free-consultation-v2/) - Book Your Free ConsultationApplication Security Risk Assessment Our risk assessment services provide an in-depth analysis of your application’s current security posture, providing a clear path forward to securing your organization’s most valuable assets. Book Your FREE Security Consultation We offer a complimentary, no-strings-attached consultation in order to better understand your specific security needs and discuss - [Thank You](https://forwardsecurity.com/thank-you/) - Thank you for registering for this event. We look forward to seeing you there. - [Book Free Consultation v1](https://forwardsecurity.com/book-free-consultation-v1/) - Book Your Free Consultation Application Security Risk Assessment Our risk assessment services provide an in-depth analysis of your application’s current security posture, providing a clear path forward to securing your organization’s most valuable assets. Book Your Free Consultation What Level of Security Do You Require? OWASP has a document called the Application Security Verification Standard - [Privacy Policy](https://forwardsecurity.com/privacy-policy/) - Last updated: August 25, 2022 This Privacy Policy describes Our policies and procedures on the collection, use and disclosure of Your information when You use the Service and tells You about Your privacy rights and how the law protects You. We use Your Personal data to provide and improve the Service. By using the Service, - [Information Security Services](https://forwardsecurity.com/information-security/) - Information is everythingIn today’s world, information is an organization’s most valuable asset. Ensuring you have the proper policies and management processes in place are critical to protect digital assets, helping save your business from potential breaches. Organizations in many industries are required to adhere to strict industry security standards or regulations, which can be complex - [Technology Due Diligence Process and Cyber Security Risks](https://forwardsecurity.com/events/) - FORWARD SECURITY PRESENTS:Technology Due Diligence Process and Cyber Security Risks When: Friday, May 21, 2021Duration: 1 hourHosted By: NCFA’s Fintech Fridays’ Podcast Share this podcast FacebookXLinkedIn Tune in on Friday, May 21st, 2021 for an insightful conversation regarding the Technology Due Diligence process and risks that are crucial for investors, M&As, and preparing your company - [Tech Due Diligence Cyber Risk Fireside Chat](https://forwardsecurity.com/duediligencefiresidechat/) - FORWARD SECURITY PRESENTS:Technology Due Diligence Interactive Fireside Chat with CIBC, FWDSEC and RiskAware When: Friday, May 28th, 2021, 10am PDT (1PM EDT)Duration: 45min + Live Q&A SessionHosted By: Farshad Abasi – Founder, CSO @ FWDSEC Share this webinar FacebookXLinkedIn Join us on Friday, May 28st, 2021 for an insightful conversation regarding the Technology Due Diligence - [Preparing for the Next Zero-Day Vulnerability](https://forwardsecurity.com/preparing-for-the-next-zero-day-vulnerability/) - LIVE WEBINAR:Preparing for the Next Zero-Day Vulnerability When: Wednesday, January 26th at 9am PST | 12pm EST | 5pm GMT Register OnlineNow that dust is settling from Log4Shell, how can you prepare for and prevent the next zero-day vulnerability from impacting your organization? Join Larry Maccherone, DevSecOps Transformation lead at Contrast Security, and Farshad Abasi, - [DevSecOps Webinar](https://forwardsecurity.com/devsecops-webinar/) - DEVSECOPS LIVE WEBINAR:Embedding Security Into Your DevOps Practices When: TBD Duration: 45min + Live Q&A Session Hosted By: Farshad Abasi – Founder, CSO @ FWDSEC Share this webinar FacebookXLinkedInRegister For The Challenge Name First Last Email Company Name Δ As technology continues to accelerate so too do the threats of cyberattacks against organizations. These threats - [Embedding Security Into The DevOps Process](https://forwardsecurity.com/embedding-security-into-the-devops-process/) - DEVSECOPS LIVE WEBINAR:Embedding Security Into Your DevOps Practices When: TBD Duration: 45min + Live Q&A Session Hosted By: Farshad Abasi – Founder, CSO @ FWDSEC As technology continues to accelerate so too do the threats of cyberattacks against organizations. These threats continue to grow in frequency and complexity year over year, putting increasing pressure on - [DevSecOps Live Webinar](https://forwardsecurity.com/devsecops-live-webinar/) - DEVSECOPS LIVE WEBINAR:Embedding Security Into Your DevOps Practices When: Wednesday, September 23 2020, 10am PT / 1pm ET Duration: 45min + Live Q&A Session Hosted By: Farshad Abasi – Founder, CSO @ FWDSEC Share this webinar FacebookXLinkedInRegister For The Challenge Name First Last Email Company Name Δ As technology continues to accelerate so too do - [Cyber Security for Startups One Week Challenge](https://forwardsecurity.com/cybersecuritychallenge/) - Forward Security and Cyber.SC Present:Cyber Security Challenge for StartupsA Workshop for Technology Execs to Learn About Easy to Implement and Maintain Security Measures When: 3 Part Series, July 19-23 | 10-11AM PDT (1PM-2PM EDT) Hosted By: Farshad Abasi—Founder, CSO @ FWDSEC, and Dominic Vogel—Founder, Chief Strategist @ Cyber.SC Share this event FacebookXLinkedInRegister For The Challenge - [Registration Success - Cybersecurity Challenge](https://forwardsecurity.com/cybersecuritychallengesuccess/) - Thanks for registering!Cyber Security Challenge for Startups When: 3 Part Series, July 19-23 | 10-11AM PDT (1PM-2PM EDT) A confirmation email with all the details will also be sent to you. Questions or comments? Reach out to us –> comms@fwdsec.com Share this challenge: FacebookXLinkedIn - [Registration Confirmation D&D](https://forwardsecurity.com/registration-confirmation-dd/) - Thanks for registering!Technology Due Diligence Interactive Fireside Chat with CIBC, FWDSEC and RiskAware When: Friday, May 28th, 2021 @10am PT (1PM ET) A confirmation email with all the details will also be sent to you. Questions or comments? Reach out to us –> comms@fwdsec.com Share this webinar FacebookXLinkedIn - [DevSecOps Webinar Signup Success](https://forwardsecurity.com/devsecops-webinar-signup-success/) - Thanks for registering! DevSecOps Webinar: Embedding Security Into Your DevOps Practices When: Wednesday, September 23 2020 @ 10am PT (1pm ET) Add To Calendar For Full Details –> Google | Outlook A confirmation email with all the details will also be sent to you. Questions or comments? Reach out to us –> comms@fwdsec.com Share this - [DevSecOps Maturity Assessment Results](https://forwardsecurity.com/devsecops-maturity-results/) - Are you ready to push your DevSecOps program forward? Contact us today for a free consultation. Let’s Talk - [DevSecOps Maturity Assessment](https://forwardsecurity.com/devsecops-maturity-assessment-2/) - [Contact Success](https://forwardsecurity.com/contact-success/) - Thanks for reaching out, one of our security specialists will be in touch. - [Career Contact Success](https://forwardsecurity.com/career-contact-success/) - Thanks for your interest! - [Browse Submissions](https://forwardsecurity.com/browse-submissions/) - [ipt_fsqm_utrackback nosubmission="No submissions yet." login="You need to login in order to view your submissions." show_register="1" show_forgot="1" formlabel="Form" filters="1" showcategory="0" categorylabel="Category" datelabel="Date" showscore="1" scorelabel="Score" mscorelabel="Max" pscorelabel="%-age" showremarks="0" remarkslabel="Remarks" linklabel="View" actionlabel="Action" editlabel="Edit" avatar="96" theme="material-default" title="eForm User Portal" logout_r=""]Welcome %NAME%. Below is the list of all submissions you have made.[/ipt_fsqm_utrackback] ## Team Members - [Vincent Dragnea](https://forwardsecurity.com/team-member/vincent-dragnea/) - Vincent has worked as a software developer and security researcher for 9 years, with a strong focus on application security. He enjoys building secure applications, with a commitment to shifting the detection of vulnerabilities as far left as possible, starting with developer education. - [Iman Sharafaldin](https://forwardsecurity.com/team-member/iman-sharafaldin/) - Iman specializes in analyzing, designing, testing, and optimizing secure systems across a wide range of business and technical environments. He has more than ten years of experience in cybersecurity, and his work has garnered over 6,000 citations, reflecting his significant contributions to the field. Outside of work, Iman enjoys hiking and exploring the outdoors. - [Rachel Sun](https://forwardsecurity.com/team-member/rachel-sun/) - Rachel is a fourth-year Media Studies and Arts Co-op student at UBC with extensive experience in social media strategy, graphic design, and marketing. She excels at creating engaging content that brings communities together, helping businesses grow and build lasting connections with their audiences. - [Danylo Lapin](https://forwardsecurity.com/team-member/danylo-lapin/) - Danylo is an experienced software engineer with advanced skills in penetration testing, and application security. Building the apps is one of his favorite activities, but his “real” passion is Cyber Security . As a hacker in nature, he is always eager for new challenges, the solution of which will make your company safer. - [Jacob Newman](https://forwardsecurity.com/team-member/jacob-newman/) - Jacob is a dedicated software engineer with a passion for understanding systems at their core. With two years of experience in embedded development, he brings valuable low-level application expertise. He holds a DEFCON black badge and has represented Canada in international cybersecurity competitions. Currently, he is completing his Computer Engineering degree at the University of - [Farshad Abasi](https://forwardsecurity.com/team-member/farshad-abasi/) - An innovative technologist with over twenty years of experience in security, software design and development, network and system architecture and management. Farshad spent a decade as a senior member of HSBC’s IT security team and currently leads OWASP’s Vancouver chapter. - [Mathieu Chretien](https://forwardsecurity.com/team-member/mathieu-chretien/) - Matt brings 17+ years of experience in IT program & project management, as well as cash flow & supply chain optimization with companies of all sizes from Deloitte, EY, BC Hydro, and GE, to emerging tech start-ups. When he’s not helping clients, he enjoys kayaking, skiing, and spending time with his children and close friends. - [Ewan Maalerud](https://forwardsecurity.com/team-member/ewan-maalerud/) - Ewan graduated from the University of British Columbia and BCIT and brings over a decade of experience in marketing, design, and sales. An entrepreneur at heart, he thrives in start-up environments where he can help small companies compete. He applies his passion for creative problem solving, psychology, brand building, and design to impact the way - [Marnie White](https://forwardsecurity.com/team-member/marnie-white/) - With a passion for optimizing operational efficiency, supporting financial processes, and driving organizational success, Marnie brings over a decade of experience in diverse office environments. She possesses a wide range of skills in operations, facilities management, and office management. - [Sasa Djolic](https://forwardsecurity.com/team-member/sasa-djolic/) - Sasa has 20 years of experience with high-performing engineering teams, VP and Program Owner, Data Science Services as Mastercard, previously worked at Persistr and Kater, and defined the concept of Event-Driven Design (EDD) - [Jared Meit](https://forwardsecurity.com/team-member/jared-meit/) - Jared has always had a passion for taking things apart, learning how they work, and forgetting how to put them back together. He brings more than 12 years of professional software development, and a zeal for all things security. His AppSec experience at one of the “Big Four” accounting firms informs the deep level of - [Bob Wang](https://forwardsecurity.com/team-member/bob-wang/) - Bob is currently a Principal at Broadtree Partners. He’s passionate about helping teams succeed and organizations thrive. Previously, Bob was the head of finance at Traction Guest, an Enterprise software company, that was acquired by a PE Group. He also started his own accounting firm, which Deloitte acquired. Bob won the Top 40 under 40 - [Dominic Rubino](https://forwardsecurity.com/team-member/dominic-rubino/) - Dominic is a serial entrepreneur, having started, bootstrapped, built and sold a number of companies in fields such as construction, pharmaceuticals, real estate, franchising and business advisory services. He believes in building high performing teams held together with a strong culture and simple systems. - [Goran Kimovski (Kima)](https://forwardsecurity.com/team-member/goran-kimovski-kima/) - Kima is a software industry veteran with 20+ years of experience building products & solutions on a variety of technology platforms. He is also a successful entrepreneur, co-founding and leading TriNimbus, a major Canadian AWS consulting business, through rapid growth and acquisitions by Onica and later Rackspace that enabled the business to become the largest ## Trusted By Companies - [ready](https://forwardsecurity.com/trusted_by_companies/ready/) - [Peoples Trust](https://forwardsecurity.com/trusted_by_companies/peoples-trust/) - [Later](https://forwardsecurity.com/trusted_by_companies/later/) - [Corportate Finanical Institute](https://forwardsecurity.com/trusted_by_companies/corportate-finanical-institute/) - [Glia](https://forwardsecurity.com/trusted_by_companies/glia/) - [neo](https://forwardsecurity.com/trusted_by_companies/neo/) - [Nicola Wealth](https://forwardsecurity.com/trusted_by_companies/nicola-wealth/) - [CALA](https://forwardsecurity.com/trusted_by_companies/cala/) - [Amazon Web Services](https://forwardsecurity.com/trusted_by_companies/amazon-web-services/) - [Microsoft Azure](https://forwardsecurity.com/trusted_by_companies/microsoft-azure/) - [Google Cloud](https://forwardsecurity.com/trusted_by_companies/google-cloud/) ## Special Events - [Join us on Game Night](https://forwardsecurity.com/special-event/canuck-night/) - Join Salt Security & Forward Security (and other cybersecurity peers) for an evening of hockey as the Vancouver Canucks battle the New Jersey Devils. November 1st, 2022 6:00pm: Arrive early for food and beverages 7:00pm: Game starts Rogers Arena 800 Griffiths Way, Vancouver, BC V6B 6G1 VS - [DeveloperWeek](https://forwardsecurity.com/special-event/developerweek-2/) - Join us at DeveloperWeek 2024 February 21st, 2024 @ 4:00 p.m. PST [In-Person] February 27th 1:00 p.m. PST [Virtual] Join us at DeveloperWeek 2024 in Oakland California, where Farshad Abasi will be speaking about CI/CD pipelines and emerging threats. If you’d like free tickets to the event, please register here. DeveloperWeek 2024 brings you cutting - [Fireside Chat Discussing AI Vs. AppSec Fundamentals](https://forwardsecurity.com/special-event/fireside-chat-discussing-ai-vs-appsec-fundamentals/) - In an era heralded by technological marvels, AI stands at the forefront, promising to revolutionize our world in countless ways. From enhancing healthcare and advancing education to streamlining business processes and tackling climate change, the narrative has been overwhelmingly positive: AI is here to "save the world." However, with great power comes great responsibility—and significant - [Next-Level AppSec: Transforming Secure Development with Semgrep & Eureka DevSecOps Platform](https://forwardsecurity.com/special-event/next-level-appsec/) - Join industry veterans Farshad Abasi and Tanya Janca in an insightful webinar exploring the integration of Semgrep's SAST capabilities with the Eureka DevSecOps Platform. This session will dive into the complexities of application security landscapes, including various scanner types and platforms, and demonstrate how integrating these tools can significantly enhance security efficiency and effectiveness. Learn - [Join us at The Dogwood Rock Rose](https://forwardsecurity.com/special-event/join-us-at-the-dogwood-rock-rose/) - We are Forward Security – a Canadian-based application and cloud security company. We just opened a new office in Austin, Texas, and to celebrate, we’re hosting an event at The Dogwood. We would be delighted if you are able to attend. - [Part 1 - How to Best Set up Identity and Access Management in Your AWS Environment](https://forwardsecurity.com/special-event/forward-security-aws-webinar-series-2023/part-1/) - ready Thursday, May 18th 10:00 – 11:00 a.m. PST Forward Security & AWS Webinar Series 2023How to Best Set up Identity and Access Management in Your AWS Environment to Reduce FraudWe are proud to partner closely with Amazon Web Services – one of the leading organizations shaping the world of technology and cybersecurity. Join Us - [Part 2 - How to Protect your AWS Environment from Network Attacks](https://forwardsecurity.com/special-event/forward-security-aws-webinar-series-2023/part-2/) - readyThursday, May 25th 10:00 – 11:00 a.m. PST Forward Security & AWS Webinar Series 2023How to Protect your AWS Environment from Network Attacks.We are proud to partner closely with Amazon Web Services – one of the leading organizations shaping the world of technology and cybersecurity. Join us for our second annual Forward Security & AWS - [Part 3 - Find Out if You Are Being Attacked Before its Too Late](https://forwardsecurity.com/special-event/forward-security-aws-webinar-series-2023/part-3/) - readyThursday, June 1st 10:00 – 11:00 a.m. PST Forward Security & AWS Webinar Series 2023Find Out if You Are Being Attacked Before its Too LateWe are proud to partner closely with Amazon Web Services – one of the leading organizations shaping the world of technology and cybersecurity. Join us for our second annual Forward Security - [Part 4 - Stay Compliant & Protect your Data with AWS](https://forwardsecurity.com/special-event/forward-security-aws-webinar-series-2023/part-4/) - readyThursday, June 8th 10:00 – 11:00 a.m. PST Forward Security & AWS Webinar Series 2023Don’t Be a Rule Breaker: Stay Compliant & Protect your Data with AWSWe are proud to partner closely with Amazon Web Services – one of the leading organizations shaping the world of technology and cybersecurity. Join us for our second annual - [Part 5 - AWS Key Management System and Encryption](https://forwardsecurity.com/special-event/forward-security-aws-webinar-series-2023/part-5/) - readyThursday, June 15th 10:00 – 11:00 a.m. PST Forward Security & AWS Webinar Series 2023Do You Know Who has the Keys to your Castle? Learn About AWS Key Management System and EncryptionWe are proud to partner closely with Amazon Web Services – one of the leading organizations shaping the world of technology and cybersecurity. Join - [Forward Security & AWS Webinar Series 2023](https://forwardsecurity.com/special-event/forward-security-aws-webinar-series-2023/) - Forward Security & AWS Webinar Series 2023May – June 2023Join us for our second annual Forward Security & AWS Webinar Series. In this 5 part webinar series, we discuss how to best set up identify and access management, how to protect your AWS environment from network attacks, how to stay compliant, and more. See SchedulePresented - [DeveloperWeek](https://forwardsecurity.com/special-event/developerweek/) - Join us at DeveloperWeek 2023 February 15th, 2023 @2:00 p.m. PST Join us at DeveloperWeek 2023 in Oakland California, where Farshad Abasi will be speaking about API security and microservices. If you’d like free tickets to the event, please register here. DeveloperWeek 2023 brings you cutting edge developer learning from industry leaders. Discover the newest - [Join us at SFU VentureLabs for a Cybersecurity AMA Info Session](https://forwardsecurity.com/special-event/venturelabs-ama-2023/) ## Case Studies - [Building Security Automation into the CI/CD Pipeline with Eureka DevSecOps Platform](https://forwardsecurity.com/case_study/building-security-automation-into-the-ci-cd-pipeline-with-eureka-devsecops-platform/) - Our client in the data analytics sector had implemented DevOps automation and CI/CD pipelines but without any security in the mix. - [Security Assessment Services for Outdoor Equipment Brand](https://forwardsecurity.com/case_study/security-assessment-services-for-outdoor-equipment-brand/) - Forward Security Inc. provided cybersecurity services for an outdoor equipment brand. They performed different AWS security assessments and tested their QA, production, and postproduction environments. - [IT Consulting Services for Data Integration Platform](https://forwardsecurity.com/case_study/it-consulting-services-for-data-integration-platform/) - Forward Security Inc. has provided IT consulting services for a data integration software company. They’ve done application penetration testing to their product to ensure the customers’ data is secure. - [Cybersecurity Compliance Services for Legal Tech Company](https://forwardsecurity.com/case_study/cybersecurity-compliance-services-for-legal-tech-company/) - Forward Security Inc. supported a legal technology startup with two security compliance projects. The first project was SOC2 process guidance, and the second one was penetration testing on their platform. - [Security Review for Instagram Marketing Platform](https://forwardsecurity.com/case_study/security-review-for-instagram-marketing-platform/) - An Instagram marketing platform partnered with Forward Security Inc. to conduct a security audit for their platform and provide basic training for their development staff. - [Cybersecurity Assessments for Fintech Company](https://forwardsecurity.com/case_study/cybersecurity-assessments-for-fintech-company/) - Forward Security performs cybersecurity consulting services for fintech company. The team examines and audits the client's products in order to see if there are vulnerabilities to their systems. - [Web Application Pentesting Needed for Compliance](https://forwardsecurity.com/case_study/web-application-pentesting-needed-for-compliance/) - Forward Security Inc. developed a penetration test for a visitor management system. They created a statement of work, managed the project’s budget, and worked on the web app’s security landscape. - [Penetration Testing and Cloud Security Assessments for Med49 ISO Certification](https://forwardsecurity.com/case_study/penetration-testing-and-cloud-security-assessments-for-med49-iso-certification/) - Forward Security Inc. provided security assessment and testing to help their client earn a necessary industry certification. Their portfolio consisted of penetration testing and cloud security assessments. ## Podcast Episodes - [Episode 3](https://forwardsecurity.com/podcast_episodes/episode-3/) - The Attacks on the CICD Pipeline (Part 2) - [Episode 2](https://forwardsecurity.com/podcast_episodes/episode-2/) - The Attacks on the CICD Pipeline (Part 1) - [Episode 1](https://forwardsecurity.com/podcast_episodes/episode-1/) - ChatGPT and the Future of Application Security ## Software / Tools - [Veracode](https://forwardsecurity.com/software_tools/veracode/) - SAST - [MergeBase](https://forwardsecurity.com/software_tools/mergebase-2/) - SCA - [SecurityChecker](https://forwardsecurity.com/software_tools/securitychecker/) - SCA - [Bundle Audit](https://forwardsecurity.com/software_tools/bundle-audit/) - SCA - [FindSecBugs](https://forwardsecurity.com/software_tools/findsecbugs-2/) - SAST - [Snyk](https://forwardsecurity.com/software_tools/snyk/) - SCA - [OWASP ZAP](https://forwardsecurity.com/software_tools/owasp-dependency-check/) - DAST - [SonarQube](https://forwardsecurity.com/software_tools/sonarqube/) - SAST - [Bandit](https://forwardsecurity.com/software_tools/bandit/) - SAST - [Brakeman](https://forwardsecurity.com/software_tools/brakeman/) - SAST - [Semgrep](https://forwardsecurity.com/software_tools/semgreg/) - SAST - [Jenkins](https://forwardsecurity.com/software_tools/jenkins/) - CI/CD - [Github Actions](https://forwardsecurity.com/software_tools/github-actions/) - CI/CD - [Azure DevOps Pipeline](https://forwardsecurity.com/software_tools/azure-devops-pipeline/) - CI/CD - [Azure DevOps](https://forwardsecurity.com/software_tools/azure-devops/) - Issue Tracking - [Jira Software](https://forwardsecurity.com/software_tools/jira-software/) - Issue Tracking ## Events - [Tampa Bay Wave CyberTech|X Accelerator](https://forwardsecurity.com/event/tampa-bay-wave-cybertechx-accelerator/) - [Join Forward Security during October for cybersecurity month](https://forwardsecurity.com/event/join-forward-security-during-october-for-cybersecurity-month/) - October is cybersecurity month and our A-Team will be travelling across North America to spread the word of AppSec! Farshad Abasi is talking about how to use Security Knowledge Framework and ASVS to build secure apps at SecTor, Bsides Calgary and LASCON Farshad will also be making his way to San Jose with a presentation - [FFCON21 Breaking Barriers: Building blocks of a security program for companies with applications in the Cloud.](https://forwardsecurity.com/event/ffcon21-breaking-barriers-building-blocks-of-a-security-program-for-companies-with-applications-in-the-cloud/) - According to *Verizon, web applications were involved in 43% of breaches in 2020. **IBM also reported that 52% of breaches were caused by malicious attacks against applications last year. These statistics highlight the importance for modern technology companies building web and mobile cloud-hosted apps to have a comprehensive information security program that covers application and cloud security as well as corporate governance and risk management. *Source: - [Technology Due Diligence Process and Cyber Security Risks](https://forwardsecurity.com/event/technology-due-diligence-process-and-cyber-security-risks/) - Tune in on Friday, May 21st, 2021 for an insightful conversation regarding the Technology Due Diligence process and risks that are crucial for investors, M&As, and preparing your company for acquisition. Hear from Daniel Lee (Managing Director of Technology & Innovation in Mid-Market Investment Banking at CIBC), Michael Castro (Founder & Risk Executive at RiskAware - [Executive Round Table: Building Security in a Software Factory](https://forwardsecurity.com/event/executive-round-table-building-security-in-a-software-factory/) - Application security is changing. It’s not enough to just secure your custom code anymore. We also need to secure the supply chain of open source and other third-party software. And recently, attackers have discovered that by attacking the software factory itself, they can insert malicious code or trojans into applications and APIs before they are even deployed. Join - [Cyber Security Challenge for Startups](https://forwardsecurity.com/event/cyber-security-challenge-for-startups/) - WHAT'S THE AGENDA? Throughout the week, you’ll be learning how to use the Security 4 Startups tool to assess the security risks of your organization. Our hosts will walk you through various security controls on the checklist that fall into three categories: organization, IT infrastructure, and applications. You’ll learn what these controls mean and how - [Preparing for the Next Zero-Day Vulnerability](https://forwardsecurity.com/event/preparing-for-the-next-zero-day-vulnerability/) - Watch Event Now Contrast Security | On-Demand Preparing for the Next Zero-Day Vulnerability Now that dust is settling from Log4Shell, how can you prepare for and prevent the next zero-day vulnerability from impacting your organization?Join Larry Maccherone, DevSecOps Transformation lead at Contrast Security, and Farshad Abasi, Chief Security Officer at Forward Security for an interactive - [Canada 360 Economic Summit: Panel 1 - Future of the Digital Economy](https://forwardsecurity.com/event/canada-360-economic-summit-panel-1-future-of-the-digital-economy/) - Alongside the economic disruptions caused by the global pandemic, Canada still faces several long-standing challenges that may hold back our economy’s potential growth. The country desperately needs a bold strategy rather than reverting to the status quo if we are serious about raising economic growth in the future. ## Categories - [Uncategorized](https://forwardsecurity.com/category/uncategorized/) - [Application Security](https://forwardsecurity.com/category/application-security/) - [Cloud Security](https://forwardsecurity.com/category/cloud-security/) - [News](https://forwardsecurity.com/category/news/) - [DevSecOps](https://forwardsecurity.com/category/devsecops/) - [Support](https://forwardsecurity.com/category/support/) ## Tags - [API](https://forwardsecurity.com/tag/api/) - [Microservices](https://forwardsecurity.com/tag/microservices/) - [API Gateway](https://forwardsecurity.com/tag/api-gateway/) - [OpenID Connect](https://forwardsecurity.com/tag/openid-connect/) - [OAuth](https://forwardsecurity.com/tag/oauth/) - [SAML](https://forwardsecurity.com/tag/saml/) - [news](https://forwardsecurity.com/tag/news/) - [GenAI](https://forwardsecurity.com/tag/genai/) ## Team Member Categories - [A-Team](https://forwardsecurity.com/team_member_category/a-team/) - [Advisory Board](https://forwardsecurity.com/team_member_category/advisory-board/) ## Specialties - [Homepage](https://forwardsecurity.com/specialties/homepage/) - [Cloud Security](https://forwardsecurity.com/specialties/cloudsecurity/) ## Case Study Categories - [DevSecOps](https://forwardsecurity.com/case_study_category/devsecops/) - [Healthcare](https://forwardsecurity.com/case_study_category/healthcare/) - [eCommerce](https://forwardsecurity.com/case_study_category/ecommerce/) - [Fintech](https://forwardsecurity.com/case_study_category/fintech/) - [Technology](https://forwardsecurity.com/case_study_category/technology/) ## Software Categories - [Scanners](https://forwardsecurity.com/software_category/scanners/) - [CI/CD](https://forwardsecurity.com/software_category/ci-cd/) - [Issue Tracking](https://forwardsecurity.com/software_category/issue-tracking/) ## Event Categories - [Conference](https://forwardsecurity.com/event-calendar/category/conference/)