Why OWASP Matters: The Cornerstone of Modern Web Application Security
Explore why OWASP is vital for web app security, offering tools, standards, and community-driven insights to combat modern cyber threats.
SOC status:Duty analyst on shift
Contributing author
Moises wrote for Insights between June and October 2025. His articles cover the fundamentals that most organisations still get wrong: malware-as-a-service and why it matters to ordinary businesses, insider threat, whaling and domain impersonation, DDoS, the dark web economy, deepfakes, shadow IT, securing a hybrid workforce, incident-response tabletop exercises, VPNs and the OWASP standards behind modern web-application security.
13 articles by Moises Salas Lopez
Explore why OWASP is vital for web app security, offering tools, standards, and community-driven insights to combat modern cyber threats.
In today’s digital world, online privacy and security have never been more important. Whether you’re browsing at home, working remotely, or connecting to free Wi-Fi at a café, your data can be exposed to hackers, advertisers, and even your internet service provider (ISP). This is where aVPN (Virtual Private Network)comes in.
Learn how Incident Response Plan (IRP) tabletop exercises prepare your team for real cyber threats. Discover their benefits, best practices, and execution tips.
A hybrid workforce is a workplace model where employees divide their time between remote work and on-site work. This flexible setup has become a standard for many organizations, delivering benefits such as greater productivity, lower costs, and improved employee satisfaction.
Discover what Shadow IT is, why employees use it, the risks it creates, and practical strategies to manage Shadow IT.
Artificial intelligence has brought us incredible tools, from voice assistants to realistic image generators. But alongside the positive uses, one of the most concerning byproducts is the rise of deepfakes. What started as a novelty on the internet has quickly grown into a serious cybersecurity and societal threat.
Discover how the dark web fuels cybercrime and learn why your business must act to protect data, assets, and reputation.
ADistributed Denial of Service (DDoS) attackis a malicious attempt to disrupt the normal traffic of a targeted server, service, or network by overwhelming it with a flood of traffic from multiple sources. Unlike a basic Denial of Service (DoS) attack, which comes from a single source, DDoS attacks leveragebotnets— networks of compromised devices — to amplify their impact and make them harder to stop.
Domain impersonation is a cyberattack where criminals create a domain name that looks almost identical to your legitimate business domain. For example, if your domain iscyberdefence.com, an attacker might registercyberdefenee.comorcyber-defence.com.
Learn what whale phishing is, how whaling differs from phishing and how to prevent costly executive-targeted cyberattacks.
In today’s increasingly digital world, cyber threats continue to evolve, becoming more sophisticated and persistent. Organizations of all sizes are prime targets, making it crucial to adopt a proactive and robust security strategy. This strategy starts with establishing and maintaining astrong security posture.
Learn what insider threats are, their types, real-world examples, and how to prevent internal cybersecurity risks.
Explore how Malware-as-a-Service (MaaS) increases cyber threats to your business — and why robust, proactive security is vital today.