Join our Newsletter — 33% off our NHI Course

OWASP Top 10 2025: what the new risk model means for IAM

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: The OWASP Top 10 2025 release candidate shifts AppSec away from symptom-level labels toward root causes, with changes such as splitting supply chain failures, elevating misconfiguration, and reframing access control and integrity issues, according to Orca Security and OWASP project leaders. That shift matters because identity, configuration, and provenance controls now sit at the centre of application risk, not beside it.

Editorial analysis by NHI Mgmt Group, based on content published by Orca Security: “OWASP Top 10 2025: Key Changes and What They Mean for Application Security”.

By the numbers:

  • A03:2025 Software Supply Chain Failures has more than 215,000 occurrences, according to Orca Security.
  • A02:2025 Security Misconfiguration covers over 719,000 mapped CWEs, according to Orca Security.
  • A04:2025 Cryptographic Failures has over 1.6 million occurrences, according to Orca Security.

Key questions

Q: What breaks when broken access control is treated as a purely application-layer issue?

A: Teams miss the service and token boundaries where authorization actually fails.

Q: Why do misconfiguration problems keep resurfacing in cloud and application stacks?

A: Because configurable systems inherit unsafe defaults unless hardening is automated and continuously checked.

Q: How should teams distinguish supply chain failures from software integrity failures?

A: Supply chain failures describe how risk enters through dependencies, build tooling, or update channels.

Practitioner guidance

  • Align appsec findings to root causes Map findings to broken access control, misconfiguration, supply chain failure, cryptographic failure, and integrity failure so remediation targets the control gap rather than the symptom.
  • Tighten backend authorisation paths Review service-to-service permissions, token handling, and SSRF-exposed paths to make sure backend trust does not bypass intended access controls.
  • Automate environment hardening checks Use repeatable configuration baselines and verification across cloud, container, and application environments to catch default accounts, open permissions, and insecure settings before release.

Bottom line: OWASP’s 2025 update reframes application security around underlying control failures rather than symptom labels, which is more useful for governance and remediation.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 16 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21545
 

OWASP Top 10 2025 is really a control taxonomy update, not a cosmetics refresh: the list now aligns more closely with how failures propagate across identity, cloud configuration, and software provenance. That makes the document more useful to practitioners because it names the control surface where exposure starts, not just the symptom that appears at the end. The implication is that appsec and IAM programmes need shared governance language for access, configuration, and integrity.

A few things that frame the scale:

  • 73% of vaults are misconfigured, leading to unauthorised access and exposure of sensitive data, according to the Ultimate Guide to NHIs.
  • 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to the Ultimate Guide to NHIs.

A question worth separating out:

Q: Should IAM teams treat appsec root causes as part of their own programme?

A: Yes, because access control, configuration, and provenance now shape the same exposure path. If IAM ignores service permissions, token handling, and trust in software delivery, it leaves key parts of application risk outside governance.

👉 Read our full editorial: OWASP Top 10 2025 shifts appsec toward root causes


This post was modified 16 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.