What is OWASP, which lists does it publish, and why are they relevant to cyber security architecture even though they target software development?
The Open Web Application Security Project, a non-profit that aims to improve software security; it publishes the Top 10 Web Application Security Risks, and since 2023 an API Security Top 10, in 2025 a Non-Human Identities Top 10, and its latest extensions (2026) cover AI, such as the GenAI LLM Top 10. They matter for CSA when a weakness cannot be fixed in the software itself.
The Top 10 Web Application Security Risks describes the ten most common mistakes in web development in detail and is updated regularly. The newer lists:
- API Security Top 10 (2023),
- Non-Human Identities Top 10 (2025), about machines, programs and services as actors,
- the latest extensions (2026) covering everything around AI, such as the OWASP GenAI LLM Top 10.
OWASP's focus is software development, but the risks reach into architecture. If a piece of software cannot be changed, for example because the source code of purchased software was never acquired, an additional construction in front of the software (such as a web application firewall) may have to provide the security the software itself lacks.