
Resources, Tech Blog
API Security Flaws in the Real World – How Business Logic Flaws Are Undermining Modern API Security
by Caleb Eghan
Want to quickly score your SIEM Platform Maturity? Free Quick Check Assessment
The RiverSafe AppSec Maturity Assessment gives you a scored, evidence-based baseline across your full application portfolio, a heatmap of where the gaps are, and a roadmap for closing them.
Framework: OWASP SAMM · BSIMM · CIS Controls 4 & 16 · NIST SSDF · ISO/IEC 27034

A maturity score is not the goal. The goal is knowing which gaps carry real risk and in what order to close them. The Assessment is structured across five practice areas:
1. Governance & Ownership
How application security requirements are defined, owned, and enforced across the organisation, including policies, standards, and risk acceptance processes.
2. Secure Design
Threat modelling, security requirements, and architecture review practices — and whether security is built into development early rather than added later.
3. Secure Development
Secure coding standards, code review practices, developer training, and the consistent use of security libraries and frameworks.


4. Security Testing
Coverage and effectiveness of SAST, DAST, SCA, and manual testing, including how findings are triaged, tracked, and resolved.
5. Vulnerability Management & Response
How vulnerabilities are managed across the lifecycle, including production monitoring, incident response, and feedback into development.
The assessment is conducted by RiverSafe practitioners using OWASP SAMM or BSIMM as the scoring framework, selected based on your organisation’s context and what you plan to do with the output.
We agree the scope, the framework, and the stakeholders who need to be involved. For most organisations this covers the full application portfolio; for larger enterprises we can scope to a specific business unit or product line first.
Structured interviews with AppSec leads, developers, architects, and security operations. Documentation review: policies, standards, process guides, tool configurations, training records. We are looking for evidence of what actually happens, not what the policy says should happen.
Each practice area is scored against the framework. Gaps are identified and classified by two factors: how far the practice falls below an acceptable level, and how much risk that gap carries given the applications in scope.
We deliver the scorecard, heatmap, and roadmap in a working session with the relevant stakeholders. The session is structured so that the team can challenge findings, ask questions, and leave with a clear picture of what to do next.

A scored view of your application security programme across all five practice areas, benchmarked against the OWASP SAMM or BSIMM framework. Each practice area shows current level, the evidence it is based on, and what the next level requires.
A visual summary of maturity across the practice areas, showing at a glance where the programme is strongest, where the gaps are, and which gaps carry the most risk. Designed to be usable in board and leadership conversations without stripping out the substance.
Specific recommendations for what to address, in what order, based on risk exposure and delivery effort. Not a list of everything that could be better, a sequenced plan for what to do next given your current state and the applications you are responsible for.
A written summary for CISOs and engineering leadership covering current maturity position, material gaps, and the investment case for the roadmap. Written to be read without a security background, without removing the substance that makes it credible.
Book a 30-minute scoping call. We will confirm the assessment approach, agree which frameworks apply to your context, and give you a timeline.