← All articles
SecurityJul 30 2026·2 min read

Web application security: what to demand from your developer

Learn the essential security practices every web system should have, and what to ask when hiring a developer.

Data leaks, breaches and financial losses from security flaws do not only happen to large companies — small and mid-sized businesses are frequent targets, often because their systems were built without basic security care. Here is what a company should demand from any developer or technology vendor.

1. Encryption of sensitive data

Passwords must never be stored in plain text, and sensitive data (such as payment information) needs to travel and be stored encrypted. That is basic, yet still ignored in many rushed projects.

2. Protection against the most common attacks

A good developer actively prevents known attacks such as SQL Injection, Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF). Those are classic entry points for attackers exploiting poorly protected systems.

3. Robust authentication and access control

Systems must have clear control over who can access what — well-defined user profiles, two-factor authentication where applicable, and expiration of inactive sessions.

4. Updates to dependencies and libraries

Most security flaws do not come from "your own" code, but from outdated libraries and frameworks with already-known vulnerabilities. Keeping dependencies up to date is a security routine, not an "extra".

5. Backups and a recovery plan

Even with good practices, incidents happen. Having automated, regularly tested backups is the difference between a manageable problem and irreversible data loss.

Questions your company should ask before hiring

  • How will the sensitive data of my customers be stored and protected?
  • Is there a security testing process before each delivery?
  • How do backups and the recovery plan work in case of an incident?
  • Who will have administrative access to the system, and how is that controlled?

Conclusion

Security should not be treated as an expensive "extra", but as a basic part of any serious software project. The cost of prevention is always lower than the cost of remediating an incident — in money, time and customer trust.

Facing something similar in your operation?

Describe in a few lines what is slowing your process down today.

AE
André Escobar
Freelance software engineer. I write about technical decisions in business language.