Skip to content

Training

Secure development training your engineers will finish.

Most annual security training is a slide deck and a quiz that everyone clicks through. This one makes developers exploit a vulnerability, then fix it, then watch their own exploit stop working.

Format
Self-paced in the browser
Modules
Two — coursework and hands-on labs
Audience
Developers, engineers, architects, DevOps
Cadence
Within 90 days of hire, renewed annually
Access
Private link per organisation, valid 12 months
Setup
Nothing to install, no LMS to administer

What's covered

Two modules

The coursework builds the vocabulary. The labs prove it stuck.

01

Secure Software Development

Six sections covering how applications actually get broken into, each ending in a knowledge check.

  • Secure design principles — least privilege, defence in depth, fail securely, threat modelling
  • Injection attacks — SQL and beyond, and the prevention techniques that hold
  • Data attacks and cryptography failures — buffer overflows, race conditions, weak crypto
  • Business logic and client-side flaws — XSS, CSRF, API abuse, Content Security Policy
  • Access control and authentication — broken access control, IDOR, privilege escalation
  • Security testing tools — what each type of testing finds, and how to use them well

02

Practical Exercises: Attack & Remediate

Four hands-on labs. Exploit the flaw in a safe simulated app, apply the fix, confirm the exploit stops working.

  • SQL injection — bypass a login, then parameterise the query
  • Insecure direct object reference — read another user's record, then enforce ownership
  • Reflected cross-site scripting — land a payload, then encode the output
  • Client-side price tampering — edit the price in the browser, then validate server-side

How it works

No platform to buy into.

Your organisation gets one private link. Anyone you send it to can work through both modules in a browser — nothing to install, no accounts to create, no seats to provision or reclaim when someone leaves.

The link is valid for twelve months, which lines up with the annual refresh most control sets ask for. When it lapses, you renew and we issue a new one.

Pricing

Priced per organisation, not per seat.

Tell us roughly how many engineers you need to cover and what you are trying to satisfy, and you will get a number back — not a discovery call about a number. Email adam@minjaresconsulting.com or use the form.