Home/Blog/Security Essentials
Security Essentials

OWASP Top 10 2025: What Changed and Why UK Teams Should Care

The OWASP Top 10 remains the shared vocabulary for web application risk. The 2025 edition is not a rebrand of the 2021 list. Two categories are new, one risk class was absorbed into another, and several familiar names moved up or down the ranking. For UK security, engineering and procurement leads, the useful question is not “did we tick the Top 10?” but “do our design reviews, pipelines and tests actually cover how these risks show up in our stack?”

This article walks the official OWASP Top 10:2025 categories, summarises what moved versus 2021, and explains where independent penetration testing helps evidence weaknesses. Attack Vector identifies issues. Your organisation decides what to fix and when. If you still brief teams from a 2021 poster or an older Attack Vector summary page, treat those as historical and align scope to the live OWASP list before the next release cycle.

In short

  • Source of truth: owasp.org/Top10/2025/.
  • A01 Broken Access Control stays first; SSRF is rolled into it.
  • A02 Security Misconfiguration rises sharply; cloud and config-heavy apps drive this.
  • A03 Software Supply Chain Failures expands beyond “outdated components.”
  • A10 Mishandling of Exceptional Conditions is new.
  • The Top 10 is an awareness document, not a certification or legal mandate.

Context: awareness list, not a pass certificate

OWASP publishes the Top 10 as a consensus awareness document for developers and application security. Boards sometimes treat it as a compliance checkbox. It is not Cyber Essentials, ISO 27001 or a statutory test. Mapping your backlog and test scope to the Top 10 is still a sensible habit because buyers, insurers and developers already speak that language.

Attack Vector is a UK-based consultancy. Lead consulting credentials include Cyber Scheme Team Leader (CSTL), from The Cyber Scheme, and Chartered Cyber Security Professional (ChCSP), the UK Cyber Security Council's chartered title.

The official OWASP Top 10:2025 list

IDCategory
A01:2025Broken Access Control
A02:2025Security Misconfiguration
A03:2025Software Supply Chain Failures
A04:2025Cryptographic Failures
A05:2025Injection
A06:2025Insecure Design
A07:2025Authentication Failures
A08:2025Software or Data Integrity Failures
A09:2025Security Logging and Alerting Failures
A10:2025Mishandling of Exceptional Conditions

What changed versus 2021

OWASP’s own introduction highlights two new categories and one consolidation:

  1. Software Supply Chain Failures (A03) expands the older “Vulnerable and Outdated Components” idea to cover dependencies, build systems and distribution infrastructure, not only known CVEs in libraries.
  2. Mishandling of Exceptional Conditions (A10) is new. It covers weak or unsafe behaviour when systems hit errors, edge cases and “fail open” paths.
  3. Server-Side Request Forgery (SSRF) is no longer a standalone Top 10 entry. Its weakness class sits under Broken Access Control (A01).

Other notable movement: Security Misconfiguration climbs to A02; Cryptographic Failures and Injection each drop two places; Insecure Design slides as other categories leapfrog it; Authentication Failures keeps position with a clearer name; Software or Data Integrity Failures stays at A08, focused on trust boundaries and integrity of code and data artefacts at a lower level than Software Supply Chain Failures. Security Logging and Alerting Failures holds A09, renamed from Logging and Monitoring to stress alerting.

Category-by-category: what to look for in practice

A01 Broken Access Control

Still the headliner. Expect horizontal and vertical privilege issues, missing object-level checks, forced browsing, and SSRF-style abuse of server-side fetch features. Automated scanners catch some of this. Role matrix testing and business-logic abuse still need human-led work.

A02 Security Misconfiguration

Default credentials, verbose errors, open cloud storage, permissive CORS, leftover admin interfaces, weak container or platform defaults. Modern apps expose more behaviour through configuration than through compiled code, which is why this category rose.

A03 Software Supply Chain Failures

Compromised packages, poisoned CI plugins, weak signing or provenance, and insecure distribution paths. Presence in historical test data can look low because many programmes never test the pipeline. Impact when it lands is often severe. Treat SBOMs, dependency policy and build hardening as first-class controls, then verify what an attacker can still reach.

A04 Cryptographic Failures

Broken or missing encryption, weak algorithms, poor key handling, secrets in logs or client storage. Often discovered when someone asks “where does this PII actually travel?” rather than when a scanner fires.

A05 Injection

SQL, command, LDAP, template and XSS-class issues remain heavily tested and heavily represented in CVE volume. Parameterisation and output encoding still matter. So does refusing to concatenate untrusted input into interpreters.

A06 Insecure Design

Missing threat modelling, unsafe trust assumptions, features that cannot be made safe by a late patch. This is architectural. A two-day scan will not invent a threat model for you.

A07 Authentication Failures

Credential stuffing resilience, session fixation, weak recovery flows, missing MFA where risk demands it. Frameworks help; custom login and “temporary” bypasses still break programmes.

A08 Software or Data Integrity Failures

Unsigned or unverified updates, insecure deserialization, CI artefacts that can be swapped, integrity checks that exist on paper only. Adjacent to supply chain, but closer to how you verify what runs in your environment.

A09 Security Logging and Alerting Failures

Missing audit trails, logs that omit identity or object IDs, alerts nobody owns, retention that fails when you need evidence. You feel this category during an incident, not during a green pipeline badge.

A10 Mishandling of Exceptional Conditions

Error paths that fail open, logic bugs under unexpected input, resource exhaustion handling that disables controls, exception handlers that leak internals or skip authorisation. Easy to miss if testing only follows happy paths.

How penetration testing maps to the list

A useful web or API test against a modern application will exercise access control across roles, probe configuration and cloud edge behaviour, attempt injection classes, review auth and session handling, and chase error-path abuse. Supply-chain and design risks are only partly visible from an external black-box test; they need scope that includes CI configuration, dependency policy evidence, or design workshops.

Do not confuse a vulnerability scan PDF with coverage of the Top 10. Scans help hygiene. They do not prove exploitability or business impact the way a scoped penetration test does. For the commercial distinction, see penetration testing vs vulnerability scanning.

Attack Vector web application testing starts from £1,500 for tightly defined scopes. Broader authenticated apps, multiple roles and APIs take more days. Pricing context sits in the UK cost guide.

Treating 2025 as a rebadge exercise

The failure mode we see most often is renaming last year’s spreadsheet “Top 10 2025” without changing test cases. If SSRF checks vanished because “SSRF left the list,” you misunderstood the consolidation. If supply chain remains “we run npm audit sometimes,” A03 is still open. If nobody tests fail-open and error handlers, A10 is wishful thinking.

The second failure mode is buying a generic report that lists OWASP category labels with no reproduction detail. Labels without evidence do not help engineers, auditors or customers.

What the Top 10 does not tell you

  • The OWASP Top 10:2025 is an awareness document, not a legal mandate or a certificate.
  • Mapping to the Top 10 does not mean every category is equally relevant to every product.
  • We identify and evidence weaknesses. We do not remediate your systems as part of a test fee.
  • No test guarantees you will pass an audit, win a tender or obtain insurance.
  • Older Attack Vector pages that summarise the pre-2025 list should be treated as historical; use this article and the official OWASP pages as the current editorial reference.

If you want a human-led web or API assessment scoped against how these risks appear in your application, try the instant quote calculator or email [email protected]. Service detail lives under web application penetration testing and the wider penetration testing services hub.

FAQ

Is the OWASP Top 10:2025 mandatory in the UK?

No. It is widely referenced in contracts, RFPs and secure-development programmes, but it is not itself a UK statute or a certification scheme.

Did SSRF disappear in 2025?

No. OWASP rolled SSRF into Broken Access Control (A01). You should still test for it where server-side requests exist.

What are the two new 2025 categories?

Software Supply Chain Failures (A03) and Mishandling of Exceptional Conditions (A10), per OWASP’s introduction to the 2025 release.

Can a vulnerability scanner cover the Top 10?

It can help with parts of misconfiguration, known injection signatures and some crypto/protocol issues. It will not reliably cover insecure design, complex access control, supply-chain pipeline abuse or many exceptional-condition paths.

How often should we reassess against the Top 10?

After major releases, architecture changes, or at least annually for material customer-facing applications. Cadence should follow change rate and assurance deadlines, not only the OWASP calendar.

Will Attack Vector fix the findings?

No. Attack Vector identifies weaknesses and provides remediation guidance for your teams to prioritise. Retest can verify closure when scoped.

Suggested Resources

#owasp#web-application-security#security-essentials

Ready to strengthen your security?

Talk to our consultants about your penetration testing requirements, or get a fast, transparent quote.