Everyday security testing: A practical guide to getting started

Learn how to build security into your day-to-day testing!

Everyday security testing: A practical guide to getting started image

TL;DR: A brand-new hands-on course for Professional Members: Everyday security testing: A practical guide to getting started is has launched today!

Created by Richard Adams, this course shows you how to incorporate simple, powerful security checks into your everyday testing. 

👉 Enrol in the course now!


Who is it for? This course is for anyone who wants to add security testing to their everyday work. Whether you're an exploratory tester, automation engineer, or developer, you’ll learn how to spot risks without needing prior security experience.

So, what? Security flaws are among the most damaging issues in software today, but you don’t need to be a specialist to start finding them. This course helps you take a practical, lightweight approach. You’ll learn to spot risks early, test for vulnerabilities hands-on, and build confidence in your ability to add security thinking to your work.

In the course, you’ll:

Get comfortable with security testing terminology.

  • Perform simple but powerful techniques like URL manipulation and bypassing UI validation.
  • Learn how to test for XSS, injection, and SQL injection vulnerabilities.
  • Practice using tools such as Postman, Chrome DevTools, and ZAP.
  • Explore threat modelling step by step, including Data Flow Diagrams and STRIDE.
  • Bring it all you've learnt together in a final hands-on challenge.

All 11 lessons are packed with activities, including hands-on testing, guided demonstrations, and reflections to help you apply your learning directly to your own work.

What’s more!

  • Practical Activities: You’ll test against safe demo sites, including Richard's own site, designed to surface common security vulnerabilities and allow you to practice safely.
  • Threat Modelling in Action: Go beyond the basics and learn to run your own threat modelling session with your team.
  • Community Reflection: Share your experiences and insights with others in the MoTaverse!

👉 Start the course today and begin building security into your testing.

Sarah Deery
Learning and Development Lead
She/Her
My main aim is to help quality professionals turn their vast knowledge and skills into bite-sized chunks that the community can digest.
MoTaverse Team
Richard Adams
Senior Test Analyst
He / Him
Passionate about quality & testing. Creator of Threat Agents card game and regularly found chatting cyber security.
Chapter Organiser
Comments
Judy Mosley
So excited for this course!!

Simon Tomes
Great news! Richard's knowledge and experience is fantastic.

Sign in to comment
Explore MoT
Choosing AI-Powered API Testing Tools: What Capabilities Really Matter image
Thu, 19 Feb
In this webinar, Parasoft experts will discuss what to look for when selecting an AI-powered API testing solution.
Everyday security testing: A practical guide to getting started image
Mitigate security risks by building simple security testing techniques into your daily routine
This Week in Quality image
Debrief the week in Quality via a community radio show hosted by Simon Tomes and members of the community
Subscribe to our newsletter
We'll keep you up to date on all the testing trends.