NowSecure, the leading standards-based mobile app security and privacy software company, today announced the world’s most comprehensive mobile app pen testing service for the OWASP Mobile Application Security Verification Standard (MASVS) and the addition of automated MASVS testing to NowSecure Platform. Now mobile organizations, mobile app developers and security teams can turn to NowSecure experts for the gold standard of mobile app testing to ensure proper compliance with the OWASP MASVS.
Mobile apps drive the global economy and 200 billion downloaded mobile apps generated over $170 billion in revenue in 2021. With more than 70% of all digital time spent in mobile apps vs. web apps, mobile is the preferred interface for customers and employees alike. But attacks and breaches also grew alarmingly in the past year with Amazon Ring, Apple iMessage, Park Mobile, Slack and U.S. Customs and Border Protection all experiencing major mobile app security incidents. Overall 85% of tested apps have security vulnerabilities and 70% leak private data as shown in the NowSecure MobileRiskTracker™. Organizations need to be vigilant about building security into their mobile apps and testing rigorously to ensure safety.
Launched in 2013, the OWASP mobile project has driven standards-based security requirements and testing strategies for nearly a decade. Used by mobile app developers, architects, security teams and security researchers, the OWASP mobile project combines three critical resources last updated in January 2022 to provide the best risk reduction approach for mobile app teams:
- OWASP Mobile Application Security Verification Standard (MASVS) establishes a baseline of security requirements for mobile apps
- OWASP Mobile Security Testing Guide (MSTG) outlines how to test the MASVS requirements
- OWASP Mobile App Security Checklist tracks security assessment tasks
NowSecure has contributed to the OWASP mobile project since its inception with NowSecure practitioners collaborating on spec evolution and tooling while the company serves as an OWASP “god mode” sponsor for the OWASP MASVS.
“The OWASP MASVS and MSTG are the foundation of a mobile appsec program,” said Carlos Holguera, OWASP project lead and NowSecure Security Researcher. “The MASVS guides developers and security analysts on architecture, threat modeling and proper techniques to secure mobile data. The MSTG has hundreds of tests you should perform and there are many nuances and edge cases to consider. Without the right expertise it can be tough to effectively achieve full MASVS compliance. The MSTG encourages the use of automated tools to leverage static and dynamic analysis but also emphasizes that having security professionals you can trust is essential.”
Over the past decade, NowSecure Services has performed more than 10,000 mobile app pen tests across a broad variety of mobile apps and industries. NowSecure offers a full slate of pen testing services including rapid, targeted, full-scope and certifications. NowSecure offers services and software for ioXt certification for IoT-connected mobile apps as an authorized ioXt certification lab and National Information Assurance Partnership (NIAP) compliance for the mobile app protection profile. Today NowSecure adds OWASP MASVS pen testing services to the list of available expert-led certifications. Built up over years of experience, NowSecure pen testing services follow a rigorous methodology partnering with mobile app development and security teams including assessment kickoff, customer policy review, industry compliance review, threat modeling, comprehensive app analysis, customized reporting, results walkthrough, remediation collaboration and retest to confirm validated remediation.
“NowSecure is the recognized expert for standards-based testing software and services, partnering with organizations to safeguard trust in their mobile app initiatives,” said NowSecure CEO Alan Snyder. “As an OWASP contributor and sponsor for years, we are committed to the evolution of the specifications. Today we are adding these products and services to help customers ensure the security and privacy of their mobile apps leveraging the gold standard of OWASP MASVS.”
With this announcement, NowSecure Platform has also added MASVS mappings to all relevant findings so that customers can leverage automation for their MASVS testing needs.
NowSecure Platform provides cloud-based automated mobile app security testing for on-demand and DevSecOps continuous testing scenarios. NowSecure Platform delivers a battery of more than 600 automated mobile app tests for comprehensive coverage of mobile security and privacy. NowSecure Platform enables organizations to build and deploy mobile apps faster with the confidence that security and privacy are built-in.
NowSecure Pen Testing Service for OWASP MASVS and NowSecure Platform with OWASP MASVS testing are components of the industry’s only full suite of mobile app sec solutions from NowSecure, including:
- NowSecure Platform for continuous security testing, observability, and remediation in the development pipeline for DevSecOps and on-demand scenarios
- NowSecure Workstation kit for pen tester productivity to test complex, high-risk mobile apps and IoT-connected mobile apps
- NowSecure Supply Chain Risk Management for continuous monitoring of mobile app stores, third-party mobile apps and mobile component risk
- NowSecure Pen Testing Services for full-scope and rapid pen tests delivered by experts using proven standards-based methodology
- NowSecure Academy training courseware for dev and security teams