Subtractive Security challenges the traditional approach of piling on security tools by focusing on removing unnecessary attack paths. In this episode, we break down the OWASP framework and explain how taking away can make you more secure than constantly adding.
- What “subtractive security” means and why it’s a shift from traditional additive approaches
- How questioning and deleting unnecessary systems can reduce your attack surface
- The hierarchy of architectural deletion, constraint, and monitoring for practical security improvement
- Real examples of removing attack paths in Active Directory and web applications
- Common reasons organizations resist this approach and where you should start to make an impact
Work with us –> https://www.securit360.com/#contact-anchor
The OWASP Subtractive Security Top 10 Project –> https://github.com/OWASP/OWASP-Subtractive-Hardening-Top-10
The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber risk through the elimination of attack paths.
Blog:Â https://offsec.blog/
Youtube:Â https://www.youtube.com/@cyberthreatpov
Twitter:Â https://x.com/cyberthreatpov
Follow Spencer on social ⬇
Spencer’s Links:Â https://spenceralessi.com
