Skip to content
Chat GPT - Tim Witzdam
Chat GPT – Tim Witzdam

Web applications and AI tools are now a part of everyday business. From customer portals, booking systems and chatbots, organisations are using them to make services quicker and easier to access.

But every new application can also introduce vulnerabilities.

During our latest Cyber Byte webinar, our cyber security specialist, Thais Ramdani looked at some of the common weaknesses they find when testing web applications and AI systems, and the practical steps organisations can take to reduce their risk.

Security needs to start before an application goes live

One of the clearest messages from the session was that security shouldn’t be considered only once an application has been built. The earlier security is considered, the easier it is to identify and address potential weaknesses.

If you’re developing a new website, customer portal, app or AI tool, think about security throughout the development process. Testing before launch can identify problems before customers – or criminals – have an opportunity to find them.

And don’t assume that an applicant that was secure when launched will remain secure. Systems change, new features are added and new vulnerabilities are discovered.

Tip – Build security testing into the lifecycle of your application, particularly after significant changes or new functionality is introduced.

Think carefully about what users can access

Sometimes the problem isn’t sophisticated hacking. It’s simply that an application gives someone access to something they shouldn’t be able to see.

During the webinar, the team discussed the importance of accessing controls: making sure users can only access the information and functions appropriate to them.

This becomes particularly important where an application holds customer information, personal data or commercially sensitive information.

Tip – Review who can access what within your application. Don’t just test whether a user can log in – consider what they can see and do once they’re inside.

Don’t forget the applications behind your website

A website might look relatively simple to the person using it, but behind it can sit databases, APIs, third-party services, login systems and other applications.

Attackers will look for weaknesses across that wider environment.

The same principle applies to applications developed by external suppliers. Outsourcing development doesn’t outsource your responsibility for understanding how your information is being protected.

Tip – Know which applications and services your organisation relies on, what information they hold and who is responsible for keeping them secure.

AI introduces some different security questions

AI applications can introduce risks that traditional web applications don’t necessarily face.

For example, organisations need to consider what information is being supplied to an AI system, what information it can access and whether users could manipulate it into revealing information or behaving in ways it wasn’t intended to.

The discussions also highlighted the importance of understanding where information goes when using third-party AI tools.

Before entering information into an AI system, organisations should understand how that information will be handled and whether it could contain confidential, personal or commercially sensitive data.

Tip – Set clear rules for how AI tools can be used within your organisation, particularly around the information employees are permitted to enter.

Don’t rely on AI-generated code without checking it

AI can help developers work more quickly, but code produced with the help of AI shouldn’t automatically be assumed to be secure.

AI-generated code can still contain vulnerabilities or introduce security problems if it is implemented without appropriate review and testing.

Human oversight remains important.

Tip – Treat AI-generated code in the same way you would any other code. Review it, test it and make sure someone understands what it is doing before it is deployed.

Penetration testing should reflect how your organisation actually works

Security testing isn’t simply about ticking a compliance box. A good penetration test looks at how an application could be attacked in practice and identifies weaknesses before a criminal can exploit them.

This might be particularly useful when you’re:

  • Launching a new website, application or customer portal.
  • Introducing an AI chatbot or AI-enabled service.
  • Making significant changes to an existing application.
  • Preparing for certification or compliance requirements.
  • Reviewing security following an incident or identified vulnerability.

The aim isn’t just to produce a list of technical findings, but to understand which weaknesses matter most and what should be fixed first.

Start with one simple question

You don’t need to be a cyber security specialist to start asking useful questions:

What applications or AI tools does our organisation rely on, and when were they last independently tested?

If you don’t know the answer, that’s a good place to start. The Cyber and Fraud Centre – Scotland’s AI and Web Application Security Assessment helps organisations identify vulnerabilities in web applications and AI-enabled systems and understand the practical steps they can take to address them.