Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
OWASP Unveils Subtractive Security Top 10 for Cyber Defense

OWASP Unveils Subtractive Security Top 10 for Cyber Defense

Posted on August 4, 2026 By CWS

The Open Worldwide Application Security Project (OWASP) has launched a groundbreaking initiative known as the Subtractive Security Top 10 Project. This effort is designed to enhance cybersecurity by removing potential attack paths, rather than solely relying on detection and monitoring strategies.

Revolutionizing Cyber Defense

Traditional cybersecurity measures often focus on enhancing security with additional products and tools like alerts and access controls. However, OWASP’s new project introduces a paradigm shift by asking security teams to consider what can be removed to hinder or nullify potential attacks.

The principle behind this initiative is straightforward: attackers can only exploit existing pathways. By eliminating unnecessary access points, trust relationships, and network exposures, organizations can significantly reduce the avenues available for attackers to exploit.

Subtractive Security Explained

OWASP outlines subtractive security on GitHub, emphasizing structural changes to eliminate attack vectors. These security controls are prioritized based on their efficiency in reducing the attack surface.

The first step involves architectural deletion, where attack paths are completely removed. This includes disabling legacy protocols, shutting down unused services, and revoking superfluous administrative privileges. The second step, architectural constraint, is applied when complete removal isn’t feasible, using methods like network segmentation and privilege restrictions.

Monitoring and detection are placed last in this hierarchy. While logging and alert systems remain crucial, OWASP emphasizes that detection alone cannot eliminate the paths that attackers might exploit.

Strategic Implementation and Measurement

The project introduces the Path Erasure Rate (PER) as a metric to evaluate security improvements. PER calculates the proportion of attack paths eradicated through structural changes, offering a quantitative measure of risk reduction.

The Subtractive Security Top 10 framework supports a repeatable process of identifying attack paths, measuring exposure, and systematically removing or constraining these paths. This process is continuously refined to enhance security architecture.

Moreover, the project provides universal security principles applicable across various technologies, offering specific guidance for platforms such as Windows, Linux, and AWS. This adaptability is crucial as attackers often navigate between different technological layers post-compromise.

Organizations can leverage this framework to diminish risks, such as ransomware exposure, by removing unnecessary accounts and restricting internal communications, thus minimizing potential attack routes.

OWASP’s Subtractive Security Top 10 Project is publicly accessible under the Apache License 2.0, enabling security professionals to review, adapt, and contribute via its GitHub repository. This collaborative approach aims to foster a more secure digital environment.

Cyber Security News Tags:Architectural Deletion, attack paths, cyber defense, cyber risks, Cybersecurity, Information Security, infrastructure security, Network Exposure, network security, OWASP, Path Erasure Rate, risk reduction, security controls, security engineering, Subtractive Security

Post navigation

Previous Post: Key Cybersecurity Announcements at Black Hat USA 2026
Next Post: Greatness PhaaS Enhances Device Code Phishing Tactics

Related Posts

Critical Cybersecurity Threats: PayPal, Chrome, BeyondTrust Critical Cybersecurity Threats: PayPal, Chrome, BeyondTrust Cyber Security News
Hackers Use ClickFix Technique to Deploy NetSupport RAT via Compromised WordPress Sites Hackers Use ClickFix Technique to Deploy NetSupport RAT via Compromised WordPress Sites Cyber Security News
Russian Hackers Attacking Network Edge Devices in Western Critical Infrastructure Russian Hackers Attacking Network Edge Devices in Western Critical Infrastructure Cyber Security News
Cyber Conflict Intensifies Amid Iran and US-Israeli Tensions Cyber Conflict Intensifies Amid Iran and US-Israeli Tensions Cyber Security News
What is Use-After-Free Vulnerability? – Impact and Mitigation What is Use-After-Free Vulnerability? – Impact and Mitigation Cyber Security News
DuckDuckGo Rolls Out New Scam Blocker to Protect Users from Online Threats DuckDuckGo Rolls Out New Scam Blocker to Protect Users from Online Threats Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • 2026 Cybersecurity Awards: Community Choice Winners Declared
  • Enhancing AI Security with Interaction-Aware Measures
  • Greatness PhaaS Enhances Device Code Phishing Tactics
  • OWASP Unveils Subtractive Security Top 10 for Cyber Defense
  • Key Cybersecurity Announcements at Black Hat USA 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • 2026 Cybersecurity Awards: Community Choice Winners Declared
  • Enhancing AI Security with Interaction-Aware Measures
  • Greatness PhaaS Enhances Device Code Phishing Tactics
  • OWASP Unveils Subtractive Security Top 10 for Cyber Defense
  • Key Cybersecurity Announcements at Black Hat USA 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark