Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
OWASP Unveils Subtractive Security Top 10 for Cyber Defense

OWASP Unveils Subtractive Security Top 10 for Cyber Defense

Posted on August 4, 2026 By CWS

The Open Worldwide Application Security Project (OWASP) has launched a groundbreaking initiative known as the Subtractive Security Top 10 Project. This effort is designed to enhance cybersecurity by removing potential attack paths, rather than solely relying on detection and monitoring strategies.

Revolutionizing Cyber Defense

Traditional cybersecurity measures often focus on enhancing security with additional products and tools like alerts and access controls. However, OWASP’s new project introduces a paradigm shift by asking security teams to consider what can be removed to hinder or nullify potential attacks.

The principle behind this initiative is straightforward: attackers can only exploit existing pathways. By eliminating unnecessary access points, trust relationships, and network exposures, organizations can significantly reduce the avenues available for attackers to exploit.

Subtractive Security Explained

OWASP outlines subtractive security on GitHub, emphasizing structural changes to eliminate attack vectors. These security controls are prioritized based on their efficiency in reducing the attack surface.

The first step involves architectural deletion, where attack paths are completely removed. This includes disabling legacy protocols, shutting down unused services, and revoking superfluous administrative privileges. The second step, architectural constraint, is applied when complete removal isn’t feasible, using methods like network segmentation and privilege restrictions.

Monitoring and detection are placed last in this hierarchy. While logging and alert systems remain crucial, OWASP emphasizes that detection alone cannot eliminate the paths that attackers might exploit.

Strategic Implementation and Measurement

The project introduces the Path Erasure Rate (PER) as a metric to evaluate security improvements. PER calculates the proportion of attack paths eradicated through structural changes, offering a quantitative measure of risk reduction.

The Subtractive Security Top 10 framework supports a repeatable process of identifying attack paths, measuring exposure, and systematically removing or constraining these paths. This process is continuously refined to enhance security architecture.

Moreover, the project provides universal security principles applicable across various technologies, offering specific guidance for platforms such as Windows, Linux, and AWS. This adaptability is crucial as attackers often navigate between different technological layers post-compromise.

Organizations can leverage this framework to diminish risks, such as ransomware exposure, by removing unnecessary accounts and restricting internal communications, thus minimizing potential attack routes.

OWASP’s Subtractive Security Top 10 Project is publicly accessible under the Apache License 2.0, enabling security professionals to review, adapt, and contribute via its GitHub repository. This collaborative approach aims to foster a more secure digital environment.

Cyber Security News Tags:Architectural Deletion, attack paths, cyber defense, cyber risks, Cybersecurity, Information Security, infrastructure security, Network Exposure, network security, OWASP, Path Erasure Rate, risk reduction, security controls, security engineering, Subtractive Security

Post navigation

Previous Post: Key Cybersecurity Announcements at Black Hat USA 2026

Related Posts

React Native’s Metro Server Targeted by Hackers React Native’s Metro Server Targeted by Hackers Cyber Security News
Katz Stealer Enhances Credential Theft Capabilities with System Fingerprinting and Persistence Mechanisms Katz Stealer Enhances Credential Theft Capabilities with System Fingerprinting and Persistence Mechanisms Cyber Security News
CISA Alerts on Critical Fortinet Vulnerabilities CISA Alerts on Critical Fortinet Vulnerabilities Cyber Security News
FortiOS SSL-VPN Vulnerability Let Attackers Access full SSL-VPN settings FortiOS SSL-VPN Vulnerability Let Attackers Access full SSL-VPN settings Cyber Security News
New Research Uncovers the Alliance Between Qilin, DragonForce and LockBit New Research Uncovers the Alliance Between Qilin, DragonForce and LockBit Cyber Security News
Microsoft Authenticator to Discontinue Password Support and Cease Operations by August 2025 Microsoft Authenticator to Discontinue Password Support and Cease Operations by August 2025 Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • OWASP Unveils Subtractive Security Top 10 for Cyber Defense
  • Key Cybersecurity Announcements at Black Hat USA 2026
  • DarkSword iOS Exploit Impacts 180 Websites and 27 Servers
  • CISO Insights: Russ Kirby on Passion and Leadership
  • Cyber Attacks Leverage Fake Software Updates for Remote Access

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • OWASP Unveils Subtractive Security Top 10 for Cyber Defense
  • Key Cybersecurity Announcements at Black Hat USA 2026
  • DarkSword iOS Exploit Impacts 180 Websites and 27 Servers
  • CISO Insights: Russ Kirby on Passion and Leadership
  • Cyber Attacks Leverage Fake Software Updates for Remote Access

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark