---
title: "Security validation should begin where attackers begin"
url: https://daily.dev/posts/security-validation-should-begin-where-attackers-begin-o7ec99usa
source_url: https://www.csoonline.com/article/4205779/security-validation-should-begin-where-attackers-begin.html
type: article
source: "CSO Online"
published: 2026-08-05T22:15:00.680Z
updated: 2026-08-06T00:00:45.343Z
tags: ["security", "webdev"]
reading_time: 4
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Security validation should begin where attackers begin

**[CSO Online](https://daily.dev/sources/csoonline)** · 4 min read · 0 upvotes · 0 comments

## Summary

Modern enterprise attacks increasingly begin at web applications — customer portals, APIs, and AI-powered services — yet most security validation is still organized by technology silos that don't reflect how attackers actually move. Attackers chain weaknesses across applications, identities, cloud resources, and infrastructure to reach business-critical systems. Security validation needs to start from the attacker's perspective, asking what can be reached from an exposed surface, and follow attack paths all the way to business impact rather than stopping at individual vulnerability detection. Horizon3.ai's NodeZero WebApp is presented as a tool that extends autonomous attack validation to authenticated web application workflows, tracing real attack paths into identity, cloud, and infrastructure.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.csoonline.com/article/4205779/security-validation-should-begin-where-attackers-begin.html>

## Similar posts on daily.dev

- [Why security validation must follow the attack path](https://daily.dev/posts/why-security-validation-must-follow-the-attack-path-pbweyapmp) · CSO Online · 0 upvotes · 0 comments
- [Why the future of security starts with who, not where](https://daily.dev/posts/why-the-future-of-security-starts-with-who-not-where-v57zzchcn) · CSO Online · 0 upvotes · 0 comments
- [How a software provider closed unknown paths to cloud compromise](https://daily.dev/posts/how-a-software-provider-closed-unknown-paths-to-cloud-compromise-dsptdwbqp) · CSO Online · 0 upvotes · 0 comments
- [Why We Shifted from Vulnerability Management to Breach Prevention at ShipStation Global](https://daily.dev/posts/why-we-shifted-from-vulnerability-management-to-breach-prevention-at-shipstation-global-ydxi70frl) · Security Boulevard · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#webdev](https://daily.dev/tags/webdev)

[View this post on daily.dev](https://daily.dev/posts/security-validation-should-begin-where-attackers-begin-o7ec99usa)
