Abstract
Business professionals are tired of waiting for IT to address their needs. Instead, they are building their own applications with low-code / no-code platforms. Recent surveys show that most enterprise apps are now built outside of IT by business professionals who hold no previous experience in building software.
Enterprises are placing developer-level power in the hands of 100x new business developers.. What could go wrong? In short, everything.
In this presentation, we will share extensive research on the security of low-code / no-code applications based on scanning >100K applications across hundreds of enterprise environments. We will demonstrate how most applications get identity, access and data flow wrong, cover a wide range of security issues found in real environments, and share their backstories and implications.
Finally, we will share the OWASP Low-Code / No-Code Top 10, the first-ever security framework for categorization and mitigation of common security issues with business-led development. We will illustrate why the involvement of AppSec teams is desperately missing from business-led development, and share stories about organizations that got it right.
Transcript status
No transcript was published because two independent recording-derived transcription passes failed the machine publication gate. Two independent recording-derived ASR passes (mlx-community/whisper-large-v3-turbo, mlx-community/whisper-large-v3-mlx) failed the machine publication gate on 2026-08-14: deterministic checks: asr-artifact-quality. No transcript text was generated or manually filled.