Make security part of the project brief
Security requirements are easier to act on when they are captured before implementation. Identify the data the application handles, the people who can access it, the consequences of unauthorised access and the team responsible for responding to an incident.
Start with account and access controls
Use unique accounts, strong authentication and role-based permissions. Give each role only the access it needs, review administrator accounts regularly and remove access when responsibilities change. Protect state-changing requests against cross-site request forgery and rate-limit sensitive entry points such as sign-in and enquiry forms.
Treat file uploads as untrusted
Allow only file types the product genuinely needs. Check file contents and extensions, set a size limit, use generated storage names, and keep executable files out of public upload storage. Never trust a browser-provided filename or content-type header by itself.
Maintain dependencies and protect data
Track framework and library updates, remove packages that are no longer needed and store secrets outside source control. Plan encrypted backups, test restoration and define how long personal information is retained.
Verify and respond
Use code review, automated checks and authorised testing before release. Document how staff report suspicious activity and who investigates. A checklist does not guarantee security, but it creates clear, reviewable responsibilities.
