

About us
We are the Manchester, UK chapter of OWASP
We're looking at putting on exciting events that range all across the security space - from soft skills & ways of working to innovative white papers - all coming from the people & companies based in and around Manchester
Are you passionate about a security topic?
Do you want to speak at a future event?
Submit your interest here - https://forms.gle/zcm9bVNhgDixe8Gq5
Does your company want to sponsor a venue and/or refreshments for a future event?
Email Paul - paul.johnston@owasp.org
---------------------------
The Open Worldwide Application Security Project (OWASP®) is a 501(c)(3) worldwide not-for-profit charitable organization focused on improving the security of software. Our mission is to make software security visible so that individuals and organizations can make informed decisions. OWASP is uniquely positioned to provide impartial, practical information about AppSec to individuals, corporations, universities, government agencies, and other organizations worldwide. Operating as a community of like-minded professionals, OWASP issues software tools and knowledge-based documentation on application security.
Upcoming events
1

Securing the Business Logic
Booking.com Manchester, The Goods Yard Building, 6 Goods Yard Street, Manchester, M3 3BG,, Manchester, GBThis September, OWASP Manchester welcomes you to the Booking Office where we will hear two talks about agentic security. Looking at it from the different aspects of pre-release and post-release.
-------------------------
Due to a corporate policy from the venue sponsor, to get into the venue & up to the event, you will need to register with your full name when signing up to the event AND show photo ID when checking in to the event on the night.
As we're still dealing with a large number of no-shows, if you don't attend without releasing your ticket, we may remove you from future events.Agenda:
-------------------------
6:00 - Open doors & networking & drinks
6:15 - Introduction
6:30 - Thomas Balin - No Human Required: Automating the Un-Automatable Vulnerability
7:15 - Refreshments (Food & Drinks & Networking)
8:00 - Cyril Noel-Tagoe - TMapping Business Logic Abuse: The OWASP BLADE Framework and Its Kill Chains
9:00 - Vacate venue -> to the pub for more socialisingLOCATION
-------------------------
Booking.com
6 Goods Yard Street Manchester
M3 3BGSPEAKERS
-------------------------
Thomas Ballin
Thomas Ballin is co-founder and Director of Cytix, a Manchester company that understands the tickets, pull requests and releases moving through a business to identify which changes have introduced risk, and provides the decision layer to validate them. He has spent the past 12+ years across penetration testing, security consulting, and product engineering, giving him a broad view of how organisations build software and where that leaves them exposed.
No Human Required: Automating the Un-Automatable Vulnerability
Business logic flaws have long been the vulnerability class that automation couldn't touch. SAST and DAST reliably miss them, there's no dangerous function to flag and no malformed input to catch, only legitimate features being used in unintended sequence. Finding and exploiting them meant a skilled human reasoning about how an application was meant to behave.Agentic AI can now perform exactly the kind of contextual, multi-step reasoning that business logic exploitation demands, and it can do so cheaply, at scale, and without the specialist on staff. We'll look at what this class of vulnerability is and why traditional tooling fails on it, how the economics of finding them have collapsed over the past two years, and how easily someone with a laptop, an AI subscription and half an hour can now exploit them with little knowledge or skill, and what that democratisation means for how we defend against it.
Cyril Noel-Tagoe
Cyril is a Principal Threat Researcher within Netacea’s Threat Intel Centre. In this role, he is responsible for providing intelligence on malicious automated cyber threat activity and the tools and actors behind it. His work helps protect the websites and APIs of some of the world's biggest retail, streaming, media and telecoms companies. He is a core contributor of the OWASP BLADE framework and has been quoted as a featured expert on automated attacks and cyber fraud in articles from mainstream media outlets such as the BBC, CNBC, USA Today and Forbes.Cyril has over ten years' experience in the cyber security industry. He comes from a security consulting background. Prior to joining Netacea, he helped financial services organisations on transformation journeys in domains such as security operations and data privacy. He has also led ISO 27001 audits and performed third party assurance work across a wide range of industries.
Mapping Business Logic Abuse: The OWASP BLADE Framework and Its Kill Chains
Traditional attack frameworks like MITRE ATT&CK and the Lockheed Martin Kill Chain were built to model attacks against technical weaknesses. They describe business logic abuse poorly, yet automated attacks that exploit the intended function of a website or API are now among the most common threats online enterprises face. The OWASP BLADE Framework closes that gap. It is an open-source knowledge base that captures the phases, tactics, and techniques adversaries use to abuse business logic, organised into a matrix and a set of comprehensive kill chains modelled on real attacks.This talk covers why BLADE exists, how the matrix is structured, and how defenders put it to work. Real-world threat intelligence walks through complete kill chains, from early reconnaissance to the abuse itself, showing how individual techniques combine into the attacks security teams actually see day to day.
SPONSORS (Thank you for supporting our community!!)
-------------------------
Booking.com - Venue Sponsor AND Food & Drink Sponsor
-------------------------80 attendees
Past events
14