Training Delivery & Duration

  • Live Online / On-Site / Private Team Training
  • Theory and Hands-on Labs
  • Duration: 1 day

Secure Coding in .Net

.NET provides unprecedented flexibility and productivity to web application developers. Application developers are responsible for understanding the limitations of .NET and adopting best practices to ensure that their code is secure.

Training Delivery & Duration

  • Live Online / On-Site / Private Team Training
  • Theory and Hands-on Labs
  • Duration: 1 day

Do you have 5 or more attendees?

Contact Us about Team Training >>
bkg-decorativelines-big-white

About this course

About this course

Course Overview

.NET provides unprecedented flexibility and productivity to web application developers. Many applications allow access to critical and confidential resources and this has made them popular targets for attack. Application developers are responsible for understanding the limitations of  .NET and adopting best practices to ensure that their code is secure.

Why Take this Course?

This course aims to provide the knowledge and resources required to improve the security of Web applications developed using .NET. This course is designed to educate developers on the skills necessary to build and deploy secure .NET applications following a Secure Development Lifecycle (SDL) process.

It is recommended that participants on the Web Application Secure Coding in .Net have completed the Web Application Security Essentials course. Please see Related Training at the end of this page.

Learning Objectives

Who Should Attend this Course?

The course is designed for:

• Software Developers
• Quality Assurance professionals
• System Architects
• Information Security Professionals

Benefits

Attendee Testimonials

Course Outline

The course is aligned with the OWASP Top 10, a world-renowned reference document which describes the most critical web application security flaws.

The topics covered include:

  • General Web Application Security Concepts
  • .NET Security Features
  • Identify security risks in code (OWASP Top 10)
  • Implement Security Controls:
    • Authentication
    • Session Management
    • Access control
    • Input validation
    • Output encoding/escaping
    • Cryptography
    • Error handling and logging
    • Secrets Management
    • Cross Origin Resource Sharing (CORS)
    • Data Protection
    • HTTP security
  • Incorporate security into the development process

Format

The course combines theory and hands-on practical exercises. The participants learn to identify vulnerabilities in a purposely-developed .Net application and fix them using secure coding best practices. This provides an ideal ‘real-life’ opportunity to exploit these vulnerabilities using different open source tools and techniques in a safe environment.

What is included?

  • Course materials. Available in digital format in the Cycubix Academy eLearning tool.
  • Access to Lab platform for hands on-real life scenarios exercises.
  • Certificate of Participation (CPE Points)

Levels

Team Training with Cycubix

Team Training with Cycubix

Instructors

The minds behind the course

The minds behind the course

Fabio Cerullo

Senior Official ISC2 Authorised Instructor for CISSP, CCSP, CSSLP and SSCP

Fabio Cerullo, CISSP, CCSP, CSSLP, SSCP, is the Managing Director of Cycubix Ltd., where he leads cybersecurity consulting, compliance programs and professional training services for organisations across a wide range of industries. His work spans secure engineering, cloud security and guidance on major regulatory and certification requirements including ISO 27001, SOC2, FedRAMP, NIS2, PCI and GDPR.

He also serves as an ISC2 Senior Authorised Instructor, delivering advanced courses that help security and engineering teams build practical skills in cloud security, software security and information risk management. His cloud expertise is reinforced by his AWS Certified Solutions Architect and AWS Security Specialty certifications and hands-on experience advising organisations on secure architecture and cloud-native security practices.

He is an active contributor to the OWASP Foundation, regularly providing training, speaking at industry events and supporting community initiatives focused on modern application security. He volunteers as Google Summer of Code administrator, mentoring new students into the cybersecurity field and guiding them through their first contributions to open source security projects.

Originally from Argentina and now based in Ireland, he holds a master’s degree in computer engineering. His interests include emerging technologies, with a particular focus on AI risks and secure AI engineering. Outside of his professional work he enjoys spending time with his family, running outdoors, and actively supporting initiatives that aim to make high-quality cyber-security education accessible to a broader audience.

Show (Instructors)

The minds behind the course

The minds behind the course

Fabio Cerullo

Fabio Cerullo, CISSP, CCSP, CSSLP, SSCP, is the Managing Director of Cycubix Ltd., where he leads cybersecurity consulting, compliance programs and professional training services for organisations across a wide range of industries. His work spans secure engineering, cloud security and guidance on major regulatory and certification requirements including ISO 27001, SOC2, FedRAMP, NIS2, PCI and GDPR.

He also serves as an ISC2 Senior Authorised Instructor, delivering advanced courses that help security and engineering teams build practical skills in cloud security, software security and information risk management. His cloud expertise is reinforced by his AWS Certified Solutions Architect and AWS Security Specialty certifications and hands-on experience advising organisations on secure architecture and cloud-native security practices.

He is an active contributor to the OWASP Foundation, regularly providing training, speaking at industry events and supporting community initiatives focused on modern application security. He volunteers as Google Summer of Code administrator, mentoring new students into the cybersecurity field and guiding them through their first contributions to open source security projects.

Originally from Argentina and now based in Ireland, he holds a master’s degree in computer engineering. His interests include emerging technologies, with a particular focus on AI risks and secure AI engineering. Outside of his professional work he enjoys spending time with his family, running outdoors, and actively supporting initiatives that aim to make high-quality cyber-security education accessible to a broader audience.