RESOLV

Train · Resolv Academy

Secure development

Practical training for developers on writing, reviewing and testing code that withstands real attacks and passes security review.

The challenge

Most vulnerabilities found in penetration tests were written by developers who were never taught how the attack works. Fixing them late is slow and costly.

Annual awareness videos do not change how code is written. Developers need to see their own language and framework exploited, and to practise the fix.

Our programme teaches secure design and coding through attack-and-fix labs, so developers recognise weaknesses as they write and review code.

Our method

How the work is done.

  1. 01

    Threat modelling

    Participants learn to identify assets, trust boundaries and threats in a design before code is written.

  2. 02

    Attack-and-fix labs

    Each vulnerability class from the OWASP Top 10 is exploited in a deliberately vulnerable application, then fixed and verified by the participant.

  3. 03

    Secure review

    Code review exercises using OWASP ASVS as the checklist, including authentication, session management and access control.

  4. 04

    Pipeline security

    Static analysis, dependency scanning and secrets detection integrated into a CI pipeline, with triage of the results.

  5. 05

    Assessment

    A practical exercise in which participants find and fix vulnerabilities in an unfamiliar codebase.

Deliverables

What you receive.

  • Instructor-led sessions tailored to your languages and frameworks
  • Vulnerable application labs for hands-on exploitation and repair
  • Secure coding checklist based on OWASP ASVS
  • Threat model template and worked examples
  • Practical assessment results per participant
  • Recommendations for pipeline security controls
  • Certificate of completion

Engagement options

Ways to buy it.

  1. 01

    Open cohort

    Scheduled programme for individual developers.

    6 weeks, part-time
  2. 02

    Private team course

    Delivered to a development team using its own stack and examples.

    3 to 6 weeks
  3. 03

    Findings-led workshop

    A short workshop built around the vulnerability classes found in your recent penetration tests.

    1 to 3 days

Standards

Frameworks we work to.

  • OWASP Top 10
  • OWASP ASVS
  • OWASP SAMM
  • NIST SSDF

Questions

What buyers ask us.

Which programming languages do you cover?

Open cohorts use common web stacks. Private courses are adapted to the languages and frameworks your team uses.

Can training be linked to our penetration test results?

Yes. A findings-led workshop uses the classes of issue identified in your tests, without exposing sensitive detail to the wider team.

Is this only for web developers?

Web and API development is the core, with optional modules for mobile applications.

Does it cover the build pipeline?

Yes. A module covers integrating and triaging automated security testing in CI/CD.

Discuss secure development.

A senior engineer reviews every enquiry and replies within one business day.