• Why bolted-on solutions are not long-term answers to web application security • Arguments in favour of a built-in approach to web application security • From theory to practice: Security in the development process and design • Using OWASP resources such as the Development Guide and ESAPI