Has anyone here used and can recommend a security consultant?
Unlike most sites I write, I will be developing one that will almost certainly be targeted by hackers and need an outside party to test it before it goes live.
At what point in the development process should a consultant be involved? Only at the end?
What do they check for? XSS, CSRF, SQL injection, server configuration? (The site will be written in ASP.NET MVC 3)
I imagine they don't come cheap.
Unlike most sites I write, I will be developing one that will almost certainly be targeted by hackers and need an outside party to test it before it goes live.
At what point in the development process should a consultant be involved? Only at the end?
What do they check for? XSS, CSRF, SQL injection, server configuration? (The site will be written in ASP.NET MVC 3)
I imagine they don't come cheap.