We're a 6-person tech startup based in Dallas building logistics software. We contracted an outside software agency on a 45,000 USD budget to develop our customer portal and order tracking module. The project was delivered, our maintenance contract with the agency ended, and we took over the codebase with our two in-house developers.
We don't have a dedicated cybersecurity specialist or auditor on our team. However, before onboarding enterprise clients, we want to ensure the system is free of core security vulnerabilities. To that end, we've decided to conduct an internal source code audit using the OWASP Top 10 as our reference.
Without a dedicated security team, which specific risks should we prioritize during an OWASP Top 10 code review? Aside from running static analysis scanners, what patterns should we look for manually in the code, and at what point does hiring outside professional help become non-negotiable?