If you were tasked to conduct a security audit on a server/database-backed web app, where would you start?


Focus on the human element of the organisation structure plus try to grab the laptop of the middle manager to see you are able to gain access to it

