- Volume 2, Issue 1 2026
By Muhammad Shahzad Khadim
10.21621/ijec.20260201.02
Keywords: SecurityDebt;WebApplicationSecurity;OWASP2025;Vulnerability Prioritization; Penetration Testi
Web application security reports are usually ordered by technical severity but low-resourced organizations want to know which vulnerability will become the most expensive security debt to repay? This paper presents SECURE-DEBT a model used to rank the 2025 OWASP web application risks to prioritize the remediation of web applications in resource-constrained healthcare-style organizations and small to medium enterprises (SMEs)? SECURE-DEBT considers the unresolved vulnerabilities as security debt thus incurring future risk based on evidence, exposure, sensitive information, exploitability, operational impact and time considerations for a fix? The study follows an empirically-driven, framework-based conceptual research article? The scoring considers mapping to OWASP Top 10:2025‚ collecting penetration-testing evidence using manual and tool-based approaches‚ defining factor scores‚ and calculating the Security Debt Priority Score? The paper then combines severity‚ exploitability‚ evidence confidence‚ sensitivity‚ operational impact‚ exposure‚ and risk of delay‚ while subtracting ease of remediation‚ to produce the security debt score? The paper compares the security debt metric to more customary High/Medium/Low reporting and CVSS-type severity scores? The paper contributes a practical‚ transparent and auditable model to help organizations who do not have the resources to remediate all vulnerabilities immediately‚ prioritize vulnerabilities for remediation in a defensible manner? The framework could be used by penetration testers‚ developers‚ healthcare application owners‚ and SME decision makers to relate technical findings to remediation decisions‚ business continuity and technical debt.
Submission Date: 24 Apr, 2026 Reviews Completed: 2 May, 2026Acceptance Date: 15 May, 2026 Publication Date: 23 Jun, 2026
