The Low Code No Code Top 10 Gets a Reframe

▶ Watch (1:53)

The original Low Code No Code Top 10 launched three years ago to address a security gap: non-traditional developers in finance, HR, and marketing were building production applications without IT training or security knowledge. The list helped security teams recognize this audience and understand the risks they introduce. Three years in security is a long time. AI-assisted coding, vibe coding tools, and AI agents have expanded what citizen developers can build, prompting a full reframe of the project.

Who Citizen Developers Are and Why They Matter to Security

▶ Watch (4:52)

Citizen developers are non-IT, non-security subject matter experts. They work in finance, HR, and marketing. They’ve always wanted to automate their work and build internal tools that make their jobs easier. Now they can. Low code, no code, AI-assisted coding, and AI agents built on platforms like Microsoft Power Platform, Salesforce Agent Force, and Ping Identity give them the same output as professional developers. The technology has changed. The security training has not.

Risk Scenarios Over Attack Scenarios, Plus a New Number One

▶ Watch (9:33)

The refactored list retains familiar risks from the low code era but reframes them for citizen developers using any combination of tools. One specific change: risk scenarios replace attack scenarios throughout. The misconfigurations citizen developers release are risk enough without framing everything as an adversarial attack. The bigger addition is blind trust, the new number one entry. It describes a human behavioral pattern, and accepting tool output without checking it feeds into every other risk on the list.

Blind Trust and the Human Biases Behind It

▶ Watch (12:13)

Shauna Rathbun defines blind trust as moving a tool’s output straight to production without asking two questions: is it accurate, and is it secure? Three cognitive biases drive it. Automation bias causes developers to assume a machine’s output is correct. Availability heuristic steers them toward the easiest option. Anchoring bias locks them to the first solution even when flawed. The result is production applications built fast, with unverified and potentially insecure components at their core.

Three Steps to Turn Blind Trust into a Security Advantage

▶ Watch (15:11)

The Blind Trust Secure Framework gives security teams three actionable steps. First, make the default path the secure path. Enforce least privilege automatically on data connections so developers never need to think about permissions. Curate a vetted component library where approved building blocks are faster than custom code. Second, extend governance to citizen-built apps. Classify them as part of the core environment and hold them to the same policies as any other application. Third, embed security at every deployment stage, from automated scans before release to continuous monitoring in production.

Q&A

When will the updated list be publicly available? The GitHub landing page will be updated the following week, and a downloadable PDF is planned for wider distribution around the same time. ▶ 22:06

Is the project open source? Yes, fully open source and hosted on GitHub, with the explicit goal of being obnoxiously open source. ▶ 22:48

How was the risk priority order determined? The current ordering inherits from the original Low Code No Code survey and tool usage data, but the team needs fresh data from the citizen development lens, including AI-assisted coding, to re-prioritize for the next version. ▶ 23:03

How do you reach citizen developers who don’t attend security conferences? The team plans to bring the top 10 to non-security venues such as education and business conferences, targeting the audiences who actually build with these tools. ▶ 24:38

Notable Quotes

Imagine your GPS has you drive straight Shauna Rathbun · ▶ 12:13

And it’s not just technical, it’s human. Shauna Rathbun · ▶ 13:03

We naturally trust what looks easy, Shauna Rathbun · ▶ 13:06

Key Takeaways

  • The OWASP citizen developer top 10 now covers AI-assisted coding tools, not just low code no code platforms.
  • Blind trust, moving tool output to production unchecked, is the new number one risk on the list.
  • Security teams should make the secure path the default, so developers build safely without extra friction.

About the Speakers

Kayla Underkoffler is a senior security engineer in the CTO office at Zenity, focused on AI security and policy advocacy. She began her career in the United States Marine Corps before transitioning into cybersecurity, where she has worked as a practitioner in vulnerability research and engineering.

Shauna Rathbun is a platform security engineer at Ping Identity, focused on securing low-code and no-code platforms and enabling citizen development safely across organizations. Her background covers cloud security and identity, with a mission to make security more approachable for practitioners and non-practitioners alike.