This document summarizes a presentation by Jeremiah Grossman on web application security. It discusses how the majority of data breaches are caused by hacking of servers and applications. It also provides statistics on the prevalence of vulnerabilities in websites and how long it takes organizations to fix them. The document advocates for regular security testing and prioritizing remediation to reduce risk. It analyzes why vulnerabilities often go unfixed and how organizations can better allocate their security budgets.