Protection of websites, web apps, and web servers from unauthorized access, malicious attacks, and data breaches. It involves implementing various security measures such as encryption, firewalls. Common web security threats include cross-site scripting (XSS), SQL injection, denial-of-service (DoS) attacks, brute force attacks, and phishing attacks.