MA-VERACODE
29.5.2024 14:31:31 CEST | Business Wire | Press release
Veracode, a global leader in application risk management, today released research revealing applications developed by public sector organizations have more security debt than those created by the private sector. Security debt, defined for this report as flaws that remain unfixed for longer than a year, exists in 59 percent of applications in the public sector, compared to the overall rate of 42 percent. The research analyzed public sector organizations in more than 25 countries across the globe.
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20240529282258/en/
Figure 2: Security Debt in Public Sector Applications (Graphic: Business Wire)
“Decades of accumulated security debt in unpatched software and poor security configurations, are in the applications that serve our government,” said Chris Eng, Chief Research Officer at Veracode. “Without a systematic and continuous approach to finding and fixing security flaws, the public sector is left dangerously exposed to attacks from hackers.”
Federal government systems are increasingly under cyberattack, as malicious criminals target public sector organizations with more damaging and disruptive techniques. In response, the federal government is enforcing a flurry of initiatives to strengthen cybersecurity, including efforts to reduce risk in the applications that serve the government. In March of 2024, the Cybersecurity and Infrastructure Security Agency (CISA) and the Office of Management and Budget (OMB) released the Secure Software Development Attestation Form to hold providers to the federal government accountable for insecure software.
Veracode researchers found that while slightly fewer public sector organizations (68 percent) have security debt than other industries (71 percent), they tend to accumulate more of it. Only three percent of applications are flaw-free, compared to six percent across other industries. Even more concerning, 40 percent of public sector entities have persistent, high-severity flaws that constitute ‘critical’ security debt, which would put the confidentiality, integrity, and availability of businesses at serious risk if exploited.
“The good news is that most organizations have the capacity to remediate all critical debt, but risk prioritization is key,” said Eng. “Two-thirds of all flaws in public sector organizations are either less than one year old or are not critical in severity. In addition, less than one percent of all flaws constitute critical security debt. By prioritizing that security debt with focused effort, organizations can achieve maximum risk reduction and then move to address non-critical flaws based on their risk tolerance and capabilities.”
According to the report, security debt in the public sector primarily affects first-party code (93 percent), but most of the critical security debt comes from third-party dependencies (55.5 percent). This reinforces the importance of the Open Source Security Software Initiative (OS3I), an inter-agency working group focused on ensuring open-source software is “as safe, secure and sustainable as it is open.” It also emphasizes the need for organizations to focus on both first- and third-party code to effectively reduce security debt.
The analysis further shows security debt in the public sector is primarily concentrated in older, larger applications (22 percent). This is especially true for critical security debt (30 percent), confirming a correlation between application age and the accumulation of security debt. Researchers also compared the security debt profile for different development languages and found that Java and .NET applications stand out as significant sources of debt in the public sector.
“The current state of software security in the public sector reinforces the importance of making secure by design a standard approach for the whole network connected world,” closed Eng. “We applaud CISA’s recent announcement of its Secure by Design Pledge and are proud to be one of the inaugural signatories. Our goal with this research is to further support our government and industry partners in promoting widespread adoption of these principles.”
The full State of Software Security Public Sector 2024 report is available to download on the Veracode website.
About the State of Software Security Report
The Veracode State of Software Security 2024 report analyzed data from large and small companies, commercial software suppliers, software outsourcers, and open-source projects. The research draws from more than a million (1,007,133) applications across all scan types, 1,553,022 dynamic analysis scans, and 11,429,365 static analysis scans. All those scans produced 96 million raw static findings, 4 million raw dynamic findings, and 12.2 million raw software composition analysis findings.
About Veracode
Veracode is a global leader in Application Risk Management for the AI era. Powered by trillions of lines of code scans and a proprietary AI-assisted remediation engine, the Veracode platform is trusted by organizations worldwide to build and maintain secure software from code creation to cloud deployment. Thousands of the world’s leading development and security teams use Veracode every second of every day to get accurate, actionable visibility of exploitable risk, achieve real-time vulnerability remediation, and reduce their security debt at scale. Veracode is a multi-award-winning company offering capabilities to secure the entire software development life cycle, including Veracode Fix, Static Analysis, Dynamic Analysis, Software Composition Analysis, Container Security, Application Security Posture Management, and Penetration Testing.
Learn more at www.veracode.com, on the Veracode blog, and on LinkedIn and X.
Copyright © 2024 Veracode, Inc. All rights reserved. Veracode is a registered trademark of Veracode, Inc. in the United States and may be registered in certain other jurisdictions. All other product names, brands or logos belong to their respective holders. All other trademarks cited herein are property of their respective owners.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20240529282258/en/
About Business Wire
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
SES Announces Extraordinary General Meeting of Shareholders15.5.2026 08:30:00 CEST | Press release
SES: Société Anonyme RCS Luxembourg B 81267 Notice is hereby given of the Extraordinary General Meeting of SES, Société Anonyme, to be held at the Company's registered office at Château de Betzdorf, L-6815 Betzdorf (the "Company"), Luxembourg, on Wednesday 17 June 2026 at 3:00 p.m. CET AGENDA Attendance list, quorum and adoption of the agenda Nomination of a secretary and of two scrutineers Cancellation of shares purchased in connection with the buy-back programme of 2 November 2023, as amended on 2 May 2024, in accordance therewith and pursuant thereto - Reduction of the share capital in accordance with article 450-5 of the law of 10 August 1915 on commercial companies, as amended, by forty-four million nine hundred ten thousand seven hundred eighty euro (EUR 44,910,780) through the cancellation of thirty-five million nine hundred and twenty-eight thousand six hundred and twenty-four (35,928,624) shares divided into (i) twenty-three million nine hundred and fifty-two thousand four hun
Experian Partners With ServiceNow to Scale Trusted Decisioning to Agentic AI15.5.2026 08:00:00 CEST | Press release
New global long‑term partnership embeds Experian’s Ascend capabilities directly into ServiceNow workflows, transforming client operations Experian, the global data and technology company, and ServiceNow (NYSE: NOW), the AI control tower for business reinvention, today unveil a new global multi-year partnership which harnesses the power of autonomous AI agents across platforms, helping businesses make faster and smarter decisions at scale. Through this partnership, autonomous AI agents can gain the ability to act faster, and more consistently, starting with employee onboarding, third-party risk management and model life cycle governance use cases. A major challenge for global organisations adopting agentic AI is achieving scale, with deployments often constrained by a lack of trusted data. In fact, industry research shows that data limitations are the primary barrier for eight in ten organisations. By connecting trusted intelligence directly into enterprise workflows, this partnership e
Meiji Seika Pharma: Positive Results from the Phase III Integral-1 Trial of Nacubactam, a Novel β-Lactamase Inhibitor, in Complicated Urinary Tract Infections or Acute Uncomplicated Pyelonephritis ― Published in The Lancet15.5.2026 03:00:00 CEST | Press release
Meiji Seika Pharma Co., Ltd. (headquartered in Tokyo; President and Representative Director: Toshiaki Nagasato) today announced that the results of the Integral-1 study, one of two global Phase III clinical trials evaluating the efficacy and safety of its novel β-lactamase inhibitor nacubactam (development code: OP0595), have been published in The Lancet. The article is entitled “---Efficacy and safety of cefepime–nacubactam and aztreonam–nacubactam compared with imipenem–cilastatin for complicated urinary tract infection or acute uncomplicated pyelonephritis (Integral-1): a double-blind, randomised phase 3 trial” (https://www.thelancet.com/journals/lancet/article/PIIS0140-6736(26)00596-9/fulltext) Integral-1 is a global, double-blind, randomized Phase III trial (jRCT2031230075) in patients with complicated urinary tract infection or acute uncomplicated pyelonephritis that compared the efficacy and safety of nacubactam co-administered with either cefepime or aztreonam versus imipenem-c
Boomi Teams up With Gong to Bring Revenue AI to Boomi Agentstudio14.5.2026 18:00:00 CEST | Press release
Gong's revenue AI is now natively available in the Boomi Enterprise Platform Boomi, the data activation company for AI, today announced a collaboration withGong, the leader in Revenue AI, to bring revenue signals captured in Gong natively into the Boomi Enterprise Platform. This collaboration enables enterprises to establish an active data foundation designed to transform customer conversations into coordinated, automated actions across systems and functions enterprise-wide with Boomi Agentstudio. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260514443012/en/ Boomi Teams Up with Gong to Bring Revenue AI to Boomi Agentstudio Gong goes beyond capturing deal activity to surface real-time insights into risk, buyer intent, competitive dynamics, and key engagement signals. That intelligence moves from conversation to coordinated action, flowing across CRM, ERP, product, and operational systems with the governance and security tha
Xsolla and Skich Announce Strategic Partnership to Bring Merchant of Record Payments to an Alternative Mobile Game Marketplace14.5.2026 18:00:00 CEST | Press release
Partnership Enables Developers To Monetize Games On The Skich Store With Xsolla Handling Payments, Tax Compliance, And Commerce Infrastructure Xsolla, a leading global video game commerce company, today announced a strategic partnership with Skich, an alternative mobile game marketplace operating on iOS in the EU under Apple's Digital Markets Act provisions and on Android globally. Under the agreement, Xsolla will serve as Merchant of Record for in-app purchases and paid game sales distributed through the Skich Store. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260514867730/en/ Graphic: Xsolla Skich serves as an alternative to traditional mobile storefronts, offering developers a way to reach players outside platform-controlled distribution channels. The partnership with Xsolla enables Skich to offer a fully compliant payment and commerce layer, with Xsolla managing payment processing, tax collection, refunds, and regulat
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
