Business Wire

Secure Code Warrior Research: Critical Infrastructure Industries Making Progress on Secure-by-Design Developer Readiness

Share

New analysis collaborated on with Paladin Global Institute highlights the critical need for developer upskilling to properly measure Secure-by-Design progress

Today, Secure Code Warrior, the global, developer-driven security leader, issued new findings on developer upskilling and its impact on organizations’ Secure-by-Design (SBD) initiatives. Since April 2024, more than 200 companies, including Secure Code Warrior, have signed the Secure-by-Design pledge. The new analysis shows that organizations across critical infrastructure industries, like financial services, defense, healthcare and IT, are making progress in preparing their developers to advance their SBD initiatives. Secure Code Warrior found that these industries’ developer teams possess an average security posture - as measured by the SCW Trust Score, a global benchmark that quantifies developer teams’ security competencies - that is higher than that of other industries.

Chief information security officers (CISOs) find it increasingly difficult to prove the true ROI in the early stages of their SBD initiatives. In recent years, the absence of a benchmark to evaluate how organizations are tracking against industry standards has been a key challenge. The key to making Secure-by-Design initiatives work is not only giving developers the skills to ensure secure code, but also assuring industry and government regulators that those skills are set in place.

“Now more than ever, we have a national responsibility to ensure SBD upskilling programs are in place,” said Chris Inglis, Senior Strategic Advisor at Paladin Capital Group and former National Cyber Director. “Risk reduction is at the core of this latest analysis, and Secure Code Warrior is leading the charge to enhance developer security learning, prevent cyberattacks, and strengthen our nation’s critical infrastructure.”

Key Findings: Secure Code Warrior’s analysis of developer upskilling across critical infrastructure industries is based on insights from over 20 million data points, across 600 enterprise customers and more than 250,000 active developers around the world. The analysis found that:

  • The total number of developers currently involved in developer-centric SBD upskilling initiatives is less than 4% of all developers globally.
  • Certain critical infrastructure sectors, like the financial services industry, possessed the highest security posture, as measured by SCW TrustScore, compared to the average of non-critical infrastructures. For example, the Financial Services average Trust Score was 336.
  • Surprisingly though, even with compliance and regulation requirements, the financial services sector had a similar security posture as several other critical sectors.
  • Large-scale and smaller-scale Secure-by-Design upskilling initiatives can be successful, and research shows that smaller-scale initiatives can ramp up quickly and run faster. But for these initiatives to be successful and deliver a measurable return on investment (ROI) sooner, research shows a mandate has to be put in place.
  • When upskilling initiatives are firmly in place, risks introduced by developers in applications are considerably fewer. The analysis found that developers within large upskilling initiatives (7000+ developers in a single company) can predictably reduce vulnerabilities by 47-53%.

Secure-By-Design is gaining momentum across the globe - as countries weave in similar guidelines to their broader cybersecurity strategies. However, providing secure defaults for developers and fostering a software developer workforce that understands security will be difficult to achieve without the right data points to inform a developer skills benchmark. A program of agile upskilling can resonate with developers, when built on established baselines, with hands-on sessions that address real-world problems developers are facing.

“At a time of unprecedented global cyber threats, these new findings demonstrate the need to enhance SBD initiatives across our digital infrastructure to reduce critical vulnerabilities,” said Kemba Walden, President of the Paladin Global Institute and former acting National Cyber Director. “This research issues a clear call to action for upskilling personnel and creating benchmarks to meet critical cybersecurity goals.”

“Baselines and benchmarks can greatly optimize an organization’s security posture by making secure coding an essential part of its DNA,” said Matias Madou, co-founder and CTO, Secure Code Warrior. “To know if a SBD initiative is making real progress, you need the quantitative evidence that developer upskilling efforts are effective, and that they absorb security best practices into their work habits. You must have complete faith that developers have truly earned their license to code.”

Many security leaders persistently highlight the difficulty of scaling most elements of an enterprise security program, especially those involving continuous upskilling and assessment of individual personnel. This is a valid concern, but in the wake of several global legislation reforms and guidelines demanding that developers have verified security skills, it must be overcome. Many organizations around the world are taking action and have implemented large-scale upskilling initiatives that are making a significant impact.

To learn more about Secure Code Warrior’s latest analysis and the SCW Trust Score, click here.

About Secure Code Warrior:

Secure Code Warrior is a secure coding platform that sets the standards that keep our digital world safe. We do this by providing the world’s leading agile learning platform that delivers the most effective secure coding solution for developers to learn, apply, and retain software security principles. More than 600 enterprises trust Secure Code Warrior to implement agile learning security programs and ensure the applications they release are free of vulnerabilities.

For more information about Secure Code Warrior, visit www.securecodewarrior.com.

View source version on businesswire.com: https://www.businesswire.com/news/home/20241015434157/en/

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Xsolla Redefines the Metaverse With New Metasites Platform for Unreal Creators15.8.2025 18:00:00 CEST | Press release

Frictionless Browser-Based 3D Worlds Empower Developers and Creators To Publish, Share, And Monetize Immersive Multiplayer Experiences Instantly No Downloads, No Installs Xsolla, a global commerce company helping developers launch, grow and monetize their games, announces today the latest evolution of its Metasite™ platform, designed to meet the growing demand for immersive, accessible, and creator-driven Metaverse experiences. Reimagined for Unreal Engine creators, studios, and digital communities, Xsolla Metasite™ offers a seamless, browser-based experience that enables developers and creators to publish, share, and monetize real-time 3D worlds with built-in multiplayer, voice chat, and monetization tools all without requiring downloads, installations, or backend infrastructure. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250815735499/en/ (Graphic: Xsolla) Powered by advancements in cloud streaming and WebGL, Xsolla Met

Xsolla Unveils Cloud Gaming Trials to Convert Game Demos Into Revenue15.8.2025 15:00:00 CEST | Press release

Upgraded Cloud Gaming Solution Helps Developers Convert More Players into Payers with Instant Access, Smarter Campaigns, and Full Control Over Game Trials, No Downloads, No Installs Xsolla, a global commerce company helping developers launch, grow and monetize their games, announces today game trials as a new focus for its Cloud Gaming solution. Designed to help developers and publishers boost visibility, player acquisition, and conversion, the upgraded Cloud Gaming solution bridges the gap between marketing and monetization by enabling instant game access, real-time performance tracking, and flexible pay-to-play models. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250815871365/en/ (Graphic: Xsolla) In an increasingly competitive cloud gaming market projected to surpass $10.4 billion in global revenue by 2025, developers are seeking scalable and cost-effective ways to engage players both before and after launch. With over

Andersen Consulting udvider platformen med Alamo Consultores15.8.2025 14:56:00 CEST | Pressemeddelelse

Andersen Consulting udvider sine kompetencer inden for teknologisk transformation gennem en samarbejdsaftale med Alamo Consultores. Alamo Consultores blev stiftet i Argentina i 2012 og er et boutique-konsulentfirma, der leverer skræddersyede teknologiløsninger til kunder i Latinamerika, Nordamerika og Europa. Virksomheden tilbyder end-to-end-support gennem hele SAP-livscyklussen, herunder implementering, opgraderinger og løbende administration, til kunder inden for detailhandel, produktion, finans, logistik, energi, sundhedsplejen og bilindustrien. Alamo Consultores' serviceudbud omfatter funktionel og teknisk rådgivning, systemmigreringer, bæredygtighedsrådgivning, digital transformation og outsourcing. "Hos Alamo Consultores fokuserer vi på at gøre kompleksitet til klarhed, så vores kunder kan udvikle sig teknologisk med fleksibilitet, integritet og langsigtet vision," siger Pablo Villamil, grundlægger og administrerende direktør. "Ved at blive samarbejdspartner med Andersen Consulti

Andersen Consulting udvider sine risikostyringskapaciteter med Nisos15.8.2025 14:19:00 CEST | Pressemeddelelse

Andersen Consulting styrker sine kapaciteter via en samarbejdsaftale med Nisos, der er et amerikansk firma med speciale i human risikostyring, der leverer efterretningsbaserede løsninger til at identificere og afbøde nye trusler rettet mod mennesker, forretningsdrift og organisatorisk integritet. Nisos, der blev grundlagt i 2015, har speciale i human risikostyring og tilbyder en række tjenester, herunder efterretninger om interne trusler, digital beskyttelse af ledere, beskyttelse mod ansættelsessvindel, tredjepartsvurderinger, hændelsesbaserede undersøgelser og trusselsmonitorering. Virksomhedens løsninger er baseret på open source-efterretninger og identificerer skadelig adfærd og leverer handlingsorienteret indsigt gennem en kombination af eksklusive tjenester og deres egen platform til human risikostyring ved navn Ascend. "Nisos blev grundlagt ud fra troen på, at menneskedrevne trusler kræver skræddersyede, efterretningsbaserede løsninger," sagde CEO for Nisos, Ryan LaSalle. "Vores

SVP Worldwide Announces Global Launch of Three New PFAFF® Sewing Machines: creative expression™ 750, quilt expression™ 725, and expression™ 71515.8.2025 00:33:00 CEST | Press release

SVP Worldwide, the parent company of PFAFF®, SINGER®, and HUSQVARNA® VIKING® sewing brands, today announced the highly anticipated global launch of three new PFAFF sewing machines: the creative expression 750, quilt expression 725, and expression 715. These machines combine precision engineering, cutting-edge technology, and the timeless craftsmanship PFAFF is known for. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250814267636/en/ SVP Worldwide, the parent company of PFAFF (R), launches three new sewing machines: the creative expression 750, quilt expression 725 and expression 715. The machines combine precision engineering, cutting-edge technology, and the timeless craftsmanship PFAFF is known for globally. The new models will be available for purchase beginning August 14, 2025 on PFAFF.com and at authorized PFAFF Dealer locations across the United States and Europe. Expanded global distribution in Latin America and Asia

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye