MA-SECURE-CODE-WARRIOR
24.3.2021 03:25:11 CET | Business Wire | Press release
New research from Secure Code Warrior ® , the global secure coding company, has revealed an attitudinal shift in the software development industry, with organisations bucking traditional practices for DevOps and Secure DevOps.
The global survey of professional developers and their managers found seven in 10 organisations (70%) recognise the importance of secure coding practices, with results indicating an industry-wide shift from reaction to prevention is underway.
Dr. Matias Madou, Chief Technology Officer and Co-Founder at Secure Code Warrior, said, “We are seeing a fundamental shift in mindsets across the world, as the industry slowly moves from reactive, band-aid solutions rolled out after a breach, to the proactive and human-led practice of writing quality software that is intrinsically free from vulnerabilities right from the very first keystroke. ”
“This research shows that ‘secure code’ is becoming synonymous with ‘quality code’ within software development, and security is becoming the responsibility of development teams and leaders—not just AppSec professionals, ” he said.
Secure coding seen as ‘reactive’
Reactive practices like using tools on deployed applications and manually reviewing code for vulnerabilities were the top two practices respondents associated with coding securely. However, a proactive shift in mindset was evidenced across the globe, with more than half (55%) of the developers surveyed also recognising secure coding as the active, ongoing practice of writing software protected from vulnerabilities.
Managers and developers are misaligned
Over half (55%) of managers surveyed said secure coding was practised and integrated throughout the entire development process, compared to only 43% of developers. Conversely, 36% of developers consider secure coding during development but not the design phase, as opposed to under one-third (32%) of managers.
Secure code an increasing indicator of success
While those surveyed identified ‘application performance’ and ‘functionality and features’ as the most common success metrics within software development (67% and 62% respectively), almost four in five (79%) respondents said the importance of ‘secure code’ was growing in prominence.
Application security is shifting
Almost half of respondents (46%) said development leads and teams should be responsible for application security rather than AppSec teams (24%). Over eight in 10 (81%) developers surveyed said they were accountable for any vulnerable code produced.
Developers motivated to upskill
‘Increased productivity and efficiency’, ‘curiosity’ and ‘avoiding problems caused by insecure code’ were identified as the leading intrinsic motivators to learn secure coding (20%, 14% and 11% respectively). Despite only 10% of respondents listing career advancement as a personal motivator, four in five (81%) managers were more likely to hire talent with secure coding skills.
More training is needed
91% of managers surveyed said they faced greater than average difficulty when implementing secure coding practices within their organisation, despite the overwhelming majority of respondents (97%) believing they were sufficiently trained. Perhaps, this is because almost nine in 10 (88%) developers surveyed said coding securely was challenging.
Madou added, “With OWASP’s Top 10 software vulnerabilities causing more security breaches over the past two decades than any others, now is the time for businesses to upskill developers to gain the knowledge and skills needed to stamp out insecure code and prevent issues from occurring in the first place. ”
“Code is at the heart of everyday interactions, and Secure Code Warrior is focused on championing security-skilled developers who can create amazing, safe software for our connected world .”
To gain early access to the report, ‘Shifting from reaction to prevention: The changing face of application security 2021’, register your interest at scw.buzz/earlyaccess
Methodology
Secure Code Warrior® commissioned Evans Data Corporation, the market intelligence leader within the IT industry, to conduct a global survey of developers and decision-makers actively engaged in software development. In August 2020, 400 respondents were surveyed across North America, India, the United Kingdom, Europe, Australia, New Zealand and South-East Asia.
About Secure Code Warrior
Secure Code Warrior is the developer-chosen solution for growing powerful secure coding skills. By making secure coding a positive and engaging experience for developers as they increase their software security skills, our human-led approach uncovers the secure developer inside every coder, helping development teams ship quality code faster.
Through inspiring a global community of security-conscious developers to embrace a preventative secure coding approach, our mission is to pioneer a people-first solution to security upskilling, stamping out poor coding patterns for good. Learn more at securecodewarrior.com .
View source version on businesswire.com: https://www.businesswire.com/news/home/20210323006113/en/
Link:
About Business Wire
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Hytera Debuts SC700 Smart 4G Body Camera at CCW 202630.6.2026 11:30:00 CEST | Press release
Hytera, a leading global provider of critical communications technologies and solutions, officially debuted its SC700 Smart 4G Body Camera at Critical Communications World (CCW) 2026. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260630283236/en/ Hytera's latest SC700 Smart 4G Body Camera Public safety operations are increasingly moving toward real-time, connected workflows, where communication, video, and situational awareness are integrated to support a faster and more coordinated response in the field. The SC700 is designed to support this shift. It enables live video, location sharing and push-to-talk communication, helping connect frontline officers with control rooms. Integrated with Hytera HyTalk PoC System, it also supports communication across broadband and PMR users to improve coordination across teams. It also features Intelligent Scene Aware, which can detect abnormal situations such as man down, inactivity, or
Global Database Launches Regis, an AI Assistant for Live Company Registry Data30.6.2026 11:13:00 CEST | Press release
Regis gives business users a ChatGPT-like experience for company research, compliance checks, ownership discovery, financial analysis, and prospect list building — powered by live data from official government registries Global Database today announced the launch of Regis, a new AI assistant designed to answer business questions using live company data from official government registries. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260630229011/en/ Unlike general-purpose AI tools that rely on training data or open web sources, Regis is connected to Global Database’s structured company intelligence platform, covering more than 600 million company profiles, sourced from over 400 government registries across more than 200 countries. For more than a decade, Global Database has been collecting, structuring, and maintaining company data directly from government registries around the world. With the launch of Regis, the company
Kraken Goes Live on Trever to Bring Full-Service Prime Brokerage to European Financial Institutions30.6.2026 10:30:00 CEST | Press release
European banks, brokers and other licensed financial institutions using Trever can now access Kraken Prime’s institutional crypto trading and qualified custody Kraken Prime, the full-service prime brokerage offering trading, qualified custody and other financial services through an integrated platform, is now available through Trever, the operating standard in digital asset banking. Trever’s Digital Asset Operating System is used by financial institutions across Europe to manage the full digital asset lifecycle within a single environment – including trading, treasury, settlement and bookkeeping. From today, banks and brokers using Trever can route execution, settle into qualified custody, record all transactions and access other services through Kraken Prime without leaving their existing operational environment. The integration extends Trever’s connectivity, bringing a prime brokerage relationship into the existing workflows institutional teams use across their digital asset operatio
Microsoft Takes Sisvel Wi-Fi Multimode Patent Pool Licence30.6.2026 10:17:00 CEST | Press release
Microsoft has become a licensee of the Sisvel Wi-Fi Multimode pool. The US computer and software giant is the latest in a string of major companies to take a licence to the standard essential patents offered through the programme. In doing so, it joins ASUS, Hewlett Packard Enterprise and Sony Group Corporation, as well as Huawei, Panasonic, Philips and ZTE which are also pool licensors alongside KPN, Mitsubishi Electric, Orange, Aegis 11 (a Sisvel affiliate), SK Telecom and Wilus. The Sisvel Wi-Fi Multimode pool covers both Wi-Fi 6 and Wi-Fi 7 and offers an efficient way to access essential Wi-Fi rights for years to come. It was publicly launched in January 2026 as the successor to the Sisvel Wi-Fi 6 patent pool. Over a three-year period under that programme, agreements were closed with 40 companies, including Acer, Netgear, Cisco and HP. “It is a pleasure to welcome Microsoft as a licensee of the Sisvel Wi-Fi Multimode pool,” says Alex Debski, Director of Licensing and Counsel Legal
STOKR Secures CASP and PI Licences in Luxembourg Ahead of MiCAR Deadline30.6.2026 10:00:00 CEST | Press release
Authorised by the CSSF just before the 1 July 2026 enforcement deadline, STOKR joins a small group of crypto-asset firms cleared to operate across the EU under a single, harmonised regime. STOKR, the Luxembourg-based digital securities platform, has received authorisation from the Commission de Surveillance du Secteur Financier (CSSF) under the EU's Markets in Crypto-Assets Regulation (MiCAR) and the Law of 10 November 2009 on payment services, securing its Crypto-Asset Service Provider (CASP) and Payment Institution (PI) licences just over a week before MiCAR's 1 July 2026 enforcement deadline. Digital securities fall outside MiCAR's scope but the payment leg does not. To receive, hold, and transfer crypto assets and stablecoins on behalf of clients during subscription and redemption, a platform requires a CASP licence under MiCAR and a PI. Without both, a platform can issue digital securities but cannot move the capital. With MiCAR's transitional period ending on 30 June 2026, a sign
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
