MA-SECURE-CODE-WARRIOR
24.3.2021 03:25:11 CET | Business Wire | Press release
New research from Secure Code Warrior ® , the global secure coding company, has revealed an attitudinal shift in the software development industry, with organisations bucking traditional practices for DevOps and Secure DevOps.
The global survey of professional developers and their managers found seven in 10 organisations (70%) recognise the importance of secure coding practices, with results indicating an industry-wide shift from reaction to prevention is underway.
Dr. Matias Madou, Chief Technology Officer and Co-Founder at Secure Code Warrior, said, “We are seeing a fundamental shift in mindsets across the world, as the industry slowly moves from reactive, band-aid solutions rolled out after a breach, to the proactive and human-led practice of writing quality software that is intrinsically free from vulnerabilities right from the very first keystroke. ”
“This research shows that ‘secure code’ is becoming synonymous with ‘quality code’ within software development, and security is becoming the responsibility of development teams and leaders—not just AppSec professionals, ” he said.
Secure coding seen as ‘reactive’
Reactive practices like using tools on deployed applications and manually reviewing code for vulnerabilities were the top two practices respondents associated with coding securely. However, a proactive shift in mindset was evidenced across the globe, with more than half (55%) of the developers surveyed also recognising secure coding as the active, ongoing practice of writing software protected from vulnerabilities.
Managers and developers are misaligned
Over half (55%) of managers surveyed said secure coding was practised and integrated throughout the entire development process, compared to only 43% of developers. Conversely, 36% of developers consider secure coding during development but not the design phase, as opposed to under one-third (32%) of managers.
Secure code an increasing indicator of success
While those surveyed identified ‘application performance’ and ‘functionality and features’ as the most common success metrics within software development (67% and 62% respectively), almost four in five (79%) respondents said the importance of ‘secure code’ was growing in prominence.
Application security is shifting
Almost half of respondents (46%) said development leads and teams should be responsible for application security rather than AppSec teams (24%). Over eight in 10 (81%) developers surveyed said they were accountable for any vulnerable code produced.
Developers motivated to upskill
‘Increased productivity and efficiency’, ‘curiosity’ and ‘avoiding problems caused by insecure code’ were identified as the leading intrinsic motivators to learn secure coding (20%, 14% and 11% respectively). Despite only 10% of respondents listing career advancement as a personal motivator, four in five (81%) managers were more likely to hire talent with secure coding skills.
More training is needed
91% of managers surveyed said they faced greater than average difficulty when implementing secure coding practices within their organisation, despite the overwhelming majority of respondents (97%) believing they were sufficiently trained. Perhaps, this is because almost nine in 10 (88%) developers surveyed said coding securely was challenging.
Madou added, “With OWASP’s Top 10 software vulnerabilities causing more security breaches over the past two decades than any others, now is the time for businesses to upskill developers to gain the knowledge and skills needed to stamp out insecure code and prevent issues from occurring in the first place. ”
“Code is at the heart of everyday interactions, and Secure Code Warrior is focused on championing security-skilled developers who can create amazing, safe software for our connected world .”
To gain early access to the report, ‘Shifting from reaction to prevention: The changing face of application security 2021’, register your interest at scw.buzz/earlyaccess
Methodology
Secure Code Warrior® commissioned Evans Data Corporation, the market intelligence leader within the IT industry, to conduct a global survey of developers and decision-makers actively engaged in software development. In August 2020, 400 respondents were surveyed across North America, India, the United Kingdom, Europe, Australia, New Zealand and South-East Asia.
About Secure Code Warrior
Secure Code Warrior is the developer-chosen solution for growing powerful secure coding skills. By making secure coding a positive and engaging experience for developers as they increase their software security skills, our human-led approach uncovers the secure developer inside every coder, helping development teams ship quality code faster.
Through inspiring a global community of security-conscious developers to embrace a preventative secure coding approach, our mission is to pioneer a people-first solution to security upskilling, stamping out poor coding patterns for good. Learn more at securecodewarrior.com .
View source version on businesswire.com: https://www.businesswire.com/news/home/20210323006113/en/
Link:
About Business Wire
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
M1X Global Announces Public Launch and Oversubscribed $3 Million Angel Round to Scale On-Chain Sovereign Finance26.3.2026 13:13:00 CET | Press release
M1X Global, a sovereign financial infrastructure and technology company, today announced its public launch alongside the close of an oversubscribed $3 million angel round. The funding, spanning strategic investments and grants, will support platform development and accelerate regulated institutional adoption of USDM1, the first USD-denominated, treasury collateralized sovereign debt instrument issued natively by a sovereign on public blockchain infrastructure. The $3 million in funding drew participation from leading figures across global capital markets and digital asset infrastructure, including Balaji Srinivasan, former CTO of Coinbase; Tama Churchouse, CEO of Cumberland Labs; Richard Gorelick, former Head of Market Structure at DRW; and Dan Robichaud, former CIO at Intel. Institutional participation from FJ Labs and grant funding from Stellar Development Foundation reflect strong alignment between private capital and mission-driven partners advancing blockchain-based market develop
500 Global Taps Former IFC CIO As Firm Expands Global Investment Platform26.3.2026 13:00:00 CET | Press release
Atul Mehta brings three decades of global investment leadership to board as 500 Global scales platforms aligning venture capital with national innovation and economic growth agendas. 500 Global today announced the appointment of Atul Mehta to its Board of Directors, marking an important step in the firm’s continued evolution as a global venture platform and institutional asset manager. Mehta brings more than three decades of global investment and institutional leadership experience at a time when 500 Global has observed governments, multilateral institutions, and long-term capital providers rethinking how technology-led growth is financed and scaled. He has held senior roles across private capital and development finance, including at the International Finance Corporation (IFC), where he managed multi-billion-dollar portfolios spanning technology, venture funds, infrastructure, agribusiness, healthcare, education, and financial services across emerging markets. Over his career, he has
AI Ambitions at Risk as Only 14% of Enterprises Fully Realize Cloud Value, NTT DATA Study Finds26.3.2026 13:00:00 CET | Press release
AI is increasing cloud dependency, yet investment levels are not aligned As legacy applications and data hold back innovation, modernization emerges as a top cloud priority Technology ecosystem complexity puts a spotlight on security investments and the need to focus on fundamentals NTT DATA, a global leader in AI, digital business and technology services, today released its new report, Cloud-led innovation in the era of AI: The new rules for driving value with cloud, revealing that just 14% of organizations have reached the highest level of cloud maturity despite nearly two decades of cloud adoption. Based on a global survey of more than 2,300 senior decision-makers across 33 countries, the findings highlight a paradox as cloud takes on a new and critical role as the execution layer of the AI operating model. While 99% of organizations say AI is increasing demand for cloud investment, 88% say current cloud investment levels are putting AI, cloud-native and modernization initiatives at
Visa Launches Enhanced Subscription Manager, Giving Consumers Greater Control Over Recurring Payments26.3.2026 12:00:00 CET | Press release
New value-added service brings subscription switching, cancellation, alerts, and insights into one seamless, in-app experienceAs global subscriptions approach 12 billion by 20301, consumers demand greater transparency and financial controlCollaboration with providers like Pinwheel expands the reach of Visa’s Digital Issuer Solutions, which helps issuers deliver modern digital experiences for cardholders Visa (NYSE: V), a global leader in digital payments, today unveiled an Enhanced Subscription Manager solution, a new value‑added service within its Digital Issuer Solutions business. As the number of subscriptions worldwide is projected to reach 12 billion by 2030, consumers are seeking simple, transparent ways to track and manage recurring charges. In support of this, Visa is collaborating with Pinwheel, a leading provider of in‑app bill management capabilities. Enhanced Subscription Manager helps issuers respond to consumer demand by offering a consolidated, easy-to-integrate solution
Smartstream Smart Agents Delivers 70% Reduction in Back-Office Investigation Time, Proving the Case for Autonomous Operations26.3.2026 10:30:00 CET | Press release
Smartstream, the trusted data solutions provider for leading global financial institutions and enterprises, today announces that Smart Agents - its agentic AI solution for bank back-office operations is delivering measurable, transformational impact, with pilot results showing a 70% reduction in investigation time per user, per break. As the industry accelerates toward a service as software (SaS) operating model, and allowing more work to get done from software solutions, Smartstream is embracing this approach with agentic AI. The results validate a fundamental shift in how financial institutions approach exception management. In one benchmark scenario, the manual processing of 500 exceptions, typically requiring 116 hours of team effort, was reduced to just a few hours under fully autonomous operations. This eliminates swivel-chair workflows and frees up teams to focus on risk oversight, decision making, and higher-value activities. Institutions continue to struggle with back-office w
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
