Business Wire

MA-VERACODE

23.8.2022 14:21:12 CEST | Business Wire | Press release

Share
Financial Services Software Has Fewer Security Flaws Than Most Industries

Veracode , a leading global provider of application security testing solutions, today released data revealing that the financial services industry ranks among the best for overall flaw percentage when compared to other industries, but has one of the lowest fix rates for software security flaws. The sector also falls to the middle of the pack for high-severity flaws, with 18 percent of applications containing a serious vulnerability, suggesting financial firms should prioritize identifying and remediating the flaws that matter most.

The findings were outlined in the company’s annual State of Software Security report v12, which analyzed 20 million scans across half a million applications in the financial, technology, manufacturing, retail, healthcare and government sectors. Across the six industries, the financial sector has the second-lowest proportion of applications containing security flaws, at 73 percent. In last year’s report, the industry boasted the lowest number of software security flaws across all sectors but has been overtaken by manufacturing in this year’s study. Despite having fewer flaws overall, the financial services sector comes joint last with technology and government for the lowest proportion of flaws that are fixed.

“One of the advantages of serving the software development community for so many years is that Veracode can see changes in development practices across industries over time. We found that while financial services applications have fewer security flaws than last year, the sector lags behind other industries when it comes to fix rate. Our research showed that security training can significantly improve remediation speeds, and that companies whose development teams had completed hands-on training using real-life applications fixed flaws 35 percent faster than those without such training,” said Chris Eng, Chief Research Officer at Veracode.

Securing the Global Software Supply Chain

While there is undoubtedly still room for progress in terms of both flaw prevalence and remediation rates, when financial services organizations do fix vulnerabilities, they move at a quicker pace than most.

Eng said, “The U.S. Executive Order on Cybersecurity, alongside mandates on security controls regarding open-source usage, such as GDPR and the New York Department of Financial Services Cybersecurity Regulations, has highlighted the importance of securing the software supply chain. Being a highly regulated sector may go some way to explain the financial industry’s relative speed in addressing vulnerable libraries discovered through software composition analysis (SCA).”

Flaws in third-party libraries found through SCA tend to stick around longer for all industries, with 30 percent still unresolved after two years. When it comes to addressing open-source vulnerabilities, however, the finance sector remediates at the same pace as other industries for the first year but then quickens its pace to gain a month on the cross-industry average.

Although the finance sector outperforms most other industries in fix times for flaws discovered by dynamic, SCA, and static, the study found there is still ample room for continued improvement when looking at the number of days it takes to resolve 50 percent of flaws—116 days for dynamic analysis, 385 days for SCA, and 288 days for static analysis. With third-party components comprising as much as 90 percent* of an application’s codebase, scanning early and often using a combination of testing types reduces unplanned emergency remediation work and mitigates the risk of introducing third-party security flaws into software.

The Veracode State of Software Security v12 financial services snapshot is available to download here and a video of the findings is available to watch here .

* The Linux Foundation Statista, Joseph Perlow, “A Summary of Census II: Open Source Software Application Libraries the World Depends On”: https://www.statista.com/statistics/617136/digital-population-worldwide/ , March 7, 2022

About the State of Software Security Report

The Veracode State of Software Security (SoSS) v12 analyzed the full historical data from Veracode services and customers. This accounts for a total of more than half a million applications (592,720) that used all scan types, more than a million dynamic analysis scans (1,034,855), more than five million static analysis scans (5,137,882) and more than 18 million software composition analysis scans (18,473,203). All those scans produced 42 million raw static findings, 3.5 million raw dynamic findings, and six million raw SCA findings.

The data represents large and small companies, commercial software suppliers, software outsourcers, and open-source projects. In most analyses, an application was counted only once, even if it was submitted multiple times as vulnerabilities were remediated, and new versions uploaded.

About Veracode

Veracode is a leading AppSec partner for creating secure software, reducing the risk of security breach, and increasing security and development teams’ productivity. As a result, companies using Veracode can move their business, and the world, forward. With its combination of process automation, integrations, speed, and responsiveness, Veracode helps companies get accurate and reliable results to focus their efforts on fixing, not just finding, potential vulnerabilities. Learn more at www.veracode.com , on the Veracode blog and on Twitter .

Copyright © 2022 Veracode, Inc. All rights reserved. Veracode is a registered trademark of Veracode, Inc. in the United States and may be registered in certain other jurisdictions. All other product names, brands or logos belong to their respective holders. All other trademarks cited herein are property of their respective owners.

Link:

ClickThru

Social Media:

https://www.facebook.com/VeracodeInc/

About Business Wire

Business Wire
Business Wire
101 California Street, 20th Floor
CA 94111 San Francisco

http://businesswire.com

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Xsolla Celebrates International Women’s Day by Spotlighting Women in Games and Advancing Its Vision for Female Leadership8.3.2026 14:00:00 CET | Press release

Accelerating Representation, Influence, And Leadership For Women Across The Gaming Industry Xsolla, a global video game commerce company that helps developers launch, grow, and monetize their games, today reaffirmed its ongoing commitment to supporting women across the global gaming ecosystem through curated community initiatives, industry events, and thought leadership platforms in key growth markets, including Türkiye, Dubai, and Cyprus. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260308595758/en/ Graphic: Xsolla As the gaming industry continues to expand across emerging and high-growth markets, Xsolla is focused on empowering developers globally, including fostering a more inclusive ecosystem that gives women founders, studio leaders, publishers, and entrepreneurs greater access to visibility, networks, and opportunities. Through a series of targeted industry gatherings and community-led discussions, Xsolla has activel

Aqara Showcases Scaling Professional-Grade Infrastructure and Unified Management at Light + Building 20268.3.2026 09:00:00 CET | Press release

From system-level software to end-to-end solutions, Aqara demonstrates how intelligent spaces are designed, operated, and scaled. Aqara, a global leader and pioneer in IoT, today unveiled its cutting-edge innovations in intelligent space technology at Light + Building 2026 (Hall 9.0, Booth A50). Aqara’s demonstration offers a glimpse into a comprehensive system that offers intelligent lighting control, energy saving, and space security experience for professional usage. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260308903989/en/ Aqara Showcases Scaling Professional-Grade Infrastructure and Unified Management at Light + Building 2026 System-level Intelligent Control Aqara introduces a centralized system solution designed to streamline the management of building deployments at any scale. Moving beyond individual device control, Aqara offers a unified solution that provides architects, facility managers, and developers with

AI Meets Traditional Culture: Huangshan Captures Widespread Attention at ITB Berlin7.3.2026 10:22:00 CET | Press release

Huangshan, one of China’s most iconic scenic destinations, drew significant attention at this year’s ITB by presenting a compelling fusion of traditional Chinese culture and cutting-edge artificial intelligence under the slogan “The world of Huangshan is for the world.” This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260307909978/en/ International visitor admires Huangshan cultural and creative exhibits at the Huangshan stand during ITB Berlin. Located in eastern China’s Anhui Province, Huangshan is famed for its “Five Natural Wonders” — fantastic pines, grotesque rocks, sea of clouds, hot spring and winter snow. The mountain is widely regarded as one of China’s greatest mountain landscapes. It is also a rare natural heritage site that simultaneously holds multiple international designations, including UNESCO World Cultural and Natural Heritage status, a UNESCO Global Geopark and a World Biosphere Reserve. At ITB, the Huangsh

Incyte Announces the European Commission Approval of Zynyz® (retifanlimab) for the First-Line Treatment of Advanced Squamous Cell Carcinoma of the Anal Canal (SCAC)6.3.2026 22:42:00 CET | Press release

- Zynyz® (retifanlimab) in combination with carboplatin and paclitaxel (platinum-based chemotherapy) is the first systemic treatment for adult patients with advanced SCAC in Europe- The EC approval is based on results of the POD1UM-303 study which showed that adult patients with advanced SCAC achieved significantly improved progression-free survival with Zynyz in combination with carboplatin and paclitaxel as a first-line treatment compared to chemotherapy alone.1 Incyte (Nasdaq:INCY) today announced that the European Commission (EC) has approved Zynyz® (retifanlimab) in combination with carboplatin and paclitaxel (platinum-based chemotherapy) for the first-line treatment of adult patients with metastatic or with inoperable locally recurrent squamous cell carcinoma of the anal canal (SCAC). “The EC approval of Zynyz marks an important step forward for patients with advanced SCAC, a rare cancer for which meaningful treatment advances have not occurred in several decades,” said Bill Meur

Dfns Launches Payouts6.3.2026 21:27:00 CET | Press release

Dfns today announced the launch of Payouts, a new API enabling institutions to convert stablecoins to fiat and route payouts across multiple bank accounts while keeping wallet-level governance and controls in place. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260305327930/en/ Convert stablecoins to fiat and settle payouts to bank accounts in 94 countries, today. Solving the problem of single-rail off-ramps Today, most fintechs and institutions still hard-wire a single payout provider into their stack, or rely on vertically integrated models that bundle routing, pricing, custody, and settlement together. That approach may be convenient early on, but it creates structural problems at scale: weak price discovery because there is no competitive pressure on margins, limited auditability because routing decisions are opaque, and operational fragility because a single provider degradation in any corridor requires architectural i

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye