Business Wire

MA-VERACODE

Share
Financial Services Software Has Fewer Security Flaws Than Most Industries

Veracode , a leading global provider of application security testing solutions, today released data revealing that the financial services industry ranks among the best for overall flaw percentage when compared to other industries, but has one of the lowest fix rates for software security flaws. The sector also falls to the middle of the pack for high-severity flaws, with 18 percent of applications containing a serious vulnerability, suggesting financial firms should prioritize identifying and remediating the flaws that matter most.

The findings were outlined in the company’s annual State of Software Security report v12, which analyzed 20 million scans across half a million applications in the financial, technology, manufacturing, retail, healthcare and government sectors. Across the six industries, the financial sector has the second-lowest proportion of applications containing security flaws, at 73 percent. In last year’s report, the industry boasted the lowest number of software security flaws across all sectors but has been overtaken by manufacturing in this year’s study. Despite having fewer flaws overall, the financial services sector comes joint last with technology and government for the lowest proportion of flaws that are fixed.

“One of the advantages of serving the software development community for so many years is that Veracode can see changes in development practices across industries over time. We found that while financial services applications have fewer security flaws than last year, the sector lags behind other industries when it comes to fix rate. Our research showed that security training can significantly improve remediation speeds, and that companies whose development teams had completed hands-on training using real-life applications fixed flaws 35 percent faster than those without such training,” said Chris Eng, Chief Research Officer at Veracode.

Securing the Global Software Supply Chain

While there is undoubtedly still room for progress in terms of both flaw prevalence and remediation rates, when financial services organizations do fix vulnerabilities, they move at a quicker pace than most.

Eng said, “The U.S. Executive Order on Cybersecurity, alongside mandates on security controls regarding open-source usage, such as GDPR and the New York Department of Financial Services Cybersecurity Regulations, has highlighted the importance of securing the software supply chain. Being a highly regulated sector may go some way to explain the financial industry’s relative speed in addressing vulnerable libraries discovered through software composition analysis (SCA).”

Flaws in third-party libraries found through SCA tend to stick around longer for all industries, with 30 percent still unresolved after two years. When it comes to addressing open-source vulnerabilities, however, the finance sector remediates at the same pace as other industries for the first year but then quickens its pace to gain a month on the cross-industry average.

Although the finance sector outperforms most other industries in fix times for flaws discovered by dynamic, SCA, and static, the study found there is still ample room for continued improvement when looking at the number of days it takes to resolve 50 percent of flaws—116 days for dynamic analysis, 385 days for SCA, and 288 days for static analysis. With third-party components comprising as much as 90 percent* of an application’s codebase, scanning early and often using a combination of testing types reduces unplanned emergency remediation work and mitigates the risk of introducing third-party security flaws into software.

The Veracode State of Software Security v12 financial services snapshot is available to download here and a video of the findings is available to watch here .

* The Linux Foundation Statista, Joseph Perlow, “A Summary of Census II: Open Source Software Application Libraries the World Depends On”: https://www.statista.com/statistics/617136/digital-population-worldwide/ , March 7, 2022

About the State of Software Security Report

The Veracode State of Software Security (SoSS) v12 analyzed the full historical data from Veracode services and customers. This accounts for a total of more than half a million applications (592,720) that used all scan types, more than a million dynamic analysis scans (1,034,855), more than five million static analysis scans (5,137,882) and more than 18 million software composition analysis scans (18,473,203). All those scans produced 42 million raw static findings, 3.5 million raw dynamic findings, and six million raw SCA findings.

The data represents large and small companies, commercial software suppliers, software outsourcers, and open-source projects. In most analyses, an application was counted only once, even if it was submitted multiple times as vulnerabilities were remediated, and new versions uploaded.

About Veracode

Veracode is a leading AppSec partner for creating secure software, reducing the risk of security breach, and increasing security and development teams’ productivity. As a result, companies using Veracode can move their business, and the world, forward. With its combination of process automation, integrations, speed, and responsiveness, Veracode helps companies get accurate and reliable results to focus their efforts on fixing, not just finding, potential vulnerabilities. Learn more at www.veracode.com , on the Veracode blog and on Twitter .

Copyright © 2022 Veracode, Inc. All rights reserved. Veracode is a registered trademark of Veracode, Inc. in the United States and may be registered in certain other jurisdictions. All other product names, brands or logos belong to their respective holders. All other trademarks cited herein are property of their respective owners.

Link:

ClickThru

Social Media:

https://www.facebook.com/VeracodeInc/

About Business Wire

Business Wire
Business Wire
101 California Street, 20th Floor
CA 94111 San Francisco

http://businesswire.com

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Andersen Global styrker sine vurderingskapaciteter i Asien og Stillehavsområdet med ETC11.12.2025 12:29:00 CET | Pressemeddelelse

Andersen Global fortsætter med at udvide sin tilstedeværelse i Asien og Stillehavsområdet gennem en samarbejdsaftale med Edmund Tie & Company (ETC), et full-service ejendomsrådgivningsfirma med hovedsæde i Singapore. ETC blev stiftet i 1995 og leverer vurderings- og rådgivningsydelser på tværs af ejendommens livscyklus, herunder lovpligtig og selskabsrelateret vurdering, investeringsrådgivning, feasibility-analyser og rådgivning om ejendomsskat. Med aktiviteter i Singapore, Malaysia og Thailand kombinerer ETC dybdegående regional viden med internationale standarder for at støtte udviklere, investorer, private og statslige fonde, selskaber, REIT'er samt ejere og lejere. Firmaet er kendt for sin forskningsbaserede tilgang og integrerede servicemodel og hjælper kunder med at navigere i komplekse lovgivninger og optimere værdien af deres aktiver. "Vores styrke ligger ikke kun i den tekniske udførelse, men i at hjælpe kunder med at se det fulde billede – at forbinde markedssignaler, lovgivn

AB InBev and International Cricket Council Announce Landmark Global Partnership11.12.2025 10:31:00 CET | Press release

World’s Leading Brewer becomes the Official Beer Partner of the ICC The International Cricket Council (ICC) announced AB InBev (Euronext: ABI) (NYSE: BUD) (MEXBOL: ANB) (JSE: ANH), the world’s leading brewer, will become the Official Beer Partner for all major ICC tournaments starting in 2026. The partnership will be led by Budweiser 0.0, Budweiser’s no-alcohol beer in India, with other ABI mega brands activating in Europe and Africa. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251211250826/en/ AB InBev and ICC announce global partnership From attending a match live in-stadium to watching one at a bar or pub with friends, with a lower alcohol-by-volume (ABV) and no-alcohol options like Budweiser 0.0, beer is the natural choice to enjoy responsibly. Through this partnership with the ICC, AB InBev will create more moments of cheers, choice and celebration for cricket fans of legal drinking age all over the world. ICC CEO, S

Spark Reply and Concept Reply Promote CO₂-optimised Charging Together With BMW11.12.2025 10:30:00 CET | Press release

Spark Reply, specialists in design and user experience, and Concept Reply, IoT and AI technology experts within the Reply Group, have developed a smart app for the BMW group as part of a research project that actively encourages electric vehicle drivers to adopt low-carbon charging habits. The “COOL” feature within the BMW Prototyping App “360° Mobility” analyses the current electricity mix and shows users in real time when it is at its cleanest. Playful interactions and personalised AI-generated images further motivate drivers to make more sustainable choices. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251211155452/en/ In a post pilot survey, 73 per cent of participants stated that they were willing to make an extra effort to charge with reduced CO₂ emissions, such as by setting a charging window in their app. This proves that 'COOL' can measurably reduce the carbon footprint of everyday electric driving. Electric mobil

Thales Launches AI Security Fabric, Providing AI Runtime Security for Agentic AI and LLM-Powered Applications11.12.2025 09:00:00 CET | Press release

Thales launches its new AI Security Fabric, delivering the first runtime security capabilities designed to protect Agentic AI, LLM-powered applications, enterprise data, and identities.New capabilities address emerging AI-specific threats—including prompt injection, data leakage, model manipulation, and insecure RAG pipelines—helping organizations innovate safely while maintaining compliance.With upcoming 2026 enhancements, Thales aims to provide a comprehensive security layer for AI ecosystems, enabling enterprises to confidently scale AI adoption across cloud and on-premises environments. AI is one of the fastest-growing technologies in the history of modern business, with the ability to revolutionize industries, optimize operations, and drive innovation, but it is also introducing security gaps, risks, and vulnerabilities. According to McKinsey, 78% of organizations are using AI in at least one business function, up from 55% two years ago. As a result, 73% of them are investing in A

Interactive Brokers Adds Access to Brazil’s B3 Exchange11.12.2025 09:00:00 CET | Press release

Interactive Brokers (Nasdaq: IBKR), an automated global electronic broker, today announced that eligible clients outside of Brazil can now trade Brazilian equities through B3, the Brazil Stock Exchange. This expansion gives investors more ways to access emerging market opportunities across Latin America alongside global stocks, options, futures, currencies, bonds, funds, and more through a single unified platform. The B3 Exchange is one of the most active and liquid markets in the region. With this addition, investors will have direct access to trade Brazilian equities, plus over 160 markets worldwide using Interactive Brokers’ powerful trading platforms and tools. “Global investors need seamless access to diverse markets to stay competitive,” said Milan Galik, Chief Executive Officer of Interactive Brokers. “By adding Brazil’s B3 Exchange, we’re giving our clients efficient, low-cost access to one of the world’s most dynamic emerging economies through our unified global platform.” Int

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye