Business Wire

MA-VERACODE

23.8.2022 14:21:12 CEST | Business Wire | Press release

Share
Financial Services Software Has Fewer Security Flaws Than Most Industries

Veracode , a leading global provider of application security testing solutions, today released data revealing that the financial services industry ranks among the best for overall flaw percentage when compared to other industries, but has one of the lowest fix rates for software security flaws. The sector also falls to the middle of the pack for high-severity flaws, with 18 percent of applications containing a serious vulnerability, suggesting financial firms should prioritize identifying and remediating the flaws that matter most.

The findings were outlined in the company’s annual State of Software Security report v12, which analyzed 20 million scans across half a million applications in the financial, technology, manufacturing, retail, healthcare and government sectors. Across the six industries, the financial sector has the second-lowest proportion of applications containing security flaws, at 73 percent. In last year’s report, the industry boasted the lowest number of software security flaws across all sectors but has been overtaken by manufacturing in this year’s study. Despite having fewer flaws overall, the financial services sector comes joint last with technology and government for the lowest proportion of flaws that are fixed.

“One of the advantages of serving the software development community for so many years is that Veracode can see changes in development practices across industries over time. We found that while financial services applications have fewer security flaws than last year, the sector lags behind other industries when it comes to fix rate. Our research showed that security training can significantly improve remediation speeds, and that companies whose development teams had completed hands-on training using real-life applications fixed flaws 35 percent faster than those without such training,” said Chris Eng, Chief Research Officer at Veracode.

Securing the Global Software Supply Chain

While there is undoubtedly still room for progress in terms of both flaw prevalence and remediation rates, when financial services organizations do fix vulnerabilities, they move at a quicker pace than most.

Eng said, “The U.S. Executive Order on Cybersecurity, alongside mandates on security controls regarding open-source usage, such as GDPR and the New York Department of Financial Services Cybersecurity Regulations, has highlighted the importance of securing the software supply chain. Being a highly regulated sector may go some way to explain the financial industry’s relative speed in addressing vulnerable libraries discovered through software composition analysis (SCA).”

Flaws in third-party libraries found through SCA tend to stick around longer for all industries, with 30 percent still unresolved after two years. When it comes to addressing open-source vulnerabilities, however, the finance sector remediates at the same pace as other industries for the first year but then quickens its pace to gain a month on the cross-industry average.

Although the finance sector outperforms most other industries in fix times for flaws discovered by dynamic, SCA, and static, the study found there is still ample room for continued improvement when looking at the number of days it takes to resolve 50 percent of flaws—116 days for dynamic analysis, 385 days for SCA, and 288 days for static analysis. With third-party components comprising as much as 90 percent* of an application’s codebase, scanning early and often using a combination of testing types reduces unplanned emergency remediation work and mitigates the risk of introducing third-party security flaws into software.

The Veracode State of Software Security v12 financial services snapshot is available to download here and a video of the findings is available to watch here .

* The Linux Foundation Statista, Joseph Perlow, “A Summary of Census II: Open Source Software Application Libraries the World Depends On”: https://www.statista.com/statistics/617136/digital-population-worldwide/ , March 7, 2022

About the State of Software Security Report

The Veracode State of Software Security (SoSS) v12 analyzed the full historical data from Veracode services and customers. This accounts for a total of more than half a million applications (592,720) that used all scan types, more than a million dynamic analysis scans (1,034,855), more than five million static analysis scans (5,137,882) and more than 18 million software composition analysis scans (18,473,203). All those scans produced 42 million raw static findings, 3.5 million raw dynamic findings, and six million raw SCA findings.

The data represents large and small companies, commercial software suppliers, software outsourcers, and open-source projects. In most analyses, an application was counted only once, even if it was submitted multiple times as vulnerabilities were remediated, and new versions uploaded.

About Veracode

Veracode is a leading AppSec partner for creating secure software, reducing the risk of security breach, and increasing security and development teams’ productivity. As a result, companies using Veracode can move their business, and the world, forward. With its combination of process automation, integrations, speed, and responsiveness, Veracode helps companies get accurate and reliable results to focus their efforts on fixing, not just finding, potential vulnerabilities. Learn more at www.veracode.com , on the Veracode blog and on Twitter .

Copyright © 2022 Veracode, Inc. All rights reserved. Veracode is a registered trademark of Veracode, Inc. in the United States and may be registered in certain other jurisdictions. All other product names, brands or logos belong to their respective holders. All other trademarks cited herein are property of their respective owners.

Link:

ClickThru

Social Media:

https://www.facebook.com/VeracodeInc/

About Business Wire

Business Wire
Business Wire
101 California Street, 20th Floor
CA 94111 San Francisco

http://businesswire.com

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Laserfiche Expands AI Data Capture with Auto-Classification to Transform Data into Business Intelligence28.1.2026 16:00:00 CET | Press release

New intelligent features automatically organize and classify documents, transforming how organizations manage information at scale. Laserfiche — the leading SaaS provider of intelligent content management — today announced major enhancements to its AI-powered data extraction tool, Smart Fields. The update introduces automated document classification and tagging, allowing organizations to move from unstructured content to informed decisions in seconds. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260128228490/en/ Using natural language prompts instead of rigid, ruled-based OCR, Smart Fields can now identify document type — such as invoices, taxpayer identification forms, or student transcripts — and automatically apply the correct metadata template using AI. Users can also use Smart Fields to automatically add informational and security tags to files that meet certain criteria, defined using a natural language prompt. Users

Intersolar Africa 2026 to Position Nairobi as East Africa’s Key Hub for Solar and Energy Storage28.1.2026 15:20:00 CET | Press release

East Africa is emerging as one of the world’s most dynamic regions for solar power and battery storage. On 3–4 February 2026, Intersolar Africa will take place at the Sarit Expo Centre in Nairobi, expanding from the successful Intersolar Summit Africa in 2025 into a full international exhibition and conference. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260128955267/en/ Intersolar Africa will take place on February 3-4 in Nairobi. East Africa’s Energy Market and Opportunities Rapid population growth, industrialization, and rising electricity demand are putting pressure on power systems across East Africa. Limited generation capacity, grid instability, and high electricity costs constrain economic growth. Solar photovoltaics combined with energy storage have emerged as the most cost-effective and scalable solution to expand capacity, stabilize supply, and strengthen long-term energy security for businesses and communities

Reply and the University of Milan Launch Experimental Research on Biological Computing Based on Cortical Labs’ CL1 Platform28.1.2026 15:10:00 CET | Press release

Reply [EXM, STAR: REY] today announced the start of a collaboration with the Department of Pathophysiology and Transplantation of the University of Milan, together with the “Centro Dino Ferrari” of the University of Milan - Ospedale Policlinico, for a new research and experimental initiative in the field of biological computing. The project aims to explore innovative approaches to learning and information processing through the integration of biological systems and digital technologies. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260128715625/en/ This initiative represents the starting point of an advanced research programme aimed at exploring new computational paradigms. At the core of the initiative is the CL1 biological computer developed by Cortical Labs, an Australian biotechnology company. Unlike conventional silicon-based computing architectures, this technology leverages the processing capabilities of living human

Brown Brothers Harriman Investor Services and SimCorp Forge Strategic Alliance to Provide Integrated End-to-End Technology, Data, and Services Solution for Global Asset Managers28.1.2026 15:00:00 CET | Press release

New offering leverages BBH Infomediary® to combine the benefits of the SimCorp One enterprise platform, including SimCorp Managed Business Services, with BBH Investor Services’ fund servicing and custody product suite. BBH Infomediary used to integrate BBH and SimCorp’s platforms and to connect to third parties in a unique open architecture model. Addresses the needs of global asset managers seeking to streamline and modernize their operating model. Quoniam Asset Management, a leading systematic manager, is the first to benefit from this data-driven offering. Brown Brothers Harriman (BBH), a privately held global financial services firm, and SimCorp, a leading global financial technology company, today announced a new strategic alliance to address the needs of global asset managers requiring an integrated, end-to-end technology, data, and services solution. Enhancing both firms’ existing offerings, this solution uses BBH Infomediary to integrate SimCorp One’s front and middle office ca

Wunderkind Joins Klaviyo Marketplace, Bringing Identity-Based Personalization and Revenue Growth to E-Commerce Brands28.1.2026 15:00:00 CET | Press release

New integration unlocks greater site identification, real-time personalization, and scalable triggered messaging Wunderkind, the AI decisioning platform that delivers identity resolution and cross-channel personalization to scale performance and reach, today announced its official debut on the Klaviyo App Marketplace. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260128210560/en/ The integration brings Wunderkind’s identity insights directly into Klaviyo’s B2C CRM, powering real-time profiles, segments, and flows that help brands recognize more customers earlier in the journey and deliver relevant experiences across email, SMS and other Klaviyo-powered channels. By layering Wunderkind’s industry-leading Identity Network — built on more than 9 billion device profiles and over a billion unique user identities — into Klaviyo’s unified customer profile, marketers can strengthen their understanding of who customers are, unify id

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye