MA-VERACODE
22.11.2022 13:51:37 CET | Business Wire | Press release
Veracode, a leading global provider of modern application security testing solutions, today revealed that almost three-quarters of applications in the retail & hospitality sector contain security flaws, but only 25 percent of these are fixed. Furthermore, 17 percent of these flaws are categorized as ‘high severity’, meaning they pose a serious risk to the business if exploited. With 76 percent of Americans planning to shop the Black Friday sales on 25 November*—and 56 percent planning to purchase entirely online**— retailers should take extra care to reinforce the security of their ecommerce systems, digital payment platforms, and supply chains.
The data was published in Veracode’s annual State of Software Security (SoSS) report v12, which analyzed 20 million scans across half a million applications in the retail, manufacturing, healthcare, financial services, technology, and government sectors.
Chris Eng, Chief Research Officer at Veracode, said, “Maintaining customer loyalty and trust is priority number one for retailers, and this will be heightened during the Black Friday period. With the average cost of a data breach in the retail sector calculated at $3.28 million***, implementing robust tools and practices to secure the applications customers use to browse and make purchases is imperative.”
Despite the relatively low number of flaws that are fixed, the retail industry takes second place for overall remediation rate, highlighting the need for software security improvements from organizations across all sectors. Eng said, “Compared with other sectors, retailers are better at fixing flaws when they’re discovered. While this is encouraging, it’s clear more needs to be done across the board to integrate flaw identification and remediation into the software development pipeline so that vulnerabilities can be addressed more efficiently.”
Server configuration, insecure dependencies, and authentication issues are the most common types of application flaws across most industries. The retail & hospitality sector follows a similar pattern; however, the sector has higher percentages in nearly every flaw category—perhaps due to the greater functional complexity of customer-facing and back-office applications.
Flaw Fix Times Fluctuate in Retail
Veracode analyzed three different scan types to generate industry comparisons for fix times: dynamic analysis security testing (DAST), static analysis security testing (SAST), and software composition analysis (SCA). Retailers were found to be the quickest to address flaws discovered by DAST, at 70 days to reach the halfway point, which is a staggering 46 days faster than financial services in second place. When it came to SAST and SCA, however, the retail sector fell to the middle of the pack, taking 346 days and 470 days respectively to reach the halfway fix point.
Across all industries, flaws in third-party libraries discovered through SCA persist for longer than those found through SAST and DAST, with 30 percent of vulnerable libraries still unresolved after two years. For the retail sector, that statistic rises to 35 percent and lags the cross-industry average by more than six months. Nevertheless, retailers should be assured that the gap is never too wide to close. Indeed, Veracode’s 2021 State of Software Security report found 92 percent of open-source flaws can be easily fixed with a simple update, which is good news for retailers looking to secure their software supply chains.
In the run-up to Black Friday, and nearly one year since the infamous Log4j vulnerability was first reported, retailers will be on high alert to maintain the speed, efficiency, and security of their applications. Businesses should take extra care to uncover vulnerabilities in third-party software using a combination of SCA and development tools. Using this approach with Veracode, Darius Radford, Application Security Architect at specialty retailer Floor & Decor, was able to get a comprehensive view of risk posed by vulnerable libraries in the company’s software: “We were able to quickly figure out all the places running Log4j and remediate the situation.” Trey Tunnel, Floor and Decor’s Chief Information Security Officer, added, “Our customers are our top priority. With Veracode, we have the confidence that our software is secure and—more importantly—our customers have the confidence that our software is secure.”
The Veracode State of Software Security v12 retail & hospitality snapshot is available to download here and the full report is available here.
* Future Publishing, “Exploring the impact of rising inflation”, June 2022, https://go.future-advertising.com/Rising-Inflation-Research-Insights.html
** Dot Digital, “Black Friday Stats: Everything You Need to Know (updated 2022), Jenna Paton, 20 September 2022, https://dotdigital.com/blog/black-friday-cyber-monday-stats/
*** IBM Security and The Ponemon Institute, “Cost of a Data Breach Report 2022”, July 2022, https://www.ibm.com/downloads/cas/3R8N1DZJ
About the State of Software Security Report
The Veracode State of Software Security (SoSS) v12 analyzed the full historical data from Veracode services and customers. This accounts for a total of more than half a million applications (592,720) that used all scan types, more than a million dynamic analysis scans (1,034,855), more than five million static analysis scans (5,137,882) and more than 18 million software composition analysis scans (18,473,203). All those scans produced 42 million raw static findings, 3.5 million raw dynamic findings, and six million raw SCA findings.
The data represents large and small companies, commercial software suppliers, software outsourcers, and open-source projects. In most analyses, an application was counted only once, even if it was submitted multiple times as vulnerabilities were remediated, and new versions uploaded.
About Veracode
Veracode is a leading AppSec partner for creating secure software, reducing the risk of security breach, and increasing security and development teams’ productivity. As a result, companies using Veracode can move their business, and the world, forward. With its combination of process automation, integrations, speed, and responsiveness, Veracode helps companies get accurate and reliable results to focus their efforts on fixing, not just finding, potential vulnerabilities. Learn more at www.veracode.com, on the Veracode blog and on Twitter.
Copyright © 2022 Veracode, Inc. All rights reserved. Veracode is a registered trademark of Veracode, Inc. in the United States and may be registered in certain other jurisdictions. All other product names, brands or logos belong to their respective holders. All other trademarks cited herein are property of their respective owners.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20221122005446/en/
About Business Wire
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
CorFlow Therapeutics Announces Successful Completion of Phase 1 and First Patients Enrolled in Phase 2 of the MOCA II Pivotal Trial, Approval to Start the REVITALISE RCT in Europe, and Strengthening of Clinical Leadership30.4.2026 13:00:00 CEST | Press release
Milestones advance clinical progress and path to commercialization CorFlow Therapeutics AG (CorFlow), a clinical-stage company focused on transforming the diagnosis and treatment for heart attack patients, today announced multiple milestones in advancing its clinical program and the strengthening of clinical leadership. Phase 1 of the company’s MOCA II FDA Pivotal Trial was successfully reached after safety and performance goals were met with STEMI heart attack patients who had the proprietary PCoFI diagnostic measurement of microvascular obstruction (MVO) made during a stenting procedure, when compared to the reference standard diagnosis by cardiac MRI in the subsequent days. Phase 1 included 19 patients enrolled across 5 US and 3 European sites. MOCA II follows the FIH MOCA I study and primarily aims to validate the threshold value of the proprietary PCoFI measurement for diagnosing MVO in the setting of primary angioplasty compared to cardiac MRI. This milestone achievement, which w
Agendia to Present New Data Demonstrating the Expanded Clinical Utility of MammaPrint® and BluePrint® at the 2026 ESMO Breast Cancer Annual Congress30.4.2026 13:00:00 CEST | Press release
Poster presentations highlight the prognostic value of MammaPrint + Blueprint in small, node-negative tumors and impact of BMI on recurrence dynamics Agendia®, Inc., a leader in precision oncology for breast cancer, today announced it will present new data at the 2026 European Society for Medical Oncology (ESMO) Annual Congress on Breast Cancer, taking place May 6-8 in Berlin, Germany. The company will present two posters featuring data from the prospective FLEX Study and an independent post hoc analysis of the landmark MINDACT trial that underscore the prognostic value of MammaPrint® + BluePrint® in early-stage breast cancer (EBC). Poster #65P | Thursday, May 7, 13:15 – 14:15 p.m. CEST | Presenter: Elena Shagisultanova Prognostic Performance of MammaPrint in Patients with Small T1a, b, and c Node-Negative Early Breast Cancer A retrospective analysis from the FLEX Study involving 4,349 patients highlights the biological heterogeneity within small, node-negative (T1a, b, and c) tumors –
The Biggest Predictor of Business Growth Is Behavior30.4.2026 09:00:00 CEST | Press release
New IDEO research reveals a gap in the behaviors that most drive growth: long-term vision, rapid experimentation, and team autonomy—with only 10% of leaders saying their company excels at the combination. IDEO, the global design and innovation company, today announced the IDEO Innovation Quotient (IDEO IQ), a new report measuring how workplace behaviors drive business performance across 100 of the world’s largest companies. Those with the highest IDEO IQ scores earned nearly $20 billion in profit last year—50% higher than average and three times more than those ranked at the bottom. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260429978890/en/ The IDEO Innovation Quotient (IDEO IQ) is a new report measuring how workplace behaviors drive business performance across 100 of the world’s largest companies. The IDEO IQ surveyed 266 leaders in product and innovation roles at 100 of the world’s largest companies across the Media &
Suzano Sells 12.7 Million Tonnes of Pulp for the First Time in Its History30.4.2026 00:22:00 CEST | Press release
Suzano(B3: SUZB3 | NYSE: SUZ), the world’s largest pulp producer, announces its results for the first quarter of 2026 (1Q26), achieving a new all‑time record in pulp sales. Over the 12‑month period from April 2025 to March 2026, the company sold 12.7 million tonnes of pulp, the highest volume ever recorded in its history. During the same period, Suzano also sold 1.7 million tonnes of paper across the packaging, printing and writing, specialty, and tissue segments. This unprecedented sales level mainly reflects the increase in production capacity following the start‑up of the Ribas do Rio Pardo pulp mill in the state of Mato Grosso do Sul, as well as Suzano’s strong operational efficiency across its production lines and supply chains, serving customers in more than 100 countries worldwide. In the first quarter of 2026, Suzano sold a total of 3.2 million tonnes, comprising 2.8 million tonnes of pulp and 378 thousand tonnes of paper. Net revenue amounted to BRL 11.0 billion, while adjuste
The Estée Lauder Companies Announces Minority Investment in Luxury Clinical Skin Care Brand 111SKIN29.4.2026 22:30:00 CEST | Press release
Surgeon-Founded Brand Anchored by Innovative NAC Y2™ Technology The Estée Lauder Companies Inc. (NYSE:EL) today announced a minority investment in 111SKIN, a luxury clinical skin care brand founded by renowned plastic and reconstructive surgeon Dr. Yannis Alexandrides. Terms of the investment were not disclosed. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260429495879/en/ 111SKIN's Reparative Collection Founded in 2012, 111SKIN was originally developed by Dr. Alexandrides to accelerate his patients’ healing time following procedures. At the heart of the brand is its innovative NAC Y2™, a pioneering complex designed to support skin repair and maintain a healthy, radiant and resilient complexion. Building on the foundation of this clinical expertise, 111SKIN has developed a portfolio of more than 30 products, anchored by its Black Diamond and Reparative collections and priced from $50 to $1,000. “Skin care is entering a new
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
