MA-VERACODE
22.11.2022 13:51:37 CET | Business Wire | Press release
Veracode, a leading global provider of modern application security testing solutions, today revealed that almost three-quarters of applications in the retail & hospitality sector contain security flaws, but only 25 percent of these are fixed. Furthermore, 17 percent of these flaws are categorized as ‘high severity’, meaning they pose a serious risk to the business if exploited. With 76 percent of Americans planning to shop the Black Friday sales on 25 November*—and 56 percent planning to purchase entirely online**— retailers should take extra care to reinforce the security of their ecommerce systems, digital payment platforms, and supply chains.
The data was published in Veracode’s annual State of Software Security (SoSS) report v12, which analyzed 20 million scans across half a million applications in the retail, manufacturing, healthcare, financial services, technology, and government sectors.
Chris Eng, Chief Research Officer at Veracode, said, “Maintaining customer loyalty and trust is priority number one for retailers, and this will be heightened during the Black Friday period. With the average cost of a data breach in the retail sector calculated at $3.28 million***, implementing robust tools and practices to secure the applications customers use to browse and make purchases is imperative.”
Despite the relatively low number of flaws that are fixed, the retail industry takes second place for overall remediation rate, highlighting the need for software security improvements from organizations across all sectors. Eng said, “Compared with other sectors, retailers are better at fixing flaws when they’re discovered. While this is encouraging, it’s clear more needs to be done across the board to integrate flaw identification and remediation into the software development pipeline so that vulnerabilities can be addressed more efficiently.”
Server configuration, insecure dependencies, and authentication issues are the most common types of application flaws across most industries. The retail & hospitality sector follows a similar pattern; however, the sector has higher percentages in nearly every flaw category—perhaps due to the greater functional complexity of customer-facing and back-office applications.
Flaw Fix Times Fluctuate in Retail
Veracode analyzed three different scan types to generate industry comparisons for fix times: dynamic analysis security testing (DAST), static analysis security testing (SAST), and software composition analysis (SCA). Retailers were found to be the quickest to address flaws discovered by DAST, at 70 days to reach the halfway point, which is a staggering 46 days faster than financial services in second place. When it came to SAST and SCA, however, the retail sector fell to the middle of the pack, taking 346 days and 470 days respectively to reach the halfway fix point.
Across all industries, flaws in third-party libraries discovered through SCA persist for longer than those found through SAST and DAST, with 30 percent of vulnerable libraries still unresolved after two years. For the retail sector, that statistic rises to 35 percent and lags the cross-industry average by more than six months. Nevertheless, retailers should be assured that the gap is never too wide to close. Indeed, Veracode’s 2021 State of Software Security report found 92 percent of open-source flaws can be easily fixed with a simple update, which is good news for retailers looking to secure their software supply chains.
In the run-up to Black Friday, and nearly one year since the infamous Log4j vulnerability was first reported, retailers will be on high alert to maintain the speed, efficiency, and security of their applications. Businesses should take extra care to uncover vulnerabilities in third-party software using a combination of SCA and development tools. Using this approach with Veracode, Darius Radford, Application Security Architect at specialty retailer Floor & Decor, was able to get a comprehensive view of risk posed by vulnerable libraries in the company’s software: “We were able to quickly figure out all the places running Log4j and remediate the situation.” Trey Tunnel, Floor and Decor’s Chief Information Security Officer, added, “Our customers are our top priority. With Veracode, we have the confidence that our software is secure and—more importantly—our customers have the confidence that our software is secure.”
The Veracode State of Software Security v12 retail & hospitality snapshot is available to download here and the full report is available here.
* Future Publishing, “Exploring the impact of rising inflation”, June 2022, https://go.future-advertising.com/Rising-Inflation-Research-Insights.html
** Dot Digital, “Black Friday Stats: Everything You Need to Know (updated 2022), Jenna Paton, 20 September 2022, https://dotdigital.com/blog/black-friday-cyber-monday-stats/
*** IBM Security and The Ponemon Institute, “Cost of a Data Breach Report 2022”, July 2022, https://www.ibm.com/downloads/cas/3R8N1DZJ
About the State of Software Security Report
The Veracode State of Software Security (SoSS) v12 analyzed the full historical data from Veracode services and customers. This accounts for a total of more than half a million applications (592,720) that used all scan types, more than a million dynamic analysis scans (1,034,855), more than five million static analysis scans (5,137,882) and more than 18 million software composition analysis scans (18,473,203). All those scans produced 42 million raw static findings, 3.5 million raw dynamic findings, and six million raw SCA findings.
The data represents large and small companies, commercial software suppliers, software outsourcers, and open-source projects. In most analyses, an application was counted only once, even if it was submitted multiple times as vulnerabilities were remediated, and new versions uploaded.
About Veracode
Veracode is a leading AppSec partner for creating secure software, reducing the risk of security breach, and increasing security and development teams’ productivity. As a result, companies using Veracode can move their business, and the world, forward. With its combination of process automation, integrations, speed, and responsiveness, Veracode helps companies get accurate and reliable results to focus their efforts on fixing, not just finding, potential vulnerabilities. Learn more at www.veracode.com, on the Veracode blog and on Twitter.
Copyright © 2022 Veracode, Inc. All rights reserved. Veracode is a registered trademark of Veracode, Inc. in the United States and may be registered in certain other jurisdictions. All other product names, brands or logos belong to their respective holders. All other trademarks cited herein are property of their respective owners.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20221122005446/en/
About Business Wire
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Thales to Strengthen Romania’s Airspace Protection With Twelve Ground Master 200 MM/A Radars24.7.2026 10:05:00 CEST | Press release
The Romanian General Directorate for Armaments and the French Direction Générale de l’Armement (DGA – the French defence procurement agency) have signed an agreement to supply twelve Thales GM200 Multi-Mission All-in-one (GM200 MM/A) radars to protect the Romanian airspace. This government-to-government agreement underlines the high level of partnership between France and Romania, within the framework of the European Union’s SAFE funding programme, in order to bolster Europe’s defence capabilities. The GM200 MM/A is part of Thales’ proven Ground Master radar family, which has already been deployed in over 40 countries, including now in Romania. In a context of growing collaboration between European nations to bolster collective security, the Romanian General Directorate for Armaments has just signed a landmark agreement with France’s Direction Générale de l’Armement (DGA) to acquire twelve Thales Ground Master 200 Multi-Mission All-in-one (GM200 MM/A) radars. This government-to-governm
Comsysto Reply Supports Audi in Evolving Its B2B Used Car Platform With an AI-Based Multi-Agent System24.7.2026 10:00:00 CEST | Press release
Comsysto Reply, the Reply Group company specialised in agile software development and cloud-native solutions, has partnered with Audi on the ongoing development of its “Used Car Platform”, the company’s central digital marketplace for B2B used car trading. A tailored multi-agent solution accelerates software development, reduces repetitive activities, and enables faster delivery of new features. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260724143396/en/ Comsysto Reply, the Reply Group company specialised in agile software development and cloud-native solutions, has partnered with Audi in evolving its digital marketplace for B2B used car trading with an AI-based multi-agent system The platform represents a key digital sales channel for Audi’s used car sector. Since 2025, it has accounted for nearly 100% of the car manufacturer's B2B business. Building on this operational relevance, Audi and Comsysto Reply have introduced
Samsung Epis Holdings Reports Second Quarter and Half-Year 2026 Financial Results24.7.2026 09:20:00 CEST | Press release
Samsung Bioepis reports revenue of 847.1 billion KRW and an operating profit of 230.6 billion KRW in the first half of 2026, recording 6% year-over-year growthExpanding direct commercialization in Europe to five products with the launch of OPUVIZ™ 40 mg/mL vial, a biosimilar to Eylea1 (aflibercept)First to announce preliminary results from Phase 1, 3 clinical studies for SB27, a biosimilar candidate referencing Keytruda2 (pembrolizumab)Samsung Epis Holdings continuing to secure next-generation growth engines through establishment of a global R&D hub in China Samsung Epis Holdings (KRX: 0126Z0), an investment company dedicated to innovations in biopharmaceuticals and biotechnology, today announced its financial results for the second quarter and first half of fiscal year 2026. “We delivered solid first-half 2026 results, achieving 6% growth year-over-year. This performance demonstrates the resilience of our biosimilar portfolio in the global market," said Kyung-Ah Kim, President and Chi
Ant International’s Alipay+ Adds New Bank Partners Amid Cross-border Mobile Payment Boom in Asia Pacific24.7.2026 06:10:00 CEST | Press release
Through Alipay+, banks are able to quickly build new revenue streams, increase digital engagement and introduce new value-added services for users through cross-border payments Alipay+, Ant International's unified wallet gateway, is adding more bank partners to its network of over 50 leading digital wallets and financial institutions. Its global bank partners range from incumbent banks to fully digital banks. The latest banking partner to join Alipay+ is Hang Seng Bank, Alipay+’s first banking partner in Hong Kong. Hang Seng Mobile App users can now make payments via QR code scan in the Chinese Mainland and overseas by simply using the Hang Seng Mobile App at over 100 million merchants across more than 55 countries/regions. Accelerating revenue growth through cross-border mobile payments Demand for outbound cross-border payments from Asia Pacific is projected to increase faster than the global average. Alongside growing adoption of digital wallets, consumer-to-consumer (C2C) and consum
mimik Operationalizes Agentic AI on the AMD Ryzen™ AI Embedded X100 Series23.7.2026 20:30:00 CEST | Press release
mimik today announced mimOE™ Embedded Edition, a package of its Agentix Operating Engine and a set of purpose-built tools for the AMD Ryzen™ AI Embedded X100 Series processor, the newest processor in a family designed for physical AI, autonomous systems, and industrial automation. Available to download today, mimOE Embedded Edition gives OEMs, tier-1 suppliers, system integrators, and agent developers the path to operationalize Agentix-Native systems (aka Agentic AI), in which autonomous agents can reason, coordinate, and act directly on devices, from PoC to scaled operations with certainty. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260723555565/en/ Agentic AI operations are both CPU and GPU bound. Enterprises can now scale with certainty. Generative AI has centered on the GPU. Agentix-Native systems must spread the work. In a real multi-agent workflow traced by mimik, more than 80 percent of operations were CPU work: d
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
