MA-VERACODE
8.12.2022 13:51:40 CET | Business Wire | Press release
Veracode, a leading global provider of modern application security testing solutions, today revealed that 24 percent of applications in the technology sector contain security flaws that are considered high risk—meaning they would cause a critical issue for the application if exploited. With, arguably, a higher proportion of applications to contend with than other industries, tech firms would benefit from implementing improved secure coding training and practices for their development teams.
Chief Research Officer at Veracode, Chris Eng, said, “Giving developers real, hands-on experience of what it takes to spot and exploit a flaw in code—and its potential impact on the application—provides the context and understanding to build their intuition about software security. Our research found that organizations whose developers had completed just one lesson in our hands-on Security Labs training program fixed 50 percent of flaws two months faster than those without such training.”
The data was published in Veracode’s annual State of Software Security (SoSS) report v12, which analyzed 20 million scans across half a million applications in the technology, retail, manufacturing, healthcare, financial services, and government sectors. Overall, the technology industry was revealed to have the second-highest proportion of applications that contain security flaws, at 79 percent, making it marginally better than the public sector at 82 percent. The tech sector lands in the middle of the pack when it comes to the proportion of flaws that are fixed.
Tech Firms Are Comparatively Quick to Fix Software Security Flaws
Encouragingly, when tech firms do discover flaws in their applications, they are comparatively fast to reach the halfway point of remediation. In fact, the sector boasts industry-leading fix times for flaws discovered by static analysis security testing (SAST) and software composition analysis (SCA). While this is a laudable accomplishment, the industry still takes up to 363 days to fix 50 percent of flaws, suggesting there is still ample room for improvement.
Eng added, “Log4j sparked a wake-up call for many organizations last December. This was followed by government action in the form of guidance from the Office of Management and Budget (OMB) and the European Cyber Resilience Act, both of which have a supply chain focus. To improve performance in the year ahead, technology businesses should not only consider strategies that help developers reduce the rate of flaws introduced into code, but also put greater emphasis on automating security testing in the Continuous Integration/Continuous Delivery (CI/CD) pipeline to increase efficiencies.”
Server configuration, insecure dependencies, and information leakage are the most common types of flaws discovered by dynamic analysis of technology applications, which broadly follows a similar pattern to other industries. Conversely, the sector exhibits the highest disparity from the industry average for cryptographic issues and information leakage, perhaps indicating that developers in the tech industry are more savvy on data protection challenges.
The Veracode State of Software Security v12 technology snapshot is available to download here and the full report is available here.
About the State of Software Security Report
The Veracode State of Software Security (SoSS) v12 analyzed the full historical data from Veracode services and customers. This accounts for a total of more than half a million applications (592,720) that used all scan types, more than a million dynamic analysis scans (1,034,855), more than five million static analysis scans (5,137,882) and more than 18 million software composition analysis scans (18,473,203). All those scans produced 42 million raw static findings, 3.5 million raw dynamic findings, and six million raw SCA findings.
The data represents large and small companies, commercial software suppliers, software outsourcers, and open-source projects. In most analyses, an application was counted only once, even if it was submitted multiple times as vulnerabilities were remediated, and new versions uploaded.
About Veracode
Veracode is a leading AppSec partner for creating secure software, reducing the risk of security breach, and increasing security and development teams’ productivity. As a result, companies using Veracode can move their business, and the world, forward. With its combination of process automation, integrations, speed, and responsiveness, Veracode helps companies get accurate and reliable results to focus their efforts on fixing, not just finding, potential vulnerabilities. Learn more at www.veracode.com, on the Veracode blog, on LinkedIn, and on Twitter.
Copyright © 2022 Veracode, Inc. All rights reserved. Veracode is a registered trademark of Veracode, Inc. in the United States and may be registered in certain other jurisdictions. All other product names, brands or logos belong to their respective holders. All other trademarks cited herein are property of their respective owners.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20221208005101/en/
About Business Wire
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Merz Therapeutics Appoints Dan Staner as President, Region Europe30.1.2026 08:00:00 CET | Press release
Merz Therapeutics today announced the appointment of Dan Staner as President, Region Europe, effective February 1, 2026. In this role, Dan will oversee the company’s European business and drive regional growth. Dan will report directly to Merz Therapeutics Chief Executive Officer, Stefan König, and will join the Therapeutics Executive Team. His appointment reflects the company’s continued commitment to strengthening its leadership capabilities and accelerating its growth strategy across key European markets. “Dan brings a strong track record of building and scaling biopharmaceutical businesses across Europe,” said Stefan König, CEO of Merz Therapeutics. “His deep commercial, strategic, and regional leadership experience will be instrumental in advancing our growth ambitions, expanding patient access to our therapies, and further strengthening our presence in Europe. We are very pleased to welcome Dan to Merz Therapeutics.” Throughout his career, Dan has held senior leadership roles i
Galderma Tackles Menopause-related Skin Changes With Global Survey and Clinical Trial Inclusivity30.1.2026 07:00:00 CET | Press release
Results from a global survey of over 4,300 women across five continents presented at IMCAS 2026 reveal a knowledge gap on the impact of menopause on the skin, despite women experiencing around three skin changes during menopause1 Galderma will also host a symposium delving into the challenges and science behind menopause-related skin changes and aesthetic solutions at the congress Galderma is committed to raising awareness of the impact of menopause on the skin, fostering meaningful dialogue between patients and healthcare professionals, and advancing science-backed solutions by incorporating menopausal status into all injectable aesthetics clinical trials Galderma (SIX: GALD) has unveiled findings from a global survey of peri- and post-menopausal women from nine countries exploring the impact of menopause on the skin at the International Master Course on Aging Science (IMCAS) 2026 World Congress in Paris, France, from January 29-31, 2026. The survey found that over 50% of women learne
Andersen Consulting styrker sine cybersikkerhedskompetencer med tilføjelsen af RedLegg30.1.2026 00:18:00 CET | Pressemeddelelse
Andersen Consulting styrker sit cybersikkerhedsudbud gennem en samarbejdsaftale med RedLegg, der er et cybersikkerhedsfirma med speciale i administreret trusselsdetektion og rådgivningsydelser. RedLegg blev grundlagt i 2008 og har hovedsæde i USA. RedLegg tilbyder skræddersyede cybersikkerhedsløsninger med fokus på risikominimering, administrerede sikkerhedstjenester og penetrationstest. Virksomhedens ydelser omfatter blandt andet managed detection and response (MDR), hændelsesrespons, udvikling af sikkerhedspolitikker samt virtuel CISO-rådgivning. RedLegg betjener mellemstore virksomheder inden for finans, forsikring, jura og sundhedssektoren og kombinerer automatisering, trusselsintelligens og et dedikeret Security Operations Center (SOC) for at hjælpe organisationer med at effektivisere deres cybersikkerhedsoperationer og opbygge langsigtet modstandsdygtighed. "Vores fokus har altid været at hjælpe kunder med at skære støjen fra og prioritere det, der virkelig betyder noget – nemlig
Andersen Consulting tilføjer samarbejdsfirmaet HaystackID29.1.2026 21:20:00 CET | Pressemeddelelse
Andersen Consulting styrker sine kompetencer inden for cybersikkerhed og teknologi gennem en samarbejdsaftale med HaystackID, en amerikansk udbyder af eDiscovery, juridiske data og cyber discovery-tjenester. HaystackID blev stiftet i 2011 og arbejder tæt sammen med advokatfirmaer, virksomheder og offentlige myndigheder om at håndtere komplekse, dataintensive juridiske sager, herunder civile retssager, myndighedsundersøgelser og interne undersøgelser. Firmaet leverer komplet processtøtte ved hjælp af cyber discovery, digital efterforskning, managed review, compliance og information governance, hvilket hjælper klienter med at identificere, analysere og forsvarligt fremlægge kritiske data. Ved hjælp af proprietære ai-drevne platforme og ekspertledede reviewteams betjener HaystackID klienter i hele Nordamerika og Europa, heriblandt Fortune 100-virksomheder. "I takt med at de juridiske og regulatoriske miljøer bliver mere datadrevne og tidskritiske, fortsætter vi med at udvikle vores kompet
Convera Appoints Industry Leader Meaghan Riley as Chief Commercial Officer to Scale Commercial Growth and Expand Revenue Opportunities29.1.2026 17:14:00 CET | Press release
Former Google Cloud and SAP executive will build on Convera’s success and leadership in the commercial payments sector Convera, a global leader in commercial payments, today announces the appointment of Meaghan Riley to Chief Commercial Officer, as the company continues its growth trajectory, expands to new markets, and drives scalable revenue opportunities across geographies and sectors. Prior to Convera, Meaghan was Chief Operating Officer for Google Cloud North America, where she led a major go-to-market transformation and launched high-growth segments. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260129799440/en/ Meaghan Riley, Chief Commercial Officer, Convera “Meaghan’s impressive career journey and proven track record brings exceptional experience and unique assets that will strengthen our leadership team at this pivotal moment in Convera’s journey,” said Patrick Gauthier, CEO, Convera. “Meaghan’s leadership will be
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
