Business Wire

MA-VERACODE

8.12.2022 13:51:40 CET | Business Wire | Press release

Share
Veracode Research Finds a Quarter of Technology Applications Contain ‘High Severity’ Security Flaws, Which Pose a Serious Cybersecurity Risk If Exploited

Veracode, a leading global provider of modern application security testing solutions, today revealed that 24 percent of applications in the technology sector contain security flaws that are considered high risk—meaning they would cause a critical issue for the application if exploited. With, arguably, a higher proportion of applications to contend with than other industries, tech firms would benefit from implementing improved secure coding training and practices for their development teams.

Chief Research Officer at Veracode, Chris Eng, said, “Giving developers real, hands-on experience of what it takes to spot and exploit a flaw in code—and its potential impact on the application—provides the context and understanding to build their intuition about software security. Our research found that organizations whose developers had completed just one lesson in our hands-on Security Labs training program fixed 50 percent of flaws two months faster than those without such training.”

The data was published in Veracode’s annual State of Software Security (SoSS) report v12, which analyzed 20 million scans across half a million applications in the technology, retail, manufacturing, healthcare, financial services, and government sectors. Overall, the technology industry was revealed to have the second-highest proportion of applications that contain security flaws, at 79 percent, making it marginally better than the public sector at 82 percent. The tech sector lands in the middle of the pack when it comes to the proportion of flaws that are fixed.

Tech Firms Are Comparatively Quick to Fix Software Security Flaws

Encouragingly, when tech firms do discover flaws in their applications, they are comparatively fast to reach the halfway point of remediation. In fact, the sector boasts industry-leading fix times for flaws discovered by static analysis security testing (SAST) and software composition analysis (SCA). While this is a laudable accomplishment, the industry still takes up to 363 days to fix 50 percent of flaws, suggesting there is still ample room for improvement.

Eng added, “Log4j sparked a wake-up call for many organizations last December. This was followed by government action in the form of guidance from the Office of Management and Budget (OMB) and the European Cyber Resilience Act, both of which have a supply chain focus. To improve performance in the year ahead, technology businesses should not only consider strategies that help developers reduce the rate of flaws introduced into code, but also put greater emphasis on automating security testing in the Continuous Integration/Continuous Delivery (CI/CD) pipeline to increase efficiencies.”

Server configuration, insecure dependencies, and information leakage are the most common types of flaws discovered by dynamic analysis of technology applications, which broadly follows a similar pattern to other industries. Conversely, the sector exhibits the highest disparity from the industry average for cryptographic issues and information leakage, perhaps indicating that developers in the tech industry are more savvy on data protection challenges.

The Veracode State of Software Security v12 technology snapshot is available to download here and the full report is available here.

About the State of Software Security Report

The Veracode State of Software Security (SoSS) v12 analyzed the full historical data from Veracode services and customers. This accounts for a total of more than half a million applications (592,720) that used all scan types, more than a million dynamic analysis scans (1,034,855), more than five million static analysis scans (5,137,882) and more than 18 million software composition analysis scans (18,473,203). All those scans produced 42 million raw static findings, 3.5 million raw dynamic findings, and six million raw SCA findings.

The data represents large and small companies, commercial software suppliers, software outsourcers, and open-source projects. In most analyses, an application was counted only once, even if it was submitted multiple times as vulnerabilities were remediated, and new versions uploaded.

About Veracode

Veracode is a leading AppSec partner for creating secure software, reducing the risk of security breach, and increasing security and development teams’ productivity. As a result, companies using Veracode can move their business, and the world, forward. With its combination of process automation, integrations, speed, and responsiveness, Veracode helps companies get accurate and reliable results to focus their efforts on fixing, not just finding, potential vulnerabilities. Learn more at www.veracode.com, on the Veracode blog, on LinkedIn, and on Twitter.

Copyright © 2022 Veracode, Inc. All rights reserved. Veracode is a registered trademark of Veracode, Inc. in the United States and may be registered in certain other jurisdictions. All other product names, brands or logos belong to their respective holders. All other trademarks cited herein are property of their respective owners.

To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.

View source version on businesswire.com: https://www.businesswire.com/news/home/20221208005101/en/

About Business Wire

Business Wire
Business Wire
101 California Street, 20th Floor
CA 94111 San Francisco

http://businesswire.com
DK

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Andersen Consulting styrker sine cybersikkerhedskompetencer med tilføjelsen af RedLegg30.1.2026 00:18:00 CET | Pressemeddelelse

Andersen Consulting styrker sit cybersikkerhedsudbud gennem en samarbejdsaftale med RedLegg, der er et cybersikkerhedsfirma med speciale i administreret trusselsdetektion og rådgivningsydelser. RedLegg blev grundlagt i 2008 og har hovedsæde i USA. RedLegg tilbyder skræddersyede cybersikkerhedsløsninger med fokus på risikominimering, administrerede sikkerhedstjenester og penetrationstest. Virksomhedens ydelser omfatter blandt andet managed detection and response (MDR), hændelsesrespons, udvikling af sikkerhedspolitikker samt virtuel CISO-rådgivning. RedLegg betjener mellemstore virksomheder inden for finans, forsikring, jura og sundhedssektoren og kombinerer automatisering, trusselsintelligens og et dedikeret Security Operations Center (SOC) for at hjælpe organisationer med at effektivisere deres cybersikkerhedsoperationer og opbygge langsigtet modstandsdygtighed. "Vores fokus har altid været at hjælpe kunder med at skære støjen fra og prioritere det, der virkelig betyder noget – nemlig

Andersen Consulting tilføjer samarbejdsfirmaet HaystackID29.1.2026 21:20:00 CET | Pressemeddelelse

Andersen Consulting styrker sine kompetencer inden for cybersikkerhed og teknologi gennem en samarbejdsaftale med HaystackID, en amerikansk udbyder af eDiscovery, juridiske data og cyber discovery-tjenester. HaystackID blev stiftet i 2011 og arbejder tæt sammen med advokatfirmaer, virksomheder og offentlige myndigheder om at håndtere komplekse, dataintensive juridiske sager, herunder civile retssager, myndighedsundersøgelser og interne undersøgelser. Firmaet leverer komplet processtøtte ved hjælp af cyber discovery, digital efterforskning, managed review, compliance og information governance, hvilket hjælper klienter med at identificere, analysere og forsvarligt fremlægge kritiske data. Ved hjælp af proprietære ai-drevne platforme og ekspertledede reviewteams betjener HaystackID klienter i hele Nordamerika og Europa, heriblandt Fortune 100-virksomheder. "I takt med at de juridiske og regulatoriske miljøer bliver mere datadrevne og tidskritiske, fortsætter vi med at udvikle vores kompet

Convera Appoints Industry Leader Meaghan Riley as Chief Commercial Officer to Scale Commercial Growth and Expand Revenue Opportunities29.1.2026 17:14:00 CET | Press release

Former Google Cloud and SAP executive will build on Convera’s success and leadership in the commercial payments sector Convera, a global leader in commercial payments, today announces the appointment of Meaghan Riley to Chief Commercial Officer, as the company continues its growth trajectory, expands to new markets, and drives scalable revenue opportunities across geographies and sectors. Prior to Convera, Meaghan was Chief Operating Officer for Google Cloud North America, where she led a major go-to-market transformation and launched high-growth segments. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260129799440/en/ Meaghan Riley, Chief Commercial Officer, Convera “Meaghan’s impressive career journey and proven track record brings exceptional experience and unique assets that will strengthen our leadership team at this pivotal moment in Convera’s journey,” said Patrick Gauthier, CEO, Convera. “Meaghan’s leadership will be

New Year, New Solutions: AMRA Medical Continues Commitment to Innovation & Data-Driven Excellence29.1.2026 16:23:00 CET | Press release

AMRA Medical, the global leader in MRI-based fat distribution and muscle composition analytics, is excited to share our brand repositioning supported by the launch of a refreshed website and the introduction of a new tagline, “Insights Within.” This strategic update reflects AMRA’s commitment to placing clients and collaborators at the center of our vision: to be the most trusted, insights-driven imaging partner in the pursuit of preventing and curing disease. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260129457626/en/ The new website provides a more structured and transparent presentation of AMRA’s biomarkers and research services, enabling our partners to have a clear understanding of our offerings, as well as the scientific value and applications of these solutions. For the first time, we’re introducing Imaging Biomarkers and Insights Biomarkers: clearly-defined, intentional offerings that are designed with your trial

NTT DATA Signs Strategic Collaboration Agreement with AWS to Accelerate Enterprise Cloud and Agentic AI Adoption29.1.2026 14:00:00 CET | Press release

NTT DATA, a global leader in AI, digital business and technology services, today announced a multi-year Strategic Collaboration Agreement (SCA) with Amazon Web Services (AWS) to help enterprises modernize legacy systems, adopt agentic AI responsibly and scale innovation across industries. Combining NTT DATA’s expertise in cloud transformation, cloud-native modernization and Agentic AI with the scale and innovation velocity of AWS services, the collaboration will deliver tailored enterprise solutions that modernize mission-critical workloads, build secure cloud foundations and drive measurable business outcomes across regulated and high-growth industries. Under the agreement, NTT DATA and AWS will accelerate enterprise transformation in four priority areas: AI-driven large-scale cloud transformation: Accelerating the migration and modernization of on-premises workloads on AWS, leveraging generative and agentic AI, automation and data platforms to unlock new business models and drive int

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye