Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Study & Research - Global Research Reveals 40 Per Cent Of Businesses Implement Security Testing At The Programming Stage
Study & Research

Global Research Reveals 40 Per Cent Of Businesses Implement Security Testing At The Programming Stage

ISBuzz TeamBy ISBuzz TeamDecember 22, 20164 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Independent research commissioned by Veracode highlights improvements made in secure development, as well as areas for future improvements in secure application delivery

LONDON, United Kingdom. Veracode, a leader in securing the world’s software, today announced compelling insight from a survey of global developers and development managers on the current state of software security. The report underscores the importance of developer-led security in the age of DevOps, and showed that businesses are recognising the importance of securing applications. Despite showing moves toward earlier and more frequent security testing throughout the development process, the survey results also indicated there are still hurdles development and security teams must overcome when it comes to securing applications.

Increased recognition, earlier testing

According to the survey, 40 per cent of developers are incorporating securing testing during the programming stage, and 21 per cent identify the design stage as the point at which security testing is completed. Testing early in the development process finds security defects in code at the point where it is the least costly to fix the defects.

The survey also shows that developers are recognising the importance of securing applications. 39 per cent of developers responded that their number one concern is protecting applications from cyberattacks and data breaches. Traditionally, developers were not focused on securing applications, and this shift in mindset helps explain the new emphasis on early testing reported in the survey.

Improving for the future

Despite the fact developers recognise the importance of securing software and the need for early security testing, areas for improvement remain. Developers are still dealing with security programmes that impede their development efforts. The report, which included respondents from the US, UK and Germany, also showed that that 52 per cent of developers feel application security testing often delays development and threatens deadlines. And, fewer than 25 per cent of developers feel they have authority over decisions regarding application security.

This lack of authority and impact of development timelines has the potential to decelerate the strides made in improving application security and making security part of the development process.

“In an age where continuous deployment and frequent innovation is critical to the success of business, it is unacceptable for security testing to hinder development efforts,” said Tim Jarrett, director of Security at Veracode. “As DevOps environments become a standard method of developing software, the industry has an opportunity to continuously improve the way it integrates security into the development proces.”

For more information on the data, please visit: https://info.veracode.com/report-veracode-developer-survey.html

Additional data points:

  • Sensitive data exposure is top concern: 52 per cent of developers and managers cited sensitive data exposure as their top concern. This includes credentials and PII such as health data. Broken authentication and session management was the second concern at 37 per cent.
  • Regional differences: In Germany and the UK, 40 per cent of developers, and 38 per cent of development managers said stopping cyberattacks and breaches was their top concern, while in the US, the opposite was true: more development managers (42 per cent) than developers (34 per cent) listed this as their top concern.
  • Budget and delivery schedules: In Germany and the UK, 26 per cent of managers said meeting budget and delivery schedules was their top concern, versus just 18 per cent of development managers in the US.
  • Healthcare prioritises compliance: Developers and managers in the healthcare industry cited meeting customer and regulatory compliance as their top concern.
  • Despite risk, open-source is of little concern: Veracode’s recent SOSS Report showed that 97 per cent of Java applications had at least one component with a known vulnerability, yet the survey results showed that only 28 per cent said that using components with known vulnerabilities was a major concern.
  • Financial services and manufacturing late to the game: 11 per cent of financial services and 16 per cent of manufacturing companies said they incorporated security later in the development cycle.

Methodology

The survey was conducted on behalf of Veracode in September 2016. An independent research organization surveyed mid-level and senior software developers as well as development operations managers in a wide range of industries with a particular focus on financial services, architecture and engineering firms, education, healthcare and manufacturing.

A total of 351 developers completed the survey. Of the total, 230 were US-based, 60 were from the UK and 61 were from Germany. For development operations managers, 151 people responded with 50 in the US, 50 in the UK, and 51 in Germany.

Respondents were dispersed among mid-sized businesses and large enterprises. Companies were broken down into three categories: 500 to 999 employees, 1,000 to 4,999 employees and more than 5,000 employees.

[su_box title=”About Veracode” style=”noise” box_color=”#336588″][short_info id=’60239′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

AppSec is dead, long live AI security

April 29, 20265 Mins Read

Managing App Access on Frontline Devices in an Always-On World

March 9, 20264 Mins Read

OWASP Top 10 2025: New Enemies, Old Foes, and an Approach to Vulnerability Remediation That Must Evolve

January 22, 20265 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}