Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Study & Research - Government Sector Ranked Last in Remediating Web and Mobile Application Vulnerabilities
Study & Research

Government Sector Ranked Last in Remediating Web and Mobile Application Vulnerabilities

ISBuzz TeamBy ISBuzz TeamJune 29, 2015Updated:April 30, 20256 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Web and Mobile Application Vulnerabilities
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Veracode’s 2015 State of Software Security Report benchmarks risk profile for 34 industries across seven vertical markets

Veracode, a leader in protecting enterprises from today’s pervasive web and mobile application threats, released the 2015 State of Software Security report that reveals concerning benchmark analytics from its cloud-based platform. The reports shows that web and mobile applications  produced or used by government organisations are more likely than those in other industries to fail standard security policies like the OWASP Top 10 when initially assessed for risk.

Veracode’s analytics also show that government organisations only remediate 27 percent of application vulnerabilities once detected – last among the seven vertical markets analysed. Moreover, government applications have the highest prevalence of SQL Injection vulnerabilities – commonly used to steal sensitive data from databases – upon initial assessment. In contrast, financial services and manufacturing ranked best across most categories, with healthcare, retail and hospitality near the bottom.

As organisations increasingly rely on software to drive their businesses, the threat surface available to cyberattackers has dramatically expanded. As a result, one of the leading causes of data breaches over the past two years has been vulnerable applications, according to Verizon’s 2015 Data Breach Investigations Report. Yet, analytics collected from more than 200,000 application risk assessments over the last 18 months found a wide disparity in how the problem is addressed across industries.

Organised into seven vertical markets for simplified benchmarking – government, financial services, retail and hospitality, technology, manufacturing, healthcare and other – Veracode’s 2015 State of Software Security Report reveals that:

  • Reliance on outdated programming languages has hamstrung government security. The government ranks last among vertical markets, with three out of four government applications failing the OWASP Top 10 when initially assessed for risk. Part of the reason for this is that many government agencies still use older programming languages such as ColdFusion which are known to produce more vulnerabilities.
  • The financial services and manufacturing industries’ attention to software security pays off. In contrast to the government sector, organisations in financial services and manufacturing more proactively remediate the majority of their vulnerabilities (65 and 81 percent respectively). These results appear to indicate a higher institutional awareness of application security risk and a stronger emphasis on enforcing enterprise-wide policies, monitoring key performance indicators (KPIs) and instituting continuous improvement processes.
  • Healthcare organisations fare poorly. Given the large amount of sensitive data collected by healthcare organisations, it’s concerning that 80 percent of healthcare applications exhibit cryptographic issues such as weak algorithms upon initial assessment. In addition, healthcare fares near the bottom of the pack when it comes to addressing remediation, with only 43 percent of known vulnerabilities being remediated.
  • Significant risk is introduced by the software supply chain. Nearly three out of four applications produced by third-party software vendors and SaaS suppliers fail the OWASP Top 10 when initially assessed.

Significant Impact of Remediation Coaching Services

The data also shows that remediation coaching services have a big impact on reducing application-layer risk. Development organisations that leverage Veracode’s remediation coaching services improve the security of their code by a factor of two and a half times compared to those that choose to do it on their own. Delivered by world-class security and development experts, these on-demand services help developers understand secure coding practices and remediate vulnerabilities more quickly and efficiently.

“Every industry faces the challenge of securing web and mobile applications – which are continuously growing in both volume and complexity – across disparate and geographically-distributed development teams,” said Chris Wysopal, Veracode CISO and CTO.  “In 2014, we helped our customers identify and remediate 4.7 million vulnerabilities, significantly reducing enterprise risk. This report clearly shows that industries that ‘get it’ have been able to achieve substantial success while others still struggle to manage the problem at scale.”

Enhanced Analytics for Improved Risk Visibility

To help customers address the challenge of benchmarking disparate development teams and drive continuous improvement across both in-house and externally-sourced code, Veracode has recently enhanced its built-in security analytics capabilities with a new business intelligence (BI) engine. The new analytics engine – integrated with Veracode’s central cloud-based platform – gives customers an instant view of their risk posture and the current status of their global application security programmes.

In particular, the self-service data mart can be queried to provide customisable views of key metrics such as scanning volume, compliance with corporate policies, and remediation status, simplifying the creation of management-level dashboards.  Built-in comparison charts allow benchmarking by business unit or development team; by severity of vulnerabilities and business criticality of applications; and by third-party software vendor.

The new analytics capability also makes it easier for multiple stakeholders across the organisation – including management, security, development and internal audit professionals – to collaborate and share information using consistent policies and metrics, to drive towards better software security.

The full State of Software Security report can be found HERE

Methodology

The State of Software Security draws on continuously-updated information from Veracode’s cloud-based platform. Unlike a survey, the data comes from actual code-level analysis of billions of lines of code uploaded to the platform by our customers, across a range of industries and geographies.

This report captures data collected over the past 18 months from 208,670 application scans performed via our cloud-based platform. It summarises information about applications produced by organisations from 34 different industries that we have organised into seven vertical markets.

[su_box title=”About Veracode” style=”noise” box_color=”#336588″]

Veracode is a leader in securing web, mobile and third-party applications for the world’s largest global enterprises.  By enabling organizations to rapidly identify and remediate application-layer threats before cyberattackers can exploit them, Veracode helps enterprises speed their innovations to market – without compromising security.Veracode’s powerful cloud-based platform, deep security expertise and systematic, policy-based approach provide enterprises with a simpler and more scalable way to reduce application-layer risk across their global software infrastructures.Veracode serves hundreds of customers across a wide range of industries, including nearly one-third of the Fortune 100, three of the top four U.S. commercial banks and more than 20 of Forbes’ 100 Most Valuable Brands.[/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

AppSec is dead, long live AI security

April 29, 20265 Mins Read

Managing App Access on Frontline Devices in an Always-On World

March 9, 20264 Mins Read

OWASP Top 10 2025: New Enemies, Old Foes, and an Approach to Vulnerability Remediation That Must Evolve

January 22, 20265 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}