Veracode Reveals Automation and Training Are Key Drivers of Software Security for Financial Services
25.10.2023 14:50:00 EEST | Business Wire | Press release
Veracode, a leading global provider of intelligent software security, today released new research that unveils the key factors influencing flaw introduction and accumulation in the Financial Services sector. The security performance of financial applications generally outperforms other industries, with automation, targeted security training, and scanning via Application Programming Interface (API) contributing to a year-over-year reduction in the percentage of applications containing flaws.
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20231025298360/en/
Figure 6: Factors Influencing the Number of Flaws Introduced (Graphic: Business Wire)
Against a backdrop of major regulations impacting the financial services sector, including the U.S. Securities and Exchange Commission cybersecurity disclosure rules and the E.U. Digital Operational Resilience Act (DORA), Veracode’s study provides recommendations to reduce risk from software vulnerabilities. While nearly 72 percent of applications in the Financial Services sector contain security flaws, this is the lowest of all industries analyzed and an improvement since last year.
“Financial services made a strong showing across the board in this year’s analysis,” said Chris Eng, Chief Research Officer at Veracode. “Increasing competition and customer expectations, combined with tighter regulations across the industry, have put greater pressure on developers and security teams to find and fix flaws at scale. Moreover, the explosion of AI and Machine Learning has pushed the pace of software development to a new level, leading to the hyperproliferation of flaws. The sector has done well to better its performance, but there is more to be done and financial organizations would benefit from increased automation and secure coding techniques to help them prevent, detect, and respond to vulnerabilities faster than ever.”
API Scanning and Training Lowers Likelihood and Introduction of Flaws
Veracode’s research found Financial Services organizations see stronger effects from the positive elements of scanning via API and security training, compared with the cross-industry average. Scanning via API is a measure of maturity in a software security program, and enterprises that integrate API usage likely have greater automation and control over the development pipeline. In fact, those that leverage scanning via API perform 11 percent better than the baseline probability of non-Financials when it comes to flaw introduction per month. Adding interactive security training into the mix reduces this further, with the two factors combined lowering the chance of flaw introduction by 19 percent per month.
The impact of scanning via API and security training on the number of flaws when they are introduced is even more pronounced. When Financial Services teams completed 10 interactive security training modules, they introduced 26 percent fewer flaws, putting the sector’s performance well above the all-industry average. Similarly launching scans via API had a stronger influence on the number of flaws introduced in Financial Services applications than in other industries.
Eng said, “The data indicates that Financial Services organizations benefit significantly from automation through API usage. Reaching automation is aspirational for many organizations but we see that launching scans via API correlates with a lower probability that flaws will be introduced, and then a reduction in the amount of flaws that do find their way into software. Unsurprisingly, training also has a direct correlation with reduced flaw introduction.”
The Power of AI and Machine Learning
The State of Software Security report also analyzed language preference by vertical and found, at 51 percent, Java is almost a de facto standard within the Financial Services sector. Veracode Fix, an AI-powered remediation tool launched earlier this year, leverages machine learning to generate fixes for 74 percent of Java static findings. Such a dramatic reduction in time and effort empowers organizations to improve security posture and lower risk even further, freeing up capacity for innovation and creation. Moreover, since Java applications are overwhelmingly (>95 percent) comprised of third-party code, Veracode’s data shows the industry benefits of Software Composition Analysis to bolster the safety and integrity of open-source code inclusion.
The Veracode State of Software Security: Financial Services report with full details and recommendations is available to download on the Veracode website.
The full global Veracode State of Software Security 2023 report is available to download here.
About the State of Software Security Report
The 13th edition of Veracode’s annual report on the State of Software Security examines historical trends shaping the software landscape and how security practices are evolving along with those trends. This year’s findings are based on the full historical data available from Veracode services and customers and represent a cross-section of large and small companies, commercial software suppliers, software outsourcers, and open-source projects. The report analyzes data collected from more than 27 million scans across 750,000 applications, and contains findings about applications that were subjected to static analysis, dynamic analysis, software composition analysis, and/or manual penetration testing through Veracode’s cloud-based platform. This new report highlights Financial Services-specific findings against Manufacturing, Retail & Hospitality, Technology, Healthcare, and the Public Sector.
About Veracode
Veracode is intelligent software security. The Veracode Software Security Platform continuously finds flaws and vulnerabilities at every stage of the modern software development lifecycle. Using powerful AI trained on a carefully curated, trusted dataset from experience analyzing trillions of lines of code, Veracode customers fix flaws faster with high accuracy. Trusted by security teams, developers, and business leaders from thousands of the world’s leading organizations, Veracode is the pioneer, continuing to redefine what intelligent software security means.
Learn more at www.veracode.com, on the Veracode blog, and on LinkedIn and Twitter.
Copyright © 2023 Veracode, Inc. All rights reserved. Veracode is a registered trademark of Veracode, Inc. in the United States and may be registered in certain other jurisdictions. All other product names, brands or logos belong to their respective holders. All other trademarks cited herein are property of their respective owners.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20231025298360/en/
Contact information
Katy Gwilliam
kgwilliam@veracode.com
About Business Wire
For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Enry’s Island Unveils “Enry’s Island Adventures”: Venture Capital Becomes a Videogame and Launches the “Strap” Movement on Kickstarter3.4.2026 10:47:00 EEST | Press release
Enry’s Island SpA (WBAG: EIOS), the world’s first publicly traded Venture Builder, today announced the upcoming Kickstarter launch of Enry’s Island Adventures (EIA), developed by its New York-based portfolio company, Enry’s Island Adventures LLC. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260402548535/en/ The game is designed to make venture capital accessible to new generations, transforming startup creation into an engaging and social gaming experience. After three years of R&D, EIA introduces a "bleisure" model (business + leisure): players learn to launch and manage startups through gameplay that includes real business KPIs, a customizable and evolving personal island, synchronous and asynchronous multiplayer modes, social events, and community-driven seasonal missions. The “VC revolution”: teaching and democratizing through play "I agree with Elon Musk that the best way to teach is through a video game, and this is
SES Announces Results of the Annual General Meeting2.4.2026 17:49:00 EEST | Press release
SES (the “Company”) held the Annual General Meeting (“AGM”) of Shareholders today in Betzdorf, Luxembourg. Following the recommendations made by the Board of Directors of SES, the shareholders have voted in favor of all resolutions, including the Company’s 2025 annual accounts and the proposed annual dividend of EUR 0.50 per A-share (EUR 0.20 per B-share). The total dividend amount comprises the interim dividend of EUR 0.25 per A-share (EUR 0.10 per B-share), which has already been paid to shareholders on October 16, 2025. The final dividend of EUR 0.25 per A-share (EUR 0.10 per B-share) will be paid to shareholders on April 16, 2026. “I would like to sincerely thank our shareholders for their active engagement, visionary support and continued confidence in SES’ strategy,” said Adel Al-Saleh, CEO of SES. “The outcomes of today’s AGM underscore our shared commitment to a bold multi-orbit approach, with Medium Earth Orbit as the strategic backbone of a dynamically evolving global interco
Forrester: Three Years Into GenAI, Enterprises Are Still Chasing Its True Transformative Value2.4.2026 17:00:00 EEST | Press release
According to Forrester’s (Nasdaq: FORR) latest report, Accelerate Your AI Voyage, most enterprises are struggling to turn growing AI adoption and investment into measurable business impact. One of the key factors holding businesses back is low artificial intelligence quotient (AIQ) — Forrester’s measure of AI aptitude — with many employees lacking a clear understanding of how to use AI. Other barriers include an overemphasis on productivity-focused use cases, difficulty measuring impact, and siloed adoption within individual functions. While these challenges can leave firms frozen in doubt or indecision, the wait-and-see approach to AI adoption is no longer viable. To unlock AI’s full potential, organizations need to focus on four key areas: Define the business outcomes and success metrics for what they want AI to achieve; identify specific use cases for AI deployment aligned to those business outcomes; establish a structured runway to plan, test, and strategically time the deployment
Andersen Consulting Adds Multiplica2.4.2026 16:30:00 EEST | Press release
Andersen Consulting enters into a Collaboration Agreement with Multiplica, a digital consulting firm that helps organizations design, build, and scale impactful digital experiences. Founded in Spain with a presence in Latin America and the U.S., Multiplica focuses on user research and discovery, customer experience research, digital strategy, data modeling and analysis, report automation and data visualization, conversion rate optimization, product design, and user experience design. The firm helps organizations accelerate digital transformation by building digital capabilities, teams, and assets that advance expertise across digital products, consulting, and talent development. Multiplica enables clients to forecast emerging trends in digital experience and transform their businesses through enhanced digital channels and customer engagement. “Collaborating with Andersen Consulting represents an exciting opportunity to extend our reach and impact,” said David Boronat, CEO of Multiplica
Brightfin Unifies Brand Following Proven Optics Merger, Delivering a New Standard for Technology Cost Optimization2.4.2026 16:00:00 EEST | Press release
Brightfin today announced that, following its merger with Proven Optics, the combined company will operate under a single brand: Brightfin. The unified company brings together deep expertise in Technology Expense Management (TEM) and IT Financial Management (ITFM) to help organizations better understand, manage, and reduce total technology spend. Technology spending will exceed $6 Trillion this year, and for most organizations, it remains one of the least understood. CIOs can tell you what they’re spending. Far fewer can tell you whether it’s working. “Over the past several months, we’ve brought these two businesses together around a shared purpose: help enterprise businesses better understand and optimize their technology spend,” said Joel Martins, CEO of Brightfin. “What we are seeing now is a shift. Visibility alone isn’t enough. Teams need to be able to act, tied to real financial outcomes. See Clearly. Spend Better. That is our north star, and that is what our platform is built to
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
