Business Wire

Veracode Reveals Automation and Training Are Key Drivers of Software Security for Financial Services

Share

Veracode, a leading global provider of intelligent software security, today released new research that unveils the key factors influencing flaw introduction and accumulation in the Financial Services sector. The security performance of financial applications generally outperforms other industries, with automation, targeted security training, and scanning via Application Programming Interface (API) contributing to a year-over-year reduction in the percentage of applications containing flaws.

This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20231025298360/en/

To view this piece of content from mms.businesswire.com, please give your consent at the top of this page.

Figure 6: Factors Influencing the Number of Flaws Introduced (Graphic: Business Wire)

Against a backdrop of major regulations impacting the financial services sector, including the U.S. Securities and Exchange Commission cybersecurity disclosure rules and the E.U. Digital Operational Resilience Act (DORA), Veracode’s study provides recommendations to reduce risk from software vulnerabilities. While nearly 72 percent of applications in the Financial Services sector contain security flaws, this is the lowest of all industries analyzed and an improvement since last year.

“Financial services made a strong showing across the board in this year’s analysis,” said Chris Eng, Chief Research Officer at Veracode. “Increasing competition and customer expectations, combined with tighter regulations across the industry, have put greater pressure on developers and security teams to find and fix flaws at scale. Moreover, the explosion of AI and Machine Learning has pushed the pace of software development to a new level, leading to the hyperproliferation of flaws. The sector has done well to better its performance, but there is more to be done and financial organizations would benefit from increased automation and secure coding techniques to help them prevent, detect, and respond to vulnerabilities faster than ever.”

API Scanning and Training Lowers Likelihood and Introduction of Flaws

Veracode’s research found Financial Services organizations see stronger effects from the positive elements of scanning via API and security training, compared with the cross-industry average. Scanning via API is a measure of maturity in a software security program, and enterprises that integrate API usage likely have greater automation and control over the development pipeline. In fact, those that leverage scanning via API perform 11 percent better than the baseline probability of non-Financials when it comes to flaw introduction per month. Adding interactive security training into the mix reduces this further, with the two factors combined lowering the chance of flaw introduction by 19 percent per month.

The impact of scanning via API and security training on the number of flaws when they are introduced is even more pronounced. When Financial Services teams completed 10 interactive security training modules, they introduced 26 percent fewer flaws, putting the sector’s performance well above the all-industry average. Similarly launching scans via API had a stronger influence on the number of flaws introduced in Financial Services applications than in other industries.

Eng said, “The data indicates that Financial Services organizations benefit significantly from automation through API usage. Reaching automation is aspirational for many organizations but we see that launching scans via API correlates with a lower probability that flaws will be introduced, and then a reduction in the amount of flaws that do find their way into software. Unsurprisingly, training also has a direct correlation with reduced flaw introduction.”

The Power of AI and Machine Learning

The State of Software Security report also analyzed language preference by vertical and found, at 51 percent, Java is almost a de facto standard within the Financial Services sector. Veracode Fix, an AI-powered remediation tool launched earlier this year, leverages machine learning to generate fixes for 74 percent of Java static findings. Such a dramatic reduction in time and effort empowers organizations to improve security posture and lower risk even further, freeing up capacity for innovation and creation. Moreover, since Java applications are overwhelmingly (>95 percent) comprised of third-party code, Veracode’s data shows the industry benefits of Software Composition Analysis to bolster the safety and integrity of open-source code inclusion.

The Veracode State of Software Security: Financial Services report with full details and recommendations is available to download on the Veracode website.

The full global Veracode State of Software Security 2023 report is available to download here.

About the State of Software Security Report

The 13th edition of Veracode’s annual report on the State of Software Security examines historical trends shaping the software landscape and how security practices are evolving along with those trends. This year’s findings are based on the full historical data available from Veracode services and customers and represent a cross-section of large and small companies, commercial software suppliers, software outsourcers, and open-source projects. The report analyzes data collected from more than 27 million scans across 750,000 applications, and contains findings about applications that were subjected to static analysis, dynamic analysis, software composition analysis, and/or manual penetration testing through Veracode’s cloud-based platform. This new report highlights Financial Services-specific findings against Manufacturing, Retail & Hospitality, Technology, Healthcare, and the Public Sector.

About Veracode

Veracode is intelligent software security. The Veracode Software Security Platform continuously finds flaws and vulnerabilities at every stage of the modern software development lifecycle. Using powerful AI trained on a carefully curated, trusted dataset from experience analyzing trillions of lines of code, Veracode customers fix flaws faster with high accuracy. Trusted by security teams, developers, and business leaders from thousands of the world’s leading organizations, Veracode is the pioneer, continuing to redefine what intelligent software security means.

Learn more at www.veracode.com, on the Veracode blog, and on LinkedIn and Twitter.

Copyright © 2023 Veracode, Inc. All rights reserved. Veracode is a registered trademark of Veracode, Inc. in the United States and may be registered in certain other jurisdictions. All other product names, brands or logos belong to their respective holders. All other trademarks cited herein are property of their respective owners.

To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.

Contact information

Katy Gwilliam
kgwilliam@veracode.com

About Business Wire

For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Reply Announces the Jury for the First AI Music Contest: Finalists Will Perform Live on Stage at Kappa FuturFestival in Turin23.5.2025 11:05:00 EEST | Press release

Reply, an international group specialized in the creation of new business models enabled by Artificial Intelligence and driven by a strong culture of innovation, is expanding its creative experimentation initiatives this year with the launch of the AI Music Contest. Organised in collaboration with Kappa FuturFestival, one of Europe’s leading electronic music festivals, the competition is open to creatives and innovators who use AI technologies to explore new forms of integration between sound and visuals. It aims to enhance the expressive potential of artificial intelligence in live performances. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250523250887/en/ The jury members include prominent figures such as Seth Troxler and DJ Tennis, who are renowned DJs and producers known for their pioneering use of AI in live performances. Also on the panel is Albertino, a DJ, radio host and the artistic director of Radio m2o. Alongsid

Kioxia Holdings Corporation Wins IPO of the Year Award in the Equity Category at the DealWatch Awards 202423.5.2025 10:00:00 EEST | Press release

Kioxia Holdings Corporation (TOKYO:285A), a world leader in memory solutions, today announced that it had won the IPO of the Year award in the Equity category at the DealWatch Awards 2024, organized by DealWatch, the most authoritative source of real-time intelligence for deal activity within Japan's capital markets. The award was presented at a ceremony held on May 20. The DealWatch Awards recognize outstanding issuers of bonds or equities in the Japanese capital market, as well as Japanese issuers who have conducted offerings overseas, and the securities firms that manage these transactions. The awards for 2024 comprised six categories: Overall, Bonds, Local Government Bonds, Cross-Border Bonds, Sustainable Finance, and Equity. Selection is based on criteria such as the appropriateness of pricing in the issuance market, price formation after transition to the trading market, contribution to the development of capital markets, and innovative efforts, with the awards designed to promot

Generix Named in the 2025 Gartner® Magic Quadrant™ for Warehouse Management Systems (WMS) for the Seventh Consecutive Year23.5.2025 10:00:00 EEST | Press release

Generix, a global business software company offering an expansive portfolio of SaaS solutions for supply chain, finance, commerce, and B2B integration, today announces it has been recognized by Gartner in the 2025 Gartner® Magic Quadrant™ for Warehouse Management Systems (WMS). This is the seventh consecutive year that Generix has been recognized for its portfolio of WMS Solutions. Designed to scale as supply chain operations grow from simple to complex flows, Generix WMS and Solochain WMS are currently in more than 2,000 warehouses globally. “We are honored to be recognized in the Gartner® Magic Quadrant™ WMS for the seventh consecutive year. Generix continues its commitment to providing WMS for every warehousing need at a global scale. With our two recognized WMS solutions, Generix WMS and Solochain WMS, we continue to innovate to better serve customer needs with the introduction of industry game-changing AI use-cases such as resource planning and computer vision,” said Si-Mohamed Sa

NuORDER by Lightspeed and Mandatory Renew Partnership to Power Hybrid Commerce at the Third Edition of the Copenhagen Event23.5.2025 10:00:00 EEST | Press release

Mandatory and NuORDER by Lightspeed, the industry’s leading B2B commerce platform, are joining forces for the third consecutive time to power the digital extension of Mandatory’s in-person trade event, taking place August 5–7 in Copenhagen. This renewed partnership reflects the continued momentum behind hybrid commerce—where physical and digital trade intersect to create smarter, more flexible buying experiences. As the Nordic fashion ecosystem expands with energy and innovation, Mandatory has become a magnet for trendsetting brands and forward-looking retailers. On NuORDER’s wholesale platform, buyer activity from Nordic-region retailers surged by 39.4% year over year in Q1 2025 (January to March). "Retailers in the Nordic region have been quick to adopt digital tools to enhance the efficiency of their buying processes. The increase in buyer activity on the NuORDER platform early this year clearly indicates a growing market demand and a renewed engagement within the industry," said Ch

Curatis discloses Corticorelin as active substance of C-PTBE-0123.5.2025 08:00:00 EEST | Press release

An epidemiological market study commissioned by Curatis Holding AG (SIX:CURN, “Curatis”) shows that the target patient group is substantially larger than previous estimates. In the US alone, over 150,000 patients suffer from peritumoral brain edema in association with malignant tumors. In previous clinical studies, human corticorelin (C-PTBE-01), demonstrated significant benefits in the treatment of PTBE. “The prospect of developing a potential blockbuster drug with that can contribute significantly to the quality of life of many patients, combined with the potential of maintaining the efficacy of immunotherapies for these patients, is very motivating and exciting,” said Dr. Roland Rutschmann, Curatis CEO. Key statements Corticorelin (hCRH), a 41 amino acid endogenous polypeptide, has demonstrated the ability to positively impact the blood-brain barrier after a disruption due to the underlying malignant tumor. Curatis intends to develop corticorelin to treat PTBE in primary and metasta

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye