Business Wire

Veracode Research Highlights Financial Sector’s Escalating Security Debt

Share

Veracode, a global leader in application risk management, today released new research that highlights the state of software security debt within the financial services sector. Security debt, defined for this report as flaws that remain unfixed for longer than a year, exists in 76 percent of organizations in the financial services sector, with 50 percent of organizations carrying critical security debt.

This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20241029540325/en/

Figure 1: Prevalence of security debt in the financial sector (Graphic: Business Wire)

With the average cost of a data breach in the financial industry estimated to be $6.08 million1, the research comes at a critical time for one of the most highly targeted industries by sophisticated threat actors. According to a U.S. Treasury Department report in March 2024, threat actors use AI-based tools to find and exploit software vulnerabilities at an unprecedented rate. At the same time, increasing industry competition and customer expectations for convenience require organizations to accelerate innovation.

“The high rate of security debt in the financial sector poses significant risks to organizations and their customers if not addressed quickly. As AI-driven cyber-attacks continue to grow in strength and numbers, and organizations struggle to keep up with evolving regulations due to existing security debt, the current landscape allows threat actors to exploit vulnerabilities at an alarming, unprecedented rate,” said Chris Wysopal, Chief Security Evangelist at Veracode. “Our latest State of Software research highlights the critical need for financial institutions to address both first-party and third-party code vulnerabilities now. Organizations that leave flaws unremedied for longer than a year are exposed to prolonged and dangerous threats.”

Delayed Flaw Remediation Threatens Financial Sector Security

Veracode researchers found 40 percent of all applications in the financial sector have security debt, which is slightly better than the cross-industry average of 42 percent. In addition, just 5.5 percent of financial sector applications are flaw-free, compared to 5.9 percent across other industries. While slightly fewer financial sector applications have security debt, they accumulate more of it.

The report also highlights the need for financial services organizations to address security debt in both first-party and third-party code. Eighty-four percent of all security debt affects first-party code, but the majority (78.6 percent) of critical security debt comes from third-party dependencies. This reinforces the importance of the Cybersecurity and Infrastructure Security Agency’s efforts to help secure the open-source ecosystem with its Open Source Software Security Roadmap and Secure by Design Pledge.

The analysis further explores remediation timelines in the financial services sector. Researchers found that financial organizations fix half of first-party flaws in the first nine months, compared to 13 months for third-party flaws. Of those, 52 percent of third-party flaws turn into security debt, while 44 percent of first-party flaws turn into security debt.

The Importance of Prioritization in Risk Remediation

The proliferation of supply chain attacks targeting the financial services industry has brought about a growing number of cybersecurity regulations with a sharper focus on software security. For example, regulatory frameworks like the ISO 20022, the Payment Card Industry Data Security Standard (PCI DSS), NIS2, and the Digital Operational Resilience Act (DORA) require organizations to prevent vulnerabilities from being deployed in applications.

This puts organizations at risk of non-compliance because of existing security debt and outdated remediation strategies. Veracode’s research reveals that organizations can address this risk by prioritizing the 3.3% of flaws that constitute critical security debt. Remediating the most dangerous flaws first means financial entities can then move on to tackle other critical flaws or non-critical debt according to their risk tolerance and capabilities.

The Role of Application Security Posture Management

The increased need for risk prioritization creates a significant demand for Application Security Posture Management (ASPM) to continuously track risk through the collection, visibility and analysis of security issues across the software development cycle. Veracode's Application Risk Management Platform provides a comprehensive, unified view of risk across code and applications, empowering developers and security teams to remediate issues swiftly. With the AI-powered solution, Veracode Fix, teams can proactively prevent new vulnerabilities and effectively reduce existing security backlogs. The platform’s contextual analysis uncovers root causes, guiding developers toward optimal next steps that maximize risk reduction with minimal effort.

Wysopal closed, “It has never been more important for the financial services sector to stay ahead of evolving cybersecurity threats, particularly with increasingly sophisticated AI-driven attacks threatening the security of their assets. I urge financial institutions to prioritize timely security debt reduction by adopting AI-powered remediation and ASPM tools which can detect, prioritize and fix vulnerabilities within seconds.”

The Veracode State of Software Security Financial Services 2024 report is available to read on the Veracode website.

1 IBM, “Cost of a Data Breach Report 2024”, IBM and Ponemon Institute, July 30, 2024

About the State of Software Security Report
The Veracode State of Software Security 2024 report analyzed data from large and small companies, commercial software suppliers, software outsourcers, and open-source projects. The research draws from more than a million (1,007,133) applications across all scan types, 1,553,022 dynamic analysis scans, and 11,429,365 static analysis scans. All those scans produced 96 million raw static findings, 4 million raw dynamic findings, and 12.2 million raw software composition analysis findings.

About Veracode
Veracode is a global leader in Application Risk Management for the AI era. Powered by trillions of lines of code scans and a proprietary AI-assisted remediation engine, the Veracode platform is trusted by organizations worldwide to build and maintain secure software from code creation to cloud deployment. Thousands of the world’s leading development and security teams use Veracode every second of every day to get accurate, actionable visibility of exploitable risk, achieve real-time vulnerability remediation, and reduce their security debt at scale. Veracode is a multi-award-winning company offering capabilities to secure the entire software development life cycle, including Veracode Fix, Static Analysis, Dynamic Analysis, Software Composition Analysis, Container Security, Application Security Posture Management, and Penetration Testing.

Learn more at www.veracode.com, on the Veracode blog, and on LinkedIn and X.

Copyright © 2024 Veracode, Inc. All rights reserved. Veracode is a registered trademark of Veracode, Inc. in the United States and may be registered in certain other jurisdictions. All other product names, brands or logos belong to their respective holders. All other trademarks cited herein are property of their respective owners.

View source version on businesswire.com: https://www.businesswire.com/news/home/20241029540325/en/

Contacts

For more information, please contact:
Katy Gwilliam
kgwilliam@veracode.com

About Business Wire

For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.

www.businesswire.com

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Fujirebio Receives Marketing Clearance for Lumipulse ® G pTau 217/ β-Amyloid 1-42 Plasma Ratio In-vitro Diagnostic Test as an Aid to Identify Patients With Amyloid Pathology Associated With Alzheimer’s Disease17.5.2025 09:58:00 EEST | Press release

Fujirebio today announced that the U.S. Food and Drug Administration (FDA) has granted 510(k) clearance for the company’s Lumipulse® G pTau 217/β-Amyloid 1-42 Plasma Ratio in-vitro diagnostic (IVD) test for the assessment of amyloid pathology in patients being evaluated for Alzheimer’s disease and other causes of cognitive decline. The test, which was granted Breakthrough Device Designation by the FDA, is the first FDA cleared blood-based IVD test in the U.S. to aid to identify patients with amyloid pathology associated with Alzheimer’s Disease (AD). Alzheimer’s disease currently affects an estimated 7.2 million Americans, a number projected to rise to nearly 14 million by 2060.1 It is a leading cause of disability and death. AD develops over many years, long before symptoms are evident, but the lack of accessible, minimally invasive diagnostics results in many patients remaining undiagnosed until the disease is well advanced, when few effective interventions remain. The Lumipulse G pT

IFF Announces Pricing of Tender Offers For Certain Outstanding Series of Notes17.5.2025 00:17:00 EEST | Press release

IFF (NYSE: IFF) announced today the Total Consideration (as defined below) payable in connection with its previously announced tender offers to purchase for cash: (i) up to $1,100,000,000 aggregate purchase price, excluding accrued and unpaid interest (the “Amended Pool 1 Maximum Amount”), of its 1.230% Senior Notes due 2025 (the “2025 Notes”), 1.832% Senior Notes due 2027 (the “2027 Notes”), 4.450% Senior Notes due 2028 (the “2028 Notes”) and 2.300% Senior Notes due 2030 (the “2030 Notes” and collectively with the 2025 Notes, the 2027 Notes and the 2028 Notes, the “Pool 1 Notes”) and (ii) up to $900,000,000 aggregate purchase price, excluding accrued and unpaid interest (the “Amended Pool 2 Maximum Amount” and, together with the Amended Pool 1 Maximum Amount, the “Amended Maximum Amounts”), of its 3.268% Senior Notes due 2040 (the “2040 Notes”), 4.375% Senior Notes due 2047 (the “2047 Notes”), 5.000% Senior Notes due 2048 (the “2048 Notes”) and 3.468% Senior Notes due 2050 (the “2050

Origins Launches in the U.S. Amazon Premium Beauty Store16.5.2025 16:00:00 EEST | Press release

Origins, with over 30 years of expertise in combining naturally-derived and scientifically crafted ingredients for powerful skincare, announced its official debut in the U.S. Amazon Premium Beauty store today. Origins will offer its iconic skincare and body care products along with giftable sets that are perfect for any occasion. Origins will now bring naturally-derived, effective beauty to Amazon customers nationwide with convenience and thoughtful gifting in mind. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250516435958/en/ This launch marks a strategic step in Origins’ ongoing efforts to meet the evolving needs of skincare shoppers, seeking high-performance, conscious beauty on their favorite platforms. By expanding to the U.S. Amazon Premium Beauty store, Origins reinforces its commitment to delivering both efficacy and accessibility to even more consumers. Amazon customers will now be able to discover and purchase Or

The smarter E Europe 2025: Studies, Technologies and Market Trends for the Energy System of Tomorrow16.5.2025 13:47:00 EEST | Press release

Exactly one week has passed since The smarter E Europe closed its doors in Munich. Once again, Europe’s largest alliance of exhibitions for the energy industry turned the Bavarian capital into the epicenter of the global energy sector and impressed with outstanding results. Over the course of three days, 2,737 exhibitors from 57 countries showcased their technologies, business models and market-ready solutions for an intelligent, interconnected and fully renewable energy system. Around 107,000 professionals from 157 nations took the opportunity to connect, initiate partnerships and launch new projects. The accompanying conferences and side events also attracted strong interest, drawing more than 2,600 participants. The message sent out by The smarter E Europe and its four exhibitions – Intersolar Europe, ees Europe, Power2Drive Europe and EM-Power Europe – was clear: We are the energy system. This press release features multimedia. View the full release here: https://www.businesswire.c

IFF Announces Early Tender Results and Increase of Tender Offers for Certain Outstanding Series of Notes16.5.2025 13:30:00 EEST | Press release

IFF (NYSE: IFF) announced today the early tender results for its tender offers to purchase for cash certain of its outstanding series of Notes. IFF also announced it has increased the previously announced Pool 1 Maximum Amount (as defined below) from $1,000,000,000 to $1,100,000,000 (the “Amended Pool 1 Maximum Amount”), the Pool 2 Maximum Amount (as defined below) from $800,000,000 to $900,000,000 (the “Amended Pool 2 Maximum Amount”, and together with the Amended Pool 1 Maximum Amount, the “Amended Maximum Amounts”), the 2027 Series Tender Cap (as defined below) from $300,000,000 to $400,000,000 and the 2050 Series Tender Cap (as defined below) from $600,000,000 to $649,114,000. The 2025 Notes Series Tender Cap and the 2040 Notes Series Tender Cap (each as defined below) remain unchanged at $500,000,000 and $450,000,000, respectively. Details of tender offers IFF initially offered to purchase for cash: (i) up to $1,000,000,000 aggregate purchase price, excluding accrued and unpaid in

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye