Veracode Report Finds 63% of Financial Services Firms Carry Critical Security Debt, Heightening Supply Chain Risk
Veracode, the global leader in application risk management, today released its 2025 State of Software Security (SoSS) Snapshot for the Financial Services Sector. The analysis reveals nearly two-thirds (63 percent) of banking, financial services, and insurance (BFSI) organizations harbor critical security debt—high-severity flaws left unfixed for longer than a year—a rate of 13 percentage points higher than the cross-industry average.
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251029207424/en/
Fig. 1: Financial service sector flaw remediation timeline based on survival analysis
"Trust is everything in financial services, yet our data reveals a silent, growing risk for the sector created by unresolved security debt," said Chris Wysopal, Co-founder & Chief Security Evangelist at Veracode. "With AI-driven attacks surging and compliance requirements tightening, finance leaders must prioritize strategic risk reduction, starting with targeted remediation of critical software flaws.”
Veracode researchers report 77 percent of financial services organizations accrue some level of security debt. With an average flaw half-life of 276 days—the time it takes to remediate 50 percent of all vulnerabilities—it takes the sector nearly a month longer to fix security issues than other industries. Despite modest gains in reducing high-severity flaws, progress has stalled as older, larger applications in the sector continue to accumulate unresolved security risks.
Open-Source Dependency Amplifies Exposure
The report found the supply chain remains a major source of risk. While third-party code represents just 17 percent of total security debt, it accounts for more than 82 percent of critical security debt at financial firms. With open-source flaws requiring 50 percent more time to remediate than first-party code, organizations face mounting exposure amid escalating regulatory pressure. Proactively assessing open-source libraries and avoiding components with known flaws significantly reduces long-term exposure and risk across applications.
Leaders vs. Laggards: Benchmarking AppSec Maturity
The report benchmarks top-performing BFSI enterprises against lower-performing organizations. Industry leaders remediate over 9 percent of open flaws monthly and limit security debt to less than 26 percent of applications, while laggards have debt in 85 percent or more of their applications and stretch fix cycles beyond a year. The gap underscores the importance of continuous code analysis, rapid remediation, and contextual risk-based prioritization with modern, AI-powered tools.
Wysopal concluded, "This report gives finance leaders the data they need to benchmark progress and target resources more effectively. By understanding where critical open-source and legacy risks are concentrated, organizations can move beyond simply finding flaws to strategically fixing the most critical issues, enabling them to protect their customers while innovating securely and with confidence.”
The Veracode 2025 State of Software Financial Services Snapshot is available to read on the Veracode website.
About the State of Software Security Report
The Veracode State of Software Security 2025 is the 15th volume of the report. It analyzed data from companies of all sizes, commercial software suppliers, software outsourcers, and open-source projects. The report contains findings about applications that were subjected to static analysis, dynamic analysis, software composition analysis, and/or manual penetration testing through Veracode’s cloud-based platform. Specifically, the data comes from:
- 1.3M unique applications with 126.4M raw findings
- 107.4M findings identified via SAST scans
- 3.9M findings identified via DAST scans
- 15M findings identified via Software Composition Analysis
About Veracode
Veracode is a global leader in Application Risk Management for the AI era. Powered by trillions of lines of code scans and a proprietary AI-assisted remediation engine, the Veracode platform is trusted by organizations worldwide to build and maintain secure software from code creation to cloud deployment. Thousands of the world’s leading development and security teams use Veracode every second of every day to get accurate, actionable visibility of exploitable risk, achieve real-time vulnerability remediation, and reduce their security debt at scale.
Veracode is a multi-award-winning company offering capabilities to secure the entire software development life cycle, including Veracode Fix, Static Analysis, Dynamic Analysis, Software Composition Analysis, Container Security, Application Security Posture Management, Malicious Package Detection, and Penetration Testing.
Learn more at www.veracode.com, on the Veracode blog, and on LinkedIn and X.
View source version on businesswire.com: https://www.businesswire.com/news/home/20251029207424/en/
Contacts
Media:
Katy Gwilliam
Head of Global Communications, Veracode
kgwilliam@veracode.com
About Business Wire
For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.
www.businesswire.com

Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Bending Spoons to acquire AOL following $2.8B debt financing29.10.2025 17:30:00 EET | Press release
Technology company Bending Spoons today announced that it has entered into a definitive agreement to acquire AOL, the web portal and email provider, from Yahoo. The acquisition is expected to close by the end of the year, subject to customary closing conditions and regulatory approvals. “AOL is an iconic, beloved business that’s in good health, has stood the test of time, and we believe has unexpressed potential,” said Bending Spoons CEO and co-founder, Luca Ferrari. “By our estimation, AOL is one of the top ten most-used email providers in the world, with a highly retained customer base counting around 8 million daily and 30 million monthly active users. We intend to invest significantly to help the product and the business flourish. Bending Spoons has never sold an acquired business—we’re confident we’re the right long-term steward for AOL, and look forward to serving its large, loyal customer base for many years to come.” “AOL and Yahoo share a great deal of history, and our new tea
Doha Debates Questions Whether Modern Architecture Contributes to Cultural Decline29.10.2025 17:15:00 EET | Press release
This week, Qatar Foundation’s Doha Debates examines how architecture reflects and shapes cultural values on their flagship show, Doha Debates. The second episode of the new season asks: Has modern architecture redefined beauty and tradition, or contributed to its decline? This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251029822479/en/ Doha Debates brought together a distinguished group of architects, thinkers, and creatives to question whether modern architecture contributes to cultural decline. From left: Sundus Saeed, Ameer Sadi, Sara Akbar, Carl Jambo, Huda Muazzam Iqbal, Tariq Khayyat, Bidisha Sinha, Dareen Abughaida, Carl W. Korsnes, Marwa Al-Sabouni, Leen Nedal Yamin, Wahed Shaik, Lina Ayman Darwish, Mudassar Raza Shakir, and John Carlos Burog. (Photo: AETOSWire) Moderated by Dareen Abughaida, the debate brings students from across Qatar with experts from around the world: Marwa Al-Sabouni, Syrian architect and author
SK pharmteco and LOTTE BIOLOGICS Sign Strategic Partnership to Strengthen Global ADC CDMO Capabilities29.10.2025 16:35:00 EET | Press release
SK pharmteco and LOTTE BIOLOGICS have announced that they have signed a Letter of Intent (LOI) for a strategic collaboration to strengthen their competitiveness in the global antibody-drug conjugate (ADC) market. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251029483889/en/ Leaders from SK pharmteco and LOTTE BIOLOGICS at the LOTTE BIOLOGICS booth at CPHI Frankfurt, Germany, following the signing of the strategic collaboration Letter of Intent on October 29, 2025. From left to right: Joon Chang, CBO, LOTTE BIOLOGICS; Jiwon Chun, CGO, LOTTE BIOLOGICS; Kern Chang, CTO, LOTTE BIOLOGICS; Yooyeol Shin, CSO, LOTTE BIOLOGICS; James Park, CEO, LOTTE BIOLOGICS; Joerg Ahlgrimm, CEO, SK pharmteco; Andy Fenny, CCO, SK pharmteco; Olivia Boyce, Global Head of Proposals, SK pharmteco; Shiuk Lee, CSO, SK pharmteco; Steve Barr, Head of Small Molecule, SK pharmteco. Through this collaboration, the two companies will jointly investigate prov
Phenom Named Strategic Leader in 2025 Fosway 9-Grid™ for Talent & People Success for Second Consecutive Year29.10.2025 15:30:00 EET | Press release
Phenom, an applied AI company that helps organizations hire faster, develop better and retain longer, has been named a Strategic Leader in the 2025 Fosway 9-Grid™ for Talent and People Success for the second consecutive year, changing their position by demonstrating increased performance for enterprises while lowering the total cost of ownership. The placement is a testament to the value delivered by its AI, automation and experience approach. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251029195746/en/ Phenom has been named a Strategic Leader in the 2025 Fosway 9-Grid™ for Talent and People Success for the second consecutive year, changing their position by demonstrating increased performance for enterprises while lowering the total cost of ownership. The placement is a testament to the value delivered by its AI, automation and experience approach. Fosway Group identifies Strategic Leaders as companies that provide a ric
Andersen Consulting Adds Collaborating Firm Vivaldi29.10.2025 15:30:00 EET | Press release
Andersen Consulting announces a Collaboration Agreement with Vivaldi, a global business and brand strategy consultancy, strengthening the organization’s strategy and business transformation offerings. Founded in 1999, Vivaldi is known for its approach to converge brand, business, and technology to keep clients in their leadership position. Operating in the U.S., Europe, and Latin America, Vivaldi works with leading global companies to build strong market positions, accelerate innovation, and design customer-centric business models. In today’s fast-evolving world shaped by AI, platform dynamics, and continuous reinvention, Vivaldi helps clients reimagine how business value is created and captured. The firm’s multidisciplinary teams blend deep consumer insight and market foresight with strategic, creative, and financial rigor to deliver tailored solutions for growth, transformation, and long-term competitiveness across industries. “Today’s business landscape demands that organizations le
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom