Veracode Report Finds 63% of Financial Services Firms Carry Critical Security Debt, Heightening Supply Chain Risk
Veracode, the global leader in application risk management, today released its 2025 State of Software Security (SoSS) Snapshot for the Financial Services Sector. The analysis reveals nearly two-thirds (63 percent) of banking, financial services, and insurance (BFSI) organizations harbor critical security debt—high-severity flaws left unfixed for longer than a year—a rate of 13 percentage points higher than the cross-industry average.
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251029207424/en/
Fig. 1: Financial service sector flaw remediation timeline based on survival analysis
"Trust is everything in financial services, yet our data reveals a silent, growing risk for the sector created by unresolved security debt," said Chris Wysopal, Co-founder & Chief Security Evangelist at Veracode. "With AI-driven attacks surging and compliance requirements tightening, finance leaders must prioritize strategic risk reduction, starting with targeted remediation of critical software flaws.”
Veracode researchers report 77 percent of financial services organizations accrue some level of security debt. With an average flaw half-life of 276 days—the time it takes to remediate 50 percent of all vulnerabilities—it takes the sector nearly a month longer to fix security issues than other industries. Despite modest gains in reducing high-severity flaws, progress has stalled as older, larger applications in the sector continue to accumulate unresolved security risks.
Open-Source Dependency Amplifies Exposure
The report found the supply chain remains a major source of risk. While third-party code represents just 17 percent of total security debt, it accounts for more than 82 percent of critical security debt at financial firms. With open-source flaws requiring 50 percent more time to remediate than first-party code, organizations face mounting exposure amid escalating regulatory pressure. Proactively assessing open-source libraries and avoiding components with known flaws significantly reduces long-term exposure and risk across applications.
Leaders vs. Laggards: Benchmarking AppSec Maturity
The report benchmarks top-performing BFSI enterprises against lower-performing organizations. Industry leaders remediate over 9 percent of open flaws monthly and limit security debt to less than 26 percent of applications, while laggards have debt in 85 percent or more of their applications and stretch fix cycles beyond a year. The gap underscores the importance of continuous code analysis, rapid remediation, and contextual risk-based prioritization with modern, AI-powered tools.
Wysopal concluded, "This report gives finance leaders the data they need to benchmark progress and target resources more effectively. By understanding where critical open-source and legacy risks are concentrated, organizations can move beyond simply finding flaws to strategically fixing the most critical issues, enabling them to protect their customers while innovating securely and with confidence.”
The Veracode 2025 State of Software Financial Services Snapshot is available to read on the Veracode website.
About the State of Software Security Report
The Veracode State of Software Security 2025 is the 15th volume of the report. It analyzed data from companies of all sizes, commercial software suppliers, software outsourcers, and open-source projects. The report contains findings about applications that were subjected to static analysis, dynamic analysis, software composition analysis, and/or manual penetration testing through Veracode’s cloud-based platform. Specifically, the data comes from:
- 1.3M unique applications with 126.4M raw findings
- 107.4M findings identified via SAST scans
- 3.9M findings identified via DAST scans
- 15M findings identified via Software Composition Analysis
About Veracode
Veracode is a global leader in Application Risk Management for the AI era. Powered by trillions of lines of code scans and a proprietary AI-assisted remediation engine, the Veracode platform is trusted by organizations worldwide to build and maintain secure software from code creation to cloud deployment. Thousands of the world’s leading development and security teams use Veracode every second of every day to get accurate, actionable visibility of exploitable risk, achieve real-time vulnerability remediation, and reduce their security debt at scale.
Veracode is a multi-award-winning company offering capabilities to secure the entire software development life cycle, including Veracode Fix, Static Analysis, Dynamic Analysis, Software Composition Analysis, Container Security, Application Security Posture Management, Malicious Package Detection, and Penetration Testing.
Learn more at www.veracode.com, on the Veracode blog, and on LinkedIn and X.
View source version on businesswire.com: https://www.businesswire.com/news/home/20251029207424/en/
Contacts
Media:
Katy Gwilliam
Head of Global Communications, Veracode
kgwilliam@veracode.com
About Business Wire
For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.
www.businesswire.com

Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Phenom Named Strategic Leader in 2025 Fosway 9-Grid™ for Talent & People Success for Second Consecutive Year29.10.2025 15:30:00 EET | Press release
Phenom, an applied AI company that helps organizations hire faster, develop better and retain longer, has been named a Strategic Leader in the 2025 Fosway 9-Grid™ for Talent and People Success for the second consecutive year, changing their position by demonstrating increased performance for enterprises while lowering the total cost of ownership. The placement is a testament to the value delivered by its AI, automation and experience approach. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251029195746/en/ Phenom has been named a Strategic Leader in the 2025 Fosway 9-Grid™ for Talent and People Success for the second consecutive year, changing their position by demonstrating increased performance for enterprises while lowering the total cost of ownership. The placement is a testament to the value delivered by its AI, automation and experience approach. Fosway Group identifies Strategic Leaders as companies that provide a ric
Andersen Consulting Adds Collaborating Firm Vivaldi29.10.2025 15:30:00 EET | Press release
Andersen Consulting announces a Collaboration Agreement with Vivaldi, a global business and brand strategy consultancy, strengthening the organization’s strategy and business transformation offerings. Founded in 1999, Vivaldi is known for its approach to converge brand, business, and technology to keep clients in their leadership position. Operating in the U.S., Europe, and Latin America, Vivaldi works with leading global companies to build strong market positions, accelerate innovation, and design customer-centric business models. In today’s fast-evolving world shaped by AI, platform dynamics, and continuous reinvention, Vivaldi helps clients reimagine how business value is created and captured. The firm’s multidisciplinary teams blend deep consumer insight and market foresight with strategic, creative, and financial rigor to deliver tailored solutions for growth, transformation, and long-term competitiveness across industries. “Today’s business landscape demands that organizations le
Ferring Pharmaceuticals to Explore Strategic Options for Rebyota ®29.10.2025 15:00:00 EET | Press release
As part of our ongoing transformation to sharpen our focus, we have decided to explore strategic options for Rebyota® (faecal microbiota, live – jslm). To date, more than five thousand patients suffering from recurrent Clostridioides difficile infection (rCDI) have found new hope when treated with Rebyota®. Without commercial critical mass in this therapy area at Ferring, we believe that this first-in-class, innovative product could benefit many more patients with a new approach to its continued commercialisation. As a result, Ferring will reduce commercial efforts in the United States while ensuring uninterrupted access for patients. Approved by the U.S. Food and Drug Administration (FDA) in 2022, Rebyota® was the first FDA-approved faecal microbiota transplant, indicated for the prevention of rCDI in adults following antibiotic treatment for recurrent CDI. This milestone marked a significant advancement in understanding the role of the human microbiome in health and disease. Ferring
GigaDevice GD32F5xx and GD32G5xx Software Test Libraries (STL) Receive TÜV Rheinland IEC 61508 Functional Safety Certification29.10.2025 15:00:00 EET | Press release
GigaDevice, a leading semiconductor company specializing in Flash memory, 32-bit microcontrollers (MCUs), sensors, and analog products, announced that its GD32F5xx and GD32G5xx Software Test Libraries have received IEC 61508 SC3 (SIL 2/SIL 3) functional safety certification from TÜV Rheinland. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251029124621/en/ Certificate This milestone expands GigaDevice’s functional safety portfolio, which already includes the GD32H7 and GD32F30x STLs, and now covers a broad range of MCUs with Arm® Cortex®-M7, Cortex®-M4, and Cortex®-M33 cores. Building on this foundation, GigaDevice will continue to deliver high-performance and safety-focused hardware and software solutions for key applications such as industrial control, energy and power, and humanoid robotics. With the growing emphasis on safety across industries like industrial automation, functional safety has become a critical considerat
375ai Launches Data Layer for the Physical World on Solana29.10.2025 15:00:00 EET | Press release
375ai, an edge data intelligence company transforming the physical world into structured, machine-readable insights, today announced the launch of its mainnet on Solana. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251028976994/en/ 375ai Launches Data Layer for the Physical World The physical world is generating more data than ever before, but most of it is invisible. Traffic systems, advertising platforms, and governments still rely on outdated infrastructure and fragmented data sources to understand how people and goods move through cities. Centralized data pipelines are expensive, slow, and often limited to incomplete or delayed insights. Meanwhile, AI systems are hungry for real world context not just synthetic inputs. Without structured, real time data, they can’t power smarter mobility, logistics, and safety solutions. 375ai enables real world data capture, unlocking a new category of physical AI infrastructure. At l
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom