Research Reveals Global Growth of Secure DevOps
New research from Secure Code Warrior ®, the global secure coding company, has revealed an attitudinal shift in the software development industry, with organisations bucking traditional practices for DevOps and Secure DevOps.
The global survey of professional developers and their managers found seven in 10 organisations (70%) recognise the importance of secure coding practices, with results indicating an industry-wide shift from reaction to prevention is underway.
Dr. Matias Madou, Chief Technology Officer and Co-Founder at Secure Code Warrior, said, “We are seeing a fundamental shift in mindsets across the world, as the industry slowly moves from reactive, band-aid solutions rolled out after a breach, to the proactive and human-led practice of writing quality software that is intrinsically free from vulnerabilities right from the very first keystroke.”
“This research shows that ‘secure code’ is becoming synonymous with ‘quality code’ within software development, and security is becoming the responsibility of development teams and leaders—not just AppSec professionals,” he said.
Secure coding seen as ‘reactive’
Reactive practices like using tools on deployed applications and manually reviewing code for vulnerabilities were the top two practices respondents associated with coding securely. However, a proactive shift in mindset was evidenced across the globe, with more than half (55%) of the developers surveyed also recognising secure coding as the active, ongoing practice of writing software protected from vulnerabilities.
Managers and developers are misaligned
Over half (55%) of managers surveyed said secure coding was practised and integrated throughout the entire development process, compared to only 43% of developers. Conversely, 36% of developers consider secure coding during development but not the design phase, as opposed to under one-third (32%) of managers.
Secure code an increasing indicator of success
While those surveyed identified ‘application performance’ and ‘functionality and features’ as the most common success metrics within software development (67% and 62% respectively), almost four in five (79%) respondents said the importance of ‘secure code’ was growing in prominence.
Application security is shifting
Almost half of respondents (46%) said development leads and teams should be responsible for application security rather than AppSec teams (24%). Over eight in 10 (81%) developers surveyed said they were accountable for any vulnerable code produced.
Developers motivated to upskill
‘Increased productivity and efficiency’, ‘curiosity’ and ‘avoiding problems caused by insecure code’ were identified as the leading intrinsic motivators to learn secure coding (20%, 14% and 11% respectively). Despite only 10% of respondents listing career advancement as a personal motivator, four in five (81%) managers were more likely to hire talent with secure coding skills.
More training is needed
91% of managers surveyed said they faced greater than average difficulty when implementing secure coding practices within their organisation, despite the overwhelming majority of respondents (97%) believing they were sufficiently trained. Perhaps, this is because almost nine in 10 (88%) developers surveyed said coding securely was challenging.
Madou added, “With OWASP’s Top 10 software vulnerabilities causing more security breaches over the past two decades than any others, now is the time for businesses to upskill developers to gain the knowledge and skills needed to stamp out insecure code and prevent issues from occurring in the first place.”
“Code is at the heart of everyday interactions, and Secure Code Warrior is focused on championing security-skilled developers who can create amazing, safe software for our connected world.”
To gain early access to the report, ‘Shifting from reaction to prevention: The changing face of application security 2021’, register your interest at scw.buzz/earlyaccess
Methodology
Secure Code Warrior® commissioned Evans Data Corporation, the market intelligence leader within the IT industry, to conduct a global survey of developers and decision-makers actively engaged in software development. In August 2020, 400 respondents were surveyed across North America, India, the United Kingdom, Europe, Australia, New Zealand and South-East Asia.
About Secure Code Warrior
Secure Code Warrior is the developer-chosen solution for growing powerful secure coding skills. By making secure coding a positive and engaging experience for developers as they increase their software security skills, our human-led approach uncovers the secure developer inside every coder, helping development teams ship quality code faster.
Through inspiring a global community of security-conscious developers to embrace a preventative secure coding approach, our mission is to pioneer a people-first solution to security upskilling, stamping out poor coding patterns for good. Learn more at securecodewarrior.com.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20210323006113/en/
Contact information
For media enquiries, to access the full report or arrange an interview:
Carly Ryan, Hotwire
E: securecodewarrior@hotwireglobal.com
About Business Wire
For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Transition Industries Signs Strategic Agreements for the Pacifico Mexinol Project, the Largest Standalone Ultra-Low Carbon Chemical Production Facility in the World30.6.2025 21:30:00 EEST | Press release
Transition Industries LLC, a developer of world-scale, net-zero carbon emissions methanol and green hydrogen projects in North America, held a signing event for an Engineering, Procurement, and Construction (EPC) contract with the consortium of Samsung E&A Co., Ltd. (Samsung E&A), Grupo Samsung E&A Mexico, S.A. de C.V., and Techint Engineering and Construction for the Pacifico Mexinol project located in Ahome, Sinaloa, Mexico, which is contingent upon the fulfillment of customary conditions precedent and obtainment of all required approvals. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250630940954/en/ MAIRE group’s technology division NextChem, through its subsidiary KT TECH SpA, also signed a Basic Engineering, Critical and Proprietary Equipment Supply Agreement with Samsung E&A in connection with its proprietary NX AdWinMethanol®Zero technology supply to the project. Transition Industries is jointly developing the Pacif
Westinghouse and ITER Sign a $180M Contract to Advance Nuclear Fusion30.6.2025 16:45:00 EEST | Press release
Westinghouse Electric Company and ITER signed a contract for $180 million for the assembly of the vacuum vessel for the fusion reactor. This is a key milestone in the construction of the ITER reactor, leading the way toward the use of fusion as a practical future source of reliable carbon-free energy. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250630497810/en/ The ITER Tokamak pit with the two vacuum vessel sector modules installed. Westinghouse has participated in the fabrication of the sectors of the vacuum vessel, as part of the Fusion for Energy (F4E) Consortium with its partners Ansaldo Nucleare and Walter Tosto. Westinghouse will be responsible for completing the vacuum vessel which is ITER’s most critical component: a hermetically sealed, double-walled steel container that will house the fusion plasma. When all the vacuum vessel sectors are in place, Westinghouse will start the most intensive stage of ITER assembl
Monetate Acquires SiteSpect to Deliver AI-Native Personalization and Testing at Enterprise Scale30.6.2025 16:00:00 EEST | Press release
Monetate, the leading AI-driven personalization platform, today announced it has acquired SiteSpect, a leader in A/B testing, to drive next-generation digital experience optimization. This acquisition accelerates Monetate’s vision to deliver intelligent, intentional, and individualized experiences at scale, powered by agentic AI and backed by the industry’s most advanced, enterprise-grade infrastructure. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250630514541/en/ The combination of Monetate’s real-time personalization and SiteSpect’s zero-flicker testing will yield an industry-first solution for enterprise-grade personalization, testing, and optimization. For the first time, global ecommerce and digital experience leaders can access unified client-side and server-side experimentation with full personalization capabilities in a single solution, designed for scalability and regulatory compliance. Monetate is now the only e
SS&C Blue Prism Recognized as a Gartner® Magic Quadrant™ RPA Leader for the Seventh Consecutive Year30.6.2025 16:00:00 EEST | Press release
SS&C Technologies Holdings, Inc. (Nasdaq: SSNC) today announced that SS&C Blue Prism has been recognized as a Leader in the 2025 Gartner Magic Quadrant for Robotic Process Automation (RPA). “We’re delighted SS&C Blue Prism has been named a Leader in the Gartner Magic Quadrant for Robotic Process Automation for the seventh year running,” said Bill Stone, CEO and Chairman of SS&C Technologies. “SS&C Blue Prism combines market-leading RPA and orchestration technologies with the latest artificial intelligence so organizations can tackle more complex tasks and dynamic business processes. We’ve scaled to more than 2,700 digital workers and AI agents across our own operations, resulting in over $200 million in annual savings. With SS&C leading the charge on deployment, customers can be confident in rolling out SS&C’s automation solutions securely, effectively, and responsibly.” More than 2,800 companies worldwide leverage SS&C Blue Prism for AI-powered automation, helping organizations delive
Takeda Announces U.S. FDA Approval of GAMMAGARD LIQUID ERC, the Only Ready-to-Use Liquid Immunoglobulin Therapy with Low Immunoglobulin A (IgA) Content 130.6.2025 15:00:00 EEST | Press release
Takeda(TSE:4502/NYSE:TAK) today announced that the U.S. Food and Drug Administration (FDA) has approved GAMMAGARD LIQUID ERC [immune globulin infusion (human)] with less than or equal to 2 µg/mL IgA in a 10% solution, the only ready-to-use liquid immunoglobulin (IG) therapy with low immunoglobulin A (IgA) content, as replacement therapy for people two years of age and older with primary immunodeficiency (PI). As a ready-to-use liquid, GAMMAGARD LIQUID ERC may help ease the administration burden for patients and their health care providers by eliminating the need for reconstitution and can be administered intravenously or subcutaneously.1 “The approval of GAMMAGARD LIQUID ERC reinforces our commitment to supporting individualized treatment approaches for people with primary immunodeficiency, including a therapeutic option that has the lowest IgA content of any ready-to-use liquid immunoglobulin therapy, and can be administered intravenously or subcutaneously,” said Kristina Allikmets, s
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom