Research: Imperfect People, Vulnerable Applications
Our latest study with Osterman Research explores the human elements that influence cyber risk in the Software Development Lifecycle. We found that 81% of developers have knowingly released vulnerable applications. Discover the factors that are contributing to the vulnerability epidemic. A hazardous disconnect exists between front-line staff and their managers Many front-line developers do not…
Our latest study with Osterman Research explores the human elements that influence cyber risk in the Software Development Lifecycle. We found that 81% of developers have knowingly released vulnerable applications.
Discover the factors that are contributing to the vulnerability epidemic.
A hazardous disconnect exists between front-line staff and their managers
Many front-line developers do not see security as their responsibility. Their senior managers disagree but are clearly failing to build a culture of ownership around security.
Under-resourced and overworked teams are struggling to shift left
Security and development teams do not have sufficient time and resources to support the necessary “shift left,” address prioritized vulnerabilities, or even work together effectively on the development of secure applications.
Information sharing and training lags behind a dynamic attack environment
Security teams feel their understanding of the latest vulnerabilities and application attacks is lacking, as is that of development teams. Training is delivered too infrequently to keep pace with a dynamic threat environment.
Security teams have little faith in the SDLC
Only a minority of security teams believe their application build environment could withstand an attack similar to SolarWinds, with confidence low in application security as a whole.
Latest Blog posts
Patch Newsday: 14 September 2021 – Lousy Browsers and Arsey RCEs Edit
15 September 2021
Analyzing the CVE-2021-40444 exploit
13 September 2021
Take the power back: Tool-up against a notorious global threat group with our new FIN7 series
13 September 2021
Episode 44: Rotten Apple or Privacy Nuts?
2 September 2021
Patch Newsday 10 August: Ironic exploitation and the spectre of PrintNightmare
10 August 2021
Kaseya supply chain attack: Prepare to respond with the Cyber Crisis Simulator
27 July 2021