Site navigation

Insecure Code Driving Security Vulnerabilities Despite Training

Elizabeth Greenberg

,

insecure code
IT leaders are still positive that security training is effective, despite the amount of vulnerabilities and breaches routed in insecure code. 

About three quarters (74%) of surveyed tech leaders reported experiencing a security breach or serious vulnerability in the past 12 months due to insecure code, research from SecureFlag found.

The organisation surveyed 100 UK c-suite and senior technology leaders to understand how firms approach secure coding training for developers, their benefits and challenges, and if these training efforts are making a tangible difference in security outcomes.

The research found that insecure coding is a major vulnerability across UK organisations, with over half of respondents having a code-related issue in just the last six months.

Still, all surveyed UK enterprises provide a secure coding training for developers, with 85% holding training sessions at least quarterly. Virtually no organisations wait for incidents to train their developers, indicating a proactive approach.

For this training, companies are using a mixed approach, including video tutorials (46%), and interactive eLearning (42%), to live instructor-led sessions (40% virtual, 40% in-person), and hands-on labs (40%).

Companies are even gamifying the training experience, with capture the flag competitions used by about one-third (32%) of organisations.

However, seeing the breaches are consistent despite this training, measuring the return on investment of these training is a top challenge, cited by 40% of leaders.

Leaders also site limited up-to-date content or tools (36%), time constraints (34%) and low developer engagement (30%). About a quarter (24%) of leaders pointed to budgets, with the same amount pointing to a lack of executive support.


Recommended reading


Despite this struggle to measure ROI, nearly nine in ten (89%) organisations are assessing their development teams’ secure coding knowledge within the last year, testing the time to remediate vulnerabilities (60%), the number of vulnerabilities per release (60%), and the reduction in known security flaws (47%).

The research found that the overwhelming majority (92%) of leaders believe secure coding training is effective and has reduced the number of security bugs in development, despite obvious examples of challenges.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data