About three quarters (74%) of surveyed tech leaders reported experiencing a security breach or serious vulnerability in the past 12 months due to insecure code, research from SecureFlag found.
The organisation surveyed 100 UK c-suite and senior technology leaders to understand how firms approach secure coding training for developers, their benefits and challenges, and if these training efforts are making a tangible difference in security outcomes.
The research found that insecure coding is a major vulnerability across UK organisations, with over half of respondents having a code-related issue in just the last six months.
Still, all surveyed UK enterprises provide a secure coding training for developers, with 85% holding training sessions at least quarterly. Virtually no organisations wait for incidents to train their developers, indicating a proactive approach.
For this training, companies are using a mixed approach, including video tutorials (46%), and interactive eLearning (42%), to live instructor-led sessions (40% virtual, 40% in-person), and hands-on labs (40%).
Companies are even gamifying the training experience, with capture the flag competitions used by about one-third (32%) of organisations.
However, seeing the breaches are consistent despite this training, measuring the return on investment of these training is a top challenge, cited by 40% of leaders.
Leaders also site limited up-to-date content or tools (36%), time constraints (34%) and low developer engagement (30%). About a quarter (24%) of leaders pointed to budgets, with the same amount pointing to a lack of executive support.
Recommended reading
- The Biggest LLMs Are Generating Vulnerable Code by Default
- AI Drives Risky Business: Over 80% of Organisations Ship Vulnerable Code
- Is the UK Lagging Behind in Global AI Race?
Despite this struggle to measure ROI, nearly nine in ten (89%) organisations are assessing their development teams’ secure coding knowledge within the last year, testing the time to remediate vulnerabilities (60%), the number of vulnerabilities per release (60%), and the reduction in known security flaws (47%).
The research found that the overwhelming majority (92%) of leaders believe secure coding training is effective and has reduced the number of security bugs in development, despite obvious examples of challenges.





