The study, Secure Code Training to Drive Compliance and Build a Secure Development Culture reveals a prevailing prioritisation of speed to market over security within organisations.
Only 20% of respondents express confidence in their ability to detect vulnerabilities before an application release, while over 60% struggle with effective remediation, and 50% fail to test application security post-release.
According to the study, attackers exploit vulnerabilities swiftly, with 25% of vulnerabilities targeted on the day of publication and 75% within 19 days. The data emphasises that securing applications later in their development lifecycle poses a significant risk. About 47% of organisations attribute challenges in remediating vulnerabilities post-production to a lack of qualified personnel.
The survey underscores a reactive approach to security education, with 68% of respondents engaging in secure coding training only due to compliance needs or in response to exploits. This indicates a heavy reliance on tools for vulnerability detection and overburdening security teams rather than investing in long-term human intervention during the development stage.
Key findings also point to a patching crisis. In the year before the study, 54% of respondents suffered security incidents due to unpatched vulnerabilities, with 51% experiencing over eight incidents. Only 11% believe they effectively patch vulnerabilities in a timely manner, while 55% blame misalignment between development, security, and compliance teams for delays in patching.
Joe Ferrera, CEO of Security Journey, commented: “We are seeing a perfect storm of application security risk that will likely drive regulators to become more stringent. While organisations are turning to AppSec tools and AI to secure their outputs, these tools only act as a safety net and knowledgeable human intervention is needed to prevent and remediate insecure code from the outset.
“Organisations need to prioritise education programs that are expertly curated, tailored to roles, and continuously reinforced to ensure knowledge retention.”
Recommended reading
- Which Data Breaches Had Everyone Talking This Year?
- 23andMe Says Breach Victims Are to Blame, Legal Action is Futile
- Report: Over Half of Data Breaches at UK Legal Firms Caused by Insiders
According to the study, only 48% of firms undertake training only annually, bi-annually, or following incidents. Of organisations providing training, over 50% lack customisation to users’ needs.
Additionally, 50% of training providers lack assessments to measure knowledge gain, only 36% teach developers to write secure code, and just 21% educate developers on vulnerability remediation. Less than half (43%) have invested in third-party training.
These statistics underscore a concerning complacency in organisations’ approach to security training, indicating that compliance-driven efforts fall short in building a secure culture or addressing a broader threat landscape in application development. Larry Ponemon, chairman and founder of the Ponemon Institute, expresses deep concern about the current application security landscape, emphasising the need for improved secure coding education in organisations.





