Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security

September 21st, 2012, 20:50 GMT · By

Report: 51% of Web App Developers Experienced Security Incidents in Last 18 Months

SHARE:

Adjust text size:

Coverity released The Software Security Risk Report
Enlarge picture
A study commissioned by Coverity Inc - "The Software Security Risk Report” - reveals the details of application security incidents experienced by North American and European web app development companies in the last 18 months.

The figures from the report show that 51% of the respondents had at least one incident in the past one and a half year. 18% of these firms reported losses of over $500,000 (400,000 EUR), while 8% claim to have lost twice as much. In a few situations, the affected organizations lost over $10 million (8 million EUR).

Respondents said business demands and code volumes forced them to put security to the side. Over 70% of them state that they don’t have funds and the right technology in order to address security issues.

Furthermore, the numbers reveal that 41% blame time-to-market pressure for not being able to push security into development.

It appears that secure development practices aren’t employed by too many web app creators. Only 42% follow secure coding guidelines and only around a quarter use threat modeling or a library of approved and banned functions.

Code auditing before integration testing is performed by less than half of the interviewed companies and only 17% of them verify their products during development.

“It's clear that security practitioners and developers aren't speaking the same language when it comes to application security, and this is leading to very costly consequences for companies,” Jennifer Johnson, VP of marketing at Coverity, explained.

“Application security begins and ends with development. Developers need to be part of the solution but the industry won't solve the problem until security is incorporated into the development process with technologies and processes that developers can understand and adopt. Force-feeding development with legacy tools built for security teams just isn't working.”


1,772 hits
Link to this article · Print article · Send to friend

MUST-READ RELATED ARTICLES:


Users of Mobile Portals Exposed to HTTP Header Pollution Attacks, Expert Finds

GlobalSign Customers Protected Against Phishing Attacks with Netcraft Technology

Australia to Test Law Enforcement Officers by Planting False Information

German Users Warned of IE Zero-Day Attacks, Told to Turn To Other Browsers

TrustGo Appoints Google Play as Fifth Safest App Market

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM