Business Wire
Welcome
  • Log In
  • Sign Up
Search News:
Help
http://www.denimgroup.com
January 06, 2010 08:30 AM Eastern Daylight Time 

Denim Group Provides Guidance on Application Security Trends for 2010

Denim Group Sees Shifts in the Application Security Landscape with New Applications Resulting in New Attack Vectors, Security Problems with HTML 5, Shift to Business Logic Attacks, and More

SAN ANTONIO--(BUSINESS WIRE)--Denim Group, an IT consultancy and strong contributor to the larger application security community, announced today that it foresees shifts in the application security landscape this year. As a trusted advisor to many Fortune 500 and large public sector organizations, the firm has just announced its guidance on the top application security trends for 2010:

“How Are We Going to Fix These Vulnerabilities?”

1. Web “Mashup” Applications Will Result in New Attack Vectors: Web applications integrating data and functionality from multiple systems are becoming increasingly more common. Unfortunately, threat models for these "mashup" applications are rarely performed, and when they are, they are rarely understood. The accelerated pace of change for software security is moving much faster than the security practitioners' ability to provide meaningful guidance to application development teams.

2. New Data Breaches Will Force Organizations to Focus on Internal Applications as Well as External: Most organizations incorrectly assume they only need to worry about external security, but publicly-revealed data breaches of internal applications have shown that an internal network is no longer a safe haven. In 2009, known breaches caused by malicious insiders resulted in the compromise of over 1.5 million records according DataLossDB.org. What is not known is the extent of incidents that were concealed or went unreported.

3. Adoption of HTML 5 and Other New Technologies Will Cause Developers to Inadvertently Build Vulnerable Applications: HTML 5 has a variety of new capabilities that can erode previously established security controls. While developers are building more ambitious applications using these new capabilities, many development teams will not consider the associated security risks of exposure of HTML-based 5 web applications until after their deployment.

4. Resurgence of Risk Management: Many organizations have postponed spending on software security during the recession at a potentially huge cost. As the economy improves, organizations will refocus on risk management rather than merely meeting compliance requirements.

5. Organizations Will Finally Start Asking, “How Are We Going to Fix These Vulnerabilities?” Security teams will shift their focus from finding vulnerabilities to working with development teams and actually fixing them. Forward-thinking organizations will treat application vulnerabilities as software defects and will leverage existing software development and maintenance practices within the organization in order to resolve security vulnerabilities.

6. Security and Development Teams Will Have Increasing Interactions: Increasing dialogue between security and application development teams will lead to improved decision-making, which incorporates risk management and understanding of the overall value of the enterprise.

7. Organizations Will Move Beyond Scan-Only Approaches to Application Security: Initial approaches to application security were often solely focused on automated scans of applications or code to identify technical vulnerabilities. However, targeted attackers are shifting their focus to business logic attacks on applications, and leading organizations will start to incorporate more manual testing and code reviews in order to respond to the these new realities.

8. The Application Security Market Will Continue Consolidating: Further consolidation of product vendors will provide product suites with a more comprehensive range of capabilities and consistent approach. Global system integrators will identify software security as a gap in their services and will try to solve the problem through acquisition.

9. Organizations Deploying Web Application Firewalls Will Increasingly Use Them for Virtual Patching: Virtual patching involves creating targeted rules for a web application firewall based on specific known vulnerabilities. Organizations will increase their use of this practice to provide interim protection while code-level fixes are implemented.

10. Application Security Metrics Will Provide a Foundation for Decision-Making: As enterprises increase the sophistication of their application security programs, standard metrics will evolve for costs for finding and resolving vulnerabilities as well as timeframes required to fix vulnerabilities. Forward-looking firms in more mature industries will begin sharing anonymized data to support benchmarking efforts.

“In the past, organizations have been doing what’s easy as opposed to what’s important, and that’s going to cost them in the long run,” said John Dickson, Principal of Denim Group. “For example, studies have shown that 1-3% of employees in an organization are bad apples that are prone to steal internal data, and it’s naïve to think that isn’t the case with your enterprise. As more security breaches happen – both internally and externally – organizations will realize that point solutions are not going to provide the increased application security they require, and to successfully confront the issue they will have to address it throughout the software development lifecycle.”

About Denim Group

Denim Group, an IT consultancy specializing in custom software development, systems integration, and application security, serves a national and international client base of Fortune 500, commercial and public sector organizations in industries including financial services, banking, insurance, healthcare and defense. With over 40 years experience in large-scale software development projects and information security, the principals are recognized experts in their fields and founded the San Antonio chapter of the Open Web Application Security Project (OWASP). Denim Group has been included in the 2008 Inc. 5000 list of the fastest-growing private companies in America, ranked 1101. The San Antonio Business Journal recognized Denim Group as the Fastest Growing Company in San Antonio in 2006 and as one of the Best Places to Work in 2007. For more information about Denim Group, visit www.denimgroup.com.

Reader Contact Information:

Denim Group, 3463 Magic Drive, Suite 315; San Antonio, TX 78229, Tel: 210-572-4400, Fax: 210-572-4401, www.denimgroup.com, john@denimgroup.com.

Contacts

Agency:
Alan Weinkrantz, 210-820-3070
alan@weinkrantz.com
or
Denim Group
John Dickson, 210-572-4400
john@denimgroup.com

http://www.denimgroup.com

Release Versions

  • EON: Enhanced Online News

Company Information Center

Denim Group RSS feed for Denim Group

Share

  • Facebook
  • Twitter
  • LinkedIn
  • Delicious
  • Reddit
  • StumbleUpon
  • Digg
  • MySpace
  • Newsvine
  • Google Bookmark
  • Yahoo! Bookmark
  • EmailEmail
Tweet
  • EmailEmail
All News
Business Wire
  • Home
    • Home
    • Membership Benefits
    • Submit a Press Release
  • News
    • All News
    • News with Multimedia
    • News by Industry
    • News by Subject
    • News by Language
    • RSS Feeds
    • Business Wire Mobile
    • Features
    • Company NewsCenters
    • Company Profiles
    • Annual Reports
  • Events
    • Trade Shows & Events
    • Earnings & Conference Calls
    • Business Wire Events
  • PR Services
    • Press Release Distribution
    • Distribution Lists
    • Industry Targeting
    • LatinoWire & Ethnic Media
    • Public Policy Wire
    • Trade Show Services
    • Photos & Multimedia Marketing
    • GloMoSoMe
    • Press Release Measurement
    • Mobile Alerts
    • Clips & Research
    • Fax & Email Services
    • Online Newsrooms
    • News Feeds
  • IR Services
    • Material News Disclosure
    • XBRL
    • EDGAR (US)
    • IPO Services
    • SEDAR (Canada)
    • European Disclosure
    • Corporate Social Responsibility (CSR)
    • Investor Targeting
    • Fax & Email Services
    • Online Investor Centers
    • IR Resource Center
  • SEO Services
    • Press Release Optimization
    • EON: Enhanced Online News
    • Webinars & Resources
  • Journalist Tools
    • PressPass: Your News
    • Conduct Surveys
    • Business Wire News Feeds
    • Business Wire News On Your Website
    • Journalism Associations
  • Support & Education
    • FAQ
    • How to Write a Press Release
    • How To Optimize a Press Release for Search
    • How to Distribute a Press Release
    • Find Your News Online
    • Sample Press Release
    • Features News Tips
    • International Media Tips
    • SEC Regulations
    • Exchange Guidelines
    • White Papers
    • Webinars & Podcasts
    • Get WiredIn!
  • About Us
    • Business Wire Newsroom
    • Contact Us
    • History
    • Jobs
  • About Us
  • Contact Us
  • Site Map
  • Privacy Statement
  • Terms of Use
  • ©2012 Business Wire

More Business Wire sites

  • Canada
  • UK/Ireland
  • Deutschland
  • France
  • Italy
  • Japan
  • EON: Enhanced Online News
  • Tradeshownews.com
  • PYMNTS.com

About Us

  • Business Wire Newsroom
  • Contact Us
  • Business Wired blog

News on BusinessWire.com

  • All News
  • RSS Feeds
  • Business Wire Mobile Apps

Follow Us on Twitter

  • @BusinessWire
  • @BWSportsWire
  • @BWPolitics
  • @BWCSRNews
  • @EONpr
  • @TradeshowNews
  • @BW_Canada
  • @BWIntlMedia
  • @BWInfoDiva
  • @BusinessWireFR
  • @BWLatinoWire

Like Us on Facebook

  • Business Wire
  • Tradeshow News