-

Research Reveals Global Growth of Secure DevOps

Secure Code Warrior report identifies application security is shifting from reaction to prevention as developers are held to account

BOSTON & SYDNEY & LONDON & BRUGES, Belgium & PORTLAND, Ore.--(BUSINESS WIRE)--New research from Secure Code Warrior®, the global secure coding company, has revealed an attitudinal shift in the software development industry, with organisations bucking traditional practices for DevOps and Secure DevOps.

The global survey of professional developers and their managers found seven in 10 organisations (70%) recognise the importance of secure coding practices, with results indicating an industry-wide shift from reaction to prevention is underway.

Dr. Matias Madou, Chief Technology Officer and Co-Founder at Secure Code Warrior, said, “We are seeing a fundamental shift in mindsets across the world, as the industry slowly moves from reactive, band-aid solutions rolled out after a breach, to the proactive and human-led practice of writing quality software that is intrinsically free from vulnerabilities right from the very first keystroke.

This research shows that ‘secure code’ is becoming synonymous with ‘quality code’ within software development, and security is becoming the responsibility of development teams and leaders—not just AppSec professionals,” he said.

Secure coding seen as ‘reactive’

Reactive practices like using tools on deployed applications and manually reviewing code for vulnerabilities were the top two practices respondents associated with coding securely. However, a proactive shift in mindset was evidenced across the globe, with more than half (55%) of the developers surveyed also recognising secure coding as the active, ongoing practice of writing software protected from vulnerabilities.

Managers and developers are misaligned

Over half (55%) of managers surveyed said secure coding was practised and integrated throughout the entire development process, compared to only 43% of developers. Conversely, 36% of developers consider secure coding during development but not the design phase, as opposed to under one-third (32%) of managers.

Secure code an increasing indicator of success

While those surveyed identified ‘application performance’ and ‘functionality and features’ as the most common success metrics within software development (67% and 62% respectively), almost four in five (79%) respondents said the importance of ‘secure code’ was growing in prominence.

Application security is shifting

Almost half of respondents (46%) said development leads and teams should be responsible for application security rather than AppSec teams (24%). Over eight in 10 (81%) developers surveyed said they were accountable for any vulnerable code produced.

Developers motivated to upskill

‘Increased productivity and efficiency’, ‘curiosity’ and ‘avoiding problems caused by insecure code’ were identified as the leading intrinsic motivators to learn secure coding (20%, 14% and 11% respectively). Despite only 10% of respondents listing career advancement as a personal motivator, four in five (81%) managers were more likely to hire talent with secure coding skills.

More training is needed

91% of managers surveyed said they faced greater than average difficulty when implementing secure coding practices within their organisation, despite the overwhelming majority of respondents (97%) believing they were sufficiently trained. Perhaps, this is because almost nine in 10 (88%) developers surveyed said coding securely was challenging.

Madou added, “With OWASP’s Top 10 software vulnerabilities causing more security breaches over the past two decades than any others, now is the time for businesses to upskill developers to gain the knowledge and skills needed to stamp out insecure code and prevent issues from occurring in the first place.

Code is at the heart of everyday interactions, and Secure Code Warrior is focused on championing security-skilled developers who can create amazing, safe software for our connected world.”

To gain early access to the report, ‘Shifting from reaction to prevention: The changing face of application security 2021’, register your interest at scw.buzz/earlyaccess

Methodology

Secure Code Warrior® commissioned Evans Data Corporation, the market intelligence leader within the IT industry, to conduct a global survey of developers and decision-makers actively engaged in software development. In August 2020, 400 respondents were surveyed across North America, India, the United Kingdom, Europe, Australia, New Zealand and South-East Asia.

About Secure Code Warrior

Secure Code Warrior is the developer-chosen solution for growing powerful secure coding skills. By making secure coding a positive and engaging experience for developers as they increase their software security skills, our human-led approach uncovers the secure developer inside every coder, helping development teams ship quality code faster.

Through inspiring a global community of security-conscious developers to embrace a preventative secure coding approach, our mission is to pioneer a people-first solution to security upskilling, stamping out poor coding patterns for good. Learn more at securecodewarrior.com.

Contacts

For media enquiries, to access the full report or arrange an interview:
Carly Ryan, Hotwire
E: securecodewarrior@hotwireglobal.com

Secure Code Warrior

Details
Headquarters: Sydney, Australia
CEO: Pieter Danhieux
Employees: 200
Organization: PRI

Release Summary
Research from Secure Code Warrior® shows attitudinal shifts in the software development industry as organisations embrace secure coding practices.

Contacts

For media enquiries, to access the full report or arrange an interview:
Carly Ryan, Hotwire
E: securecodewarrior@hotwireglobal.com

Social Media Profiles
More News From Secure Code Warrior

Secure Code Warrior Unveils SCW Trust Score to Quantify Developer Team Security Posture

SAN FRANCISCO--(BUSINESS WIRE)--Secure Code Warrior, the global, developer-driven security leader, today unveiled SCW Trust Score, the industry’s first benchmark that quantifies the security posture of organizations’ developer teams. SCW Trust Score provides a vital baseline of the impact of their learning programs, assesses its effectiveness, and enables security, developer and engineering teams to more effectively collaborate and recalibrate skills training. The demand for faster application...

Secure Code Warrior’s Agile Learning Platform Empowers Netskope Developers to Code Cloud Solutions at Scale

BOSTON & LONDON & SYDNEY--(BUSINESS WIRE)--Secure Code Warrior, the global, developer-driven security leader, today announced that Netskope, a global SASE leader, launched its developer training program through Secure Code Warrior’s agile learning platform. Thousands of customers trust Netskope and its powerful NewEdge network to address evolving threats, new risks, technology shifts, organizational and network changes, and new regulatory requirements. Its global developer team plays an integra...

Secure Code Warrior to Host 3rd Annual Devlympics Competition

SYDNEY--(BUSINESS WIRE)--Secure Code Warrior, the global, developer-driven security leader, today announced that it will host its third annual Devlympics secure coding competition on October 17-18, 2023. Devlympics is a free tournament that welcomes developers from all over the world and levels of expertise to participate in coding challenges. The winner will be crowned, “The Ultimate Warrior” and receive recognition and prizes. Hosted on Secure Code Warrior’s agile learning platform, developer...
Back to Newsroom