Web application security breaches effect more than one in two businesses

Web application security breaches effect more than one in two businesses
Web application breaches cause huge losses

A new research study into web application, has found serious security concerns with the applications produced by web developers, including multimillion pound security breaches and a complete lack of security in the underlying code.

The survey, of 240 North American and European software development influencers from companies that develop web applications sponsored by development testing business Coverity and conducted by analysts Forrester found over half (51%) of all developers had at least one web application security incident in the last 18 months resulting in loses in the millions – with two businesses admitting to losses of over £6 million.

Among those reporting incidents, 18 per cent put their losses at more than £308,000 while another eight per cent saw losses in excess of £0.6 million.

Nearly three-quarters (71%) of those who experienced a breach said they lack the right security technologies suitable for development, and their security can't keep up with the volume of code they produce (79%), and that they lack the funding to invest in security (71%).

Just over a third (42%) of respondents said they follow secure coding guidelines, and only 28 per cent use a library of approved or banned functions and barely a quarter utilise threat modelling, a most surprisingly only 17 per cent said they test code during the development cycle.

The bad news for businesses is that those involved with security and the developers can't decide on who is to blame for this situation. According to the developers surveyed, the top three challenges to working with current web application security tools include; the lack of integration with their current development environment, the need for too much security expertise and high false positives. By comparison, some security practitioners agreed that integration was a primary challenge, but none believed security tools were complex or required too much expertise to use

"It's clear that security practitioners and developers aren't speaking the same language when it comes to application security, and this is leading to very costly consequences for companies," said Jennifer Johnson, VP of Marketing at Coverity. "Application security begins and ends with development. Developers need to be part of the solution but the industry won't solve the problem until security is incorporated into the development process with technologies and processes that developers can understand and adopt. Force-feeding development with legacy tools built for security teams just isn't working."

Latest in Security
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
Major ransomware attack sees Tata Technologies hit - 1.4TB dataset with over 730,000 files allegedly stolen
Security
Broadcom releases fixes for multiple VMware security flaws
A graphic showing fleet tracking locations over a city.
Lost & Found tracking site hit by major data breach - over 800,000 could be affected
US President Donald Trump speaks to the press as he signs an executive order to create a US sovereign wealth fund, in the Oval Office of the White House on February 3, 2025, in Washington, DC.
US set to pause cyber-offensive operations against Russia - but CISA says it won't stop
Web DDoS attacks see major surge as AI allows more powerful attacks
Polish space agency says it was hit by a cyberattack
Latest in News
The Samsung Galaxy Ring in Titanium Silver
A future Samsung Galaxy Ring could have a feature to stop you burning yourself on your morning coffee
The maps feature of the Strava app open on an iPhone 15 Pro
Strava does a u-turn as users are allowed to post external links again
CorelDraw Go homepage showing design examples
Adobe arch-rival unveils online graphic design tool for beginners - and yes, it has a subscription
Android Auto
Android Auto is about to get a big Gemini upgrade – and there's good news and bad news
Tony Hawk's Pro Skater 3+4 promo image featuring the Doom Slayer glaring at Tony
Tony Hawk's Pro Skater 3+4 is real and the Digital Deluxe Edition literally turns it into a Doom game
Ada Lovelace as a leader in Civilization 7.
Sid Meier's Civilization 7 update 1.1.0 finally stops AI leaders from flooding your territory with armies of explorers