Many financial firms have high-severity software security flaws over a year old

Autonomous finance
(Image credit: Shutterstock / MK photograp55)

New research from Veracode has revealed over three-quarters (76%) of financial institutions have ‘Security debt’, which it defines as any flaw that has gone unfixed for longer than a year - and shockingly, 50% have ‘critical security debt’ from high severity flaws.

The financial sector is facing a rising number of cyberattacks, and critical infrastructure is proving to be a top target for threat actors.

The average cost of a data breach in the financial sector has hit a staggering $6.08 million, Veracode says - so any security flaw could be costly.

AI driven attacks

Of all applications in the industry, 40% have security debt, but just 5.5% are flaw-free, so the clock is ticking. The flaws primarily come from financial organizations own code (84%), however the critical flaws overwhelmingly come from third party dependencies (78%).

Whilst security teams do fix half of the first-party flaws within nine months, the flaws stick around longer in third party code, only being fixed after an average of 13 months. Of those, only 44% of first party flaws turn into security debt compared to 52% from third parties.

“The high rate of security debt in the financial sector poses significant risks to organizations and their customers if not addressed quickly," said Chris Wysopal, Chief Security Evangelist at Veracode.

“As AI-driven cyber-attacks continue to grow in strength and numbers, and organizations struggle to keep up with evolving regulations due to existing security debt, the current landscape allows threat actors to exploit vulnerabilities at an alarming, unprecedented rate."

This trend is one we’ve seen repeated across the board, with AI changing the cybersecurity landscape on both sides. Cybercriminals show no signs of relenting, so even minor flaws could end up costing your organization millions.

More from TechRadar Pro

Ellen Jennings-Trace
Staff Writer

Ellen has been writing for almost four years, with a focus on post-COVID policy whilst studying for BA Politics and International Relations at the University of Cardiff, followed by an MA in Political Communication. Before joining TechRadar Pro as a Junior Writer, she worked for Future Publishing’s MVC content team, working with merchants and retailers to upload content.

Read more
Hands on a laptop with overlaid logos representing network security
How AI-powered remediation can help tackle security debt
security
The true cost of a security breach
Security padlock in circuit board, digital encryption concept
Rising cost of breaches forces organizations to rethink cybersecurity
Hacker Typing
Racing against time on a menacing caldera: survey finds majority of organizations take days to tackle critical vulnerabilities, each of them a potential open goal for cybercriminals
API
Businesses are being plagued by API security risks - with nearly 99% affected
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Sounding the alarm on AI-powered cybersecurity threats in 2025
Latest in Pro
cybersecurity
What's the right type of web hosting for me?
Security padlock and circuit board to protect data
Trust in digital services around the world sees a massive drop as security worries continue
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
construction
Building in the digital age: why construction’s future depends on scaling jobsite intelligence
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)