Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking & Finance Review®

Global Banking & Finance Review® - Subscribe to our newsletter

Company

    GBAF Logo
    • About Us
    • Advertising and Sponsorship
    • Profile & Readership
    • Contact Us
    • Latest News
    • Privacy & Cookies Policies
    • Terms of Use
    • Advertising Terms
    • Issue 81
    • Issue 80
    • Issue 79
    • Issue 78
    • Issue 77
    • Issue 76
    • Issue 75
    • Issue 74
    • Issue 73
    • Issue 72
    • Issue 71
    • Issue 70
    • View All
    • About the Awards
    • Awards Timetable
    • Awards Winners
    • Submit Nominations
    • Testimonials
    • Media Room
    • FAQ
    • Asset Management Awards
    • Brand of the Year Awards
    • Business Awards
    • Cash Management Banking Awards
    • Banking Technology Awards
    • CEO Awards
    • Customer Service Awards
    • CSR Awards
    • Deal of the Year Awards
    • Corporate Governance Awards
    • Corporate Banking Awards
    • Digital Transformation Awards
    • Fintech Awards
    • Education & Training Awards
    • ESG & Sustainability Awards
    • ESG Awards
    • Forex Banking Awards
    • Innovation Awards
    • Insurance & Takaful Awards
    • Investment Banking Awards
    • Investor Relations Awards
    • Leadership Awards
    • Islamic Banking Awards
    • Real Estate Awards
    • Project Finance Awards
    • Process & Product Awards
    • Telecommunication Awards
    • HR & Recruitment Awards
    • Trade Finance Awards
    • The Next 100 Global Awards
    • Wealth Management Awards
    • Travel Awards
    • Years of Excellence Awards
    • Publishing Principles
    • Ownership & Funding
    • Corrections Policy
    • Editorial Code of Ethics
    • Diversity & Inclusion Policy
    • Fact Checking Policy
    Original content: Global Banking and Finance Review - https://www.globalbankingandfinance.com

    A global financial intelligence and recognition platform delivering authoritative insights, data-driven analysis, and institutional benchmarking across Banking, Capital Markets, Investment, Technology, and Financial Infrastructure.

    Copyright © 2010-2026 - All Rights Reserved. | Sitemap | Tags

    Editorial & Advertiser disclosure

    Global Banking & Finance Review® is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    1. Home
    2. >Business
    3. >NEW STUDY REVEALS TOO MANY GLOBAL ORGANISATIONS ARE GAMBLING THEIR BUSINESS FUTURE ON POOR CODE
    Business

    New Study Reveals Too Many Global Organisations Are Gambling Their Business Future on Poor Code

    Published by Gbaf News

    Posted on March 13, 2017

    7 min read

    Last updated: January 21, 2026

    Add as preferred source on Google
    An inviting image showcasing Belize's stunning scenery, representing the country's appeal as a secure haven for global investors in international banking. This visual emphasizes the stability and privacy offered by Belize's banking sector.
    A serene view of Belize's lush landscapes symbolizing international banking security - Global Banking & Finance Review
    Why waste money on news and opinion when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    Global CRASH Report from CAST uncovers applications in Financial Services can be exploited to steal confidential information

    CAST, a leader in software analysis and measurement, announced findings from its latest CRASH Report, the largest objective study of software ‘health factors’ such as Reliability and Security. Health factors indicate the volume and severity of structural software flaws in business applications.

    The report, which analysed 1.03 billion lines of code across 1,850 applications submitted by over 329 organisations in 8 different countries, exposes the overall quality of too many mission critical functions across the globe is POOR. Security scores varied widely with some of the highest and worst scores observed for any Health Factor. The lowest security scores of some applications indicate there is a significant amount of unsecured code out there.

    This represents a big gamble for organisations whose business operations rest on poor code. Financial Services were specifically found to be particularly susceptible to security risk. Retail and Telco scored marginally better than Financial Services. For an industry carrying large amounts of sensitive data, Financial Services organisations are at risk of severe regulatory fines.

    “Lack of security architecture combined with porous code in legacy systems produce easy targets for hackers. This is especially concerning in Financial Services applications,” said Dr. Bill Curtis, SVP and Chief Scientist at CAST Research Labs. “Despite the push to ‘go digital’ our CRASH Report findings indicate there is a significant amount of bad code lingering in enterprise systems. The takeaway for IT is clear: poor software quality is exposing many businesses to excessive risk.”

    Key findings of the study include:

    Security is lagging behind

    • Security scores varied widely with some of the worst falling into this category. Geographically, the UK scores the lowest out of all regions. France scores best.
    • The Financial Services industry scored worst with, compared to the highest, Government.

    Smaller is better

    • The findings reveal a team size ‘sweet spot’. Teams of under 10 people perform best across most areas of structural quality.
    • Teams of over 20 consistently perform the worst across all Health factors.

    Maturity must be improved to avoid gambling

    • Organisations at the least mature development processes (Level 1) as measurement by the Capability Maturity Model Integration (CMMI) have the worst scores in all areas of structural quality. Such organisations too often have overworked developers on unrealistic schedules. They make myriad mistakes without having adequate time to detect and correct them. Organisations at Level 2 that have implemented basic project controls or at Level 3 that have standardised their processes produce far better software.

    A hybrid method is the way to go

    • Findings revealed the highest scores developed software using a Hybrid method that combines practices from both Agile and Waterfall methods.  The lowest scores were obtained by those reporting use of ‘no method’. Both Agile and Waterfall were consistently achieved lower scores than Hybrid methods. This confirms the same finding in the last CRASH Report two years ago.
    • By combining up front analysis and design of application architectures with rapid feedback on defects during short, iterative coding sprints, hybrid methods produce higher structural quality than Agile or Waterfall methods alone.

    A copy of the CRASH Executive summary and the full report can be downloaded here.

    Methodology

    CAST Research on Application Software Health (CRASH) is a biennial report on global trends in the structural quality of business applications. It reports scores on Health factors which represent attributes of the engineering soundness of the architecture and code of software systems. The technology that generated the data in CRASH Reports measures the number and severity of violations of good architectural and coding practice. These are the defects most likely to cause operational problems such as outages, performance degradation, unauthorised access, or data corruption. The health factors measured in the report look at five traits: Robustness, Security, Performance Efficiency, Changeability and Transferability. Scores are computed on a scale of 1 (high risk) to 4 (low risk).

    Global CRASH Report from CAST uncovers applications in Financial Services can be exploited to steal confidential information

    CAST, a leader in software analysis and measurement, announced findings from its latest CRASH Report, the largest objective study of software ‘health factors’ such as Reliability and Security. Health factors indicate the volume and severity of structural software flaws in business applications.

    The report, which analysed 1.03 billion lines of code across 1,850 applications submitted by over 329 organisations in 8 different countries, exposes the overall quality of too many mission critical functions across the globe is POOR. Security scores varied widely with some of the highest and worst scores observed for any Health Factor. The lowest security scores of some applications indicate there is a significant amount of unsecured code out there.

    This represents a big gamble for organisations whose business operations rest on poor code. Financial Services were specifically found to be particularly susceptible to security risk. Retail and Telco scored marginally better than Financial Services. For an industry carrying large amounts of sensitive data, Financial Services organisations are at risk of severe regulatory fines.

    “Lack of security architecture combined with porous code in legacy systems produce easy targets for hackers. This is especially concerning in Financial Services applications,” said Dr. Bill Curtis, SVP and Chief Scientist at CAST Research Labs. “Despite the push to ‘go digital’ our CRASH Report findings indicate there is a significant amount of bad code lingering in enterprise systems. The takeaway for IT is clear: poor software quality is exposing many businesses to excessive risk.”

    Key findings of the study include:

    Security is lagging behind

    • Security scores varied widely with some of the worst falling into this category. Geographically, the UK scores the lowest out of all regions. France scores best.
    • The Financial Services industry scored worst with, compared to the highest, Government.

    Smaller is better

    • The findings reveal a team size ‘sweet spot’. Teams of under 10 people perform best across most areas of structural quality.
    • Teams of over 20 consistently perform the worst across all Health factors.

    Maturity must be improved to avoid gambling

    • Organisations at the least mature development processes (Level 1) as measurement by the Capability Maturity Model Integration (CMMI) have the worst scores in all areas of structural quality. Such organisations too often have overworked developers on unrealistic schedules. They make myriad mistakes without having adequate time to detect and correct them. Organisations at Level 2 that have implemented basic project controls or at Level 3 that have standardised their processes produce far better software.

    A hybrid method is the way to go

    • Findings revealed the highest scores developed software using a Hybrid method that combines practices from both Agile and Waterfall methods.  The lowest scores were obtained by those reporting use of ‘no method’. Both Agile and Waterfall were consistently achieved lower scores than Hybrid methods. This confirms the same finding in the last CRASH Report two years ago.
    • By combining up front analysis and design of application architectures with rapid feedback on defects during short, iterative coding sprints, hybrid methods produce higher structural quality than Agile or Waterfall methods alone.

    A copy of the CRASH Executive summary and the full report can be downloaded here.

    Methodology

    CAST Research on Application Software Health (CRASH) is a biennial report on global trends in the structural quality of business applications. It reports scores on Health factors which represent attributes of the engineering soundness of the architecture and code of software systems. The technology that generated the data in CRASH Reports measures the number and severity of violations of good architectural and coding practice. These are the defects most likely to cause operational problems such as outages, performance degradation, unauthorised access, or data corruption. The health factors measured in the report look at five traits: Robustness, Security, Performance Efficiency, Changeability and Transferability. Scores are computed on a scale of 1 (high risk) to 4 (low risk).

    More from Business

    Explore more articles in the Business category

    Image for Submit Your Entry for Years of Excellence Awards 2026
    Submit Your Entry for Years of Excellence Awards 2026
    Image for Nominations Open for Travel & Hospitality Awards 2026
    Nominations Open for Travel & Hospitality Awards 2026
    Image for Submit Your Entry Today for Telecom Awards 2026
    Submit Your Entry Today for Telecom Awards 2026
    Image for Submit Your Entries for The Next 100 Global Awards 2026
    Submit Your Entries for the Next 100 Global Awards 2026
    Image for Submit Your Entry: Public Sector & Governance Excellence Awards 2026
    Submit Your Entry: Public Sector & Governance Excellence Awards 2026
    Image for Nominations Invited for Real Estate Development Awards 2026
    Nominations Invited for Real Estate Development Awards 2026
    Image for Submit Your Entry: Process & Product Awards 2026
    Submit Your Entry: Process & Product Awards 2026
    Image for Call for Entries: HR & Recruitment Awards 2026
    Call for Entries: HR & Recruitment Awards 2026
    Image for Submit Your Nominations Today for Education & Training Awards 2026
    Submit Your Nominations Today for Education & Training Awards 2026
    Image for Join the Corporate Governance Awards 2026: Showcase Your Organisation’s Leadership
    Join the Corporate Governance Awards 2026: Showcase Your Organisation’s Leadership
    Image for Submit Your Entry Today for Business Awards 2026
    Submit Your Entry Today for Business Awards 2026
    Image for Decentralized Masters’ ‘family culture’ building trust instead of hierarchy
    Decentralized Masters’ ‘family Culture’ Building Trust Instead of Hierarchy
    View All Business Posts
    Previous Business PostCostless Ways to Boost Employee Productivity
    Next Business PostBusiness Need to Prepare for Real Work of Currency Switch, Cummins Allison States