Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking and Finance Review

Global Banking & Finance Review

Company

    GBAF Logo
    • About Us
    • Profile
    • Privacy & Cookie Policy
    • Terms of Use
    • Contact Us
    • Advertising
    • Submit Post
    • Latest News
    • Research Reports
    • Press Release
    • Awards▾
      • About the Awards
      • Awards TimeTable
      • Submit Nominations
      • Testimonials
      • Media Room
      • Award Winners
      • FAQ
    • Magazines▾
      • Global Banking & Finance Review Magazine Issue 79
      • Global Banking & Finance Review Magazine Issue 78
      • Global Banking & Finance Review Magazine Issue 77
      • Global Banking & Finance Review Magazine Issue 76
      • Global Banking & Finance Review Magazine Issue 75
      • Global Banking & Finance Review Magazine Issue 73
      • Global Banking & Finance Review Magazine Issue 71
      • Global Banking & Finance Review Magazine Issue 70
      • Global Banking & Finance Review Magazine Issue 69
      • Global Banking & Finance Review Magazine Issue 66
    Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

    Global Banking & Finance Review® is a leading financial portal and online magazine offering News, Analysis, Opinion, Reviews, Interviews & Videos from the world of Banking, Finance, Business, Trading, Technology, Investing, Brokerage, Foreign Exchange, Tax & Legal, Islamic Finance, Asset & Wealth Management.
    Copyright © 2010-2025 GBAF Publications Ltd - All Rights Reserved.

    ;
    Editorial & Advertiser disclosure

    Global Banking and Finance Review is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    Home > Business > UK ORGANISATIONS NEED A NEW MINDSET TO SECURE SOFTWARE DEVELOPMENT AND THRIVE IN THE DIGITAL ECONOMY
    Business

    UK ORGANISATIONS NEED A NEW MINDSET TO SECURE SOFTWARE DEVELOPMENT AND THRIVE IN THE DIGITAL ECONOMY

    UK ORGANISATIONS NEED A NEW MINDSET TO SECURE SOFTWARE DEVELOPMENT AND THRIVE IN THE DIGITAL ECONOMY

    Published by Gbaf News

    Posted on January 23, 2018

    Featured image for article about Business

    Global Study Highlights Existing Organisational Culture as a Key Hurdle to Embed Security Throughout the Software Development Lifecycle

    CA Technologies (NASDAQ:CA) has revealed the results of a global study of more than 1,200 IT leaders, including 466 across six countries in Europe, on the topic of secure software development. Conducted by IT industry analyst firm Freeform Dynamics, the new report entitled, “Integrating Security into the DNA of Your Software Lifecycle,” highlights the influence of culture on the ability of UK organisations to integrate security practices as part of the software development lifecycle – a practice critical to business success in the digital economy.

    In the study, 94% of UK respondents confirm that software development supports growth and expansion, and 86% say it drives digital transformation. The findings also reveal that 65% agree that security threats arising from software development issues are a growing concern. However, half (51%) of UK organisations cite “existing culture” as a key barrier to embedding security within processes, and only 16% strongly agree the organisation’s culture and practices support collaboration across development, operations and security – the lowest figure in Europe. Against this backdrop, CA Veracode’s State of Software Security Report 2017 indicates that vulnerabilities continue to crop up in previously untested software at alarming rates, with organisations globally reporting that 77% of apps have at least one vulnerability on initial scan.

    “Security is a key principle in any Modern Software Factory. While our study confirms an overarching recognition of the importance of building and maintaining applications securely, the culture within UK organisations still needs to be modified to improve collaboration between IT teams, and get faster feedback from the real world on vulnerabilities and how to tackle them quickly,” says Stephen Walsh, Sr Director, Security, CA Technologies. “Building security into every step of application delivery with DevSecOps, together with advanced technologies like machine learning and behavioural analytics, can significantly drive better business outcomes and ultimately, change the way business is conducted.”

    Security needs to be embedded into development 

    The research highlights that a majority of UK organisations recognise that rapidly changing business and regulatory demands require organisations to modify how security is managed in their software development processes. In particular, it reveals that the traditional approach of testing security at the end of the development process is no longer sufficient: 91% of UK organisations believe it is essential or important to make security a more embedded part of the software development process, not tagged on, often hurriedly, at the end. Some 70% also agree/strongly agree that it is critical to integrate security practices earlier in the software development cycle – in other words adopt DevSecOps. This compares with 88% of respondents in France and 79% in Spain.

    In reality though, only 30% of UK organisations have already made security an integral part of DevOps (i.e. implementing DevSecOps), compared with 44% in France and a Europe-wide average of 28%. Moreover, just 26% have already implemented early and continuous testing of apps for security vulnerabilities, compared with 38% in Italy.

    Lack of skills and time impede security – but automation is imminent

    In addition to existing organisational culture being identified as a key hurdle to secure software development, some 52% of UK organisations agree that a lack of skills also prevents them from making security integral to the entire software development process – from application requirements assessment through design to delivery – while 71% cite time pressures. The immense challenges associated with these processes make the use of automation tools essential as few, if any, organisations have the skilled human resources or time available to tackle such complex, urgent challenges.

    Two emerging technologies with automation at the core – behavioural analytics and machine learning – can help address the skills gap and time issues while improving security. According to the study, 83% of UK organisations see both of these advanced technologies as key to providing a better user experience while still protecting user data (compared with 94% of Spanish organisations and 92% of Italian ones). This is fundamental to taking pre-emptive action to avoid a data breach and/or mitigate the impact of one, and essential to authenticating controls based on what a user is doing and what is known about them. In fact, 77% of organisations are now using analytics, machine learning and artificial intelligence to enrich insights into customer needs and behaviours (6% more than the European average), while 78% are increasing automation across the software development lifecycle.

    Software Security Masters show the way forward in Europe

    The report showcases characteristics of “Software Security Masters” (the top 32% of EMEA respondents) which are organisations that have been able to fully integrate security fully into the software development life cycle. This includes conducting early and continuous application testing for security vulnerabilities as well as embracing the practice of DevSecOps.

    At a pan-European level, when compared with the mainstream, 1.7x more Software Security Masters strongly agree that in addition to protecting a company’s data and systems, they viewed security as an enabler of new business opportunities, and exhibited the following attributes:

    • 50% higher profit growth
    • 40% higher revenue growth
    • Are 2.4x more likely to have security testing keep up with frequent app updates
    • Are 1.9x more likely to be outpacing their competitors

    “Organisations that are Software Security Masters not only show a strong correlation between embedding security in the DNA of software development and achieving strong top and bottom line performance, they also exemplify the mindset and skills needed to succeed in the digital economy and are agents of change as they shape the organisational culture that’s so key to creating the workplace of the future,” concluded Walsh. “Not every organisation is at the stage of being a Software Security Master, but employing a strategy of continuous security can accelerate the move to becoming a master, thereby improving time to market and enhancing the organisation’s ability to compete and grow.”

    Survey Methodology

    The global online survey of 1,279 senior IT and business executives was sponsored by CA Technologies and conducted by industry analyst firm Freeform Dynamics in July 2017. It included 466 respondents from six European countries: France, Germany, Italy, Spain, Switzerland and the UK. The research was augmented by in-depth telephone interviews with key industry executives. For full survey methodology details, please see the report, “Integrating Security into the DNA of Your Software Lifecycle.”

    Download the full report and other supporting materials:

    • Report: Integrating Security into the DNA of Your Software Lifecycle

    Global Study Highlights Existing Organisational Culture as a Key Hurdle to Embed Security Throughout the Software Development Lifecycle

    CA Technologies (NASDAQ:CA) has revealed the results of a global study of more than 1,200 IT leaders, including 466 across six countries in Europe, on the topic of secure software development. Conducted by IT industry analyst firm Freeform Dynamics, the new report entitled, “Integrating Security into the DNA of Your Software Lifecycle,” highlights the influence of culture on the ability of UK organisations to integrate security practices as part of the software development lifecycle – a practice critical to business success in the digital economy.

    In the study, 94% of UK respondents confirm that software development supports growth and expansion, and 86% say it drives digital transformation. The findings also reveal that 65% agree that security threats arising from software development issues are a growing concern. However, half (51%) of UK organisations cite “existing culture” as a key barrier to embedding security within processes, and only 16% strongly agree the organisation’s culture and practices support collaboration across development, operations and security – the lowest figure in Europe. Against this backdrop, CA Veracode’s State of Software Security Report 2017 indicates that vulnerabilities continue to crop up in previously untested software at alarming rates, with organisations globally reporting that 77% of apps have at least one vulnerability on initial scan.

    “Security is a key principle in any Modern Software Factory. While our study confirms an overarching recognition of the importance of building and maintaining applications securely, the culture within UK organisations still needs to be modified to improve collaboration between IT teams, and get faster feedback from the real world on vulnerabilities and how to tackle them quickly,” says Stephen Walsh, Sr Director, Security, CA Technologies. “Building security into every step of application delivery with DevSecOps, together with advanced technologies like machine learning and behavioural analytics, can significantly drive better business outcomes and ultimately, change the way business is conducted.”

    Security needs to be embedded into development 

    The research highlights that a majority of UK organisations recognise that rapidly changing business and regulatory demands require organisations to modify how security is managed in their software development processes. In particular, it reveals that the traditional approach of testing security at the end of the development process is no longer sufficient: 91% of UK organisations believe it is essential or important to make security a more embedded part of the software development process, not tagged on, often hurriedly, at the end. Some 70% also agree/strongly agree that it is critical to integrate security practices earlier in the software development cycle – in other words adopt DevSecOps. This compares with 88% of respondents in France and 79% in Spain.

    In reality though, only 30% of UK organisations have already made security an integral part of DevOps (i.e. implementing DevSecOps), compared with 44% in France and a Europe-wide average of 28%. Moreover, just 26% have already implemented early and continuous testing of apps for security vulnerabilities, compared with 38% in Italy.

    Lack of skills and time impede security – but automation is imminent

    In addition to existing organisational culture being identified as a key hurdle to secure software development, some 52% of UK organisations agree that a lack of skills also prevents them from making security integral to the entire software development process – from application requirements assessment through design to delivery – while 71% cite time pressures. The immense challenges associated with these processes make the use of automation tools essential as few, if any, organisations have the skilled human resources or time available to tackle such complex, urgent challenges.

    Two emerging technologies with automation at the core – behavioural analytics and machine learning – can help address the skills gap and time issues while improving security. According to the study, 83% of UK organisations see both of these advanced technologies as key to providing a better user experience while still protecting user data (compared with 94% of Spanish organisations and 92% of Italian ones). This is fundamental to taking pre-emptive action to avoid a data breach and/or mitigate the impact of one, and essential to authenticating controls based on what a user is doing and what is known about them. In fact, 77% of organisations are now using analytics, machine learning and artificial intelligence to enrich insights into customer needs and behaviours (6% more than the European average), while 78% are increasing automation across the software development lifecycle.

    Software Security Masters show the way forward in Europe

    The report showcases characteristics of “Software Security Masters” (the top 32% of EMEA respondents) which are organisations that have been able to fully integrate security fully into the software development life cycle. This includes conducting early and continuous application testing for security vulnerabilities as well as embracing the practice of DevSecOps.

    At a pan-European level, when compared with the mainstream, 1.7x more Software Security Masters strongly agree that in addition to protecting a company’s data and systems, they viewed security as an enabler of new business opportunities, and exhibited the following attributes:

    • 50% higher profit growth
    • 40% higher revenue growth
    • Are 2.4x more likely to have security testing keep up with frequent app updates
    • Are 1.9x more likely to be outpacing their competitors

    “Organisations that are Software Security Masters not only show a strong correlation between embedding security in the DNA of software development and achieving strong top and bottom line performance, they also exemplify the mindset and skills needed to succeed in the digital economy and are agents of change as they shape the organisational culture that’s so key to creating the workplace of the future,” concluded Walsh. “Not every organisation is at the stage of being a Software Security Master, but employing a strategy of continuous security can accelerate the move to becoming a master, thereby improving time to market and enhancing the organisation’s ability to compete and grow.”

    Survey Methodology

    The global online survey of 1,279 senior IT and business executives was sponsored by CA Technologies and conducted by industry analyst firm Freeform Dynamics in July 2017. It included 466 respondents from six European countries: France, Germany, Italy, Spain, Switzerland and the UK. The research was augmented by in-depth telephone interviews with key industry executives. For full survey methodology details, please see the report, “Integrating Security into the DNA of Your Software Lifecycle.”

    Download the full report and other supporting materials:

    • Report: Integrating Security into the DNA of Your Software Lifecycle
    Related Posts
    Cybersecurity as a Profit Engine: Turning Financial Services Security into Measurable Business Value
    Cybersecurity as a Profit Engine: Turning Financial Services Security into Measurable Business Value
    How Investability Helps Companies Navigate Transformational Times
    How Investability Helps Companies Navigate Transformational Times
    88% of UK and US organisations concerned about state-sponsored cyber attacks as national threat levels surge, IO research reveals
    88% of UK and US organisations concerned about state-sponsored cyber attacks as national threat levels surge, IO research reveals
    One in three SME leaders do not fully understand cash flow, despite 82% facing cash flow problems
    One in three SME leaders do not fully understand cash flow, despite 82% facing cash flow problems
    Inside the Company that Predicted the Remote Work Mega-Trend Before It Became Mainstream
    Inside the Company that Predicted the Remote Work Mega-Trend Before It Became Mainstream
    SEO Consultant Adrian Czarnoleski on How to Increase Business Value Before Exit
    SEO Consultant Adrian Czarnoleski on How to Increase Business Value Before Exit
    No SOC 2, No Deal: Why You’re Already Losing Clients - and What You Can Do About It
    No SOC 2, No Deal: Why You’re Already Losing Clients - and What You Can Do About It
    Jose Tolosa Guides Organizations Forward with Clarity, Purpose, and Integrity
    Jose Tolosa Guides Organizations Forward with Clarity, Purpose, and Integrity
    Reducing Freight Costs to Drive Global Trade Expansion
    Reducing Freight Costs to Drive Global Trade Expansion
    The Psychology of Music in the Modern Workplace
    The Psychology of Music in the Modern Workplace
    Revealed: Low-Cost/No-Cost Marketing Hacks For Results Oriented Businesses
    Revealed: Low-Cost/No-Cost Marketing Hacks For Results Oriented Businesses
    Finance teams still stuck in spreadsheets as manual processes stall digital transformation
    Finance teams still stuck in spreadsheets as manual processes stall digital transformation

    Why waste money on news and opinions when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    More from Business

    Explore more articles in the Business category

    The Future of Remote & Hybrid Leadership: Leading With Data-Driven Foresight

    The Future of Remote & Hybrid Leadership: Leading With Data-Driven Foresight

    2025-2030: The Next Technological Innovations for Business

    2025-2030: The Next Technological Innovations for Business

    The CFO’s New Playbook: 5 Ways AI Is Redefining Finance with Insights from Rishi Oberoi

    The CFO’s New Playbook: 5 Ways AI Is Redefining Finance with Insights from Rishi Oberoi

    Revolutionizing Payments: Secure, Scalable, Sovereign

    Revolutionizing Payments: Secure, Scalable, Sovereign

    Why Trademark Abuse in Paid Search Is a Growing Risk for Financial Institutions

    Why Trademark Abuse in Paid Search Is a Growing Risk for Financial Institutions

    E-commerce Customer Service: Tips

    E-commerce Customer Service: Tips

    When to Automate Your Warehouse: The Tipping Point for Operations Growth

    When to Automate Your Warehouse: The Tipping Point for Operations Growth

    Hurt at Work? 5 Financial Facts You Need to Know

    Hurt at Work? 5 Financial Facts You Need to Know

    Against the Odds: Resilience in Consumer Subsectors Offers Prime Opportunities for Investors

    Against the Odds: Resilience in Consumer Subsectors Offers Prime Opportunities for Investors

    Empower Your Workforce With Financial Wellness This Labor Day

    Empower Your Workforce With Financial Wellness This Labor Day

    Build a brand that stands out with five simple strategies, from defining your UVP to using storytelling and building loyalty. Find out more.

    Build a brand that stands out with five simple strategies, from defining your UVP to using storytelling and building loyalty. Find out more.

    The Hybrid Office Playbook for Financial Services: How to Design Hybrid Offices to Optimize People and Spaces

    The Hybrid Office Playbook for Financial Services: How to Design Hybrid Offices to Optimize People and Spaces

    View All Business Posts
    Previous Business PostMOTIVATING YOUR TEAM DURING THE LEAST PRODUCTIVE TIME OF THE YEAR
    Next Business PostHow does Shopify work