Table of contents

New ESG Research Report Outlines Best Practices for Effective Application Security Programs

New ESG Research Report Outlines Best Practices For Appsec

Table of contents

New research from TechTarget’s Enterprise Strategy Group (ESG) has identified that organizations’ application security programs struggle to keep up with the pace of software development, and it reveals best practices to secure modern software applications.

As software delivery accelerates and the volume of releases increases rapidly, the risk from vulnerabilities and the threat of malicious packages grow, but the report, “Optimizing Application Security Effectiveness,” exposes some concerning findings about the readiness of companies to handle these issues. 

The scale of the problem

69 percent of organizations have experienced at least one serious security incident from a software vulnerability in the last 12 months.

Nevertheless, only 52 percent of companies say they can effectively remediate a critical vulnerability, and even fewer ― just 41 percent ― are confident in their ability to manage the security and compliance risks associated with open source software components used within internally developed applications.

New ESG Research Report Outlines Best Practices for Effective Application Security Programs - esg report1

Key best practices for effective application security programs  

Establish strong collaboration early

Organizations that report the ability to efficiently remediate vulnerabilities were much more likely to encourage collaboration between application development, security, and operations to build a culture of security (52% versus 34%). 

New ESG Research Report Outlines Best Practices for Effective Application Security Programs - ESG4 1

Shift security responsibilities left – with security support

Organizations able to keep up with vulnerabilities are 3.3x more likely to have extensively incorporated security into development processes.  These organizations are also more likely to have automated the identification and remediation of configuration and software vulnerabilities before deployment to production (78% versus 61%).

Security plays a centralized role

Companies that can efficiently remediate vulnerabilities were much more likely to say their security team is entirely centralized and separate from development teams (53% versus 30%).

Know what’s in your code 

Organizations able to efficiently remediate vulnerabilities were also more likely to say they view being able to answer questions about their code – such as knowing its source — as critical (49 percent vs. 31 percent).

New ESG Research Report Outlines Best Practices for Effective Application Security Programs - ESG 5 1

Measuring program effectiveness: Preventing incidents

Finally, companies that can keep up with critical vulnerabilities succeed with the ultimate KPI for application security programs: lower security incident rates. Organizations that report the ability to efficiently remediate vulnerabilities were nearly twice as likely to say they have not experienced any serious security incidents tied to a software vulnerability/web application exploit internally developed applications over the last 12 months.

It’s this combination of aligning development and security teams, a full understanding of application composition, the adoption of DevSecOps, and the management of dependencies and risk that results in robust application security without compromising the speed of development.

Proactive AppSec starts here

Recent resources

New ESG Research Report Outlines Best Practices for Effective Application Security Programs - npm supply chain attack blog

NPM Supply Chain Attack: Sophisticated Multi-Chain Cryptocurrency Drainer Infiltrates Popular Packages

A sophisticated npm supply chain attack compromised popular packages

Read more
New ESG Research Report Outlines Best Practices for Effective Application Security Programs - sbom security key components and use cases blog

SBOM Security: 6 Key Components and Top 3 Use Cases

Discover 6 core components and 3 top use cases of SBOM security.

Read more
New ESG Research Report Outlines Best Practices for Effective Application Security Programs - blog a guide to standard SBOM formats

What Is A Software Bill of Materials (SBOM) & 4 Critical Benefits

Learn how SBOMs improve transparency, security, and compliance.

Read more