news-details
Government

Veracode Research Reveals Increased Cyber Risk in Government Applications: 59% Have Unfixed Flaws for Over a Year

Veracode, a global leader in application risk management, has released its latest research indicating that public sector applications face significantly higher security debt compared to those in the private sector. The "State of Software Security Public Sector 2024" report highlights that 59% of government applications contain flaws that have been left unfixed for over a year, compared to 42% across all sectors. This extensive study examined public sector organizations in over 25 countries.

"Decades of accumulated security debt in unpatched software and poor security configurations are present in applications serving our government," stated Chris Eng, Chief Research Officer at Veracode. "Without a systematic and continuous approach to finding and fixing security flaws, the public sector remains dangerously exposed to cyberattacks."

Federal government systems are increasingly targeted by cybercriminals employing more damaging and disruptive techniques. In response, federal initiatives are underway to enhance cybersecurity, including efforts to mitigate risks in government-serving applications. In March 2024, the Cybersecurity and Infrastructure Security Agency (CISA) and the Office of Management and Budget (OMB) introduced the Secure Software Development Attestation Form to hold federal software providers accountable for security shortcomings.

Veracode's findings reveal that while 68% of public sector organizations have security debt, slightly fewer than other industries (71%), they tend to accumulate more of it. Only 3% of public sector applications are flaw-free, compared to 6% in other industries. Alarmingly, 40% of public sector entities possess persistent, high-severity flaws constituting 'critical' security debt, which jeopardizes business confidentiality, integrity, and availability if exploited.

"The good news is that most organizations can remediate all critical debt, but risk prioritization is key," Eng noted. "Two-thirds of all flaws in public sector organizations are less than a year old or not critically severe. Furthermore, less than one percent of all flaws constitute critical security debt. By focusing efforts on critical security debt, organizations can achieve maximum risk reduction and then address non-critical flaws based on their risk tolerance and capabilities."

The report indicates that security debt in the public sector primarily affects first-party code (93%), though most critical security debt originates from third-party dependencies (55.5%). This highlights the importance of the Open Source Security Software Initiative (OS3I), an inter-agency effort to ensure the security and sustainability of open-source software. Organizations need to focus on both first- and third-party code to effectively reduce security debt.

Security debt is concentrated in older, larger applications (22%), particularly for critical security debt (30%), suggesting a correlation between application age and security debt accumulation. The research also identified Java and .NET applications as significant sources of debt in the public sector.

"The current state of software security in the public sector underscores the necessity of making 'secure by design' a standard approach for our interconnected world," Eng concluded. "We applaud CISA’s recent Secure by Design Pledge and are proud to be one of its inaugural signatories. Our aim with this research is to support our government and industry partners in promoting the widespread adoption of these principles."

Related News

Emirates Stallions Group Repor ...

Emirates Stallions Group (ADX: ESG), a leading conglomerate with operations in Workforce Solutions, Construction, and Real Estate, and a subsidiary of International Holding Company...

Investopia Global Talks Launch ...

The Investopia Global Talks initiative has launched a new session in Chennai, Tamil Nadu, India, with a focus on enhancing the economic partnership between the United Arab Emirates...

Samsung Gulf Hosts Inaugural G ...

Samsung Gulf Electronics celebrated the UAE's vibrant creative community at its first Galaxy Creators' Day event, showcasing the latest flagship devices from the Galaxy lineup. The...

Huawei’s Oman Commercial Roads ...

Huawei hosted the Oman leg of its Middle East and Central Asia (ME&CA) Commercial Roadshow on July 22 in Muscat, focusing on advancing digital transformation in line with Oman ...

SuperBridge Summit 2024 to Showcase ...

The Dubai World Trade Centre (DWTC) and the SuperBridge Council have reaffirmed their commitment to establishing the Middle East as a premier destination for innovation and entrepr...

Mamo Secures $3.4 Million to Enhanc ...

Mamo, a UAE-based fintech startup dedicated to streamlining payment collection, corporate cards, and expense management for small and medium-sized businesses (SMEs), has successful...

Dubai International Chamber Attract ...

The Dubai International Chamber, part of Dubai Chambers, has made significant strides in attracting foreign direct investment and supporting local companies' global expansion effor...

Applications Open for MBZUAI’s Six- ...

Mohamed bin Zayed University of Artificial Intelligence (MBZUAI) invites thirty local and international executives to apply for its upcoming six-day intensive program, the MBZUAI E...

Fourth Phase of Riviera by Azizi De ...

Azizi Developments, a prominent private real estate developer in the UAE, has announced significant progress in the fourth phase of Riviera, their French Mediterranean-inspired wat...

GPCA to Recognize Young Talent in A ...

The Gulf Petrochemicals and Chemicals Association (GPCA) is set to celebrate the innovative ideas and talents of GCC university students in the field of agri-nutrient sustainabilit...