security-debtai-securitythird-party-riskremediation

Veracode - State of Software Security 2024

Quantifies the prevalence of security debt in applications and highlights the increased remediation friction for third-party vulnerabilities.

Summary

The 14th annual State of Software Security report finds that security debt—unremediated flaws older than one year—exists in 42% of applications and 71% of organizations. Applications grow by approximately 40% annually, leading to a continuous accumulation of flaws that outpaces remediation capacity. Approximately 70% of applications contain flaws in third-party code, and these vulnerabilities take 50% longer to fix than first-party flaws. While human-generated and AI-generated code contain similar percentages of security flaws, the increased velocity of AI-assisted development is expected to accelerate the introduction of new vulnerabilities and the overall accumulation of security debt.

Related Checks

VULN_SLOW_REMEDIATION

Research shows that fixing third-party vulnerabilities takes organizations 50% longer than fixing first-party flaws.

Adverse Outcome

prolonged exposure to upstream vulnerabilities due to slow downstream remediation cycles

Because

the increased friction in updating third-party components makes slow remediation a reliable signal of high organizational security risk.

VULN_UNFIXED

42% of applications contain security debt, defined as flaws that remain unremediated for over one year.

Adverse Outcome

running production software with vulnerabilities that have been known for over 12 months

Because

identifying unfixed flaws that exceed the 12-month debt threshold directly detects the 'critical' security debt identified as a major risk factor.

Gaps Analysis

Evidence

Applications grow by about 40% year on year irrespective of their original size. As these apps grow and age, flaws accumulate, further driving up security debt.

Blind Spot

Risk Guard does not track the growth rate of a dependency's codebase as a risk factor for future security debt accumulation.

Actionable Capability

Risk Guard would be better if it monitored codebase growth velocity and complexity as leading indicators of potential security debt.

← Previous Next →