Get all your news in one place.
100’s of premium titles.
One app.
Start reading
TechRadar
TechRadar
Ellen Jennings-Trace

Many financial firms have high-severity software security flaws over a year old

Autonomous finance.

New research from Veracode has revealed over three-quarters (76%) of financial institutions have ‘Security debt’, which it defines as any flaw that has gone unfixed for longer than a year - and shockingly, 50% have ‘critical security debt’ from high severity flaws.

The financial sector is facing a rising number of cyberattacks, and critical infrastructure is proving to be a top target for threat actors.

The average cost of a data breach in the financial sector has hit a staggering $6.08 million, Veracode says - so any security flaw could be costly.

AI driven attacks

Of all applications in the industry, 40% have security debt, but just 5.5% are flaw-free, so the clock is ticking. The flaws primarily come from financial organizations own code (84%), however the critical flaws overwhelmingly come from third party dependencies (78%).

Whilst security teams do fix half of the first-party flaws within nine months, the flaws stick around longer in third party code, only being fixed after an average of 13 months. Of those, only 44% of first party flaws turn into security debt compared to 52% from third parties.

“The high rate of security debt in the financial sector poses significant risks to organizations and their customers if not addressed quickly," said Chris Wysopal, Chief Security Evangelist at Veracode.

“As AI-driven cyber-attacks continue to grow in strength and numbers, and organizations struggle to keep up with evolving regulations due to existing security debt, the current landscape allows threat actors to exploit vulnerabilities at an alarming, unprecedented rate."

This trend is one we’ve seen repeated across the board, with AI changing the cybersecurity landscape on both sides. Cybercriminals show no signs of relenting, so even minor flaws could end up costing your organization millions.

More from TechRadar Pro

Sign up to read this article
Read news from 100’s of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.