Understanding Security Debt in the Financial Services Sector
In a world where technology continually evolves, maintaining the security of software applications is paramount for financial institutions. Veracode, a leader in application risk management, recently released insightful research shedding light on the alarming levels of security debt present in the financial services industry. This report highlights the need for urgent attention towards addressing the flaws in software security that threaten both organizations and their customers.
The Alarming State of Security Debt
According to the findings, a staggering 76 percent of organizations in the financial sector carry security debt, defined as any software vulnerabilities that have remained unresolved for over a year. Of those, approximately 50 percent grapple with critical security debt, representing major risks in an industry where the average cost of a data breach is estimated at $6.08 million. This situation is even more pressing considering the advancements in cyberattack tactics that increasingly leverage artificial intelligence.
Challenges of Addressing Vulnerabilities
As financial organizations work to innovate and meet rising customer expectations, they simultaneously face an ever-growing threat landscape. A report by the U.S. Treasury Department has stated that cyber adversaries utilize AI-powered tools to locate vulnerabilities quicker than before. As innovation accelerates, organizations struggle to balance new developments with the essential task of cybersecurity.
Flaws in Software Due to Delayed Remediation
The research unveiled that about 40 percent of all applications within the financial sector exhibit security debt, which is slightly better than the cross-industry average. Unfortunately, only 5.5 percent of these applications are devoid of any flaws. This lack of flaw-free code within the financial services sector indicates that while some vulnerabilities might be addressed promptly, many remain lingering, further compounding the crisis.
First-party vs. Third-party Code Vulnerabilities
A significant concern highlighted by the research was the impact of both first-party and third-party code vulnerabilities. While 84 percent of security debt affects first-party code, a startling 78.6 percent of critical security debt stems from third-party dependencies. This emphasizes the necessity for financial services firms to bolster their defenses against risks introduced by external software components.
Remediation Timelines and Industry Standards
Another notable finding relates to the timelines for fixing identified flaws. Financial organizations tend to resolve half of their first-party flaws within nine months, yet third-party flaws take much longer—about 13 months. Alarmingly, a significant portion of these flaws evolve into security debt, with 52 percent of third-party flaws remaining unaddressed.
Prioritization is Key
The urgency to remediate security flaws is further underscored by recent regulatory frameworks emphasizing software security within the industry. Guidelines such as the ISO 20022 and PCI DSS require that organizations address vulnerabilities promptly to avoid non-compliance issues. Veracode’s findings suggest that prioritizing the 3.3 percent of flaws that represent critical security debt can help organizations effectively manage risk.
Utilizing Application Security Posture Management
A growing focus on Application Security Posture Management (ASPM) allows organizations to continuously monitor and address risk across their software development lifecycle. Veracode’s platform delivers a unified view of application risk, enabling developers to quickly respond to security issues. The AI-powered solution, Veracode Fix, aids teams in identifying and mitigating vulnerabilities that are pressing.
A Call for Action in the Financial Sector
In conclusion, Chris Wysopal, Chief Security Evangelist at Veracode, emphasized the urgent need for entities within the financial services sector to act decisively against current cyber threats. With the increasing sophistication of AI-driven attacks, institutions must not only prioritize but also expedite their remediation strategies to safeguard their software and customer data.
Frequently Asked Questions
What is security debt?
Security debt refers to unresolved software vulnerabilities that persist for over a year, posing risks to organizations.
Why is the financial sector so vulnerable to cyber threats?
The financial sector is highly targeted due to its critical data and sensitive customer information, making it appealing for cybercriminals.
How does third-party code impact security?
Third-party code can introduce additional vulnerabilities that organizations may not fully control, exacerbating security challenges.
What steps can financial institutions take to reduce security debt?
Institutions should prioritize fixing critical vulnerabilities, improve remediation timelines, and adopt tools like ASPM to track and manage risks effectively.
What role does AI play in cybersecurity?
AI can automate the detection of vulnerabilities and streamline the remediation process, although it is also used by adversaries to exploit weaknesses in software.