50% of financial orgs have high-severity security flaws in their apps

Share:

Financial sector apps accumulate more security debt

With the average cost of a data breach in the financial industry estimated to be $6.08 million, the research comes at a critical time for one of the most highly targeted industries by sophisticated threat actors. According to a U.S. Treasury Department report in March 2024, threat actors use AI-based tools to find and exploit software vulnerabilities. At the same time, increasing industry competition and customer expectations for convenience require organizations to accelerate innovation.

“The high rate of security debt in the financial sector poses significant risks to organizations and their customers if not addressed quickly. As AI-driven cyber-attacks continue to grow in strength and numbers, and organizations struggle to keep up with evolving regulations due to existing security debt, the current landscape allows threat actors to exploit vulnerabilities at an alarming rate,” said Chris Wysopal, Chief Security Evangelist at Veracode.

“Our latest State of Software research highlights the critical need for financial institutions to address both first-party and third-party code vulnerabilities now. Organizations that leave flaws unremedied for longer than a year are exposed to prolonged and dangerous threats,” added Wysopal.

Veracode researchers found 40% of all applications in the financial sector have security debt, which is slightly better than the cross-industry average of 42%. In addition, just 5.5% of financial sector applications are flaw-free, compared to 5.9% across other industries. While slightly fewer financial sector applications have security debt, they accumulate more of it.

Security debt in first-party and third-party code demands attention

The report also highlights the need for financial services organizations to address security debt in both first-party and third-party code. 84% of all security debt affects first-party code, but 78.6% of critical security debt comes from third-party dependencies. This reinforces the importance of the Cybersecurity and Infrastructure Security Agency’s efforts to help secure the open-source ecosystem with its Open Source Software Security Roadmap and Secure by Design Pledge.

The analysis further explores remediation timelines in the financial services sector. Researchers found that financial organizations fix half of first-party flaws in the first nine months, compared to 13 months for third-party flaws. Of those, 52% of third-party flaws turn into security debt, while 44% of first-party flaws turn into security debt.

The proliferation of supply chain attacks targeting the financial services industry has brought about a growing number of cybersecurity regulations with a sharper focus on software security. For example, regulatory frameworks like the ISO 20022, the Payment Card Industry Data Security Standard (PCI DSS), NIS2, and the Digital Operational Resilience Act (DORA) require organizations to prevent vulnerabilities from being deployed in applications.

This puts organizations at risk of non-compliance because of existing security debt and outdated remediation strategies. Research reveals that organizations can address this risk by prioritizing the 3.3% of flaws that constitute critical security debt. Remediating the most dangerous flaws first means financial entities can then move on to tackle other critical flaws or non-critical.

“It has never been more important for the financial services sector to stay ahead of evolving cybersecurity threats, particularly with increasingly sophisticated AI-driven attacks threatening the security of their assets. I urge financial institutions to prioritize timely security debt reduction by adopting AI-powered remediation and ASPM tools which can detect, prioritize and fix vulnerabilities within seconds,” concluded Wysopal.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
11:15 pm, Jun 26, 2025
weather icon 18°C
L: 17° | H: 19°
broken clouds
Humidity: 54 %
Pressure: 1017 mb
Wind: 10 mph WSW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 78%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:44 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 10:00 pm
weather icon
17° | 19°°C 1 mm 100% 13 mph 69 % 1021 mb 0 mm/h
Sat Jun 28 10:00 pm
weather icon
18° | 28°°C 0 mm 0% 11 mph 87 % 1025 mb 0 mm/h
Sun Jun 29 10:00 pm
weather icon
19° | 32°°C 0 mm 0% 6 mph 79 % 1025 mb 0 mm/h
Mon Jun 30 10:00 pm
weather icon
22° | 36°°C 0 mm 0% 15 mph 66 % 1020 mb 0 mm/h
Tue Jul 01 10:00 pm
weather icon
21° | 29°°C 0 mm 0% 9 mph 66 % 1015 mb 0 mm/h
Tomorrow 1:00 am
weather icon
17° | 18°°C 0 mm 0% 9 mph 53 % 1018 mb 0 mm/h
Tomorrow 4:00 am
weather icon
15° | 16°°C 1 mm 100% 7 mph 68 % 1019 mb 0 mm/h
Tomorrow 7:00 am
weather icon
15° | 15°°C 0.72 mm 72% 8 mph 69 % 1021 mb 0 mm/h
Tomorrow 10:00 am
weather icon
20° | 20°°C 0 mm 0% 11 mph 57 % 1020 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
23° | 23°°C 0 mm 0% 11 mph 44 % 1020 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
28° | 28°°C 0 mm 0% 12 mph 40 % 1019 mb 0 mm/h
Tomorrow 7:00 pm
weather icon
26° | 26°°C 0 mm 0% 13 mph 37 % 1020 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
21° | 21°°C 0 mm 0% 10 mph 61 % 1021 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€91,611.24
-0.30%
Ethereum(ETH)
€2,066.64
-0.37%
Tether(USDT)
€0.86
-0.02%
XRP(XRP)
€1.81
-2.94%
Solana(SOL)
€120.20
-2.41%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.137411
-2.85%
Shiba Inu(SHIB)
€0.000009
-3.20%
Pepe(PEPE)
€0.000008
-2.71%
Scroll to Top