Research Reveals Software Security at Public Sector Organizations Lagging
Veracode, a leading global provider of intelligent software security, today released research indicating that applications developed by public sector organizations tend to have more security flaws than applications created by the private sector. The findings are notable because increased numbers of flaws and vulnerabilities in applications correlate with increased levels of risk. The research comes amid a flurry of recent initiatives by the federal government to strengthen cybersecurity, including efforts to reduce vulnerabilities in applications that perform critical government functions.
Researchers found that just under 82 percent of applications developed by public sector organizations had at least one security flaw detected in their most recent scan over the last 12 months, compared to 74 percent of private sector organizations. Depending on the type of flaw tracked, public sector applications had a 7–12 percent higher probability of having a flaw introduced in the last 12 months.
"The difference between the rate at which flaws appear in public and private sector applications is significant. Efforts by the government to close the gap are necessary and should continue. As stewards of public safety, agencies have a responsibility to close this gap and strengthen security to protect the nation and its citizens,” said Chris Eng, Chief Research Officer at Veracode.
Analysis of data collected from more than 27 million scans across 750,000 applications helped to produce Veracode’s latest annual report on the State of Software Security. This new report showcases the public sector-specific findings from those scans and applications, including results from federal, state, and local government.
Numbers alone don’t convey the consequences that occur when hackers exploit software flaws and vulnerabilities. In early May this year, a ransomware attack against the city of Dallas hobbled functions relied on to deliver public services, including IT systems used by public safety agencies. More than three weeks after the attack occurred, Dallas’s public agencies hadn’t fully recovered.
High Severity Flaws: A Win for the Public Sector
Veracode’s research also found reasons for public sector organizations to be optimistic about application security. Discovery of “high severity” flaws in public sector applications (16.5 percent) in a 12-month period was lower than in non-public sector applications (19 percent). This is noteworthy because high severity flaws, when exploited, have greater potential to impact systems adversely.
Modern application testing encourages the use of multiple types of security scanning tools, such as static application security testing (SAST) and software composition analysis (SCA), because different scan types excel at uncovering different types of flaws. SAST and SCA found application flaws in a smaller percentage of public sector agencies compared to private sector applications.
Finding fewer flaws when using SCA tools could signal the initial impact of the May 2021 Executive Order (EO 14028), which directs U.S. federal agencies to invigorate efforts to protect the software supply chain. This EO also calls for greater use of software bills of material (SBOMs), which list the ingredients in software, thereby promoting information sharing, transparency, and visibility. Elsewhere, the Federal Risk and Authorization Management Program (FedRAMP) standardizes security assessment of cloud products and services. Similarly, StateRAMP enables state and local governments to verify cloud service providers’ compliance with cybersecurity policies.
“As modern IT systems have evolved and become more complex, the taxonomy of application flaws has become more varied,” Eng said. “As such, the use of multiple scan types to find and fix flaws has become a best practice.”
An Ounce of Prevention is Worth a Pound of Cure
A stark difference between public and private sector applications is the rate at which scans discover new flaws in aging software. By the time software has been in production for five years, the two sectors diverge sharply: rates of new flaws introduced in private sector applications increase, while rates for public sector agencies decline.
This trend suggests that public sector agencies are more vigilant about keeping applications secure over time, and not just during the first few years of the lifecycle. Applications outside government, by contrast, experience a gradual and steady increase in the introduction of new flaws as they age.
The State of Software Security Public Sector 2023 report recommends four actions agencies can take to improve their cybersecurity posture.
- Catch Up: fix the backlog of known flaws
- Scan regularly: inconsistent scanning makes fixing flaws more difficult, leading to more backlogs
- Automate: automating testing via APIs reduces the introduction of flaws into applications
- Add DAST to the stack: use dynamic scanning to discover flaws that other scan types miss
“The public sector has come a long way in strengthening the security of applications that serve our government, but there is still more work to be done for agencies to improve their cyber posture and repel incoming threats. By focusing security efforts on the root cause of most cyber breaches—the application layer—agencies can achieve necessary improvements. Scanning regularly with a variety of testing types and addressing security debt—the accumulated software vulnerabilities that threaten a system’s safety—will pave the way toward a more secure future for government agencies," Eng concluded.
The full public sector research from the Veracode State of Software Security report is available and provides core comparative metrics among government agencies.
The full Veracode State of Software Security 2023 is available to download.
About the State of Software Security Report
The 13th volume of Veracode’s annual report on the State of Software Security examines historical trends shaping the software landscape and how security practices are evolving along with those trends. This year’s findings are based on the full historical data available from Veracode services and customers and represent a cross-section of large and small companies, commercial software suppliers, software outsourcers, and open-source projects. The report contains findings about applications that were subjected to static analysis, dynamic analysis, software composition analysis, and/or manual penetration testing through Veracode’s cloud-based platform. The report considers data that was provided by Veracode’s customers and information that was calculated or derived in the course of Veracode’s analysis.
About Veracode
Veracode is intelligent software security. The Veracode Software Security Platform continuously detects flaws and vulnerabilities at every stage of the modern software development lifecycle. Prompted by powerful AI trained by trillions of lines of code, Veracode customers fix flaws faster with high accuracy. Trusted by security teams, developers, and business leaders from thousands of the world’s leading organizations, Veracode is the pioneer, continuing to redefine what intelligent software security means. Veracode is accredited for the FedRAMP and StateRAMP Risk and Authorization Management Program.
Copyright © 2023 Veracode, Inc. All rights reserved. Veracode is a registered trademark of Veracode, Inc. in the United States and may be registered in certain other jurisdictions. All other product names, brands or logos belong to their respective holders. All other trademarks cited herein are property of their respective owners.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20230605005099/en/
Contact information
Katy Gwilliam
kgwilliam@veracode.com
About Business Wire
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Hanshow and the University of Cambridge Launch Joint Research on Augmented Intelligent Hybrid Wireless Technology25.12.2025 12:34:00 CET | Press Release
Hanshow, a global leader in electronic shelf labels (ESL) and digital store solutions, has entered into a multi-year research collaboration with the University of Cambridge, one of the world’s most prestigious academic institutions. The partnership will focus on joint research and innovation in next-generation intelligent hybrid wireless technologies, marking an important milestone in Hanshow’s continued investment in core technologies and long-term innovation. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251225988816/en/ This collaboration leverages the University of Cambridge’s deep expertise in fundamental wireless technology research, alongside Hanshow’s extensive industry experience, to further strengthen multi-protocol integration capabilities and expand scalable applications across diverse retail scenarios. Guided by shared principles of innovation, collaboration, openness, and knowledge sharing, the two parties aim
Social Development Bank Highlights Strategic Partnerships and Global Initiatives at DeveGo 202524.12.2025 17:27:00 CET | Press Release
The Social Development Bank (SDB) hosted the second edition of the Entrepreneurship and Modern Business Practices Forum, “DeveGo 2025”, from 21 to 23 December in Riyadh. Held under the patronage of His Excellency Eng. Ahmed bin Sulaiman Al Rajhi, Minister of Human Resources and Social Development and Chairman of SDB’s Board of Directors, the forum brings together government leaders, global experts, investors, and entrepreneurs to shape the future of entrepreneurship and modern business practices in the Kingdom of Saudi Arabia. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251224036724/en/ From right to left: Ahmed Al Rajhi, Saudi's Minister of Human Resources and Social Development, H.E. Rebeca Grynspan, Secretary-General of UNCTAD, and Sultan Al Hamidi, CEO of Social Development (Photo: AETOSWire) Opening the forum, Minister Al Rajhi delivered a keynote speech on the growing vibrancy of Saudi Arabia’s entrepreneurial movem
Making Science Unveils ‘AWAKE’: The AI Venture Studio Industrialising Startup Creation and AI-First Innovative Solutions23.12.2025 20:51:00 CET | Press Release
Making Science, the global digital acceleration consultancy, today announced the launch of AWAKE Venture Studio. This "AI-first" model represents a new era in systematic innovation, designed to identify, prototype, and scale both internal proprietary solutions and independent AI-native startups with global reach. The launch of AWAKE is motivated by the significant efficiency gains of orders of magnitude that Making Science has already achieved through the internal integration of AI. By applying these methods, the firm has achieved a 2x acceleration in tech feature development reducing time in the deployment of AI Agents. This model has already proven its commercial and innovative power through the acceleration of startups like ad-machina, which has multiplied its value by 10 since joining the Making Science ecosystem. These proven benchmarks serve as the technical foundation for AWAKE’s two interconnected engines, which formalise this efficiency into a repeatable manufacturing process
FDA Clears First Extended Depth of Focus Contact Lens for Presbyopia23.12.2025 18:07:00 CET | Press Release
The Cataltheia Group and its U.S. subsidiary, Bruno Vision Care LLC, a leader in eye health innovation, today announced that the U.S. Food and Drug Administration (FDA) has cleared the first and only Daily Disposable Soft (Hydrophilic) Contact Lens for Presbyopia utilizing patented Extended Depth of Focus (EDOF) optical design technology, enabling commercial distribution in the United States. Deseyne® delivers smooth, continuous focus across near, intermediate, and distance vision, providing clear, natural vision without compromise. This performance is enabled by Cataltheia’s patented hyper-refractive central zone, engineered to precisely redirect light in a controlled manner. The result is a clear clinical advantage over the only other available contact lens option for presbyopia, multifocal lenses, which rely on multiple optical zones and often require prolonged visual and cognitive adaptation. “We are proud to offer the first contact lens solution for the world’s aging population th
Aramco Awards SLB Long-Term Contract to Support Kingdom’s Unconventional Gas Production Growth23.12.2025 14:58:00 CET | Press Release
Global technology company SLB (NYSE: SLB) has been awarded a five-year contract by Aramco to provide stimulation services for its unconventional gas fields. This award is part of a broader multi-billion contract, supporting one of the largest unconventional gas development programs globally. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251223074948/en/ The contract encompasses advanced stimulation, well intervention, frac automation, and digital solutions, which are important to unlocking the potential of Saudi Arabia’s unconventional gas resources. The contract encompasses advanced stimulation, well intervention, frac automation, and digital solutions, which are important to unlocking the potential of Saudi Arabia’s unconventional gas resources — a cornerstone of the Kingdom’s strategy to diversify its energy portfolio and support the global energy transition. “This agreement is an important step forward in Aramco’s effor
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
