All the latest UK technology news, reviews and analysis

Outsourcing code puts security at risk

by Iain Thomson

More from this author

07 Apr 2008

Be the first to comment

  • Tweet this
Outsourcing
The top code development outsourcers are financial services organisations

A study into companies that outsource code development has found that six out of 10 do not include security specifications.

The Quocirca report found that many companies are outsourcing more code development than ever before, and that nine out of 10 outsource more than 40 per cent.

The National Institute of Standards and Technology reported recently that 92 per cent of vulnerabilities affecting computer networks are contained in software applications.

However, when it comes to specifying outsourced code, one in five companies do not even consider security when designing applications.

Fran Howarth, principal analyst at Quocirca and author of the report, said: "The findings indicate that not enough is being done by organisations to build security into the applications on which their businesses rely.

"They are also entrusting large parts of their application development needs to third parties.

"This creates an even greater onus for organisations to thoroughly test all code generated for applications, without which they could be playing into the hands of hackers."

The top outsourcers are financial services organisations, 72 per cent of which outsource more than 40 per cent of new code development.

Only seven per cent of utility companies outsource more that eight per cent of code development.

Howard Schmidt, a board member at Fortify Software, and a former cyber-security advisor to the White House, said: "These survey results help explain the sudden rise in data breaches.

"It should serve as a wake-up call to any executive whose company sits on a pile of mission-critical application code."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Information Security Manager

My client is a well established, non profit organisation;...

PHP Web Developer

PHP Web Developer – £30,000 - £35,000 PHP, MySQL, HTML...

HEAD OF DIGITAL - London - £80-95K+

HEAD OF DIGITAL - London - £80-95K + Excellent Bens...

Agile C# Developer - (North London)

Agile C# Developer - (North London) £55,000 - £65,000...

To send to more than one email address, simply separate each address with a comma.