A study into companies that outsource code development has found that six out
of 10 do not include security specifications.
The Quocirca report found that many companies are outsourcing more code
development than ever before, and that nine out of 10 outsource more than 40 per
cent.
The National Institute of Standards and Technology reported recently that 92
per cent of vulnerabilities affecting computer networks are contained in
software applications.
However, when it comes to specifying outsourced code, one in five companies
do not even consider security when designing applications.
Fran Howarth, principal analyst at Quocirca and author of the report, said:
"The findings indicate that not enough is being done by organisations to build
security into the applications on which their businesses rely.
"They are also entrusting large parts of their application development needs
to third parties.
Not enough is being done by organisations to build security into the applications on which their businesses rely
Fran Howarth Quocirca
"This creates an even greater onus for organisations to thoroughly test all
code generated for applications, without which they could be playing into the
hands of hackers."
The top outsourcers are financial services organisations, 72 per cent of
which outsource more than 40 per cent of new code development.
Only seven per cent of utility companies outsource more that eight per cent
of code development.
Howard Schmidt, a board member at Fortify Software, and a former
cyber-security advisor to the White House, said: "These survey results help
explain the sudden rise in data breaches.
"It should serve as a wake-up call to any executive whose company sits on a
pile of mission-critical application code."
Do you agree?
Have your say on this article