The State of Software Security in 2025 with Veracode’s Chris Wysopal
Chris Wysopal discusses Veracode’s State of Software Security 2025 research. The 15th edition of its seminal research, based on an extensive dataset of 1.3 million unique applications and 126.4 million raw findings, highlights important trends and offers a new view of software security maturity to improve application risk management practices.
Transcript
This is Textron tv. Hey everyone. Welcome back here to Textron tv.
I'm happy to have my buddy Chris, Chris Weal, chief security evangelist at Veracode on today's text, strong tv. I think the last time we checked in on Chris, Chris, you had just transitioned. That doesn't sound great.
Yeah. You had just transitioned from CTO to chief Security evangelist. Yeah, that that's right.
And that was, I'm going to guess four months, three months ago. Maybe A little further back. I think September or October.
I don't know the exact timeframe. Yeah. Well, time flies when you're having fun.
So, so how's it, how's it been being a chief security evangelist? I mean, I think it's great because I can focus externally 100% of the time. I mean, that's what I love to do, and that's what I feel like I kept getting drawn to do, uh, to be part of the community.
Uh, thankfully the community welcomes me, um, and, and, and, and, you know, you keep getting pulled back to if you have teams that rely on you to manage them. So now I'm 100% outward focused and I get to talk to you twice as much. I hope Alan, I I would hope so.
You know, you, you know, you have a standing invite whenever you want to pop in, unless you feel like escaping. Well, it's getting spring. I was gonna say, if you wanna escape the winter weather, come down here, we could do these in person.
That would be fun. Always A lot of fun. Anyway, it is that time of year though.
Yep. For the Veracode state of software security. This is the 2025 edition, hard to believe.
15 years Yes. Of Veracode State of security reports and surveys and research. Wow.
It, It, it really highlights how long that we have been struggling with this Problem. Problem as an industry. Say it really highlights how old we're getting, Chris.
Well, there's that too. It's okay. There's that too.
I was looking for the positive spin where we've been working on A problem. Absolutely. Well, no, this, it's okay being older.
It's, it's positive. We're wiser. That's right.
Um, so let's set the table a little bit. 15 years you guys are doing this. Look, 15 years ago, the whole AppSec thing was, I don't want to say new, but it wasn't as well settled as it is today.
Right, right. The, the idea of AppSec and, you know, and, and for those who don't know the, the genesis of Veracode and the at stake teams and the, you know, all of the different kinda machinations leading to what today is Veracode, you know, there are a lot of really smart people who've worked on this thing for 15 years. Man, really smart.
And, and the greatest, in my mind, the greatest thing about it is that you do have 15 years of data now to Kinda look at. Yeah. I mean, it, it just, I, I, I love looking back and, and we have slices in this report from volume one 15 years ago in 2010, which I think was the third or fourth year of operations for Veracode.
So we, we did have some significant amount of customers to actually talk about. And then we also have volume 10 from five years ago and today, and we can look at what's happened over the last 15 years. It's not many companies can do that.
I think we're the only one. No, I, I don't disagree, man. It's crazy, right?
Yeah. Um, so, you know, in, in the meantime, again, before we even jump into the findings, this report has really become sort of like a cornerstone report used by so many people and so many, you know, different organizations, uh, throughout the world, really. Yeah.
I think one of the reasons is it's not a survey, it's actual data. Like, you know, Verizon puts out their DBIR, which started a few years before we did it, and we, we learned a lot from that actually. We used some of the same people to help us with our analytics that work on that.
Um, and it's the, the thing that really makes, I think these reports impactful is they're based on real data. This isn't the survey. This isn't what some developer thinks, or what some application security expert thinks, or what some CISO thinks On what they want you to think, What they want you to think.
This is what's actually going on. Like, so when we say whether or not the app has a, a high severity flaw in it or not, it's not an opinion, right? It's either there or it isn't.
And, um, I think that makes the data, uh, more compelling and that's, that's one of the real benefits of using service providers, right? And this, this is one thing, when I started Veracode, I didn't really understand all the benefits of a SaaS company. And one of them is to be able to look across all customers and help a customer benchmark themselves, help them understand where they sit relative to other customers and where the industry averages are.
And if you're doing better than the industry average, thumbs up. But if you're doing worse, you know, you don't wanna do worse when you get a breach and you're, your, you, all your metrics are lower than the industry average that just shows you are incompetent or perhaps negligent. So this helps companies protect themselves and know what good is and where they should be striving for.
Absolutely. Absolutely. Um, you know, Chris, I, I feel obligated to just mention that, you know, the data set that you guys are pulling, as you mentioned, it's not a survey.
This is actually data taken from Veracode's monitoring and, and applications. Of course it's anonymized. 3 million unique applications Yep.
With over 126 million raw findings, right. That are all being, you know, uh, number crunched in here to get to get some of these. Uh, and, and, you know, and what you're really looking for is trends and, you know, the, the kinds of things that you could, patterns that you could pick out and point things.
Um, enough of, of the background. Let's jump into some of the findings this year, if you can. Yeah, sure.
I think, you know, one of the things that we wanted to highlight was this report really showed that there is good news. And, you know, for such a long time, you know, things haven't changed. You know, it was just like, oh yeah, people are still doing SQL ejection, people still are shipping code with high risk vulnerabilities in it.
And of course that's happening today, but it's to a lesser extent. And so when we look back to 2010 and we analyzed every, we, we, we held up every application to the O os top 10, only 23% of the apps passed, which means, you know, let me do my math, right, 77% had one or more of the awas top 10 flaws, which we all know are the exactly the kind of things we want to fix, because attackers know how to exploit those. Right?
In 2020, it went up to 32% passed. So in 10 years we got 9% of improvement. And so you can see where it's like, yeah, that's not that exciting.
10 years to go up, 9% slow. But the thing that one, why we said that we see you some really good news is, is in 20 25, 50 2% passed. So in the last five years, we've had a 20% increase, and we finally have the majority of applications that we look at having no o os top 10 vulnerabilities in them.
And I got excited about that when I was talking to the press and analyst before I talked to you and, and, and one of the reporters came to me and said, you're getting excited that 50 only 52% are passing. And I guess I, I, I was a little introspective and said, that's, that's how jaded I am, that I'm getting excited that we finally got a majority of apps with no au top 10. But we're there, and I think I see this as a very positive trend.
What's happened over the last five years. Absolutely. First of all, thank you for not including me with those precedent analyst types.
I never considered myself one of them. I'm a security person and I have been for 25 plus years. But you know what, I'm excited too, Chris.
I'm excited too. We, we crossing that 50% mark is a huge threshold. Right.
You know, all we hear about is too many people b***h and moan about the OAS top 10 not changing enough. Right. You don't wanna know why it doesn't, didn't change a lot because it was still the same crap that people had in their applications.
Exactly. That's why it's still a problem. All those things are Still a problem.
It wasn't a question of, oh, not wanting to change. It was a question of these were the same vulnerabilities that we were fighting year in and year out, day in and day out, 50%. You know, I'm a big believer in that crossing the chasm model, Right?
Right. There's always the 15% of early adopters, then there's the 35% of the, of the early mainstream, then there's 35% later mainstream and then 15% laggards. Exactly.
If you crossed 50%, you're into that second 35% of the mainstream. What we may never get the 15% laggards. Right.
But now where are the, the back nine, if you will. Right, Exactly. And, and it's, and the improvement is accelerating.
So the way I looked at it absolutely was it was like 1% a year or even a little less for 2010 to 2020. I was like, I am going to be dead before we get to 60, 70%. It would be Both.
But the fact that we, we went up basically, you know, 2% a year now, um, uh, I, I think, you know, we could, we could be sitting here five years from now and we're be gonna be at like 72% apps. So That would be amazing. I, I think amazing.
We, we, we've, we've crossed some chasm here and I, I think I, I'm happy to bring that news because I'm someone who's been here a long time and, and, and been, been, been disappointed in the improvements development teams have made, but now they are making an improvement. It's, it's quantifiable. Let me ask you a question.
Do you think we're seeing this improve? Why do you think we're seeing this improvement? Is it that we are modernizing our apps a lot more than we were before?
And as part of that modernization, we are fixing these kind of mundane, if you will, you know, vulnerabilities and stuff in there. Is AI have something to do with it? Are we all of a sudden got, have we gotten religion about security?
A combination of all the above? What do you think? Yeah, I think there is something to be said about the languages and frameworks.
The more modern are, are, are, are protecting things from things like cross site scripting and SQL injection at a framework level. I think that's having an effect. But I think a bigger effect is that, um, things like the Biden Cybersecurity eo, which talked about, um, you know, attesting to your software development process and having an SBO m because of course no one wants an SBO m that they're handing over to a customer that is full of third party vulnerabilities.
Right. Because when I talk about these vulnerabilities, this is first party and third party, so it's all in there. Um, and so I think the fact that the federal government is saying, we're requiring this, we're gonna ask our customers.
There are things in the EU regulations that have come forth. It means that customers of people delivering software are asking questions. They're saying, do you have an sbo m What is your software development lifecycle like?
And I, and I think there's some positive pressure coming from the consumers of enterprise software and commercial software that is making companies say, you know, we kind of have to do this now. Yeah. I agreed.
Agreed. Um, I, well, I don't wanna say I'm gonna, I, I'm hopeful, Chris, that I think we're gonna see this accelerate, we'll see this 2% rate double to 4% Yeah. In the, in the coming years.
And I, I do think there are some, I think AI is gonna really help with this. 'cause though right now AI generates, you know, maybe not as good a code as a, a real person would, would generate. I do think it's gonna improve.
And one of the things that could really improve on is generating code that doesn't, if you tell it, these are the kinds of flaws to look for. These are the kinds of vulnerabilities we don't want in our code. It could do a good, I think it could do a good job.
Yeah. I, I think, I think two ways AI can help. One is when people are prompting AI to write a routine or, or do some functionality, put in your prompt, you know, and you know these exactly what you're saying, like make sure that the o os top 10 is not in there.
Think about application security as you're writing the code. And I think that will make the code better. But the we, that's not gonna make the code perfect.
We're still gonna have to test the code. We're still gonna find Absolutely. One of the, one of the challenges is AI's context window is not the whole program.
It's small, so it can't really, it, it can think about not putting in SL injection, but it doesn't, it doesn't have the context of the whole rest of the program in there. So it can't always know what it's doing, could be causing a problem. So we still have to have testing.
But I think the thing that really is helpful with AI is fixing code. And I think we're gonna see a lot of auto remediation. We have Veracode fix doing this today.
It's very, very successful. If you point it out a vulnerability and say, Hey, there's, there's SQL injection on this line of code, it will just give you the right code to put in. And fixing flaws actually doesn't need a lot of context because you're, you're telling it there is a flaw on this line of code because you found it with manual testing, with dynamic testing, with static testing, you're, that is what had the big context and you're telling it about it.
And we find that it's really good at fixing flaws. And so this is ly I think ai it's, it's, it's okay at writing code. It's okay at finding, but it's really good at fixing.
And so we're pushing for that. And that's, that's also good news. Yeah.
All What other, what other findings in this year's report, Chris? Well, you, we did have, we did have some bad news. Um, and it's kind of interesting and this, I think this really does go to the way we're building applications.
We've seen the length of time it takes to fix a flaw on average go from 59 days to 2010 to 171 days in 2020 to 252 days in 2025. So this is also accelerating the length of time it takes to fix code. And so I think apps are getting more complicated.
Remediation is getting more siloed. Um, you know, these cloud environments are more complicated. We got code running in containers.
We got all these microservices. It might be an ai, I'm sorry, an API that another team within your enterprise is building. And it turns out that the fixing is just taking longer and longer to happen.
And I think that's because it's not a single team in a single monolithic piece of code. The, the flaws are spread out more now. And it's, it's just more complex.
And also we're going faster. So we're writing more code per unit of time. So we're generating more vulnerabilities per unit of time.
Just given everything equal. That means we have to fix more vulnerabilities per unit of time. And I don't think we're doing that yet.
And hopefully the AI fixing can help, but I, I think that we're just not fixing the flaws per unit of time like we used to because we're going faster and, and we're doing it at the expense of fixing. So why look at that problem and say, okay, fixing more vulnerability vulnerabilities per unit of time is, is worthy. And with ai, I think we can, we can absolutely move that needle.
Are we ever gonna develop better quality code? Um, you know, I, I think the only hope for that is the AI prompting when we're, when we're generating code. Um, I think we've done a lot at the language and framework level.
I don't know if we can do much more there. Um, you know, we can certainly not code in CNC plus plus, uh, anymore. Well, I Mean you bring that up, but the legacy all there.
Yeah. Well, and a lot of it is legacy stuff. But look, this is a big debate raging in the Linux community right now, right?
Because Linus and, and some of the other folks, you know, they want to go, they want to use more rust. Yep. Right?
And so, I mean, it's great for new code, but the, the thing is like, how much new code are you adding a year to the kernel? 5% does it, so does it take over 20 years to get the benefit, true benefit of it? It just slowly gets in there.
So that's, that's one of the challenges of that legacy absent CNC plus plus, no one wants to rewrite an app. I mean, no, that almost never happens. No one does.
But I, I'll tell you, you know, uh, last week I was at suson down in Orlando, you know, from the suse, Linux and Yep. Rancher and everything they do. Um, and I, I had a chance to talk to folks from Dell and, and AWS and a bunch of other companies.
Um, and, and not only that, in talking to people over the last few months, we're, we're, we're at an interesting time right now when it comes to app development and app modernization, Chris, right. And I'm not, no one's a villain. I'm not, don't get me wrong.
I'm not trying to bad mouth anyone here, but, you know, you've got a lot of people reevaluating their commitment to VMware in light of licensing and pricing changes. Part of that reevaluation is do I continue to run it in a data center or do I wanna move it to the cloud because the cloud is offering some great migration paths. Mm-hmm.
And if I'm gonna move it to the cloud, should I just go all in and, and maybe rearchitect my app and you know? Yeah. Uh, microservice architectures versus monoliths, right?
Um, should I, should I go cloud native, right. All in go cloud native. Should I run Cobe on bare metal?
Should I move stuff to the edge? Should I, we have, so how much a, you know, how, how can I leverage AI in all of this? There are so many Things in flux right now.
Yeah. And I Is that, you know, what's happening, I would hope that security would be part of the decision because almost anytime you go to a more modern architecture, more modern languages and frameworks that security has been considered in, in the building of, of, of those things. And it just makes a More than it was in the past.
We like to think anyway, right? Yes. In the last five years for sure.
Mm-hmm. For sure. And some things just need to get deprecated.
I mean, I, the, the poster child for this is, is, is Flash. Um, well, But you know what, that's one, and remember the b******g and moaning Yeah. Herd when this was going on.
Yep. You don't see flash anymore for, for pretty much. No, no.
And, and, and Adobe, Somehow we've managed to survive. We have Adobe was realistic at some point. They said, we've tried, we've tried.
It's just the code is this too much? C code iss too complicated. We can't secure it.
And, and so everything else is a little less bad than that. But these things that are close and people are still trying to secure them, and they're not, they're not, I I call it, you know, basically security bankruptcy, they declared security bankruptcy. Let's start again.
Yeah. But you know what? So I'm, I'm the boy in the room with all that pony crap saying, I know there's a pony here somewhere.
Yeah. Um, I, I am optimistic that we are on the cusp of, of really making changes here for a lot of reasons I haven't mentioned the quantum word. Right.
All of a sudden, Chris, I'm, I'm hearing people starting to talk about quantum, like it's almost real. You know, I, it, it, I I've, I've, I've gone to plenty of presentations from, you know, people with PhDs and they basically say it'll be sometime within the next three and 40 years. Yeah.
That's, that, that nails it down. Yeah. I mean, you know, okay.
Right around Around with Fusion. I, I can't look out 40 years on, on how a computer is going to be built. It's crazy.
Well, that, that's funny. I I, we did a story on Textron gang last week, I think it was meta, maybe open AI meta. And another company came out and said that by the year 2050, Okay.
Most of their data centers will be running on nuclear energy. Okay. The fact that they even said the year 2050 tells me that they don't, they don't believe idea.
They Don't really know. Because it would be idea it would be 2035 if you had a plan, Right. If you really had a plan.
Right. 2050, you might as well just say, you Know, they won't even be working at those companies Anymore. Pick fly.
Exactly. They're making a prediction for the next generation at those companies that are lifers. Yeah.
So that's, you know, to me that that's the kind of stuff we we see with this. Yeah. All right, Chris, we're running low on time.
Okay. Gimme one other prediction and then let's tell people how they can go dive in themselves. Yeah.
So I mean, there was one final piece of this, which was, um, third party risk and critical third party risk was worse than first party risk. When you just look at the critical vulnerabilities, there's actually more in the third party code than the first party code. And I, I looked into this and it, it's actually pretty hard to fix a lot of third party code.
And, and people don't really, they think, oh, I just update my library. Yeah. Right.
No, sometimes you actually have to change the code, and sometimes you have many packages that are dependent on another package, and you gotta get it all right. It can't just be one package, it's sometimes a dozen packages. So I think we gotta get better at fixing third party code, and hopefully AI can help there.
But that to me is now one of the new bigger problems, is you're gonna get bitten by a critical bug that has been hanging out in your code for a year and you haven't been able to fix Software supply chain security and SBOs, my friend. Yes, absolutely. Hey, I'm sorry, go ahead.
No, I was just gonna say, SBOs are kind of a forcing function that makes people fix the code because they don't want to share that they have these vulnerable packages in their, in Their apps. Absolutely. But we have to, and we, we've gotta get better about downloading software from repos.
Yeah. Not, not be, we are pretty good at downloading software for repo. Right.
Making sure what we're downloading doesn't have making sure is is secure. Yeah. Malicious code in it.
And it is, it's secure. Yes. Chris, where can people get more information on their, uh, state of software security 2025?
com, you can, you can find out about state of software security report. Uh, we just scratched the surface with like three or so metrics. There's a couple dozen.
If you haven't seen it before, you're gonna learn a lot. Absolutely. Chris, thank you.
Thank you to everyone at Veracode. I know this is a, look, this isn't a trivial thing to get this report out every year, so thank you to everyone who worked on it. Thank you for all the great stuff you do.
I will see you in person, I assume, at RSA, but I will be there. I'm Speaking, maybe we'll see you before. I'm gonna be actually talking about some of this data.
I'm speaking with Jay Dyson from Columbia, and the title of our talk is Secure by Design. Are we winning? And I'm gonna show some of the good news and bad news from the report.
Hopefully the good news shows, maybe we are winning. We'll see. I I like to think I'm, I'm that half, half full kind of guy.
Yeah, I'm 52% full. Okay. There you go.
This year. You are? This year.
All right, Chris. It's good seeing you. Alright, take care, Alan.
Chris Weiss, chief Security Evangelist of Veracode here on Text Drug tv. We'll be back in just a moment. Bye-bye.