JFrog-Sponsored IDC Study Shows Growing Developer Focus on Software Security, Impacting Companies’ Competitive Advantage
Titled the "Hidden Costs of DevSecOps," the IDC InfoBrief Reveals Companies Spend an Average of $28KPerDeveloper Annually on Identifying, Evaluating, and Addressing Software Security Concerns
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20241009432650/en/
New IDC InfoBrief Shows Growing Developer Focus on Software Security, Impacting Companies’ Competitive Advantage (Graphic: Business Wire)
"Securing the software supply chain already poses significant challenges for organizations, but it becomes more complex when multiple tools are used, forcing developers to toggle between multiple environments, leading to inefficiencies, wasted time, and increased risk,” said
Half of survey respondents said they spend an estimated 19% of their weekly hours on security-related tasks, oftentimes outside normal working hours, which could lead to a reactive approach to security rather than a proactive one. Other key findings from the IDC survey include:
- Chasing Ghosts: Eliminating False Positives: Developers spend 3.5 hours on average manually reviewing security scanning findings because of false positives and duplicates.
- Context Matters: 69% of developers agree or strongly agree that their security-related responsibilities require them to frequently switch contexts between various tools, slowing efficiency. Multitool context switching can also increase token usage for bypassing reauthentication per platform. Tokens can be helpful in application development but can also be quickly forgotten and leave backdoors in companies’ systems for attacks.
- Secrets are No Fun: Developers devote 50% of their time to understanding and interpreting secrets scanning results, making changes to code to remediate findings, and updating secrets management measures.
- Infrastructure Investigation: Infrastructure-as-Code (IaC) – used to automate the provisioning and management of IT infrastructure, such as servers, networking, operating systems, and storage – must be scanned every time code changes, with more than 54% of developers saying they run IaC scans weekly or monthly.
- SAST Isn’t a Blast: Despite static application security testing (SAST) tools being integrated to local development environments to provide findings as developers code, only 23% of developers are running SAST scans before deploying code into production, leaving a huge gap for malicious code to slip through.
"DevSecOps is not just a business imperative; it is the cornerstone of building the secure applications of the future. However, a significant challenge lies in overcoming inefficient, poorly implemented tools that squander developers’ time and inflate costs,” said
The IDC InfoBrief surveyed senior developers, team leaders, product owners and development managers from companies in 20+ industries with 1K+ employees across the
Like this story? Tweet this: New @IDC survey finds that developers severely underestimate the time they spend performing #DevSecOps tasks, leading to hidden costs for their organizations. Read the full report: https://bit.ly/4feUtjl #DevOps #security #MLOps #softwaresupplychain
About JFrog
View source version on businesswire.com: https://www.businesswire.com/news/home/20241009432650/en/
Media Contact:
Investor Contact:
Source: