AI DevwWrld CyberDSA Chatbot Summit Cyber Revolution Summit CYSEC Global Cyber Security & Cloud Expo World Series Digital Identity & Authentication Summit Asian Integrated Resort Expo Middle East Low Code No Code Summit TimeAI Summit

Public vs private sector: differences in application security

How government organizations can overcome security challenges in software applications to ensure effective data protection

This pill is also available in Italian language

Applications developed by public sector organizations tend to have more security flaws than those created by the private sector, as noted by Veracode. These findings are of particular significance as an increase in flaws and vulnerabilities in applications translates into increased levels of risk. The research emerges in the context of a number of recent US federal government initiatives to strengthen cybersecurity, including efforts to reduce vulnerabilities in applications that perform critical government functions.

The security difference between public and private sector applications

The researchers found that just under 82 percent of applications developed by public sector organizations had at least one security flaw detected during their last scan in the past 12 months, compared to 74 percent of private sector organizations. Depending on the type of defect tracked, public sector applications had a 7 to 12 percent higher chance of introducing a defect in the past year. “The difference between the rate at which defects appear in public and private sector applications is significant. Government efforts to close this gap are needed and should continue. As custodians of public safety, agencies have a duty to close this gap and strengthen security to protect the nation and its citizens,” said Chris Eng, chief research officer at Veracode.

Security anomalies and impact on public functions

However, the numbers alone do not convey the consequences that occur when attackers exploit software flaws and vulnerabilities. For example, in May of this year, a ransomware attack against the city of Dallas crippled the functions they rely on to deliver public services, including the IT systems used by public safety agencies. Over three weeks after the attack, public agencies in Dallas still hadn't fully recovered.

Positive prospects for the public sector and actions needed to improve safety

Despite the worrying data, Veracode's research also found reasons to be optimistic about the security of applications in the public sector. The discovery of "high severity" defects in public sector applications (16.5%) over a 12 month period was lower than in private sector applications (19%). This is notable because high-severity flaws, when exploited, have a greater potential to negatively impact systems. However, to further improve their security posture, agencies need to take four actions: remediate the accumulation of known defects, run scans regularly, automate testing through APIs to reduce the introduction of defects into applications, and use dynamic scanning to discover defects that other types of scans may not detect. “The public sector has made great strides in strengthening the security of applications that serve our government, but there is still much work to be done to improve their cyber security posture and fend off incoming threats. Focusing security efforts on the root cause of most cyber breaches, i.e. the application layer, agencies can achieve the necessary improvements,” concluded Eng.

Follow us on Google News for more pills like this

06/07/2023 04:01

Editorial AI

Last pills

Serious vulnerability discovered in Rabbit R1: all user data at riskVulnerability in Rabbit R1 exposes sensitive API keys. What are the privacy risks?

Cyber attack in Indonesia: the new Brain Cipher ransomware brings services to their kneesNew ransomware hits Indonesia: learn how Brain Cipher crippled essential services and the techniques used by hackers

Patelco Credit Union: security incident halts customer services in CaliforniaService disruption and customer frustration: Patelco Credit Union works to resolve security incident

Cyber attack on TeamViewer: immediate response and investigations underwayStrengthened security measures and international collaborations to counter the cyber threat