Black Duck

42 STATS5 REPORTS

All Statistics

54% of organizations using at least four compliance controls remediate critical vulnerabilities within a day.

Compliance ControlsVulnerability ManagementCritical VulnerabilitiesCritical Vulnerability Remediation

76% of organizations check AI code for security risks.

AI CodeSoftware DevelopmentAI Code Security RisksVulnerability Management

Organizations that effectively track and manage open source dependencies are 85% more prepared to secure open source software compared to the overall average of 57%.

Open SourceSoftware SecurityOpen Source DependenciesVulnerability Management

63% of respondents that prioritize SBOM validation say they're highly prepared to evaluate third-party software.

Third-Party Software SecuritySoftware Supply ChainSBOM ValidationVulnerability Management

60% of organizations that perform automatic continuous monitoring report remediating critical software vulnerabilities within a day.

Vulnerability ManagementSoftware DevelopmentAutomatic Continuous MonitoringCritical Software Vulnerabilities

Only 24% of organizations have adopted comprehensive strategies to secure AI-generated code.

AI-Generated CodeSoftware DevelopmentAI-Generated Code SecurityVulnerability Management

35% of respondents cite interpreting and operationalizing complex regulatory requirements as their biggest challenge.

ComplianceRegulatory

Only 45% of the full respondent pool say they remediate critical software vulnerabilities within a day.

Vulnerability ManagementCritical Software VulnerabilitiesCritical Software Vulnerability Remediation

59% of respondents that prioritize SBOM validation typically respond to critical software vulnerabilities within one day.

SBOMSBOM ValidationVulnerability Management

95% of surveyed organizations reported using AI tools in software development.

AI ToolsSoftware Development

49% of organizations using at least three compliance controls remediate critical vulnerabilities within a day.

Compliance ControlsVulnerability ManagementCritical VulnerabilitiesCritical Vulnerability Remediation

31.5% of organizations produce SBOMs due to industry regulations.

AISBOMs

96.1% of organizations are integrating open source AI models into their products.

AI

18% of companies are affected by "Shadow AI".

AIShadow AI

21.1% of companies lack confidence in their ability to prevent AI from introducing security vulnerabilities.

AISecurity vulnerabilities

70.8% of organizations now produce Software Bills of Materials (SBOMs).

AISBOMs

39.4% of organizations produce SBOMs due to customer and partner requirements.

AISBOMs

89.3% of organizations are already using AI-powered coding assistants.

AIAI coding assistant

A decisive shift towards memory-safe languages has been adopted by 80.4% of companies.

AI

91% of audited applications contain outdated open source software components.

86% of audited applications contained open source vulnerabilities, with 81% containing high- or critical-risk vulnerabilities.

The number of open source files in an average application has tripled over the last four years.

64% of open source components were transitive dependencies.

56% of all audited applications had license conflicts.

97% of all applications evaluated contained open source software.

Nearly 30% of component license conflicts were caused by transitive dependencies.

90% of the applications contain components more than 10 versions behind the most current version.

33% had open source software components with no license or a customized license.

Automated verification of infrastructure security surged by more than 50%.

Black DuckBSIMM16·1y ago
Infrastructure SecurityAutomationApplication Security

Teams using attack intelligence to track emerging AI vulnerabilities increased by 10%.

Black DuckBSIMM16·1y ago
AI SecurityThreat IntelligenceApplication SecurityAI Vulnerabilities

Application of custom rules to automated code review tools to catch issues unique to AI-generated code increased by 10%.

Black DuckBSIMM16·1y ago
AI SecurityCode ReviewDeveloper ToolsAI-Generated Code

Use of risk-ranking methods to determine where LLM-generated code is safe to deploy increased by 12%.

Black DuckBSIMM16·1y ago
AI SecurityRisk ManagementApplication SecurityLLM-Generated Code

Streamlining of responsible vulnerability disclosure grew by more than 40%.

Black DuckBSIMM16·1y ago
Vulnerability DisclosureRegulatory ComplianceApplication SecurityResponsible Vulnerability Disclosure

Organizations delivering expertise through open collaboration channels increased by 29%.

Black DuckBSIMM16·1y ago
Collaboration

Establishment of standardized technology stacks rose by more than 40%.

Black DuckBSIMM16·1y ago
Technology StackApplication Security

Nearly 30% more organizations now produce SBOMs to meet transparency requirements.

Black DuckBSIMM16·1y ago
SBOMRegulatory Compliance

The number of organisations conducting adversarial tests (abuse cases) has doubled year-on-year.

Black DuckBSIMM15 Report ·1y ago
Adversarial tests

There has been a 67% increase in the number of organisations performing software composition analysis (SCA) on code repositories.

Black DuckBSIMM15 Report ·1y ago
SCA

The number of organisations employing research groups to develop new attack methods has grown by 30%.

Black DuckBSIMM15 Report ·1y ago
Research groups

A 22% rise in the number of organizations creating software bills of materials (SBOMs) for deployed software has been observed.

Black DuckBSIMM15 Report ·1y ago
SBOMs

In 2008, 100% of organizations in BSIMM1 conducted software security awareness training. By BSIMM15, this rate has declined to 51.2% of organizations, marking the lowest rate to date.

Black DuckBSIMM15 Report ·1y ago
Software security awareness training

Only 51.2% of organisations now offer basic security training, which is the lowest rate observed since the BSIMM initiative began in 2008.

Black DuckBSIMM15 Report ·1y ago
Training