Checkmarx
Reports
All Statistics
Companies with 81–100% AI-generated production code ship software with known security vulnerabilities at a 47% rate compared with 14% for companies with 1–20% AI-generated production code, making them nearly three times more likely.
Within one year, the share of organizations knowingly shipping vulnerable code decreases from 81% to 75%.
96% of developers acknowledge having AI tooling integrated in their IDEs.
Half of CISOs, AppSec managers and developers already use AI security code assistants.
Fewer than half of the CISOs, AppSec managers and developers report deploying foundational security tools like dynamic application security testing (DAST) or infrastructure-as-code scanning.
Just 51% of North American organisations report adopting DevSecOps
49% of CISOs say that buyers now factor application security (AppSec) into purchasing decisions.
In North America, only 8% of respondents report security is “always” a factor in purchasing decisions.
In the Asia Pacific region, 33% of respondents report security is “always” a factor in purchasing decisions.
21% of developers surveyed say that security is their top priority when coding.
90% of developers rank the effectiveness of the training they receive as medium or high.
41.53% of responding developers reported that they understand the vulnerability tickets they receive, as well as how the vulnerability manifests during runtime, from 41-60% of the time.
18% of developers apply security continuously as they write code.
95% of CISOs feel pressure to suppress or delay compliance-related security issues when business deadlines are at stake.
75% of organizations knowingly deploy vulnerable code at some point.
Within one year, the proportion of companies with formal AI governance policies increases from 18% to 22%.
93% of organizations acknowledge a recent breach tied to their own applications.
73% of organizations describe their security posture as 'advanced' or 'highly mature'.
78% of organizations lack formal AI governance policies.
More than 80% of developers do not apply application security continuously as code is written.
Only half of organisations surveyed actively use core DevSecOps tools.
34% of CISOs, AppSec managers and developers admit that more than 60% of their code is AI-generated.
98% of organisations experienced a breach stemming from vulnerable code in the past year.
Within the next 12 to 18 months, nearly a third (32%) of CISOs, AppSec managers and developers expect Application Programming Interface (API) breaches via shadow APIs or business logic attacks.
Only 18% of organisations have policies governing AI use.
81% of organisations knowingly ship vulnerable code.
Up to 60% of code is being generated by organisations using AI coding assistants.
20% of organisations still forbid the use of AI coding assistants.
Only 39% of business operations run on secured applications, according to CISOs.
In nearly half of software-based product companies, security oversight has moved outside the CISO’s office entirely.
In Europe, 58% of respondents report that security is “always” a factor in purchasing decisions.
24% of respondents indicated that application security is “always” a factor in purchasing decisions.
56% of organisations say that most of their development teams are fully integrated with AppSec programmes.
In organisations developing software-based products, responsibility is split: 50% of organisations assign security responsibility to CISOs, while 43% move security oversight to development teams.
62% of CISOs report AppSec metrics to their board.
72% of developers spend more than 17 hours each week on security-related tasks.
99.6% of developers have access to security training.
One in four developers spends more than 25 hours each week on security-related tasks.
28.3% of organisations are tracking mean time to remediate as a metric.
46.27% of organisations are tracking ability to meet deadlines