Checkmarx
Reports
All Statistics
Within one year, the share of organizations knowingly shipping vulnerable code decreases from 81% to 75%.
96% of developers acknowledge having AI tooling integrated in their IDEs.
Companies with 81–100% AI-generated production code ship software with known security vulnerabilities at a 47% rate compared with 14% for companies with 1–20% AI-generated production code, making them nearly three times more likely.
Fewer than half of the CISOs, AppSec managers and developers report deploying foundational security tools like dynamic application security testing (DAST) or infrastructure-as-code scanning.
Just 51% of North American organisations report adopting DevSecOps
Only half of organisations surveyed actively use core DevSecOps tools.
In North America, only 8% of respondents report security is “always” a factor in purchasing decisions.
In the Asia Pacific region, 33% of respondents report security is “always” a factor in purchasing decisions.
Only 39% of business operations run on secured applications, according to CISOs.
72% of developers spend more than 17 hours each week on security-related tasks.
99.6% of developers have access to security training.
18% of developers apply security continuously as they write code.
95% of CISOs feel pressure to suppress or delay compliance-related security issues when business deadlines are at stake.
75% of organizations knowingly deploy vulnerable code at some point.
Within one year, the proportion of companies with formal AI governance policies increases from 18% to 22%.
93% of organizations acknowledge a recent breach tied to their own applications.
73% of organizations describe their security posture as 'advanced' or 'highly mature'.
78% of organizations lack formal AI governance policies.
More than 80% of developers do not apply application security continuously as code is written.
34% of CISOs, AppSec managers and developers admit that more than 60% of their code is AI-generated.
98% of organisations experienced a breach stemming from vulnerable code in the past year.
Within the next 12 to 18 months, nearly a third (32%) of CISOs, AppSec managers and developers expect Application Programming Interface (API) breaches via shadow APIs or business logic attacks.
Only 18% of organisations have policies governing AI use.
81% of organisations knowingly ship vulnerable code.
Up to 60% of code is being generated by organisations using AI coding assistants.
Half of CISOs, AppSec managers and developers already use AI security code assistants.
81% of organisations knowingly ship vulnerable code.
20% of organisations still forbid the use of AI coding assistants.
In nearly half of software-based product companies, security oversight has moved outside the CISO’s office entirely.
49% of CISOs say that buyers now factor application security (AppSec) into purchasing decisions.
In Europe, 58% of respondents report that security is “always” a factor in purchasing decisions.
24% of respondents indicated that application security is “always” a factor in purchasing decisions.
56% of organisations say that most of their development teams are fully integrated with AppSec programmes.
In organisations developing software-based products, responsibility is split: 50% of organisations assign security responsibility to CISOs, while 43% move security oversight to development teams.
62% of CISOs report AppSec metrics to their board.
90% of developers rank the effectiveness of the training they receive as medium or high.
One in four developers spends more than 25 hours each week on security-related tasks.
21% of developers surveyed say that security is their top priority when coding.
28.3% of organisations are tracking mean time to remediate as a metric.
46.27% of organisations are tracking ability to meet deadlines
41.53% of responding developers reported that they understand the vulnerability tickets they receive, as well as how the vulnerability manifests during runtime, from 41-60% of the time.