Report by ArmorCode & Purple Book Community

The Rise of the AppSec Leader: Survey Findings

13 FINDINGSPublished Apr 28, 2025
View Original Report →

Key Findings

86% of respondents are already using or exploring generative AI tools in their security programmes.

ArmorCode & Purple Book CommunityThe Rise of the AppSec Leader: Survey Findings ·Apr 28, 2025
Application securityAIAppSec

Among those who have encountered issues with AI-generated code, 83% cited lack of transparency as major concerns.

ArmorCode & Purple Book CommunityThe Rise of the AppSec Leader: Survey Findings ·Apr 28, 2025
Application securityAIAppSec

65% believe AI will significantly reshape the AppSec function within the next year.

ArmorCode & Purple Book CommunityThe Rise of the AppSec Leader: Survey Findings ·Apr 28, 2025
Application securityAIAppSec

84% said that supply chain vulnerabilities were the most significant threat to their enterprise applications.

ArmorCode & Purple Book CommunityThe Rise of the AppSec Leader: Survey Findings ·Apr 28, 2025
Application securityEnterpriseSupply chainVulnerabilitiesAppSec

84% recognise the role of the AppSec leader as more important now than ever. More than 84% believe their role is more important now than it was a few years ago. This increased importance is linked to factors such as growing challenges from AI-generated code and open source software.

ArmorCode & Purple Book CommunityThe Rise of the AppSec Leader: Survey Findings ·Apr 28, 2025
Application securityAIOpen source softwareAppSec

Speed of software development outpacing security priorities was also a concern for 71%.

ArmorCode & Purple Book CommunityThe Rise of the AppSec Leader: Survey Findings ·Apr 28, 2025
Software developmentAppSec

65% highlighted a lack of visibility across AppSec tools

ArmorCode & Purple Book CommunityThe Rise of the AppSec Leader: Survey Findings ·Apr 28, 2025
AppSec AppSec

63% still report moderate or significant friction in getting developers to adopt security team feedback, despite increased DevSecOps collaboration.

ArmorCode & Purple Book CommunityThe Rise of the AppSec Leader: Survey Findings ·Apr 28, 2025
DevSecOpsAppSec

Among those who have encountered issues with AI-generated code, 92% reported insecure code as a concern.

ArmorCode & Purple Book CommunityThe Rise of the AppSec Leader: Survey Findings ·Apr 28, 2025
Application securityAIAppSec

76% of respondents named application security posture management (ASPM) as their top investment focus for 2025.

ArmorCode & Purple Book CommunityThe Rise of the AppSec Leader: Survey Findings ·Apr 28, 2025
ASPMAppSec

64% of organizations are growing their AppSec teams.

ArmorCode & Purple Book CommunityThe Rise of the AppSec Leader: Survey Findings ·Apr 28, 2025
Application securityAppSec

Managing the sheer volume of vulnerabilities and false positives were the biggest challenges in securing code, cited by 78% of respondents.

ArmorCode & Purple Book CommunityThe Rise of the AppSec Leader: Survey Findings ·Apr 28, 2025
Application securityVulnerabilitiesFalse positives

Open-source risks and cloud misconfigurations followed supply chain vulnerabilities closely at 73%.

ArmorCode & Purple Book CommunityThe Rise of the AppSec Leader: Survey Findings ·Apr 28, 2025
Application securitySupply chainVulnerabilitiesCloud misconfigurationOpen source software