Report by Checkmarx

A CISO’s Guide to Steering AppSec in the Era of DevSecOps

10 FINDINGSPublished May 13, 2025
View Original Report →

Key Findings

In North America, only 8% of respondents report security is “always” a factor in purchasing decisions.

CheckmarxA CISO’s Guide to Steering AppSec in the Era of DevSecOps·May 13, 2025
Application security

In the Asia Pacific region, 33% of respondents report security is “always” a factor in purchasing decisions.

CheckmarxA CISO’s Guide to Steering AppSec in the Era of DevSecOps·May 13, 2025
Application security

Only 39% of business operations run on secured applications, according to CISOs.

CheckmarxA CISO’s Guide to Steering AppSec in the Era of DevSecOps·May 13, 2025
Application security

In nearly half of software-based product companies, security oversight has moved outside the CISO’s office entirely.

CheckmarxA CISO’s Guide to Steering AppSec in the Era of DevSecOps·May 13, 2025
Application security

49% of CISOs say that buyers now factor application security (AppSec) into purchasing decisions.

CheckmarxA CISO’s Guide to Steering AppSec in the Era of DevSecOps·May 13, 2025
Application security

24% of respondents indicated that application security is “always” a factor in purchasing decisions.

CheckmarxA CISO’s Guide to Steering AppSec in the Era of DevSecOps·May 13, 2025
Application security

In Europe, 58% of respondents report that security is “always” a factor in purchasing decisions.

CheckmarxA CISO’s Guide to Steering AppSec in the Era of DevSecOps·May 13, 2025
Application security

In organisations developing software-based products, responsibility is split: 50% of organisations assign security responsibility to CISOs, while 43% move security oversight to development teams.

CheckmarxA CISO’s Guide to Steering AppSec in the Era of DevSecOps·May 13, 2025
Application security

56% of organisations say that most of their development teams are fully integrated with AppSec programmes.

CheckmarxA CISO’s Guide to Steering AppSec in the Era of DevSecOps·May 13, 2025
Application security

62% of CISOs report AppSec metrics to their board.

CheckmarxA CISO’s Guide to Steering AppSec in the Era of DevSecOps·May 13, 2025
Application security