logo

Deadlines vs. secure code: What AppSec teams can do 

ID: ef8ee45d-1485-5f95-bcb7-01f448943cf3

STIX ID: report--ef8ee45d-1485-5f95-bcb7-01f448943cf3

Feed Name: ReversingLabs Blog

Date Published: 2025-09-23

Date Updated: 2026-04-29

Author: John P. Mello Jr.

...
...

Surveys by Cypress Data Defense and Checkmarx indicate most organizations knowingly release vulnerable code due to delivery pressures, fragmented security tooling, and alert fatigue; experts recommend mitigating this through contractual safeguards (e.g., SLAs, secure development warranties, RACI), continuous monitoring and automated validation, business-contextual risk scoring/tiering (CVSS/EPSS/SSVC), and transparency via SBOMs, due diligence, and independent testing, with dynamic third-party monitoring as software and dependencies evolve.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.