# How the financial services industry can solve the issue of vulnerable code
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2021-02-03
Category: FINANCE
Category URL: https://financedigest.com/category/finance
Meta Title: The Rise of Secure Coding in Financial Services
Meta Description: Discover how organisations in the UK can tackle cybersecurity threats by prioritising secure coding practices for their developers. Learn more with Matias
URL: https://financedigest.com/how-the-financial-services-industry-can-solve-the-issue-of-vulnerable-codehtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/untitled-design-5-1736838593020-compressed.jpg)

_By **Matias Madou,** Co-Founder and CTO of Secure Code Warrior_

With 2020 bringing a heavy focus on online business, it is fair to say that most organisations are expanding their digital footprint, and the resulting demand for software developers has never been so high. _IBISWorld_ reports that the market size of the software development industry in the [UK has grown 7.3% per year on average between 2015 and 2020](https://www.ibisworld.com/united-kingdom/market-size/software-development/#:~:text=What%20is%20the%20growth%20rate,to%20increase%205.1%25%20in%202020.&text=past%205%20years%3F-,The%20market%20size%20of%20the%20Software%20Development%20industry%20in%20the,average%20between%202015%20and%202020.) and it doesn’t end there. Software development is one of the top three skills for hiring managers going into 2021, according to [research by Robert Half](https://www.cio.com/article/3525575/uk-it-hiring-trends-to-watch-2020.html).

This trend is being felt across the financial services sector in particular, where digitalisation has been rapid. Unfortunately, cybersecurity [skills and processes are not growing](https://www.financedigest.com/finance-teams-using-ai-outperform-peers-as-demand-for-skills-grows.html "Finance Teams Using AI Outperform Peers as Demand for Skills Grows") at the same pace. With the industry’s reliance on software at an all-time high and a correlative rise in [cybersecurity threats](https://www.financedigest.com/hackers-for-hire-are-biggest-cybersecurity-threat-eu-agency.html "Hackers-for-hire are biggest cybersecurity threat -EU agency"), organisations are at breaking point. Just last year [, 70% of financial companies experienced a cybersecurity incident.](https://pages.clearswift.com/rs/591-QHZ-135/images/csw-the-unknown-threat-report-guide.pdf?_ga=2.154910584.1515187320.1601680767-547152612.1601680762) Not only this, but organisations are not future-proofing their IT infrastructure to deal with this magnitude of attacks. According to Deloitte’s report, “Pursuing Cybersecurity Maturity at Financial Institutions“, financial institutions dedicate a less than impressive average 0.3% of revenue and 10% of their IT budget to cybersecurity. This is particularly consequential in an [industry that holds such sensitive and confidential data](https://www.financedigest.com/navigating-consumer-data-in-the-finance-industry.html "NAVIGATING CONSUMER DATA IN THE FINANCE INDUSTRY"), and financial institutions must take security more seriously in order to see change.

The thing is, investing in strong cybersecurity doesn’t always mean splashing tonnes of cash on [application security](https://www.financedigest.com/five-ways-bad-bots-are-trying-to-crack-your-virtual-vaults-by-erez-hasson-strategist-application-security-at-imperva.html "Five Ways Bad Bots Are Trying To Crack Your Virtual Vaults") tools. A [2019 study found](https://www.ptsecurity.com/upload/corporate/ww-en/analytics/web-vulnerabilities-2020-eng.pdf) out of 32 web applications, 82% of vulnerabilities were located in the application code itself. That’s a lot of [risk that can be mitigated](https://www.financedigest.com/ai-holds-the-key-for-both-competitive-advantage-and-risk-mitigation-in-2022.html "AI holds the key for both competitive advantage and risk mitigation in 2022") by creating secure code in the first place. So, why are so many organisation’s still struggling to ‘start left’ and build a security-first mindset when it comes to coding?

**Dangling the carrot to encourage secure coding**

A survey of [400 security professionals](https://www.prnewswire.com/news-releases/synopsys-and-ponemon-release-new-study-highlighting-software-security-practices-and-challenges-in-the-financial-services-industry-300894781.html) across financial services by the Ponemon Institute found that only 43% of respondents said their organisations impose cybersecurity requirements on third parties involved in developing financial software and systems. This is an alarming amount of potentially insecure code flowing through the financial [services industry](https://www.financedigest.com/why-sustainability-presents-one-of-the-greatest-opportunities-for-the-financial-services-industry.html "Why sustainability presents one of the greatest opportunities for the Financial Services industry"), yet if training in secure coding was the norm, a lot of risk could be mitigated up-front.

There can be a reluctance [towards training developers on how to code securely](https://www.financedigest.com/steps-toward-fostering-a-security-first-culture.html "Steps Toward Fostering a Security-First Culture") due to a misconception that it will take them away from the job they are tasked to do and, naturally, are most interested in: building features. This is exacerbated by [rising consumer demands on financial institutions](https://www.financedigest.com/unfolding-the-great-payments-disruption-how-consumers-can-navigate-this-new-financial-world-and-how-financial-institutions-can-rise-to-the-challenge.html "Unfolding the Great Payments Disruption – how consumers can navigate this new financial world and how financial institutions can rise to the challenge") and ever shorter development release cycles. But this doesn’t have to be the case. Instead, organisations should take a proactive [approach in encouraging developers to take security](https://www.financedigest.com/as-saas-grows-financial-services-must-rethink-their-security-approach.html "As SaaS grows, financial services must rethink their security approach") more seriously, and remind them that coding securely is a skill to add to their toolbox, and once they learn how, they will get faster over time, reducing rework, and eliminating recurring security bugs at the root of the problem.

![Matias Madou](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/matias-madou-450x450-1736838592756-compressed.jpg)

Matias Madou

Another point to consider when motivating developers is that when they take the necessary steps to become security-aware, they stand out as a more efficient [member of the team](https://www.financedigest.com/playground-xyz-appoints-new-team-members-as-it-solidifies-its-position-as-a-leader-in-the-attention-space.html "Playground xyz appoints new team members as it solidifies its position as a leader in the attention space"). Their skill set reduces complete dependence on expensive, unreliable scanning tools, and helps bridge the gap for more specialist security personnel that are in short supply. Additionally, they become instrumental in [protecting their employer from cyberattacks and data breaches](https://www.financedigest.com/how-financial-organisations-can-stay-protected-from-financial-data-breaches.html "How Financial Organisations can Stay Protected from Financial Data Breaches "), and in a wider sense, become a more sought-after developer, opening themselves up for more prestigious and lucrative job opportunities.

**Providing developers with the right tools to code securely**

It is all well and good convincing [developers that security is important, but how does an organisation go about providing the developers with the tools to learn](https://www.financedigest.com/prioritising-employee-wellbeing-in-finance-firms-through-learning-and-development.html "Prioritising employee wellbeing in finance firms through learning and development") how to code securely? You are not likely to [change a developer’s mindset with traditional](https://www.financedigest.com/insurers-must-reimagine-traditional-risk-models-to-adapt-to-climate-change.html "Insurers Must Reimagine Traditional Risk Models to Adapt to Climate Change ") teaching methods like classroom-based training, or hours of videos irrelevant to their day jobs. In order to captivate their attention, and demonstrate how security can seamlessly fit into their current coding practises, they [must be given the opportunity to get hands-on training](https://www.financedigest.com/banks-and-insurers-right-to-prioritise-technical-skills-in-operational-risk-but-must-not-overlook-training-in-nurturing-talent.html "Banks and insurers right to prioritise technical skills in operational risk but must not overlook training in nurturing talent  ") by receiving dynamic exercises that mimic the code they would be working on a daily basis.

The most successful way of doing this is through hyper-relevant gamified [learning platforms](https://www.financedigest.com/brand-strategy-tactics-for-an-online-learning-platform.html "Brand Strategy Tactics for an Online Learning Platform"), which are integrated with day-to-day tasks. If the developer is actively led through how coding and security can be combined into the same offering, without taking them away from their job, they are more likely to continue best practise in the future.

While there is still a long way to go before the financial services industry eliminates insecure code, the sector is showing promising signs of change. Despite cybersecurity being relatively new in many organisations, it is refreshing that financial institutions are truly open-minded and innovative in their [quest to provide safe](https://www.financedigest.com/analysis-investors-face-expensive-quest-for-year-end-cash-and-safe-assets.html "Analysis-Investors face expensive quest for year-end cash and safe assets"), secure software. Many have laid the groundwork to be more security-aware than others, identifying a [need for and dedicating resources to holistic training programmes for not just application security](https://www.financedigest.com/no-collateral-no-problem-here-is-what-you-need-to-know-to-secure-a-business-loan.html "No Collateral, No Problem: Here is What You Need to Know to Secure a Business Loan") professionals, but also their (typically very large and globally scattered) development teams. Many have seen the benefit of upskilling the development team with engaging learning platforms that help not just fix existing problems, but give them the tools to [code securely in the future](https://www.financedigest.com/digital-democratisation-through-low-code-the-future-of-finance-success.html "Digital democratisation through low-code – the future of finance success"), creating a more robust security posture for the industry, its customers and society.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

