IDC InfoBrief Focuses on "The Hidden Costs of DevSecOps," Revealing That Enterprises Spend an Average of $28,000 Per Developer Per Year to Identify, Assess, and Resolve Software Security Issues
October 14, 2024 - JFrog, the streaming software company and creator of the JFrog Software Supply Chain Platform, released an IDC survey showing that developers are spending significantly more time on security-related tasks (such as manual application scanning reviews, context switching, and confidential information detection), and enterprises are spending up to $28,000 per developer per year on such tasks . The IDC InfoBrief, "The Hidden Cost of DevSecOps: A Developer's Time Assessment," sponsored by JFrog, shows that 50% of senior developers, team leaders, product owners, and development managers are spending significantly more time per week on software security-related tasks, which affects their ability to innovate, build, and deliver new business applications.
“Enterprises already face significant challenges in securing their software supply chains, and the situation becomes even more complicated when multiple tools are used, forcing developers to frequently switch between multiple online work environments, which reduces productivity, increases time costs and increases risks, ” said Asaf Karas, CTO of JFrog Security. “IDC’s survey provides a strong argument for enterprises to invest in more streamlined security processes, tools, and training that will help their developers more efficiently and effectively protect their software supply chains.”
In the survey, half of the respondents said that they spend about 19% of their time each week on security-related tasks, often outside of normal working hours, which may lead them to take a reactive rather than proactive approach to software security. Other key findings from the IDC survey include:
●Chasing Shadows: Eliminating False Positives: Developers spend an average of 3.5 hours manually reviewing security scan results to exclude false positives and duplicates.
●Context matters: 69% of developers agree or strongly agree that their security-related responsibilities require them to frequently switch context between various tools, which reduces their productivity. Multi-tool context switching also increases the use of tokens due to the need to bypass re-authentication for each tool platform. Tokens are helpful for application development, but they can also be forgotten in the workflow, leaving security holes in the company's systems that attackers can exploit.
●Key management is not easy: Developers spend 50% of their time parsing key scan results, modifying code to fix discovered issues, and updating key management practices.
●Infrastructure Survey: Infrastructure as Code (IaC) is used to automatically configure and manage IT infrastructure such as servers, networks, operating systems, and storage. It must be scanned every time the code is changed. More than 54% of developers said they run IaC scans once a week or month.
●SAST is not foolproof: Although static application security testing (SAST) tools have been integrated into local development environments and can provide test results as developers write code, only 23% of developers run SAST scans before deploying code to production environments, which leaves a huge hidden danger for malicious code to sneak in.
"DevSecOps is not only an enterprise imperative, it is also the cornerstone for building secure applications of the future. However, the industry is struggling to overcome the challenges of inefficient and poorly applied tools that waste developer time and drive up costs," said Katie Norton, research manager, DevSecOps and Software Supply Chain Security at IDC. "To succeed, IT and software development team leaders must automate repetitive and time-consuming tasks, ensure DevSecOps tools deliver accurate results with minimal false positives, and provide developers with ongoing application security education and resources to stay on top of the growing threat landscape."
The IDC Information Brief survey included senior developers, team managers, product owners, and development managers from more than 20 companies with more than 1,000 employees in the United States, the United Kingdom, France, and Germany.
Previous article:Qualcomm attends 2024 China Mobile Global Partner Conference: Renewing intelligence and creating a 5G+AI digital future
Next article:Mouser Electronics Now Shipping Molex UltraWize Wire-to-Board Connectors that Provide High Power Density for Data Center Applications
- Popular Resources
- Popular amplifiers
- Keysight Technologies FieldFox handheld analyzer with VDI spread spectrum module to achieve millimeter wave analysis function
- Qualcomm launches its first RISC-V architecture programmable connectivity module QCC74xM, supporting Wi-Fi 6 and other protocols
- Microchip Launches Broadest Portfolio of IGBT 7 Power Devices Designed for Sustainable Development, E-Mobility and Data Center Applications
- Infineon Technologies Launches New High-Performance Microcontroller AURIX™ TC4Dx
- Rambus Announces Industry’s First HBM4 Controller IP to Accelerate Next-Generation AI Workloads
- NXP FRDM platform promotes wireless connectivity
- WPG Group launches Wi-Fi 7 home gateway solution based on Qualcomm products
- Exclusive interview with Silicon Labs: In-depth discussion on the future development trend of Bluetooth 6.0
- Works With Online Developer Conference is about to start, experience the essence of global activities online
- LED chemical incompatibility test to see which chemicals LEDs can be used with
- Application of ARM9 hardware coprocessor on WinCE embedded motherboard
- What are the key points for selecting rotor flowmeter?
- LM317 high power charger circuit
- A brief analysis of Embest's application and development of embedded medical devices
- Single-phase RC protection circuit
- stm32 PVD programmable voltage monitor
- Introduction and measurement of edge trigger and level trigger of 51 single chip microcomputer
- Improved design of Linux system software shell protection technology
- What to do if the ABB robot protection device stops
- CGD and Qorvo to jointly revolutionize motor control solutions
- CGD and Qorvo to jointly revolutionize motor control solutions
- Keysight Technologies FieldFox handheld analyzer with VDI spread spectrum module to achieve millimeter wave analysis function
- Infineon's PASCO2V15 XENSIV PAS CO2 5V Sensor Now Available at Mouser for Accurate CO2 Level Measurement
- Advanced gameplay, Harting takes your PCB board connection to a new level!
- Advanced gameplay, Harting takes your PCB board connection to a new level!
- A new chapter in Great Wall Motors R&D: solid-state battery technology leads the future
- Naxin Micro provides full-scenario GaN driver IC solutions
- Interpreting Huawei’s new solid-state battery patent, will it challenge CATL in 2030?
- Are pure electric/plug-in hybrid vehicles going crazy? A Chinese company has launched the world's first -40℃ dischargeable hybrid battery that is not afraid of cold
- [RVB2601 Creative Application Development] LoRa Gateway Wireless Host Computer
- Newcomer Report
- There is a program with a total of 10 feeders
- Why can't DSP connect? TMS320C6416T+seed-XDS510 PLUS
- Application of TI's high-performance charging and discharging solution in battery test equipment (Battery Test System)
- About the multi-channel link problem of sim7600ce
- Smart network desk lamp, project submission
- We are looking for positions such as speaker R&D and manufacturing engineers.
- Serial communication-What is the reason for the decrease of impedance to ground?
- [Evaluation of SGP40] + STM32CUBE + STM32G4 + UART communication test sensor