Research Reveals 75% of CISOs Are Worried Too Many Application Vulnerabilities Leak Into Production, Despite a Multi-Layered Security Approach
Dynatrace (NYSE: DT) released findings from a global survey of 1,300 CISOs, revealing challenges in vulnerability management in complex multicloud environments. 75% of CISOs report security gaps, and 79% say continuous runtime vulnerability management is essential. However, only 4% have real-time visibility into runtime vulnerabilities. The report highlights the need for the convergence of security and observability to enhance risk management and incident response. Automation is identified as key for improving efficiency in vulnerability management.
- 79% of CISOs say continuous runtime vulnerability management is essential.
- Survey highlights growing recognition of the need for observability and security convergence.
- Only 4% of organizations have real-time visibility into runtime vulnerabilities.
- 75% of CISOs report persistent coverage gaps in their security posture.
Findings from the research include:
-
69% of CISOs say vulnerability management has become more difficult as the need to accelerate digital transformation has increased. -
More than three-quarters (
79% ) of CISOs say that automatic, continuous runtime vulnerability management is key to filling the gap in the capabilities of existing security solutions. However, just4% of organizations have real-time visibility into runtime vulnerabilities in containerized production environments. -
Only
25% of security teams can access a fully accurate, continuously updated report of every application and code library running in production in real time.
“These findings underscore that there are always opportunities for vulnerabilities to slip past security teams, regardless of how robust their defenses might be. Both new applications and stable legacy software are prone to vulnerabilities that are more reliably detected in production. Log4Shell was the poster child for this problem, and there will undoubtedly be other scenarios like it in the future,” said Bernd Greifeneder, Chief Technology Officer at
Additional findings include:
- On average, organizations receive 2,027 alerts of potential application security vulnerabilities each month.
-
Less than a third (
32% ) of the application security vulnerability alerts organizations receive each day require action, compared to42% last year. -
On average, application security teams waste
28% of their time on vulnerability management tasks that could be automated.
“Organizations realize that to manage vulnerabilities in the cloud-native era effectively, security must become a shared responsibility. The convergence of observability and security is critical to providing development, operations, and security teams with the context needed to understand how their applications are connected, where the vulnerabilities lie, and which need to be prioritized. This accelerates risk management and incident response,” continued Greifeneder. “To be truly effective, organizations should look for solutions that have AI and automation capabilities at their core, enabling AISecDevOps. These solutions empower their teams to quickly identify and prioritize vulnerabilities at runtime, block attacks in real time, and remediate software flaws before they can be exploited. This means teams can stop wasting time in war rooms or chasing false positives and potential vulnerabilities that will never make it into production. Instead, they confidently deliver better, more secure software faster.”
The report is based on a global survey of 1,300 CISOs in large-size organizations with more than 1,000 employees, conducted by
About
Curious to see how you can simplify your cloud and maximize the impact of your digital teams? Let us show you. Sign up for a free 15-day
View source version on businesswire.com: https://www.businesswire.com/news/home/20220601005391/en/
meg.brenner@dynatrace.com
Source:
FAQ
What did the Dynatrace survey reveal about CISO challenges?
How many CISOs believe continuous runtime vulnerability management is essential?
What percentage of organizations have real-time visibility into runtime vulnerabilities according to Dynatrace?
What key finding does the Dynatrace report mention regarding security alerts?