Outsourcing
The top code development outsourcers are financial services organisations

Outsourcing code puts security at risk

Mission-critical application code not being tested

Written by Iain Thomson

Not enough is being done by organisations to build security into the applications on which their businesses rely

Fran Howarth Quocirca

A study into companies that outsource code development has found that six out of 10 do not include security specifications.

The Quocirca report found that many companies are outsourcing more code development than ever before, and that nine out of 10 outsource more than 40 per cent.

The National Institute of Standards and Technology reported recently that 92 per cent of vulnerabilities affecting computer networks are contained in software applications.

However, when it comes to specifying outsourced code, one in five companies do not even consider security when designing applications.

Fran Howarth, principal analyst at Quocirca and author of the report, said: "The findings indicate that not enough is being done by organisations to build security into the applications on which their businesses rely.

"They are also entrusting large parts of their application development needs to third parties.

"This creates an even greater onus for organisations to thoroughly test all code generated for applications, without which they could be playing into the hands of hackers."

The top outsourcers are financial services organisations, 72 per cent of which outsource more than 40 per cent of new code development.

Only seven per cent of utility companies outsource more that eight per cent of code development.

Howard Schmidt, a board member at Fortify Software, and a former cyber-security advisor to the White House, said: "These survey results help explain the sudden rise in data breaches.

"It should serve as a wake-up call to any executive whose company sits on a pile of mission-critical application code."

Further reading

Traditional IT department 'dead' by 2013

Hosted services model will make IT a utility   More...

Lack of skilled staff hampers IT

Chief execs highlight biggest headaches   More...

Traditional development dooming web projects

Developer offers tips for success   More...

UK business still outsourcing to India

Lower costs and higher satisfaction keeps services abroad   More...

Related articles

Marketing firms routinely losing customer data

Security firms slam cavalier attitude   More...

Google Apps adds email security

Message filtering, encryption and archiving   More...

Bug exposed in web security standard

VBAAC flaw could affect hundreds of thousands of sites   More...

Utility firms sitting on hacking time bomb

Power could be the next target   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

04 Jul 2008

5.51 MBPodcast Special: Views from the Valley More...

03 Jul 2008

3.46 MBGreen grid computing, Trojans stop play and location-based services More...

02 Jul 2008

3.2 MBOnline TV, SME security and flexible laptops More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Online pornography

US rebate cheques spent on porn

Economic stimulus package works wonders   More...

Louis Vuitton

UK online fake goods market worth £800m

Legal experts warn of dramatic rise in 'e-fencing'   More...

Advertisement

Fibre-optics

New fibre-optic connections overtake cable

Broadband first-timers choosing fibre where possible   More...

Stars and Stripes

Cyber-crooks celebrate Independence Day

Security firms warn users to take extra care   More...

Advertisement