Veracode commissioned Forrester Consulting to interview four decision-makers and conduct a Total Economic Impact™ (TEI) study to better understand the benefits, costs, and risks associated with the Veracode Application Risk Management Platform.1 This abstract will focus on a fifth interviewee with experience using Veracode Fix, a key value driver for the Veracode Platform.
Veracode Fix is an AI code remediation tool that helps organizations reduce security debt and eliminate new flaws. Along with Veracode Static Analysis, which automatically finds flaws, Veracode Fix integrates into common developer environments and workflows — integrated development environments, command line interfaces, and continuous integration/continuous delivery practices — to offer remediation tuned to an organization’s specific requirements.
Forrester interviewed an application security (AppSec) leader at an insurance organization that tested and adopted Veracode Fix. Their company:
The interviewee’s organization is beholden to various compliance authorities such as HIPAA and the Securities and Exchange Commission and has other reporting requirements. The interviewee noted, “We play by their rules for establishing an application security program and ensuring that we're managing risk according to that program.”
The organization’s application estate included 250 internal applications segmented from the company network and an additional 350 internet-facing applications that interact with customers and processed customer data. The interviewee noted that their organization relied predominantly on a custom code that it tested through static analysis and open source software composition analysis, along with other analysis services in the Veracode Application Risk Management Platform. The organization relied on some third-party code from external developers while also leveraging a large ecosystem of open source components and libraries throughout the company. The interviewee said, “We do a pretty good job at actually monitoring our external applications for security vulnerabilities and remediating those vulnerabilities in very specific time periods according to our own policy.” The organization also worked with Veracode to evaluate its security debt against that of its peers using Veracode’s patented Peer Benchmarking.
The AppSec leader at this insurance company ran a proof of value exercise that measured its developers’ ability to find vulnerabilities manually without any tools and compared it to the legacy remediation automation tool and to Veracode Fix.
The interviewee’s organization adopted Veracode Fix to reduce its security debt and the number of new flaws developed. They noted investment drivers such as:
The results of the investment for the interviewee’s organization include the ability to:
Find flaws faster. Across all code types tested, including first- and third-party, the AppSec leader shared that their organization improved its time to detect security vulnerabilities in its code.
They also said that their organization saw a 92% reduction in the time to detect flaws with Veracode Static Analysis compared to their prior, manual AppSec processes: “It took [developers] roughly 150 minutes to find vulnerabilities with no plugin, and then that went down to 15 minutes with [our legacy tool that was not used much]. Then once we started to use Fix, it went from 150 minutes down to 12 minutes.”
Fix flaws faster. The interviewed AppSec leader remarked that their organization was able to remediate software vulnerabilities much faster than with its prior manual processes and decommissioned plugin.
They indicated a substantial improvement over their legacy software scanners in detecting and remediating flaws: “Not only is Veracode Fix tied into the new IDE, and static analysis is built right into the IDE, but it also gives us flaw remediation faster. You’ve got to wait literally less than 30 seconds, and you’ve got something that would take you hours to write. … The mean time to remediate versus our legacy [automated tool] was over 200% faster because we [started from] a very manual process.”
Fix more flaws. The interviewee discussed multiple ways in which Veracode Fix amplified their organization’s remediation efforts, including:
Fix flaws better. The interviewee discussed how their organization improved important code quality metrics like flaw density per megabyte of code with Veracode Fix. Better context and faster processes compounded, making it easier for developers to fix more flaws and therefore produce and refine a higher quality code base. As a result, flaw density decreased by 50%, and 15 times more flaws were ultimately fixed. Veracode Fix helped to:
Additional benefits. In addition to fulfilling its primary investment objectives of finding and fixing code more effectively and efficiently, the interviewee discussed additional benefits conferred by their organization’s use of Veracode Fix, including:
Readers should be aware of the following:
This study is commissioned by Veracode and delivered by Forrester Consulting. It is not meant to be used as a competitive analysis.
Forrester makes no assumptions as to the potential ROI that other organizations will receive. Forrester strongly advises that readers use their own estimates within the framework provided in the study to determine the appropriateness of an investment in Veracode Fix.
Veracode reviewed and provided feedback to Forrester, but Forrester maintains editorial control over the study and its findings and does not accept changes to the study that contradict Forrester’s findings or obscure the meaning of the study.
Veracode provided the customer names for the interviews but did not participate in the interviews.
1 Total Economic Impact is a methodology developed by Forrester Research that enhances a company’s technology decision-making processes and assists solution providers in communicating their value proposition to clients. The TEI methodology helps companies demonstrate, justify, and realize the tangible value of business and technology initiatives to both senior management and other key stakeholders.
Cookie Preferences
Accept Cookies
A cookie is a small text file that a website saves on your computer or mobile
device when you visit the site. It enables the website to remember your actions (data inputs, website
navigation), so you don’t have to re-enter data when you come back to the site or browse from one page to
another.
Behavioral information collected by our web analytics vendor is used to
analyze
data pertaining to visitor trends, plan website enhancements, and measure overall website effectiveness. We
may also use cookies or web beacons to help us offer you products, programs, or services that may be of
interest to you and to deliver relevant advertising. We may use third-party advertising companies to help
tailor website content to users or to serve ads on our behalf. These companies may also employ cookies and
web beacons to measure advertising effectiveness.
Please accept cookies and the collection of behavioral information to receive
full functionality and enhance your experience. If you decline cookies, some features of the website may not
function normally.
Please see our
Privacy Policy for more information.
https://mainstayadvisor.com/go/mainstay/gdpr/policy.html