Why security debt belongs on the boardroom agenda
Security leaders have made significant progress in improving threat visibility across businesses.
Most organizations can now identify vulnerabilities across their applications, dependencies, and development pipelines with far more consistency than previously.
Yet, a fundamental imbalance remains — vulnerabilities are being discovered faster than they can be remediated.
CISO at Veracode.
This imbalance is growing. As it stands, the majority (82%) of organizations currently carry security debt, categorized as accumulated vulnerabilities that have remained unresolved for more than a year.
At the same time, the share of vulnerabilities that are both severe and likely to be exploited continues to increase.
As a result, vulnerabilities are persisting in production environments long enough to be discovered and weaponized.
Despite this growing risk, many CISOs still need to convince the C-suite that reducing security debt is a business-wide issue that justifies sustained investment, rather than a challenge limited only to security teams.
Treating security...
Copyright of this story solely belongs to techradar.com. To see the full text click HERE