1. https://appdevelopermagazine.com/security
  2. https://appdevelopermagazine.com/aspm-2024-report-from-cycode/
12/15/2023 7:30:45 AM
ASPM 2024 report from Cycode
Cycode,State of ASPM Report,Software Security,Generative AI
/ASPM-2024-report-from-Cycode-App-Developer-Magazine_mjh5r5es.jpg
App Developer Magazine

Security

ASPM 2024 report from Cycode


Friday, December 15, 2023

Richard Harris Richard Harris

Cycode has released their inaugural State of ASPM 2024 Report, which found that 77% of CISOs believe software supply chain security is a bigger blind spot than generative AI.

Cycode announced the release of its inaugural State of ASPM 2024 report. The research found that AppSec chaos reigns, with 78% of CISOs responding that today’s AppSec attack surfaces are unmanageable and 90% of responders confirmed relationships between their security and development teams need to improve. Surprisingly, 77% of CISOs believe software supply chain security is a bigger blind spot for AppSec than Gen AI or open source.

The State of ASPM 2024 report from Cycode

The State of ASPM 2024 report was compiled from a survey of 500 U.S. CISOs, AppSec Directors, and DevSecOps team members. Half of the sample came from companies with 5,000+ employees and half with 1,000 - 5,000 employees. The research consolidates and correlates findings across more than thirty different categories and data points across the industry.

Prioritization of AppSec risks and activities is a significant problem for most organizations as highlighted in the State of ASPM research. The vast majority (85%) of CISOs acknowledge dev teams suffer from vulnerability noise and alert fatigue, which strains the relationship between security and dev teams. Additionally, 88% acknowledge that because of alert fatigue developers are not focused on remediating critical vulnerabilities, which increases the potential for a security breach and puts the business at risk.

Only 21% of respondents believe that both security and development are equally responsible for application security, confirming that many security professionals question whether application security is a team sport. An overwhelming 77% majority said that understanding who owns application security is challenging, indicating that more clarity is needed about who is responsible for AppSec in most organizations.

The report also shows that alert fatigue is not the only cause of the souring relationship between security and development teams. Many of the challenges stem from diverse vulnerability sources and the proliferation of AppSec tools. A staggering 75% of security professionals struggle with the complexity of managing multiple security tools.

According to Gartner, "By 2026, over 40% of organizations developing proprietary applications will adopt ASPM to more rapidly identify and resolve application security issues."

"Despite industry forecasts, our research reveals a much more condensed time frame for ASPM adoption. While all the hype right now is focused on AI, software supply chain security issues are just as or even more critical, and any ASPM solution needs to have best-in-class capabilities," said Lior Levy, co-founder and CEO, of Cycode.

"Much of the Cycode report findings align with what we're seeing in the market, starting with the criticality of software supply chain security. Our 2023 DevSecOps Adoption, Techniques, and Tools Survey identified a vulnerable software supply chain as a top application security gap. Our IDC research also found that companies struggle with developer and security misalignment and have prioritized fostering coordination," said Katie Norton, Senior Research Analyst at IDC.

In addition, 92% of CISOs confirmed they are looking to consolidate their AppSec tools into a single platform in the next 12 months. This comes straight off the heels of Cycode’s announcement of an expanded, complete approach to ASPM that enables security and development teams to manage the burden, cost, and inefficiencies of having too many siloed (and vendor-locked) security tools from code to cloud - which brings order to better maintain strong application security posture.

The capstone of Cycode's complete ASPM solution was its recent ConnectorX announcement, a click-and-connect third-party ASPM integration platform that provides companies with the choice to use Cycode’s native ASPM tools or maximize their investments in their existing AppSec tools. Using ConnectorX, companies can plug in any AppSec solution (i.e., SCA, SAST, Secrets, etc.) and within minutes, gain accurate, real-time visibility into their security posture.

Combined with significant enhancements to its Risk Intelligence Graph (RIG) for smarter, risk-based prioritization, Cycode delivers the capabilities needed for a complete approach to ASPM, enabling security and development teams to align, build trust, and collaborate on maintaining strong application security posture.

ASPM 2024 report from Cycode







Subscribe to App Developer Magazine

Become a subscriber of App Developer Magazine for just $5.99 a month and take advantage of all these perks.

MEMBERS GET ACCESS TO

  • - Exclusive content from leaders in the industry
  • - Q&A articles from industry leaders
  • - Tips and tricks from the most successful developers weekly
  • - Monthly issues, including all 90+ back-issues since 2012
  • - Event discounts and early-bird signups
  • - Gain insight from top achievers in the app store
  • - Learn what tools to use, what SDK's to use, and more

    Subscribe here



Stay Updated

Sign up for our newsletter for the headlines delivered to you

SuccessFull SignUp

Featured Stories


Intersignal Releases Braid Pathfinder Developer Preview
Intersignal Releases Braid Pathfinder Developer Preview Monday, August 17, 2026


Agentic AI transforming how families access and bolster legal help
Agentic AI transforming how families access and bolster legal help Thursday, August 13, 2026


Creator-led growth fails subscription apps without attribution
Creator-led growth fails subscription apps without attribution Wednesday, August 12, 2026




TypeMock Launches Test Review for Smarter Unit Testing
TypeMock Launches Test Review for Smarter Unit Testing Monday, August 3, 2026


FTC AI accuracy policy puts chatbot trust under review
FTC AI accuracy policy puts chatbot trust under review Tuesday, July 21, 2026


Human-Made Video Ads Outperform AI-Generated Creativity
Human-Made Video Ads Outperform AI-Generated Creativity Monday, July 20, 2026


SpaceX accelerates AI push with new hires
SpaceX accelerates AI push with new hires Monday, July 20, 2026


NearLens: Smart Glasses Privacy Taken Seriously
NearLens: Smart Glasses Privacy Taken Seriously Wednesday, July 15, 2026


Agentic Commerce Grows Cequence Unveils AI-Era Bot Defense
Agentic Commerce Grows Cequence Unveils AI-Era Bot Defense Wednesday, July 15, 2026


Nearly all developers use AI but few secure the code it generates
Nearly all developers use AI but few secure the code it generates Monday, July 13, 2026


Get More App News