Fingers on keyboard
Hacking risks are higher when coding is outsourced, survey suggests

Firms overlook security when outsourcing software development

Frequent hacking victims all outsource a portion of their programming, says research

Written by Janie Davies

Companies that say they are frequently hacked all outsource part of their software programming, and 90 per cent of them outsource at least 40 per cent, according to a survey by analyst Quocirca.

Sixty per cent of companies that outsource their coding said they do do not mandate built-in security for their applications.

And a further 20 per cent of UK firms said they do not even consider security when developing applications.

Built-in security is not being taken seriously enough, said Fran Howarth, principal analyst at Quocirca and author of the report.

“The findings of this report indicate that not enough is being done by organisations to build security into the applications on which their businesses rely," said Howarth.

"Not only that, but they are entrusting large parts of their application development needs to third parties. This creates an even greater onus for organisations to thoroughly test all code generated for applications — without which they could be playing into the hands of hackers.”

Half of firms that consider software development to be business critical or important outsource more than 40 per cent of their programming needs.

Fifty-five per cent of public sector organisations outsource more than 40 per cent of their coding and 64 per cent say development is only moderately important.

Utility companies place the greatest importance on software development, with 90 per cent citing it as important or business critical. Only seven per cent of utilities outsource more than eight percent of code development.

The survey questioned 250 senior executives and IT directors at medium to large firms in the UK, US and Germany.

See also:

reader comments

related articles

Gala Coral had its network disabled by a new type of hack

Home Office delay on hacking law continues

Denial of service attacks and selling of hacking tools not yet criminalised 03 Apr 2008

 

Security strategy failing on cyber protection, say Tories

Government needs to do more to safeguard critical national infrastructure 03 Apr 2008

China cracks down on insider cyber hacking

Four hackers sentenced for larceny, but foreign sites remain targets 03 Apr 2008

Spammers are using hacked Facebook profiles

Identity thieves are selling legitimate login information to advertisers, says security firm 31 Mar 2008

Tories unveil cyber-crime policies

Current government policy lacks co-ordination, focus and urgency, says shadow home secretary 06 Mar 2008

Government slows ID card rollout plans

People renewing a passport after 2010 will no longer be obliged to receive an ID card 06 Mar 2008

Outsourcing code puts security at risk

Mission-critical application code not being tested 07 Apr 2008

Web threats continue to rise

Latest Symantec threat report finds a big increase in site specific attacks 08 Apr 2008

Google Apps adds email security

Message filtering, encryption and archiving 05 Feb 2008

latest news

Acer grabs top spot in EMEA PC market

HP ousted as top dog in EMEA as Acer continues its bid for world domination 15 Oct 2008

Eurodata boosts services with Transam

VAR leaps into SAM, SaaS and email archiving markets with acquisition 15 Oct 2008

Salmon tickled pink over Microsoft accolade

Integrator secures Microsoft Gold Partner status in first year of partnership 15 Oct 2008

poll

Education gap?

Education gap?

Is there still business up for grabs in the education space?

Previous poll results

Vendor Q&A Session: Rick Wallis, NEC Computers

Vendor Q&A Session: Rick Wallis, NEC Computers

During this Q&A session Rick Wallis, UK Sales Director at NEC Computers, talks about the firm’s reasons for committing to a 100 per cent channel strategy

In The Studio with CRN: Dave Poskett, HP

CRN TV catches up with Dave Poskett, director of Solutions Partner Organisation for the UK & Ireland at HP

events

Channel Awards logo

CRN Channel Awards 2008

The Channel Awards recognise excellence and exceptional performance from businesses and individuals in the UK technology channel

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

White papers

Search white papers

Top categories

Primary Navigation