SourceSecurity.com
  • Products
    CCTV
    • CCTV cameras
    • CCTV software
    • IP cameras
    • Digital video recorders (DVRs)
    • Dome cameras
    • Network video recorders (NVRs)
    • IP Dome cameras
    • CCTV camera lenses
    Access Control
    • Access control readers
    • Access control software
    • Access control controllers
    • Access control systems & kits
    • Audio, video or keypad entry
    • Electronic locking devices
    • Access control cards/ tags/ fobs
    • Access control system accessories
    Intruder Alarms
    • Intruder alarm system control panels & accessories
    • Intruder detectors
    • Intruder warning devices
    • Intruder alarm communicators
    • Intruder alarm accessories
    • Intruder alarm lighting systems
    One system, one card
    One system, one card
    Hikvision AOV 4G Solar Camera Series for Off-Grid Video Security

    Hikvision AOV 4G Solar Camera Series for Off-Grid Video Security

    KentixONE – IoT Access and Monitoring For Data Centres

    KentixONE – IoT Access and Monitoring For Data Centres

    Climax Technology HSGW-Gen3 Modular Smart Security Gateway

    Climax Technology HSGW-Gen3 Modular Smart Security Gateway

    Delta Scientific DSC50 ‘S’ Barrier: Portable, Crash-Rated Vehicle Mitigation Solution

    Delta Scientific DSC50 ‘S’ Barrier: Portable, Crash-Rated Vehicle Mitigation Solution

  • Companies
    Companies
    • Manufacturers
    • Distributors
    • Resellers / Dealers / Reps
    • Installers
    • Consultants
    • Systems integrators
    • Events / Training / Services
    • Manned guarding
    Companies by Product area
    • CCTV
    • Access control
    • Intruder alarm
    • IP networking products
    • Biometrics
    • Software
    • Digital video recording
    • Intercom systems
    One system, one card
    One system, one card
  • News
    News
    • Product news
    • Corporate news
    • Case studies
    • Events news
    Latest
    • Alcatraz achieves SOC 2 for biometric security
    • Datalogic AI tech drives retail innovation at NRF 2026
    • Deep Sentinel launches Mobile Monitoring Trailer
    • Eplan and CADENAS partnership enhances data access
    One system, one card
    One system, one card
  • Insights
    Insights
    • Expert commentary
    • Security beat
    • Round table discussions
    • Round Table Expert Panel
    • eMagazines
    • Year in Review 2023
    • Year in Review 2022
    Featured
    • Why open matters in the age of AI
    • What are emerging applications for physical security in transportation?
    • What is the most overlooked factor when installing security systems?
    • Amid rising certificate demands, stricter compliance and quantum threats, PKIaaS is a necessity
    One system, one card
    One system, one card
  • Markets
    Markets
    • Airports & Ports
    • Banking & Finance
    • Education
    • Hotels, Leisure & Entertainment
    • Government & Public Services
    • Healthcare
    • Remote Monitoring
    • Retail
    • Transportation
    • Industrial & Commercial
    One system, one card
    One system, one card
    Alamo enhances security with Alcatel-Lucent solutions

    Alamo enhances security with Alcatel-Lucent solutions

    The University of Dundee implements HID for modern access control

    The University of Dundee implements HID for modern access control

    The Camp: Enhance security with ASSA ABLOY Aperio wireless locks

    The Camp: Enhance security with ASSA ABLOY Aperio wireless locks

    SBB upgrades surveillance with Hanwha Vision cameras

    SBB upgrades surveillance with Hanwha Vision cameras

  • Events
    Events
    • International security
    • Regional security
    • Vertical market
    • Technology areas
    • Conferences / seminars
    • Company sponsored
    Virtual events
    • Video Surveillance
    • Access Control
    • Video Analytics
    • Security Storage
    • Video Management Systems
    • Integrated Systems
    One system, one card
    One system, one card
    Intersec Dubai 2026

    Intersec Dubai 2026

    DIMDEX 2026

    DIMDEX 2026

    DISTRIBUTECH International 2026

    DISTRIBUTECH International 2026

    Munich Security Conference (MSC) 2026

    Munich Security Conference (MSC) 2026

  • White papers
    White papers
    • Video Surveillance
    • Access Control
    • Video Analytics
    • Video Compression
    • Security Storage
    White papers by company
    • HID
    • ASSA ABLOY Opening Solutions
    • Milestone Systems
    • Eagle Eye Networks
    • Hanwha Vision America
    Other Resources
    • eMagazines
    • Videos
    One system, one card

    One system, one card

    Aligning physical and cyber defence for total protection

    Aligning physical and cyber defence for total protection

    Understanding AI-powered video analytics

    Understanding AI-powered video analytics

    Modernizing access control

    Modernizing access control

About us Advertise
  • Wire-free locks
  • AI special report
  • Cyber security special report
  • Casino security & surveillance
  • 6
Video analytics
  • Home
  • About
  • White papers
  • News
  • Expert commentary
  • Security beat
  • Case studies
  • Round table
  • Products
  • Videos

Check out our special report on casino security

Get it now!

NISC survey finds 9 of 10 security leaders believe companies should face consequences for releasing insecure software

1 Nov 2022

NISC survey finds 9 of 10 security leaders believe companies should face consequences for releasing insecure software
Contact company
Contact Vercara, LLC (formerly Neustar Security Services LLC)
icon Add as a preferred source Download PDF version
Related Links
  • Neustar Security Services expands global security network with Dubai data centre
  • Neustar Security Services expands partner network in EMEA

Organisations plan to invest in DevSecOps in 2023, and the level of urgency for them to do so has grown.

In a recent survey conducted by the Neustar International Security Council (NISC), 93 percent of participating information technology and security professionals reported that DevSecOps would be a significant budgeting priority in 2023, with 55 percent emphasising it would be a very significant priority with their organisation.

Factors to consider

Additionally, 86 percent of respondents agree that the urgency to prioritise DevSecOps has increased within their organisation over the past 12 months.

The top three factors driving this urgency were growing risk driven by accelerating digitisation of their business (60 percent), the proliferation of high-profile supply chain attacks across the industry (53 percent), and an increasingly complex and rigorous regulatory and compliance landscape marked by growing liability for their organisation should customers or partners be put at risk.

Identifying vulnerabilities 

DevSecOps should help better position organisations to identify potential vulnerabilities early"

“DevSecOps has become a high priority for organisations as they look to better establish security as a central tenet through every phase of the software development lifecycle and ensure every release has security baked into the code,” said Carlos Morales, senior vice president of solutions at Neustar Security Services.

“By making security a shared responsibility across development, operations, and security teams, DevSecOps should help better position organisations to identify potential vulnerabilities early in the process ideally before being put into production, and save them from much bigger headaches down the line.”

Insecure software consequences 

Application vulnerabilities can be costly, both in resources allocated to fix security gaps and in revenue should a breach result in lost business and confidence. Among NISC survey participants, 92 percent agreed - 40 percent strongly that companies should face consequences if their software is found to be unsound or insecure.

Many favoured government interventions, with approximately half (51 percent) saying government bodies should force the culprit to implement more rigorous security measures and adopt DevSecOps, while nearly four in ten (38 percent) felt government bodies should punish the offending company with sizable fines.

Software supply chain security controls

A strong proportion of respondents were also in favor of recourse for impacted companies. 50 percent felt the liable party should foot the bill for all mitigation and remediation costs by impacted downstream organisations, while 44 percent said downstream companies or customers relying on the vulnerable software should be able to file suit for damages. 

Moreover, 93 percent of organisations agree that federal mandates for software supply chain security controls are a good idea and should be implemented broadly, and more than one-third (36 percent) feel strongly about the prospect.

Implementing the DevSecOps strategy 

Only 13 percent of surveyed participants confirmed that their organisation has fully implemented its strategy

While more than nine in 10 organisations reside somewhere on the spectrum between building and fully implementing a formal DevSecOps strategy, only 13 percent of surveyed participants confirmed that their organisation has fully implemented its strategy.

Almost one-third (29 percent) are in the process of implementing a strategy, while 15 percent are on the cusp of implementation and 35 percent are still in the process of building a formal strategy.

Drivers of adoption 

Various drivers are contributing to organisations’ adoption of DevSecOps. Nearly three-quarters (72 percent) of respondents identified improving their ability to discover, profile and monitor a growing inventory of applications and APIs through automated processes as one of the three most important drivers of their adoption of DevSecOps.

Other important drivers of adoption include the need for more thorough code monitoring to better detect vulnerabilities throughout development, testing, and operations (64 percent), driving a more robust security-centric culture for the organisation (63 percent), and better compliance monitoring (62 percent).

Factors for delayed DevSecOps adoption 

Despite the growing importance of adopting DevSecOps, a range of factors are holding organisations back from doing so successfully. Chief among them is the shortage of security talent needed to implement the programme, as cited by 42 percent of respondents.

Other factors detracting from efforts include the organisational culture (37 percent), tool incompatibility (36 percent), difficulty in finding a project champion or shared responsibility for the initiative (33 percent), and a lack of buy-in from senior leadership (29 percent).

Security concerns 

System compromise and ransomware followed as top concerns among 20 percent and 17 percent of respondents

In other security concerns, professionals during the reporting period of July and August 2022 remained focused on the potential for DDoS attacks, which were identified by 21 percent as their highest perceived threat. Similar to past survey periods, system compromise and ransomware followed as top concerns among 20 percent and 17 percent of respondents, respectively.

Also similar to last period, ransomware was perceived to be an increasing threat among 75 percent of survey respondents, while generalised phishing jumped in visibility and was on the radar for 74 percent of participants. DDoS attacks, targeted hacking, and social engineering via email were closely followed and reported as increasing by 72 percent, 71 percent, and 70 percent of surveyed professionals, respectively.

DDoS attacks

DDoS attacks continue to be prevalent, and 86 percent of enterprises surveyed indicated that they have been on the receiving end of a DDoS attack at some point, a one-percentage-point increase over the previous survey period.

The majority (56 percent) outsource their DDoS mitigation, and most (62 percent) indicated that mitigation of attacks typically occurred between 60 seconds and 5 minutes, consistent with previous survey findings.

NISC survey 

The NISC survey was conducted in September 2022 and reflects respondents’ activity and concerns during July and August 2022.

The survey enlisted feedback from senior information technology and security professionals from across six EMEA and U.S. markets.

Learn why leading casinos are upgrading to smarter, faster, and more compliant systems

Download PDF version Download PDF version
Google logo Add as a preferred source on Google
  • Network / IP
  • Biometrics
  • Office surveillance
  • Digital video surveillance
  • Office security systems
  • Office security
  • Industrial security
  • Commercial security
  • Security management
  • Security policy
  • Security installation
  • Security tagging
  • Security cameras
  • Security camera systems
  • Security monitoring system
  • Facial recognition systems
  • Network monitoring
  • Video analytics
  • Intrusion detection
  • Identity management
  • Fingerprint reader
  • Industrial security systems
  • Security software
  • Security service
  • Industrial surveillance
  • Integration software
  • Cyber security
  • Crime prevention
  • Crowd Management
  • Corporate Security
  • Indoor Security
  • Data Security
  • Network Video Recorders
  • Digital Video Recorders
  • Incident Management
  • Cloud security
  • Related categories
  • CCTV software
  • Access control software
  • Digital video recorders (DVRs)
  • Access control readers
  • Network video recorders (NVRs)
  • Access control cards/ tags/ fobs
Related white papers
Understanding AI-powered video analytics

Understanding AI-powered video analytics

Download
Open credential standards and the impact on physical access control

Open credential standards and the impact on physical access control

Download
What is a universal RFID reader?

What is a universal RFID reader?

Download
Related articles
Transforming video data: Videonetics 2025 vision

Transforming video data: Videonetics 2025 vision

Genetec's state of physical security report 2026

Genetec's state of physical security report 2026

Secure Logiq expands APAC with DAS partnership

Secure Logiq expands APAC with DAS partnership

Follow us

Sections Products CCTV Access Control Intruder Alarms Companies News Insights Case studies Markets Events White papers Videos AI special report Cyber security special report Casino security & surveillance RSS
Topics Artificial intelligence (AI) Mobile access Healthcare security Counter terror Cyber security Robotics Thermal imaging Intrusion detection Body worn video cameras
About us Advertise About us 10 guiding principles of editorial content FAQs eNewsletters Sitemap Terms & conditions Privacy policy and cookie policy
  1. Home
  2. Topics
  3. Video analytics
  4. News
  5. Corporate news
See this on SecurityInformed.com

Subscribe to our Newsletter

Stay updated with the latest trends and technologies in the security industry
Sign Up

DMA

SourceSecurity.com - Making the world a safer place
Copyright © Notting Hill Media Limited 2000 - 2025, all rights reserved

Our other sites:
SecurityInformed.com | TheBigRedGuide.com | HVACinformed.com | MaritimeInformed.com | ElectricalsInformed.com

Subscribe to our Newsletter


You might also like
One system, one card
One system, one card
Understanding AI-powered video analytics
Understanding AI-powered video analytics
Security and surveillance technologies for the casino market
Security and surveillance technologies for the casino market
Modernizing access control
Modernizing access control
SourceSecurity.com
SecurityInformed.com

Browsing from the Americas? Looking for our US Edition?

View this content on SecurityInformed.com, our dedicated portal for our Americas audience.

US Edition International Edition
Sign up now for full access to SourceSecurity.com content
Download Datasheet
Download PDF Version
Download SourceSecurity.com product tech spec