Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

BSIMM9 Study Highlights Impact of Cloud Transformation and Growth of Software Security Community

by The Gurus
October 16, 2018
in Editor's News
Share on FacebookShare on Twitter

Earlier this month, Synopsys released BSIMM9, the latest version of the Building Security In Maturity Model (BSIMM) designed to help organisations plan, execute, and measure their software security initiatives (SSIs). The ninth iteration of BSIMM reflects data collected over a 10-year study of real-world SSIs across 120 firms. BSIMM9 highlights the impact of cloud transformation, the emergence of a new vertical industry—retail—represented in the data pool, and the growth of the software security community.

“Development, security, and operations teams need to align, and BSIMM9 provides data suggesting this is taking place through automation, particularly as software shifts to the cloud,” said Dr. Brian Chess, senior vice president of infrastructure and security for NetSuite at Oracle. “This is a huge move in the right direction: greater velocity and better security at the same time.”

BSIMM9 describes the work of more than 7,800 software security professionals whose work guides and maximises the security efforts of 415,000 developers across approximately 135,000 applications. BSIMM9 firms represent industry verticals including financial services, independent software vendors (ISVs), cloud, healthcare, Internet of Things (IoT), insurance, and retail.

Key findings from the BSIMM9 study:

  • Cloud transformation: Firms are moving their workloads and development pipelines to the cloud—a paradigm shift that requires different approaches to software security. Three new activities directly or indirectly related to cloud transformation were observed and added to the BSIMM. Furthermore, activities observed among independent software vendors, IoT companies, and cloud firms (three of the most prominent verticals) have begun to converge, suggesting that common cloud architectures require similar software security approaches.
  • BSIMM across verticals: The BSIMM can be used to compare SSIs within and between verticals. A new vertical industry—retail—emerged in the BSIMM9 data. SSIs in retail are maturing relatively quickly as new models focused on e-commerce become critical to sustaining a healthy business. The retail vertical is already more mature in security than healthcare and insurance.
  • Population growth: BSIMM9 includes data collected from 120 firms, up from 109 firms in BSIMM8. The number of software security practitioners it measures grew by 65 percent, and the number of developers included grew by 43 percent. This notable growth in the BSIMM population indicates that software security is a growing priority.

“The BSIMM project has become a de facto standard for assessing and improving software security initiatives,” said Dr. Gary McGraw, vice president of security technology at Synopsys. “By measuring your firm with the BSIMM measuring stick, you can directly compare and contrast your security approach to some of the most mature firms in the world. BSIMM9 is the culmination of a decade of objective, observation-based work in the field, and it incorporates the largest set of data collected about software security anywhere.”

The BSIMM includes data collected from firms that have established real SSIs, quantifying the occurrence of 116 activities to show the common ground shared by many initiatives as well as the variations that make each initiative unique. The BSIMM data shows that high-maturity initiatives are well-rounded, carrying out numerous activities in all 12 of the practices described by the model. Organisations can use the BSIMM to compare initiatives and determine which additional activities might be useful to support their overall strategies.

To download the report, visit www.bsimm.com/download.html.

ShareTweet
Previous Post

Janrain Survey Shows Consumers Still Trust Brands but Want More Control over Data

Next Post

Top UK Cyber Talents Reveal The Biggest Threats And Opportunities Facing The Cyber Security Industry.

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol