Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Sunday, 14 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Lack of Developer Training Fuels Cyber Breaches Across UK Organisations

40% of businesses fail to mandate secure coding training despite majority reporting security incidents caused by flawed code.

by The Gurus
August 18, 2025
in Featured
Lack of Developer Training Fuels Cyber Breaches Across UK Organisations
Share on FacebookShare on Twitter

A new survey from SecureFlag has revealed serious shortcomings in how UK businesses protect themselves from software-related threats. In a poll of 100 C-suite and technology leaders, 67% admitted their organisation had suffered at least one cybersecurity breach or major incident in the past 12 months due to insecure coding practices, with nearly half experiencing multiple incidents.

Despite this, the research shows that 40% of companies still do not require developers to undergo regular secure coding training; a gap experts warn leaves businesses exposed.

“This should be a wake-up call for every business that develops software,” said Andrea Scaduto, CEO and co-founder of SecureFlag. “It’s frankly shocking that in 2025 so many breaches are still happening because of avoidable coding flaws. Our survey exposes a clear and present danger: too many development teams lack the security training to prevent vulnerabilities, and attackers are exploiting that gap. The message is loud and clear – without a serious investment in developer education, organisations will continue to be at risk.”

The survey underscores a disconnect between awareness and action. While 88% of executives acknowledged that insecure coding poses a significant risk to their business, only one in three currently provides continuous, hands-on secure coding training. Just 29% expressed high confidence in their developers’ ability to write secure-by-design code. Time, budget, and resource limitations were among the top reasons cited for not training more frequently.

The cost of inaction, however, is significant. Respondents reported that breaches tied to insecure code led to customer data exposure, service downtime, and financial losses. These findings align with the UK government’s Cyber Security Breaches Survey, which found that 43% of businesses overall suffered a cyber attack or breach in the past year. SecureFlag’s study goes further by pinpointing insecure software code as a primary driver of these incidents, with common issues including SQL injection, weak authentication flows, and inadequate code review processes.

Emilio Pinna, CTO and co-founder of SecureFlag, emphasised the urgency of tackling the problem head-on. “The fact that so many organizations are being compromised through code errors is alarming. Breaches stemming from coding mistakes are preventable – but only if companies invest in proper training,” he said. “We urge businesses not to wait for a disaster. Ensuring your developers can recognize and avoid vulnerabilities must be a top priority. It’s far cheaper to train a developer than to clean up after a breach.”

To meet this challenge, SecureFlag is doubling down on its mission to equip development teams with practical skills to build secure software from the outset. Its immersive training platform gives developers real-world experience in secure coding, helping organisations shift security from a reactive measure to a proactive foundation.

With this latest research serving as a stark warning, SecureFlag is calling on industry leaders to act now, before the next coding-related breach makes headlines.

ShareTweet
Previous Post

Smishing in the Amazon

Next Post

New EMA Research Highlights Keeper’s Strength in Modern PAM

Recent News

Nagomi Control Brings CTEM Into Action

2 in 5 Organisations Experienced Cyber Incidents Tied to Suppliers in Past Year

June 12, 2026
Certes Research Warns Legacy Systems Are Biggest Barrier to Quantum Security Readiness

KnowBe4 Expands Gamified Training Library With Launch of “Spot the Vish” Game

June 12, 2026
Swan Song For Infosec’s Most Gripping Awareness Training Series: The Inside Man Goes Out With A Star-Studded Bang

Swan Song For Infosec’s Most Gripping Awareness Training Series: The Inside Man Goes Out With A Star-Studded Bang

June 12, 2026
artificial-intelligence

The More Confident Organizations Are in Their AI Security, the More Likely They’ve Been Breached, New Research Finds

June 11, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol