Digital Transformation

The 2023 State of Secure Development & ATO in U.S. Government Agencies

A Quarterly interactive e-book publication of primary research findings conducted for Security Compass. The report quantifies the challenges and opportunities being confronted by US government agencies at the federal, state and local levels. Software development methods, security expertise, developer controls and mitigations, communication approaches, and current approaches to ATO compliant software development are explored.

2022 Year in Review – Interactive Report of Annual Research Findings on Cybersecurity

What follows are highlights from primary research studies Security Compass commissioned in 2022 on topics in cybersecurity, covering Developer Perspectives on Application Development, DevSecOps Perspectives on AppSec Training, and Application Security in the Mid-Market.
The research was conducted independently by Golfdale Consulting, Inc.

2022 DevSecOps Perspectives on AppSec Training

Given the importance that eLearning plays in developing secure software, this ebook provides an overview of our research into AppSec training approaches. Findings include “deep dives” into budgeting, training challenges, time consuming elements, how best to reinforce AppSec eLearning, and the value of accreditation to individual contributors, managers, and organizations.

2022 Developer Perspectives on Application Security

Most developers involved in product builds believe their companies to have a mature security posture but nonetheless struggle to keep up to date with growing regulations and compliance requirements. On the cybersecurity front, developers view automated modeling, integration with other tools, and matching the speed of new threats that emerge as all highly important. Security must start with design and remain a critical element at each stage of the SDLC.

2022 Application Security in the Mid-Market

Over 90% of mid-market companies that develop software are interested in solutions that automate proactive security and compliance processes.
Companies looking to accelerate their software development in tandem with stronger cybersecurity compliance measures are looking to just-in-time training (JITT) for their software developers and automated built-to-purpose cybersecurity software for accomplishing these goals.

TrustArc 2022 Global Privacy Benchmarks Report

The TrustArc Global Benchmark report provides a 360 view of how enterprises manage data protection and privacy. Feedback came from senior leadership inside the privacy office and privacy team members. We also comprehensively surveyed senior executives, middle management, and non-managerial full-time employees. For the 3rd year running, insights are provided on current privacy challenges and global privacy trends.