ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Managing security debt

Chris Eng at Veracode asks whether AI-assisted remediation is the key to reducing security debt

 

We all know the dangers of letting financial debt get out of control. Making minimum monthly payments on a credit card and keeping the debt collector at bay doesn’t address the persistent underlying issue. That debt accumulates interest over time, causing further issues down the line.

 

But for organisations around the world, there’s another form of debt that represents major business risk and compounds in a surprisingly similar way as personal debt— security debt. 

 

Security debt refers to flaws in applications that do not get fixed; for the purposes of this article, we’ll say that a flaw becomes security debt when it’s unfixed for longer than a year. Over time, if flaws are not fixed, security debt keeps growing, widening the range of vulnerabilities that can be exploited by attackers. Research has found that seven out of 10 organisations have some level of security debt, and nearly 50% of all firms have high-severity, persistent flaws, also known as ‘critical’ security debt. 

 

Thankfully, despite these grim statistics, there are ways to drastically reduce a business’ security debt. 

 

How did it get so bad?

Before we delve into how to reduce security debt, it is important to reflect on how we got here. The main reason behind the mounting security debt is that organisations are not prioritising well enough and therefore not focusing on fixing the flaws that pose the greatest risk: the critical ones. 

  

Application age and size play a significant role in the accumulation of security debt. We have repeatedly observed a recency bias in the way developers fix security flaws: the more time that passes from a flaw appearing, the lower the chance it will ever be fixed. Recent research found that 42% of all flaws roll over to become security debt, so the older the app, the higher the debt accumulation.

 

Application size is also key. As the codebase of most applications grows over time, it is only logical that there is a correlation between age and the accumulation of older, unremediated flaws. Large applications therefore have the highest proportion of security debt, with 40% of them having security debt, and 47% having critical debt. And while it is not always the youngest and smallest apps that have the least debt, older monolithic applications present a greater challenge. 

 

Flaws in open-source third-party code tend to become security debt slightly faster than first-party code. What’s more, third-party flaws tend to emerge continuously as new vulnerabilities are discovered by security researchers. This means, unless organisations keep their libraries up to date, applications will accumulate more and more risk as time passes, even if nothing has been added to the codebase

 

Another major factor contributing to an organisation’s compounding debt is the increased use of generative AI to write code - a practice that will only increase over time, with Gartner predicting 75% of enterprise software engineers will use AI code assistants by 2028.

 

Using AI is not a problem in and of itself; AI-generated code is not inherently less secure than human-generated code, but it’s also not more secure. The problem is an over-reliance on AI and the erroneous assumption that it will automatically produce properly functioning, flaw-free code.

 

Large Language Models used to generate code are often trained on insecure open-source projects and other publicly available code, meaning AI-generated code can be insecure as well. Failure to vet this code properly adds to an organisation’s security debt over time and may even accelerate security debt as AI helps developers code faster than ever.

 

It is also important to note that security debt is not solely the result of mismanagement, poor decisions, or failure to execute. Time and resource pressures mean developers and product managers must decide which flaws to fix and which to let lie. 

 

Fighting AI with AI

Thankfully, innovation is slowly lifting the pressure on development teams. New technologies like AI, when implemented with appropriate safeguards, mean developers need not leave so many flaws unaddressed - or have their time and resources spread so thinly.

 

AI has already fundamentally changed the paradigm of future business. Although it may seem counter intuitive based on the aforementioned risks, we are in an age where we need to consider fighting AI with AI. 

 

Let’s consider the role that AI should play in both creating and safeguarding our software. AI can make the dream of accelerating code fixes a reality, however, it’s up to us to harness its power responsibly. 

 

AI-driven tools, particularly those based on GPT models with supervised training on curated security-specific datasets, excel at cyber-security tasks. These models can provide highly reliable flaw remediation suggestions, ensuring that vulnerabilities are addressed promptly and effectively.

 

However, it is crucial that any tool handling source code, especially for security purposes, maintains the highest standards of data integrity and security.

 

Incorporating AI into the software development lifecycle not only enhances efficiency but also has the potential to fortify the security posture of applications. By identifying and addressing vulnerabilities early, development teams can deliver robust, secure software that meets the ever-evolving demands of the digital landscape.

 

Using AI to reduce security debt

Knowing that a flaw exists is not the same as fixing it. That is why frequent code scans do not always correlate with less debt. Knowing is only half the battle; the other half is doing something about it. 

 

Continuous scanning must come with continuous fixing, but even the biggest teams with ample resources typically do not fix all their flaws. The problem has grown beyond the ability of humans alone to manage it, so AI-powered tools are becoming necessary.

 

Despite fears from many that it could be a threat to security, the truth is Artificial Intelligence is increasingly part of the solution to help developers fix more efficiently.

 

Leveraging AI, developers can shift security left in the development cycle, meaning they identify and fix vulnerabilities as they write code. This proactive approach allows organisations to detect and address potential security risks at an earlier stage, reducing the likelihood of costly and time-consuming issues later down the line.

 

A more secure future

As we look to the future, it is clear AI will continue to revolutionise the way we approach technology and security. With 71% of organisations experiencing a high backlog of security debt, development teams need all the support they can get to tackle an ever-growing number of vulnerabilities. 

 

The future of software security will be less about finding and fixing vulnerabilities, and instead focused on preventing security vulnerabilities from ever making their way into the code. AI can make the dream of accelerating code-fixes a reality, especially when the software has been trained on specific types of vulnerabilities and to work alongside developers to suggest secure fixes at scale.

 

This is the type of scaling factor that can break through developers’ existing fix capacity constraints to help eliminate all security debt, and not just the most critical security debt. 

 


 

Chris Eng is Veracode’s Chief Research Officer

 

Main image courtesy of iStockPhoto.com and rawintanpin


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543