Even relatively small security issues on the surface have opened up opportunities for significant cyber-attacks. The Log4Shell exploit is a recent example of how a malicious code has revealed opportunities for a successful attack. Many businesses have admitted to knowingly shipping vulnerable code, and clearly, this is a calculated risk based on time to market with new features and products. However, the consequences of these calculated risks to shipping lower-quality code could be far greater than projected, resulting in very costly data breaches.
Kamer van Koophandel shares how it embedded secure coding into everyday development through role-based certifications, Trust Score benchmarking, and a culture of shared security ownership.