Australian banks leading with "Developers as the First Line of Defence" approach to application security
Australian banks are leading the charge globally to develop a strong security mindset among their software developers according to Pieter Danhieux, leading secure software evangelist and co-founder of Australian start-up Secure Code Warrior.
Danhieux said five out of Australia's top six banks were now actively engaging their developers to build secure coding skills through Secure Code Warrior's online, self-paced, gamified learning environment, as well as reviewing real-time metrics and reporting to verify the strengths and weaknesses of their developers and teams. The first contract was AUDM with one major bank in August 2016, followed by contracts with four more since then.
"Traditional banks have come under strong pressure from non-traditional competitors to accelerate their speed-to-market, enhance quality and increase flexibility. This has led them to adopt more agile development frameworks which focus on rapid development of features and functions at the expense of security," said Danhieux.
"The average cost of a data breach now stands at USD.6M and the odds of a company being impacted are as high as one in four. Most of the world's major security breaches to coding errors which allows hackers to gain more privileges on computer networks, giving them access to harvest critical data," he added.
Mr Danhieux cited breaches in recent years including Qatar National Bank, VTech, Mossack-Fonseca (Panama Papers), and TalkTalk where hackers took advantage of poor software security practices.
Danhieux, long-time ethical hacker, Principal Instructor for the SANS Institute and AISA's 2016 Cyber Security Professional of the Year, strongly supports Agile Development methodologies that integrate security from the start, practices employed by many tech companies and an increasing number of financial services institutions.
"The shift to Agile Development has some great speed benefits for companies and customers, but it has created significant new challenges with respect to preventing security vulnerabilities. Every developer now needs security built into their DNA, maintaining speed but reducing security bugs which are typically expensive to fix."
Secure Code Warrior was founded in Sydney and London in 2015 when Danhieux, his business partner John Fitzgerald and three other aussie cybersecurity professionals, decided they wanted to help software developers embrace security as a core responsibility of their job.
"Current application security tools focus on moving from right to left in the Software Development Life Cycle (SDLC), an approach that supports detection and reaction - detect the vulnerabilities in the written code and react to fix them. We focus on the extreme left of the SDLC, making the developer the first line of defence in their organisation and helping to prevent vulnerabilities from happening in the first place," said Mr Danhieux.
The fast-growing start-up now has offices in Sydney, London, Belgium and Boston and leading financial services, telecommunications and technology customers in nine countries. The company now has 10,000 active users and has doubled its customers and tripled its revenue in the last six months.
Craig Davies, CEO of the Australian Cyber Security Growth Network (AustCyber) predicts that this type of hands-on evidence based training will become a fundamental activity for organisations developing applications.
"Companies who code securely from the start will not only significantly reduce their risk but strip out huge costs and delays with their product innovation," says Mr Davies.
Danhieux has been impressed with the Australian banks, who he says recognised that the risk was real and have been quick to reduce their exposure. "The pace of new customers onboarding Secure Code Warrior around the world makes it clear that financial service institutions everywhere are recognising the importance of building security excellence into every line of code, and that Secure Code Warrior is an easy solution to address the challenge rapidly and sustainably."
Govern AI-driven development before it ships
Measure AI-assisted risk, enforce secure coding policy at commit, and accelerate secure delivery across your SDLC.
Explore more articles
Access expert content on secure coding, AI governance, and software risk management.

Forbes: A New Frontier: NSA Proposes “Security By Design” Considerations For AI Enablement
The cybersecurity industry, which has been advocating for “security by design” principles for more than a decade, stands in wide-eyed amazement at the risks posed by artificial intelligence (AI). As organizations rush to embrace AI enablement, a CISO’s most pressing priority is to avoid becoming a roadblock. However, without effective AI usage and governance, observability and traceability, organizations may be blindsided by their AI risk.

Techpartner.news: Secure Code Warrior introduces framework to govern AI use in software development
Secure Code Warrior has introduced the SCW AI Adoption Model, a framework designed to help organisations govern AI use in software development as the industry shifts from the traditional software development lifecycle (SDLC) toward what the company calls the Agentic Development Lifecycle (ADLC).

DevOps.com: Are LLMs Equally Good (or Bad) at Building Secure Software?
With many software engineering teams moving from AI coding assistants into full agentic AI code generation and increasing the amount of code they produce exponentially, ensuring the security of that code must be a top priority. The study produces practical guidance for organizations that are getting on board the AI-assisted or agentic code development train.
Secure AI-driven development before it ships
See developer risk, enforce policy, and prevent vulnerabilities across your software development lifecycle.
