New study shows healthcare lagging behind in software security

Oct. 19, 2015

Cigital, a vendor of software security solutions, released data from BSIMM6 – the latest from the industry’s first and only software security measurement tool built on real-world data. BSIMM6 also marks the addition of the healthcare industry, providing healthcare organizations a critical mass of data to help them assess, compare, and contrast their software security initiative with others in the industry. The data, following on the heels of the Anthem and UCLA Health data breaches, confirm underlying issues in healthcare software security practices.

Adding the healthcare industry deepens the BSIMM data set and provides a sharp view of the value of the BSIMM. The BSIMM data for healthcare clearly demonstrates that healthcare organizations lag in software security practices, falling significantly behind independent software vendors, financial services firms, and even consumer electronics providers. For healthcare organizations looking to address the problem, the BSIMM provides an objective measurement of an organization’s software security initiative and where these measurements fall within their industry. The data and associated context enable firms to plan a roadmap built on science to mature their software security initiative.

“We are very proud of the growth of the BSIMM data set and of its accuracy,” says Dr. Gary McGraw, CTO, Cigital. “The addition of healthcare in BSIMM6 enriches the model and shows growing awareness of all verticals toward measuring their software security initiative. The healthcare data show that the industry has plenty to learn from other industries when it comes to software security. Fortunately, the BSIMM community is set up to facilitate and accelerate that learning.

Dr. McGraw, along with Jacob West, Chief Architect, NetSuite, and Sammy Migues, Principal, Cigital, analyzed data collected during the past seven years of software security research

Other highlights of the report include the top 12 activities frequently performed by the most mature software security initiatives.

Sponsored Recommendations

Six Cloud Strategies to Combat Healthcare's Workforce Crisis

The healthcare workforce shortage is a complex challenge, but cloud communications offer powerful solutions to address it. These technologies go beyond filling gaps—they are transformin...

Transforming Healthcare with AI Powered Solutions

AI-powered solutions are revolutionizing healthcare by enhancing diagnostics, patient monitoring, and operational efficiency - learn how to integrate these innovations into your...

Enhancing Healthcare Through Strategic IT and AI Innovations

Learn how strategic IT and AI innovations are transforming healthcare - join Tomas Gregorio as he explores practical applications that enhance clinical decision-making, optimize...

The Intersection of Healthcare Compliance and Security in the Age of Deepfakes

As healthcare regulations struggle to keep up with rapid advancements in AI-driven threats like deepfakes, the security gaps have never been more concerning.