VendorsCheckmarx
Checkmarx
Cybersecurity reports and statistics published by Checkmarx
8 categories4 reports
Research Reports
Reports and publications from Checkmarx
Recent Statistics & Reports
More than 80% of developers do not apply application security continuously as code is written.
6/15/2026•
Application SecurityDeveloper PracticesSecure Coding
78% of organizations lack formal AI governance policies.
6/15/2026•
AI Governance
73% of organizations describe their security posture as 'advanced' or 'highly mature'.
6/15/2026•
Application SecuritySecurity PostureRisk Perception
18% of developers apply security continuously as they write code.
6/15/2026•
Application SecurityDeveloper PracticesSecure Coding
95% of CISOs feel pressure to suppress or delay compliance-related security issues when business deadlines are at stake.
6/15/2026•
Application SecurityGovernanceExecutive Risk
75% of organizations knowingly deploy vulnerable code at some point.
6/15/2026•
Application SecurityVulnerable CodeRisk Management
Within one year, the proportion of companies with formal AI governance policies increases from 18% to 22%.
6/15/2026•
AI GovernanceApplication Security
93% of organizations acknowledge a recent breach tied to their own applications.
6/15/2026•
Application SecurityData BreachIncident Response
96% of developers acknowledge having AI tooling integrated in their IDEs.
6/15/2026•
Application SecurityDeveloper ToolsAI Tooling
Companies with 81–100% AI-generated production code ship software with known security vulnerabilities at a 47% rate compared with 14% for companies with 1–20% AI-generated production code, making them nearly three times more likely.
6/15/2026•
Application SecurityAI CodeSoftware Vulnerabilities
Within one year, the share of organizations knowingly shipping vulnerable code decreases from 81% to 75%.
6/15/2026•
Application SecurityVulnerable Code
Half of CISOs, AppSec managers and developers already use AI security code assistants.
8/14/2025•
AIAI coding assistant
Within the next 12 to 18 months, nearly a third (32%) of CISOs, AppSec managers and developers expect Application Programming Interface (API) breaches via shadow APIs or business logic attacks.
8/14/2025•
AIAPIShadow APIs
34% of CISOs, AppSec managers and developers admit that more than 60% of their code is AI-generated.
8/14/2025•
AIAI coding assistant
98% of organisations experienced a breach stemming from vulnerable code in the past year.
8/14/2025•
AIVulnerable codeBreach
Only half of organisations surveyed actively use core DevSecOps tools.
8/14/2025•
AIDevSecOps
Fewer than half of the CISOs, AppSec managers and developers report deploying foundational security tools like dynamic application security testing (DAST) or infrastructure-as-code scanning.
8/14/2025•
AIDASTInfrastrucutre-as-code scanning
Only 18% of organisations have policies governing AI use.
8/14/2025•
AIAI policy
20% of organisations still forbid the use of AI coding assistants.
8/14/2025•
AIAI coding assistant
Up to 60% of code is being generated by organisations using AI coding assistants.
8/14/2025•
AIAI coding assistant
Showing 1-20 of 42 results