“ImmediateShortTerm3MthsAfterThatLOL”: Developer Secure-Coding Sentiment, Practice and Culture in Organisations

Research output: Chapter in Book/Report/Conference proceedingsConference proceedingpeer-review

Abstract

As almost all areas of human endeavour undergo rapid digital transformation, secure coding is increasingly important to personal, commercial and national security. Yet studies have shown that software developers do not always prioritise or even understand security. Our large survey of organically sourced coders (n=863) examines how software developers currently experience secure coding in the workplace. We found that developers express an interest in secure coding, display basic security knowledge, and turn to their managers and teams first for help with security concerns. We found that developer secure coding sentiment and security practice do not correlate with organisational statistics such as size, but do correlate weakly with measures of security culture, indicating that organisational security support goes hand-in-hand with secure development. Most developers would look for help in-house if they had security concerns. Investigating the effects of code breaches, we found that for almost half of cases, code security does not increase, or increases only for a short time.

Original languageEnglish
Title of host publicationProceedings - 2025 IEEE/ACM 47th International Conference on Software Engineering
Subtitle of host publicationSoftware Engineering in Practice, ICSE-SEIP 2025
PublisherInstitute of Electrical and Electronics Engineers
Pages551-562
Number of pages12
Edition2025
ISBN (Electronic)9798331536855
DOIs
Publication statusPublished - 2025
Event47th IEEE/ACM International Conference on Software Engineering: Software Engineering in Practice, ICSE-SEIP 2025 - Ottawa, Canada
Duration: 27 Apr 20253 May 2025

Conference

Conference47th IEEE/ACM International Conference on Software Engineering: Software Engineering in Practice, ICSE-SEIP 2025
Country/TerritoryCanada
CityOttawa
Period27/04/253/05/25

Keywords

  • secure coding
  • secure software development
  • software security
  • software security culture
  • software security practice

Fingerprint

Dive into the research topics of '“ImmediateShortTerm3MthsAfterThatLOL”: Developer Secure-Coding Sentiment, Practice and Culture in Organisations'. Together they form a unique fingerprint.

Cite this