• Advertise
  • Contact Us
  • Supplier Directory
  • SCB YouTube
  • About Us
  • Login
  • Subscribe
  • Logout
  • My Profile
  • LOGISTICS
    • Air Cargo
    • All Logistics
    • Facility Location Planning
    • Freight Forwarding/Customs Brokerage
    • Global Gateways
    • Global Logistics
    • Last Mile Delivery
    • Logistics Outsourcing
    • LTL/Truckload Services
    • Ocean Transportation
    • Parcel & Express
    • Rail & Intermodal
    • Reverse Logistics
    • Service Parts Management
    • Transportation & Distribution
  • TECHNOLOGY
    • All Technology
    • Artificial Intelligence
    • Cloud & On-Demand Systems
    • Data Management (Big Data/IoT/Blockchain)
    • ERP & Enterprise Systems
    • Forecasting & Demand Planning
    • Global Trade Management
    • Inventory Planning/ Optimization
    • Product Lifecycle Management
    • Robotics
    • Sales & Operations Planning
    • SC Finance & Revenue Management
    • SC Planning & Optimization
    • Supply Chain Visibility
    • Transportation Management
  • GENERAL SCM
    • Business Strategy Alignment
    • Customer Relationship Management
    • Education & Professional Development
    • Global Supply Chain Management
    • Global Trade & Economics
    • Green Energy
    • HR & Labor Management
    • Quality & Metrics
    • Regulation & Compliance
    • Sourcing/Procurement/SRM
    • SC Security & Risk Mgmt
    • Supply Chains in Crisis
    • Sustainability & Corporate Social Responsibility
  • WAREHOUSING
    • All Warehouse Services
    • Conveyors & Sortation
    • Lift Trucks & AGVs
    • Order Management & Fulfillment
    • Packaging
    • RFID, Barcode, Mobility & Voice
    • Warehouse Automation
    • Warehouse Management Systems
  • INDUSTRIES
    • Aerospace & Defense
    • Apparel
    • Automotive
    • Chemicals & Energy
    • Consumer Packaged Goods
    • E-Commerce/Omni-Channel
    • Food & Beverage
    • Healthcare
    • High-Tech/Electronics
    • Industrial Manufacturing
    • Pharmaceutical/Biotech
    • Retail
  • THINK TANK
  • WEBINARS
    • On-Demand Webinars
    • Upcoming Webinars
    • Webinar Library
  • PODCASTS
  • WHITEPAPERS
  • VIDEOS
Home » Blogs » Think Tank » Retailers Can’t Afford to Neglect Software Security

Think Tank
Think Tank RSS FeedRSS

Retailers Can’t Afford to Neglect Software Security

E-commerce
January 3, 2021
Chris Eng, SCB Contributor

The COVID-19 pandemic has upended retail and accelerated digital transformation: Online retail surged in 2020, and U.S. holiday e-commerce sales rose a whopping 49% from the previous year.

With so much volume, retailers’ digital presence must be robust and secure. Web applications need to meet customer demands for ease of use and speed, but with 43% of all breaches occurring as a result of a vulnerability at the application layer, the security of these applications is paramount.

With the spike in online retail — and corresponding importance placed on these applications to drive revenue — retailers can benefit from insight into securing their applications.

Veracode’s recent State of Software Security Report (SoSS) highlighted the frequency of vulnerabilities in applications across different industry verticals, including the retail and hospitality sector. The report found that:

  • 26% of retail applications have high-severity security flaws
  • 76% of retail applications have flaws
  • 74% of total retail flaws are being fixed

To make sense of this data, we can compare the retail sector against other industries to find out how well retailers are securing applications and protecting their customers. The frequency of flawed retail applications is high, with more than three out of every four applications containing at least one flaw. Despite this daunting prevalence of vulnerabilities, retail has one of the best rates of fixing software flaws at 74%, second to only financial services at 75%, and better than healthcare, manufacturing, technology and government verticals.

Similar to this success in fix rate, retailers have the best flaw-remediation speed, with the average application requiring 125 days to fix half of its known defects. While retail and hospitality start out with more flaws than some other industries, developers are quick to dig in and fix those flaws in an effort to improve application security and protect customer data.

Overall, the retail industry’s effectiveness for fixing vulnerabilities in applications is promising. But what does it mean in the context of the past year? The new normal has impacted every industry and pushed business even further into the digital realm, meaning more traffic across applications everywhere. This holds especially true for industries like retail.

It’s worth noting the SoSS report found that 55% of severe retail and hospitality flaws fell into the category of information leakage. This type of flaw, if exploited, could ruin the trust customers have with retail brands and tarnish a brand’s reputation. The bottom line is that as more customer interactions shift online, retail application security must continue to improve. Organizations must rise to the challenge to continue integrating security throughout the software development lifecycle, running security checks on their applications frequently and regularly, and using multiple types of scans, through both static and dynamic analysis, to identify defects.

While application security teams should strive to continue to improve remediation speed, one of the best ways retail can improve its security posture is to limit the number of flaws going into applications to begin with.

Providing security education to the developers who are building and deploying these applications would help achieve this goal. Training developers on how to avoid common security flaws and write secure code from the start will reduce the number of new flaws, which in turn will make it easier to fix existing flaws over time. From there, AppSec programs in retail organizations will be better prepared to handle faster release cycles without slowing down developers.

Chris Eng is chief research officer at Veracode.

Technology Quality & Metrics Supply Chain Security & Risk Mgmt

RELATED CONTENT

RELATED VIDEOS

Subscribe to our Daily Newsletter!

Timely, incisive articles delivered directly to your inbox.

Featured Product

Popular Stories

  • Businessman using AI agent system on laptop computer.

    AI in Supply Chain Can’t Succeed Without Foundational Systems

    Artificial Intelligence
  • A LARGE CYLINDRICAL OBJECT SHRINK-WRAPPED IN WHITE PLASTIC IS LOWERED BY CRANE ONTO A FLAT BED TRUCK ON A DOCK

    AI Boom Has European Buyers Paying Extra to Secure Gas Turbines

    Technology
  • 016_ai_and_data_transformation_in_distribution_v1-(540p).png

    Watch: AI and Data Transformation in Distribution

    Artificial Intelligence
  • DOMINO EFFECT FINANCIAL MONEY KNOCK-ON CONSEQUENCES iStock-Devrimb-1500012566.jpg

    Podcast | The Tariff Conundrum for Supply Chains: Pass Along, or Absorb?

    Supply Chain Finance & Revenue Management
  • TWO WORKERS DISCUSS DATA SHOWN ON COMPUTER SCREENS

    Gartner: Gap in SC AI Talent Cannot Be Closed by Hiring Alone

    Artificial Intelligence

Digital Edition

2026 esg cover main scb q2 2026 cover

SupplyChainBrain 2026 ESG Guide: ESG — The Supply Chain’s Biggest Secret

VIEW THE LATEST ISSUE

Case Studies

  • Recycled Tagging Fasteners: Small Changes Make a Big Impact

  • A GRAPHIC SHOWING MULTIPLE FORMS OF SHIPPING, WITH A HUMAN STANDING AT THE CENTER, TOUCHING A SYMBOLIC MAP OF THE WORLD

    Enhancing High-Value Electronics Shipment Security with Tive's Real-Time Tracking

  • A GRAPHIC OF INTERLACING HONEYCOMBED ELEMENTS REPRESENTING GLOBAL BUSINESS TRANSACTIONS

    Moving Robots Site-to-Site

  • JLL Finds Perfect Warehouse Location, Leading to $15M Grant for Startup

  • Robots Speed Fulfillment to Help Apparel Company Scale for Growth

Visit Our Sponsors

4flow Arkieva Blue Yonder
Carton Cloud CoEnterprise Dassault
Duravant E2Open General Logistics Systems
Hy-Tek iGPS Korber
Lyngsoe Procurability Quinyx
SAP Sikick Systech
S&P Global Mobility TADA TransImpact
US Bank Werner Enterprises WSI
  • More From SCB
    • Featured Content
    • Video Library
    • Think Tank Blog
    • SupplyChainBrain Podcast
    • Whitepapers
    • On-Demand Webinars
    • Upcoming Webinars
  • Digital Offerings
    • Digital Issue
    • Subscribe
    • Manage Email Preferences
    • Newsletters
  • Resources
    • Events Calendar
    • 2026 Event Coverage
    • SCB's Great Supply Chain Partners
    • Supplier Directory
    • Case Study Showcase
    • Supply Chain Innovation Awards
    • 100 Great Partners Form
  • SCB Corporate
    • Advertise on SCB.COM
    • About Us
    • Privacy Policy
    • Contact Us
    • Data Sharing Opt-Out

All content copyright ©2026 Keller International Publishing Corp All rights reserved. No reproduction, transmission or display is permitted without the written permissions of Keller International Publishing Corp

Design, CMS, Hosting & Web Development :: ePublishing