IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more

70% of IT workers skip key security steps due to work pressures

Report finds that a fifth of DevOps and security professionals have considered quitting their jobs due to stress

Security and development teams are groaning under the strain of securing organizations, according to a report released this week. 

The report, released by web application security tools company Invicti Security, found 78% of respondents reported increased stress levels over the last year. One in five DevOps and security professionals have considered quitting their jobs due to these pressures. 

The report blames the problem on a backlog of security tasks, caused in part by a cyber security skills shortage. It says that the average IT team member would need a two-week break from their regular work just to catch up with what it calls 'security debt'. 

The report, which surveyed 600 executives and hands-on practitioners across security, development and DevOps roles, found that the heavy workload had an effect on the security process. 70% of respondents frequently or always skipped security steps when delivering projects, it said. 

A lack of security in the software development lifecycle isn't helping. Almost half of all developers said that application security testing is completely separate from development, with only one in five reporting that they have fully integrated it into the development process. The result is less secure software, with one in three security issues making it through the development and testing stage to production. 

A lack of focus on post-deployment application scanning exacerbates the problem, as professionals fail to allocate enough resources to it, the report said. Only seven in ten of those that fully adopted security in the software development phase regularly scanned more than three quarters of their applications for vulnerabilities and then remediate them. 

Related Resource

The truth about cyber security training

Stop ticking boxes. Start delivering real change.

Pair of feet in socks with a chair and plant in the backgroundFree download

Security professionals want more automation to help lighten the load. One in six of them said that their companies do not have enough automation in place to test and remediate security issues. 

That's due in part to a lack of trust in the tools. Only half of the respondents were confident enough in the accuracy of their vulnerability scanning software, prompting almost four in five to manually verify results. Each verification takes around an hour. 

Invicti recommends better training for developers and security teams, paying more attention to post-deployment vulnerability scanning, and automating manual tasks where possible. Machine learning is also making tools more aware of vulnerability context, it concluded. 

Featured Resources

Mastering retention

Turning user behaviour insights into retention strategies

Free Download

Dell PowerEdge with AMD

IT applications and infrastructure are the prime catalyst for new revenue creation

Free Download

Building for success with off-premises private cloud

Leveraging co-location facilities to execute your cloud strategy

Free Download

Cyber resiliency and end-user performance

Reduce risk and deliver greater business success with cyber-resilience capabilities

Free Download

Most Popular

46 US states call for Meta monopoly lawsuit to be reinstated
mergers and acquisitions

46 US states call for Meta monopoly lawsuit to be reinstated

20 Sep 2022
Anonymous hacks Iranian government and state broadcasters
cyber attacks

Anonymous hacks Iranian government and state broadcasters

22 Sep 2022
Why collaboration is key to digital transformation

Why collaboration is key to digital transformation

13 Sep 2022