Report: UK lags behind US in auditing code for security flaws
The CTO of open source software firm SUSE suggested the US’ DevOps maturity can be attributed to the difference in aptitude


The US is leading the tech industry in auditing codebases for security issues, with the UK reportedly lagging well behind.
Germany was also identified as one of the nations that was underperforming when it comes to code auditing, despite significant cyber security challenges across the industry.
The findings came from open source software firm SUSE’s latest report, showing a disparity in the way in which the nations see code auditing as an operational priority.
According to the report, nearly half (45%) of respondents in the US regard code audits as a priority, and invest accordingly, while only 23% and 26% of respondents in Germany and the UK respectively adopt the same attitude.
RELATED RESOURCE
SUSE’s global CTO Brent Schroeder said he believes that the US’ potentially more mature DevOps environments could be an influential factor.
“The US being ahead is probably more about the maturity of the US with DevOps and DevSecOps,” Schroeder told ITPro.
Citing his experience with meeting customers, Schroeder said the importance of bringing the integration of security and security practices into the developer pipeline and notes that “companies, at least in the US, are really starting to embrace and recognize that”.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
“If they don’t bring security into the process, they encounter one of two things: One is the speed and agility with which code is delivered is significantly diminished because near the end of the process they have to do checks for security.
“They do everything they can to do the integration as quickly as possible but then releasing new applications, major new features into a production environment, they’ve got to pause to check with the security team: does this pass all the audits and the requirements?
“Or else you deliver vulnerabilities at scale.”
Who cares about source code audits?
Being aware of what is in one’s software supply chain is critical. Recent security incidents have demonstrated the importance of detecting, remediating, and monitoring vulnerabilities in applications.
Across the US, Germany, and the UK, an average of 33% of respondents to the survey believed that goals on source code audits would be revised upwards, rising to 46% if one only considers software and network engineers, technical architects, and developers.
95% also intended to review their software supply chain to increase security. This included 51% that had already done so, increasing to 68% of US-based respondents but going down to only 40% of those that are Europe-based.
Why are the UK and Germany lagging?
The difference in approach could potentially be attributed to governmental and regulatory approaches.
In the US, the M-22-18 memorandum set a deadline for compliance with the National Institute of Standards and Technology (NIST) Secure Software Development Framework (SSDF), SP 800-218, and the NIST Software Supply Chain Guidance.
The M-22-18 memorandum, dated 14 September 2022, set clear dates for US government agencies to adopt the requirements.
Ninety days were given for a software inventory, 120 days for a vendor communication process, and 270 days for attestation letters not posted publicly by software providers for “critical software”.
US companies keen to do business with government agencies must therefore ensure they comply with the NIST requirements, aimed at addressing software security and secure development practices.
The EU’s Network and Information Security (NIS) directive was the first piece of EU-wide legislation on cyber security but, as a briefing on NIS2 in February 2023 noted, implementation proved difficult and resulted in fragmentation across member states.
NIS2 entered into force on 16 January 2023 and is set to be implemented in each member states’ national law by 17 October 2024.

Richard Speed is an expert in databases, DevOps and IT regulations and governance. He was previously a Staff Writer for ITPro, CloudPro and ChannelPro, before going freelance. He first joined Future in 2023 having worked as a reporter for The Register. He has also attended numerous domestic and international events, including Microsoft's Build and Ignite conferences and both US and EU KubeCons.
Prior to joining The Register, he spent a number of years working in IT in the pharmaceutical and financial sectors.
-
Box reveals new AI capabilities at BoxWorks 2025
News Extract and Automate will help businesses make better use of their data, the cloud company claims
-
Big tech CEOs are fueling the fire of AI confusion
Opinion Mixed messaging on the effectiveness of AI only raises fears that the technology will steal human jobs
-
Senior developers are all in on vibe coding, but junior staff lack the experience to spot critical flaws
News Experienced developers are far more confident in using AI-generated code
-
Hexaware partners with Replit to take secure 'vibe coding' to the enterprise
News The new collaboration enables business teams to create secure, production-grade applications without the need for traditional coding skills
-
Microsoft says AI is finally having a 'meaningful impact' on developer productivity – and 80% 'would be sad if they could no longer use it'
News Researchers at Microsoft wanted to demystify how AI is being used by software developers – their findings show the benefits are finally becoming clear.
-
Google's new Jules coding agent is free to use for anyone – and it just got a big update to prevent bad code output
News Jules came out of beta and launched publicly earlier this month, but it's already had a big update aimed at improving code quality and safety.
-
Using an older version of Python? You’re leaving ‘money and performance on the table’ if you don’t upgrade – and missing out on big developer efficiency gains
News New research from JetBrains shows a majority of enterprises are using a version of Python that’s a year or more older – and it's having a big impact on efficiency and performance.
-
Developers say AI can code better than most humans – but there's a catch
News A new survey suggests AI coding tools are catching up on human capabilities
-
84% of software developers are now using AI, but nearly half 'don't trust' the technology over accuracy concerns
News AI coding tools are delivering benefits for developers, but they’re still worried about security and compliance
-
Think AI coding tools are speeding up work? Think again – they’re actually slowing developers down
News AI coding tools may be hindering the work of experienced software developers, according to new research