REPORT
The State of Application Security: How Enterprises Are Developing Secure Applications
New research reveals where enterprise AppSec programs are maturing, and where critical gaps remain.
AI-generated code, software supply-chain attacks, containerized environments, and evolving DevSecOps practices are reshaping application security risk. While many organizations have formal AppSec programs in place, Dark Reading’s latest report shows that maturity does not always translate into measurable security capability.
Inside the report, you’ll learn:
- Why 60% of organizations treat AI-generated and human-written code the same in testing pipelines, while 53% still rely on manual developer review.
- How software supply chain security has become a top AppSec pain point for enterprise teams.
- Where containerization, microservices, APIs, and CI/CD pipelines are creating new attack surfaces.
- Why secure coding training, role-based education, and hands-on practice are becoming essential to building application security capability at scale.

TRUSTED BY THE WORLD'S LARGEST ENTERPRISES
What our customers say
"Similar to flight simulators, CMD+CTRL is the perfect complement to traditional training because it immerses the learner in a realistic environment and prepares them for the cybersecurity battle they will face."
"We began training with a single cyber range event. It generated so much excitement that teams immediately asked when we’re running the next one."
"CMD+CTRL has earned a reputation for being a trusted security advisor to their clients. This is keenly reflected in their training solutions, which help organizations build a culture of security."
Let's Discuss Your Needs
We'd like to learn more about your software security training initiatives and share how organizations just like yours have improved their security posture.