---
title: "Position Paper – Code at Risk"
date: "2025-07-31T08:08:14+00:00"
url: "https://staging.checkmarx.com/position-paper-code-at-risk/"
description: "Organizations that invest in unified application security today will be tomorrow’s leaders - trusted, agile, and secure by design."
---

# Position Paper – Code at Risk

    ![background image](https://staging.checkmarx.com/wp-content/uploads/2025/07/Code_at_Risk_hero_bg_2x-scaled.webp) Position Paper

# Code at Risk

Why DevOps Teams Need to Unify Application Security

 [Read Now](#form)

 ![Code_at_Risk_hero_image_2x](https://staging.checkmarx.com/wp-content/uploads/2025/07/Code_at_Risk_hero_image_2x.webp)

 ![Apple-White](https://staging.checkmarx.com/wp-content/uploads/2024/07/Apple-White.svg)

 ![04 Salesforce](https://staging.checkmarx.com/wp-content/uploads/2024/07/04-Salesforce.svg)

 ![05 Siemens](https://staging.checkmarx.com/wp-content/uploads/2024/07/05-Siemens.svg)

 ![06 Walmart](https://staging.checkmarx.com/wp-content/uploads/2024/07/06-Walmart.svg)

 ![Ford-White](https://staging.checkmarx.com/wp-content/uploads/2024/07/Ford-White.svg)

 ![08 CITI](https://staging.checkmarx.com/wp-content/uploads/2024/07/08-CITI.svg)

 ![VISA-White](https://staging.checkmarx.com/wp-content/uploads/2024/07/VISA-White.svg)

 ![Carlsberg](https://staging.checkmarx.com/wp-content/uploads/2025/02/Carlsberg.svg)

 ![10 Elevance Health](https://staging.checkmarx.com/wp-content/uploads/2024/07/10-Elevance-Health.svg)

 ![12 Orange](https://staging.checkmarx.com/wp-content/uploads/2024/07/12-Orange.svg)

 ![13 Airbus Group](https://staging.checkmarx.com/wp-content/uploads/2024/07/13-Airbus-Group.svg)

 ![14 Novartis](https://staging.checkmarx.com/wp-content/uploads/2024/07/14-Novartis.svg)

 ![16 GE](https://staging.checkmarx.com/wp-content/uploads/2024/07/16-GE.svg)

 ![17 Sainsbury's](https://staging.checkmarx.com/wp-content/uploads/2024/07/17-Sainsburys.svg)

 ![18 PWC](https://staging.checkmarx.com/wp-content/uploads/2024/07/18-PWC.svg)

 ![19 The weather company](https://staging.checkmarx.com/wp-content/uploads/2024/07/19-The-weather-company.svg)

 ![20 CGI](https://staging.checkmarx.com/wp-content/uploads/2024/07/20-CGI.svg)

 ![21 Adidas](https://staging.checkmarx.com/wp-content/uploads/2024/07/21-Adidas.svg)

 ![22 SAP](https://staging.checkmarx.com/wp-content/uploads/2024/07/22-SAP.svg)

Too many applications are being built using code that is unsafe. According to the Ponemon Institute, 76% of applications have at least one security flaw. NIST has found that the average enterprise app contains over 26 vulnerabilities.

This is happening due to the demand for faster development. It’s also the result of traditional AppSec that is no longer fit for purpose in a world of cloud-based apps, microservices, GenAI code creation and containerization.

And this is real business risk, contained in every line of vulnerable code.

So how can you contain that risk without slowing down development? The answer is fundamentally reimagining how security integrates with those building your application.

In this position paper, explore these crucial issues in more depth to better understand where the code risk might lie in your organization. Then take a proactive approach by considering how you can change your structure and culture to enjoy both the security and speed your business demands. This includes:

- Setting the stage for the successful unification of DevOps.

- How to obtain centralized visibility from Code to Cloud.

- Ensuring tool integration across teams, stages, and processes.

**Tomorrow can’t wait**

**Organizations that invest in unified application security today will be tomorrow’s leaders – trusted, agile, and secure by design.**

### Explore Crucial Issues

## What Our Customers Say About Us

See why enterprises trust our approach to AppSec to secure their business-critical applications.

“We view Checkmarx as our trusted partner. They’ve elevated our security posture by consolidating our SAST, SCA, and API Security into a unified platform, Checkmarx One, enabling us to achieve vulnerability remediation, reduce noise, and benefit from strong support.”

 ![Matthew Hurewitz Checkmarx](https://staging.checkmarx.com/wp-content/uploads/2025/06/Matthew-Hurewitz-Checkmarx-150x150.webp)Matthew Hurewitz

Director, Platforms and Application Security

 ![best buy cx logo](https://staging.checkmarx.com/wp-content/uploads/2025/06/best-buy-cx-logo.svg)

“Incorporating Checkmarx’s technology has revolutionized our development culture. It’s more than just technology; it serves as the foundation of our security strategy, ensuring that our applications are secure by design.”

 ![Sudharma Thikkavarapu](https://staging.checkmarx.com/wp-content/uploads/2024/04/Sudharma-Thikkavarapu-150x150.webp)Sudharma Thikkavarapu

Sr. Director, Product Security Engineering

 ![Dell](https://staging.checkmarx.com/wp-content/uploads/2024/04/Dell.svg)

“Checkmarx One definitely checks all my boxes from a security standpoint and has a great interface that’s engaging and easy to use. Some of the solutions we considered were more complicated. With Checkmarx One, it’s easy to get right to the problem with little to no learning curve.”

 ![Joel Godbout](https://staging.checkmarx.com/wp-content/uploads/2024/04/Joel-Godbout-150x150.webp)Joel Godbout

Cybersecurity and Networking Manager

 ![PCL](https://staging.checkmarx.com/wp-content/uploads/2024/04/PCL.svg)

“The success of our AppSec program can be directly attributed to the tooling, processes and support provided by Checkmarx managed services. Our mission revolves around providing secure and compliant lottery and gaming applications and services to our clients around the globe, and with Checkmarx SAST, SCA and associated components enhanced by their stellar service support, we deliver on this promise with confidence and certainty.”

 ![Dion Alexopoulos](https://staging.checkmarx.com/wp-content/uploads/2024/04/Dion-Alexopoulos-150x150.webp)Dion Alexopoulos

Head of Information Security

 ![Allwyn](https://staging.checkmarx.com/wp-content/uploads/2024/04/Allwyn.svg)

“After nearly nine years of using Checkmarx’s SAST, CGI’s journey has been one of seamless integration and consistent satisfaction. The last three years have been particularly smooth, reflecting the solution’s reliability and our successful partnership.”

 ![Abhishek Das](https://staging.checkmarx.com/wp-content/uploads/2024/04/Abhishek-Das-150x150.webp)Abhishek Das

Lead Security Analyst

 ![CGI](https://staging.checkmarx.com/wp-content/uploads/2024/04/CGI.svg)

“After reviewing the Checkmarx platform, I’m not sure how Veracode is able to exist while being at a similar price point.”

Financial Services:

DevSecOps Engineering

“By Far The Best AppSec Tooling Decision We Have Made!!”

 ![Gartner](https://staging.checkmarx.com/wp-content/uploads/2024/04/Gartner.svg)

“We were thrilled to find Checkmarx, which helped us improve the SLA for identifying and remediating risk, reduce risk and the number of vulnerabilities, and eliminate high- and medium-risk issues.”

 ![Ubirajara Aguiar Jr.](https://staging.checkmarx.com/wp-content/uploads/2024/04/Ubirajara-Aguiar-Jr-150x150.webp)Ubirajara Aguiar Jr.

Tech Lead, Red Team/DevSecOps

 ![Pismo](https://staging.checkmarx.com/wp-content/uploads/2024/04/Pismo.svg)

“Checkmarx made security team and developers life easier.”

Security Analyst

IT Services

 ![Gartner](https://staging.checkmarx.com/wp-content/uploads/2024/04/Gartner.svg)

## Market Technology Leadership

40%

of Fortune 100

1800+

Customers in 70 countries

75+

Languages 100+ frameworks

6X

Leader at Gartner® Magic Quadrant™ for Application Security Testing

## Industry Recognition

 ![01 Forrester](https://staging.checkmarx.com/wp-content/uploads/2025/05/01-Forrester.svg)

 ![02_gartner](https://staging.checkmarx.com/wp-content/uploads/2024/06/02_gartner.webp)

 ![03_cyber_security_](https://staging.checkmarx.com/wp-content/uploads/2024/06/03_cyber_security_.webp)

 ![CRN Security 100 2024 Awards](https://staging.checkmarx.com/wp-content/uploads/2024/06/04_crn.webp)
