Why Software Flaws Are the Top Security Risk

The Growing Threat of Accidental Cyber Incidents
While cybersecurity headlines often focus on malicious attacks, the fallout from accidental cyber incidents is becoming a more significant threat to businesses. On the surface, the danger posed by malicious actors may seem more tangible, but the rapid pace at which software is now being developed is exposing organizations to new and complex security risks.
Recent research conducted by Fastly revealed that software bugs were responsible for 40% of cyber incidents in 2025, an increase from 33% in 2024. This figure has surpassed the percentage of incidents attributed to external attackers, which stood at 39%. These statistics highlight a critical shift in the nature of cyber threats, emphasizing the need for a reevaluation of current security strategies.
The Cost of Coding Faster
The adoption of AI in software development has contributed to an increase in software-related issues. Some reports suggest that AI can nearly double the output of engineers. However, a survey conducted last year found that 30% of senior developers have seen their time savings negated by the need to address failures in AI-generated code.
Both human and AI coders can introduce bugs that must be identified through code reviews. Unfortunately, companies are sometimes sacrificing these reviews in favor of AI automation efficiency. This trend not only increases the risk of vulnerabilities but also complicates the management of infrastructure, as companies grapple with the challenges of securing systems that are still evolving.
Security Challenges in Large Organizations
The impact of these issues is particularly pronounced in large enterprises. Organizations with over 10,000 employees reported an average of 57 incidents in 2025, which is nearly 40% above the mean of 40. This data underscores the importance of investing in robust defenses, but it also suggests that traditional security measures alone may not be sufficient.
Modern security strategies must go beyond just investing in tools. They require a fundamental rethink of processes and organizational structures. Only 37% of organizations have shifted security responsibilities towards platform engineering or DevOps, despite the high frequency of incidents related to bugs and misconfigurations.
Establishing Accountability
Strong security postures rely on both effective processes and advanced tooling. While reinforcing defenses remains a priority, shifting focus towards budget allocation and team structure can enhance resilience. Software development has undergone significant changes, and organizations must adapt their approaches accordingly.
Centralized security teams that focus primarily on perimeter defense are often too removed from where risks are created. Bringing security closer to software decision-making is essential for any company aiming to scale its outputs in the face of increasing AI-driven competition.
In practice, this means that security should have oversight earlier in the software development process, rather than just during post-build reviews. Clear accountability helps reduce the risk of delayed responses when incidents occur.
Over half (51%) of AI-first businesses—those that integrate AI as a core part of their operations—are unsure about who handles incident response. These businesses are particularly vulnerable. Defining ownership, identity governance, and escalation paths before deployment ensures that teams can recover quickly when incidents arise.
Secure by Design in the AI Era
I have long advocated for a "secure by design" approach to minimize risk. Baking security into projects from the outset creates a strong security posture. This approach encourages security teams to make systems and coding environments more secure rather than relying solely on individual employees to get everything right the first time.
AI has changed the landscape of secure by design. At 72% of organizations, speed-to-market is prioritized over building resilience into systems. Accelerated software deployment cycles amplify the chances of something going wrong, regardless of the security tools in place.
Security architects and executives should have a voice in decisions about implementing AI. As AI systems become vectors through which businesses can be exposed, they should be treated as privileged infrastructure requiring access control and monitoring from day one.
Build Fast Without Breaking
There is a significant opportunity for businesses scaling their software development to gain a competitive edge by recognizing software errors as a threat equal to external attackers. Organizations that simply bolt on tools and isolate their security teams from the rest of the business are more likely to accumulate risks and find themselves constantly firefighting.
A secure by design approach tailored for the modern age will allow businesses to differentiate themselves from their peers. This strategy should not be a burden on software teams; instead, it should empower them to work with confidence and avoid negative headlines.
We've featured the best encryption software.
This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today. The views expressed here are those of the author and are not necessarily those of or Future plc. If you are interested in contributing, find out more here: https://www.techradar.com/pro/perspectives-how-to-submit. Like this article? For more stories like this, follow us on MSN by clicking the +Follow button at the top of this page.