Opens in a new tab
vmblog logo 2024 wht (updated)

Veracode 2025 Predictions: GenAI to Impact Secure Coding and Saddle Organizations with More Security Debt

Share: 

David Marshall | Published: January 28, 2025

vmblog-predictions-2025 

Industry executives and experts share their predictions for 2025.  Read them in this 17th annual VMblog.com series exclusive.

By Chris
Wysopal, Chief Security Evangelist and Founder of Veracode

2024 saw the rapid adoption of GenAI across a multitude of
industries, and cybersecurity was no exception. While GenAI boosts developer
productivity, enabling a massive increase in the volume of code being written,
it also means more code needs to be analyzed-which if left unchecked, can pose significant
threats to the state of software security.

In 2025, we will see the continued rise and adoption of
GenAI, and, most notably, its impact on the way developers coexist and
remediate vulnerabilities-ultimately leading to increased security debt as the
cybersecurity industry grapples with an influx of compliance risks, security
alerts and quality issues. To keep up, we will also see a rapid increase in the
adoption of AI-powered remediation tools to fix new vulnerabilities and halt
rising security debt.

GenAI to change the way we code

As GenAI-based flaw remediation continues to grow in
popularity, it will become far less important for developers to learn secure
coding. Developers are going to learn less about secure coding because they’re
going to rely more and more on automated means of remediation. It’s analogous
to the task of calling someone on the phone. The task now is to tap a contact
vs. remember their number.

For developers, the task will be to produce secure code and
not learn about secure code creation. We will see adoption of processes to
automatically test for vulnerabilities and when they’re found, automatically
fix those vulnerabilities. It’s not as important for developers to know about
secure coding, or even if generative AI has learned how to write secure code
because we’re going to find it and fix it anyway – automatically.

More code, more security debt

In addition, we can expect to see GenAI-driven coding saddle
organizations with more security debt. The number of vulnerabilities and
critical security debt will grow next year as AI-fueled code velocity
increases. With more code being created at a rapid pace, developers will become
inundated with compliance risks, security alerts and quality issues.

Identifying a solution to help with the growing crisis is
key. As security debt grows, so does the demand for automated security
remediation. However, GenAI coding is still two years ahead of using AI for
security hardening and remediation. This is why in 2025,
we can expect rapidly increased adoption of AI-powered remediation to fix
vulnerabilities faster and bring a material reduction of security debt.

The rise of GenAI
presents a dual-edged sword for software development and cybersecurity. While
it accelerates innovation and productivity, it also amplifies the challenges of
managing security vulnerabilities and debt. To strike a balance, organizations
must adopt AI-driven remediation tools and prioritize automated security
measures. The evolution of secure coding will reshape how developers approach
software security today. Those who proactively integrate these advancements
will not only reduce their security debt but also build a stronger foundation
for sustainable growth in the GenAI era.

##

ABOUT THE AUTHOR

Chris-Wysopal 

Chris Wysopal is the Chief Security Evangelist at Veracode, responsible for enhancing the company’s industry presence, advocating robust security practices, and fostering customer and peer relationships. Prior to co-founding Veracode in 2006, Chris was vice president of research and development at security consultancy @stake, which was acquired by Symantec. In the 1990s, Chris was one of the original vulnerability researchers at The L0pht, a hacker think tank, where he was one of the first to publicize the risks of insecure software. He has testified to the US Congress on the subjects of government security and how vulnerabilities are discovered in software.

Chris received a BS in computer and systems engineering from Rensselaer Polytechnic Institute.