Opens in a new tab
vmblog logo 2024 wht (updated)

Purple Book Community and ArmorCode Announce New Research, 'The Rise of the AppSec Leader'

Share: 

David Marshall | Published: April 28, 2025

ArmorCode in partnership with the Purple Book Community (PBC), a community of senior security leaders, released “The Rise of the AppSec Leader.” The new research, which surveyed CISOs and other security leaders, found that ASPM is becoming a strategic investment priority (76 percent), largely due to major increases in AI-generated code, with 92 percent reporting insecure code as a concern. Sixty-five percent believe AI will significantly reshape the AppSec function, making the role of the AppSec leader more important now than ever to protect enterprises rapidly transformed by AI, cloud-native development and rising application threats.

As organizations become digital-first and rapidly adopt generative AI for software development, code is being created faster than ever while adding new security gaps. The research finds that AppSec leaders are growing in importance to solve this challenge by protecting enterprise applications, bridging development and security, guiding secure AI use, and harnessing platforms like ASPM for visibility and independent governance over increasingly fragmented environments.

Key Findings:

  • AI Is Reshaping AppSec Programs: 86% of respondents are already using or exploring generative AI tools in their security programs. Meanwhile, 65% believe AI will significantly reshape the AppSec function in the next year. Among those who have encountered issues with AI-generated code, 92% reported insecure code and 83% cited lack of transparency as major concerns.
  • ASPM Becomes a Strategic Technology and Talent Investment Priority: 76% of respondents named Application Security Posture Management as their top investment focus for 2025. With organizations juggling multiple security tools across siloed teams, ASPM is emerging as the needed independent governance layer to provide unified risk mitigation for applications, tools and infrastructure. 64% of organizations are growing their AppSec teams, with 84 percent noting the role of the AppSec leader as now more important than ever. This reflects the shifting prioritization toward securing the application layer as threats and complexity increase.
  • Supply Chain and Open-Source Threats Are Top Concerns: Supply chain vulnerabilities were noted as the most significant enterprise application threat by 84% of respondents. Open-source risks and cloud misconfigurations followed closely at 73%. Managing the sheer volume of vulnerabilities and false positives were the biggest challenges in securing code, cited by 78% of respondents. Speed of software development outpacing security priorities was also a concern for 71%, with 65% highlighting a lack of visibility across AppSec tools.

Purple Book Community Member Perspectives

“This is a defining moment for AppSec,” said Karthik Swarnam, Chief Security and Trust Officer for ArmorCode and Purple Book Community member. “Applications are now central to how businesses operate and compete. But as development accelerates with AI-generated code, we need stronger governance, deeper collaboration, and leaders who understand both software risk and velocity. That’s where the AppSec leader comes in and why more than 84 percent of survey respondents believe their role is more important now than it was a few years ago.”

“Visibility is always one of the industry’s biggest challenges,” said Mayank Joshi, Head of Cloud Security and GRC at NetApp. “With so many moving parts in modern software development, exacerbated by the fast adoption of AI-generated code, ASPM gives us the clarity we need to prioritize what matters most and connect all the dots.”

“With the rapid technological transformation in engineering and critical infrastructure-such as connected devices, Industry 4.0, and new regulations like the CRA and SOCI Act-product security is also becoming an imperative component of business strategy,” said Jagadish Namboodiri, Director of Global Product Cybersecurity Operations at Wabtec. “Product security is all about embedding cybersecurity into the product lifecycle holistically, right from drawing board till the end of life of the product, while improving the value and resiliency of the product to the customer and the business.”

“Software supply chain threats have emerged as one of the most significant concerns and risks in enterprise application security,” stated Mithun Rajoor, Head of Application and Infrastructure Security at S&P Global. “Application Security Posture Management (ASPM) enables us to comprehensively assess and mitigate these risks across both internal and third-party components, spanning applications, infrastructure, and code. At S&P Global, we are integrating our threat response across these domains to holistically enhance our overall security posture.”