Published 10 days ago • loading... • Updated 10 days ago
Application Security Training is Broken: 85% of Companies Require It, But Developers Aren’t Asking for It
The analysis says compliance drives AppSec training, while 0% of developers requested it and large enterprises face more than $1.2 million in annual productivity loss.
Secure Coding Practices released an analysis of three independent studies showing 85% of organizations mandate AppSec training, yet 0% of developers have ever requested it, revealing a fundamental disconnect in application security programs.
Compliance requirements, not developer demand, drive training decisions in most organizations, with founder Leon I. Hicks of Secure Coding Practices noting training is delivered for compliance rather than how developers actually work.
Current training models fail to align with real development work: 57% is compliance-driven while 58% of AppSec teams spend over half their time chasing vulnerabilities, with training delivered outside developer tools, forcing context switching and remaining event-based rather than integrated into workflows.
This misalignment creates what teams describe as a defensive tax, costing large enterprises over $1.2 million annually in lost productivity, as training completion fails to reduce vulnerabilities and false positives erode trust in security systems.
Without alignment between training, tools, and workflows, organizations will continue seeing low ROI from AppSec programs; 35% of developers report false positive impacts while 86% adopt AI/ML but training models lag behind security strategies.