iTnews
  • Home
  • News
  • Technology
  • Security

Software developers putting data at risk

By Staff Writers
Jan 11 2008 2:04PM
Follow google news

Over half of UK companies use actual rather than disguised customer data to test applications during the development process, according to a survey by Compuware Corporation.

Software developers putting data at risk
The report, created in conjunction with privacy management firm the Ponemon Institute, concludes that this practice compromises critical information as these environments are less secure than production environments.

Testing data may be exposed to a variety of unauthorised sources, including in-house staff, consultants, partners and even offshore personnel.

Some 35 per cent of respondents outsourced their application testing, and 38 per cent shared live data with the outsourced organisation.

"For many organisations, large customer data files represent an easy and cheap source of data to use when testing applications," said Dr Larry Ponemon, chairman and founder of the Ponemon Institute.

"But this process introduces a huge element of risk to the challenge of maintaining the integrity of sensitive information, particularly when third parties and offshore resources are involved."

The study points to a need for greater awareness and accountability over how sensitive data is used within organisations.

"Common practices as they relate to all uses of live data must be evaluated to assess risk, and safeguards implemented to ensure data security," said Dr Ponemon.
Of the 58 per cent of companies using actual customer data, 79 per cent use customer files and 68 per cent use customer lists.

Examples of the live data include employee and vendor records, customer account numbers, credit card numbers, Social Security numbers and other credit, debit or payment information.

Furthermore, 43 per cent of respondents admitted to having no way of knowing whether the data used in testing had been compromised, and 17 per cent reported not protecting live data used in software development.

The report also highlighted the confusion surrounding the ownership of sensitive test data.

Some 11 per cent of respondents did not know who was responsible for securing test data, 43 per cent believed that the development organisation is responsible and 14 per cent thought that the business units sponsoring the development were responsible.

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.
Copyright ©v3.co.uk
Tags:
atdatadevelopersputtingrisksecuritysoftware

Related Articles

  • Meta accuses NSO Group of violating court order by WhatsApp spear phishing Meta accuses NSO Group of violating court order by WhatsApp spear phishing
  • Researchers build self-replicating AI worm with BYO LLM Researchers build self-replicating AI worm with BYO LLM
  • Anthropic opens Claude Mythos Preview AI program to Australia Anthropic opens Claude Mythos Preview AI program to Australia
  • Defence says Palantir is "sandboxed" in its environment Defence says Palantir is "sandboxed" in its environment
Join our WhatsApp Channel

Partner Content

CommBank creates opportunities for technologists to upskill  with frontier AI companies
Partner Content CommBank creates opportunities for technologists to upskill with frontier AI companies
Thomas Peer Solutions unveils data cloud platform and executive leadership forum for 2026
Partner Content Thomas Peer Solutions unveils data cloud platform and executive leadership forum for 2026
Onel Consulting Strengthens Its White-Glove Services With Strategic COO Appointment
Promoted Content Onel Consulting Strengthens Its White-Glove Services With Strategic COO Appointment
Intelligence × Trust: the equation that will decide Australia's AI winners
Promoted Content Intelligence × Trust: the equation that will decide Australia's AI winners

Sponsored Whitepapers

Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
High-volume data sources for AI-driven security analytics
High-volume data sources for AI-driven security analytics
How healthcare organisations can get more value from cloud
How healthcare organisations can get more value from cloud
1 in 3 companies lose SaaS data. Here’s how to prevent it
1 in 3 companies lose SaaS data. Here’s how to prevent it

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • The 2026 iAwards The 2026 iAwards
  • Integrate 2026 Integrate 2026
  • Security Exhibition & Conference Security Exhibition & Conference
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Anthropic opens Claude Mythos Preview AI program to Australia

Anthropic opens Claude Mythos Preview AI program to Australia

Defence says Palantir is "sandboxed" in its environment

Defence says Palantir is "sandboxed" in its environment

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Microsoft backs down on legal threats against 0day disclosing researchers

Microsoft backs down on legal threats against 0day disclosing researchers

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.