Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

AppSec budget growth: are teams getting real security ROI?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: AppSec budgets are rising while tool sprawl, manual triage, and late-stage remediation still drain time and money, according to OXSecurity. The practical shift is from compliance-led spending to risk-based, automated secure-by-design controls that reduce rework and improve software security ROI.

NHIMG editorial — based on content published by OXSecurity: AppSec budget optimisation and secure-by-design ROI

By the numbers:

Questions worth separating out

Q: What breaks when AppSec budgets grow without better governance?

A: Budgets without governance usually produce tool sprawl, duplicate findings, and slow remediation.

Q: Why do fragmented security tools increase breach risk even when visibility is high?

A: Because attackers exploit the delay between detection and enforcement.

Q: How can security teams know if contextual AppSec is working?

A: They should measure the share of findings that are reachable in production, the time from detection to owner assignment, and the percentage of backlog items that are closed without repeated re-triage.

Practitioner guidance

  • Rebuild AppSec spend around risk concentration Map budget lines to the applications, pipelines, and data paths that create the highest breach exposure, then cut spend that only satisfies compliance reporting.
  • Consolidate overlapping application security controls Reduce duplicate scanners and disconnected posture tools that force manual reconciliation across teams.
  • Embed security checks into CI/CD workflows Move SAST, SCA, and secrets scanning into build and review stages so vulnerabilities are identified before deployment.

What's in the full article

OXSecurity's full article covers the operational detail this post intentionally leaves for the source:

  • How OXSecurity frames AppSec budget optimisation across compliance, tool consolidation, and secure-by-design investment choices.
  • The platform-centric argument for ASPM, including how centralised correlation changes developer remediation workflows.
  • Examples of no-code workflow automation that reduce manual AppSec handling and enforce policy during release.
  • The article's specific claims about MTTR reduction, security debt reduction, and developer-centric enforcement.

👉 Read OXSecurity's analysis of AppSec budget optimisation and secure-by-design ROI →

AppSec budget growth: are teams getting real security ROI?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Compliance-led AppSec budgeting creates a false sense of control. When programmes optimise for passing audits rather than reducing exposure, spend becomes detached from actual risk. The article captures this tension clearly: buying for compliance can increase cost without improving decision quality. For identity and NHI teams, the same pattern appears when controls exist on paper but are not tied to lifecycle enforcement. The practitioner conclusion is to fund risk reduction, not checkbox coverage.

A few things that frame the scale:

  • The average organisation believes more than 1 in 5 of their non-human identities are insufficiently secured, according to 2024 ESG Report: Managing Non-Human Identities.
  • 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, including 46% confirmed and 26% suspected.

A question worth separating out:

Q: Which control model is better for AppSec, compliance-first or risk-based?

A: Risk-based control models are more effective because they align spending with the applications, data, and threats that matter most. Compliance still matters, but it should not dictate every investment. A programme that only optimises for audit outcomes often misses the operational gaps that attackers actually exploit.

👉 Read our full editorial: AppSec budget growth is shifting toward secure-by-design ROI



   
ReplyQuote
Share: