Security training teaches hacking, not fixing — and the data shows the cost
Most hands-on cybersecurity platforms, including PortSwigger, Hack The Box, and TryHackMe, mark exercises complete once an exploit succeeds, with no requirement to understand or implement a fix. This offensive-first design was built for penetration testers but is now the primary training path for developers, students, and career changers whose actual job is to prevent attacks. A 2024 OpenSSF survey found nearly one-third of development professionals were unfamiliar with secure coding practices, with most relying on years of on-the-job experience to fill the gap. Secure Code Warrior's nine-year analysis found that developers trained in fix-oriented, secure-by-design methods introduced up to 53% fewer vulnerabilities, yet only around 4% of developers globally apply such practices. Meanwhile, Veracode and HackerOne data show security debt and unresolved vulnerability backlogs growing sharply, suggesting the industry is generating more findings than it can remediate.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in