Amsterdam, October 24, 2023 - The OWASP® Foundation, with the lead of AI expert Rob van der Veer, has introduced the OWASP AI exchange. This initiative seeks to foster open-source collaboration from experts addressing AI security and the associated regulatory challenges.

Benefiting from Software Improvement Group’s threat model, the OWASP AI exchange provides a space for professionals worldwide to share insights and strategies to mitigate security threats to AI. As a key member of the CEN/CENELEC security working group for the EU AI Act, Van der Veer recognizes the importance of collaborative efforts. "With the rapid evolution of AI, ensuring its security is a shared responsibility. We aim to consolidate expertise and work towards common goals," states Rob.

This initiative serves as a call to action for AI experts and industry professionals. "We encourage participation: visit the GitHub repository at owaspai.org and contribute to the growing body of knowledge. Every perspective helps in refining our approach," Van der Veer notes.

The OWASP AI Exchange, using Software Improvement Group’s AI framework, is pivotal to helping secure AI systems and consistently regulate AI threats through feedback and contributions from the global community. By sharing knowledge and best practices, we can help to make AI systems more secure and trustworthy for everyone. - OWASP Foundation

As AI continues to shape industries and influence innovations, it's essential to prioritize its safe integration into our systems. The OWASP AI exchange exemplifies this commitment by creating a platform for shared knowledge and collaboration - and it will benefit other initiatives such as ISO/IEC 27090, the OWASP ML top 10, the OWASP Top 10 For Large Language Models, OpenCRE.org, and more.

For more information or to contribute, please visit owaspai.org or reach out directly to rob.vanderveer@owasp.org.

 

About OWASP® Foundation

The OWASP® Foundation works to improve the security of software through its community-led open source software projects, hundreds of chapters worldwide, tens of thousands of members, and by hosting local and global conferences. Learn more at https://owasp.org/.


About Rob van der Veer

A veteran in AI and cybersecurity expert, Rob is Senior Director at Software Improvement Group. He is the author and co-author of various security and AI standards. Rob co-leads the OWASP Integration standards project - the creators of openCRE.org. Rob is the lead author of the ISO/IEC 5338 standard on AI engineering,  a member of the CEN/CENELEC security working group for the EU AI Act, and the ISO/IEC 27090 group.

About Software Improvement Group

Software Improvement Group (SIG) supports enterprise clients and governments to build future-fit software. SIG combines its software assurance platform, Sigrid®, with human expertise to dig deep into the build quality and security of enterprise software and its architecture. Scanning, ranking, and recommending clients’ software landscapes against the world’s largest software analysis benchmark database to help them get a grip on their technology risks and challenges.

 

Contact details for the press

Rob van der Veer

Senior Director, Software Improvement Group

press@softwareimprovementgroup.com

+31 20 314 09 50
10.06.2024
Reading time: 2-3 minutes

SIG M&A Software Analysis Reveals Concerning Trends In Software Quality

NEW YORK, NY, USA, June 10, 2024

Software Improvement Group (SIG), the leading independent institute specializing in software health analysis, has significant concerns about the quality of software involved in mergers and acquisitions (M&A). Out of 531 M&A-related software projects analyzed, SIG found that the average software quality scores were significantly below the market average. This implies that companies face two times lower development efficiency and a considerably higher risk of defects and vulnerabilities.

Key findings

  • Quality Scores Below Market Average: The study revealed that software involved in these transactions often lags behind industry standards, presenting substantial risks for acquirers.
  • High Technical Debt: On average, technical debt constitutes 31% of the total code volume, indicating severe underlying issues in software maintainability and scalability.
  • Informed Investment Decisions: Companies that utilized SIG’s software economics methodology were able to make strategic investments to mitigate these technical debt challenges effectively.

SIG possesses unparalleled expertise and resources to assess the build quality, scalability, and security of software assets. With the world’s largest software metrics database, encompassing an impressive 200 billion lines of code and 18,000 system inspections spanning over 300 technologies, SIG provides comprehensive evaluations that stand as a testament to our unwavering dedication to creating a healthier digital world.

Luc Brands, CEO of Software Improvement Group: “At SIG, we believe private equity firms are not as in control as they could and should be. Through software economics, we ensure thorough code analysis, benchmarking, architecture investigation, and cost modeling. This approach guarantees clarity regarding the true scalability of acquired assets.”

To further facilitate this conversation, Software Improvement Group and Carnegie Mellon University (CMU) will be hosting a webinar titled “Software Economics for Private Equity: How to Evaluate the Quality and Value of Software Assets” on June 27th. The webinar will provide private equity companies with insights into the importance of software asset valuation. Private equity firms are invited to join the webinar to gain valuable knowledge and insights from industry experts.

In conclusion, software assets represent a significant opportunity for private equity firms to drive value creation. By embracing advanced software economics and leveraging SIG’s expertise, private equity firms can make informed decisions that maximize returns and mitigate risks in their software investments.

For more information about SIG and to register for the upcoming webinar, please visit Software Improvement Group’s webinar page.

For the full report, visit the benchmark report.

About SIG
Software Improvement Group (SIG) leads in traditional and AI software quality assurance, empowering businesses and governments worldwide to drive success with reliable and robust IT systems. Sigrid® – its software excellence platform – analyzes the world’s largest benchmark database of over 200 billion lines of code across more than 18,000 systems in 300+ technologies, and intelligently recommends the most crucial initiatives for organizations. SIG complies with multiple ISO/IEC standards, including ISO/IEC 27001 and 17025, and has co-developed ISO/IEC 5338, the new global standard for AI lifecycle management.
SIG was founded in 2000 and has offices in New York, Copenhagen, Brussels, and Frankfurt, and is headquartered in Amsterdam.

Sigrid®, together with expert consultants, and nearly 25 years of industry-leading research, position Software Improvement Group as the foremost authority on software excellence.

For more information, please visit Software Improvement Group’s website or social media channels.

Experience Sigrid live

Request your demo of the Sigrid® | Software Assurance Platform:
  • This field is for validation purposes and should be left unchanged.

Software Landscape Scan

Uncover inefficiencies and identify risks in your software portfolio. In just 2 weeks.