
The 2025 Tech Power Players in the software and cloud sector
But it didn't take that long.
King took over as
Thank artificial intelligence. Training AI requires massive amounts of data, making its storage and organization critical to the development of the rapidly spreading technology.
'There's no AI strategy without a data strategy,' King says. 'We have the ability and the unique position for people to get more from their AI investments.'
Advertisement
King graduated from the University of Strathclyde in Glasgow, Scotland, in 1995, and earned a master's degree in computer and information science at the University of Pennsylvania a year later. She worked at a handful of companies, including digital marketing firm Razorfish and internet domain company Verisign, before joining Veracode in 2006.
King started at Veracode as vice president of service delivery. She became CEO in 2019 after private equity firm Thoma Bravo bought the company for $950 million from software and chip producer Broadcom. King stayed another five years, steering Veracode through another sale — to private equity firm TA Associates.
During her time off, King became more involved in the local tech scene. She became interim executive committee chair of the Mass Technology Leadership Council, a trade group, and participated in the Civic Action Project, a public policy program for graduate students and government and business leaders.
Advertisement
King has spent her first months at Nasuni meeting with staff and clients around the world. The company, whose 850 customers include Mattel, Patagonia, and Boston Scientific, was valued at $1.2 billion when it raised an undisclosed amount from private equity firms Vista Equity Partners, TCV, and KKR last year.
King says she was drawn to Nasuni not only for its global reach, but also for its home in Boston. Nearly half of the company's 500 employees work in Massachusetts.
'I'd had the great privilege of helping to build my previous company into a great Boston brand,' King says. 'I was eager to build a global brand with Boston roots.'
More tech power players to watch in the software and cloud sector:
Explore more sectors
Aidan Ryan can be reached at

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles
Yahoo
9 hours ago
- Yahoo
Public Sector Application Risk Accumulates as Security Debt Grows Across Government Systems
Veracode's Public Sector State of Software Security 2025 Report Reveals 78% of Government Organizations Operate with Unaddressed Security Flaws, with Critical Vulnerabilities Persisting for Years BURLINGTON, Mass., June 11, 2025--(BUSINESS WIRE)--Veracode, a global leader in application risk management, today released its Public Sector State of Software Security 2025 report, revealing alarming trends in software security across government organizations. Drawing from an extensive analysis of 1.3 million unique applications and 126.4 million raw findings, the research shows 78 percent of public sector organizations are operating with significant security debt—flaws left unaddressed for more than a year. Moreover, 55 percent are burdened with 'critical' security debt, representing long-standing vulnerabilities with severe risk potential. Public Sector Security Debt Exceeds Industry Average In an era where public trust and digital infrastructure security are paramount, the public sector continues to struggle with timely vulnerability remediation. The research reveals that public sector entities require an average of 315 days to fix half their software vulnerabilities—significantly higher than the overall average of 252 days. This 63-day delay creates substantial windows of opportunity for potential application-layer attacks and data breaches. The data further reveals that even after two years, one-third of security flaws in government applications remain unresolved, with 15 percent persisting for more than five years. This prolonged remediation (depicted in the survival curve in Fig. 1) illustrates how unaddressed vulnerabilities accumulate into widespread security debt. "Many government organizations are facing growing challenges in keeping up with vulnerability remediation, potentially leaving critical systems and data that run essential government services exposed," said Chris Wysopal, Chief Security Evangelist at Veracode. "Our research highlights an urgent need for the public sector to modernize its security practices, especially when it comes to managing risk in open-source software." Veracode collaborates directly with public sector agencies to tackle these cybersecurity challenges. Backed by findings from more than 360 trillion lines of code analyzed over two decades, the Veracode platform provides comprehensive risk visibility from design through deployment, enabling organizations to remediate vulnerabilities with speed and precision. Third-Party Code Presents Disproportionate Risk Profile A particularly concerning finding reveals that while third-party and open-source code comprise less than 10 percent of overall security debt, they account for a staggering 70 percent of critical security debt in government systems. Worse yet, these flaws take approximately 50 percent longer to fix compared to flaws in first-party software developed internally. Wysopal said, "This disproportionate risk highlights the importance of securing software supply chains and carefully vetting open-source dependencies. Without extending visibility and remediation efforts beyond internal code, public sector entities risk leaving the most dangerous flaws unaddressed. As the use of AI-generated code increases across organizations, comprehensive open-source analysis is more essential than ever to prevent hidden flaws from slipping through." Security Maturity Benchmarks Reveal Performance Disparities Despite overall concerning trends, Veracode's research reveals leading government agencies are successfully reducing security debt and resolving vulnerabilities nearly four times faster than others. These high-performing organizations demonstrate that meaningful improvement is achievable, offering a clear path forward for peers looking to strengthen their software security posture. The report identifies five key metrics that measure an organization's application security maturity and debt management capability, revealing distinct performance gaps between leading and lagging public sector organizations: Flaw Prevalence: Leading agencies have flaws in fewer than 33 percent of applications, while lagging agencies show flaws in 100 percent of their applications. Remediation Capacity: Leaders address more than nine percent of flaws monthly, compared to just 0.1 percent for laggards. Resolution Speed: Top performers resolve half of their flaws within 3.3 months, while bottom performers take more than 11 months for similar results. Security Debt Prevalence: Less than 26 percent of applications in leading agencies carry security debt, compared to more than 85 percent in lagging organizations. Open-Source Debt: Even among leaders, 84 percent of applications contain open-source critical debt, rising to 100 percent for lagging peers. "The disparity between top- and bottom-performing government organizations is striking and raises important questions about the factors that make a material difference to security posture," added Wysopal. "This data provides public sector security teams with a clear framework to assess their maturity, identify gaps, and improve their performance based on the practices of top-performing agencies." A Clear Call to Action As public sector organizations face mounting cyber threats and expanding regulatory compliance requirements, Veracode recommends two strategic shifts: Implement Risk-Based Prioritization: Deploy context-driven security posture management capabilities that correlate findings from multiple security tools and data sources. Advanced solutions like Veracode Risk Manager surface the most exploitable and urgent vulnerabilities, offering automated resolution. Enhance Comprehensive Visibility: Establish continuous scanning and developer enablement across the complete software development lifecycle. Proactive flaw identification before deployment remains the most cost-effective and impactful AppSec investment. Wysopal concluded, "In today's threat landscape, security debt is no longer an acceptable risk. With the right focus, metrics, and automation, public sector agencies can take control of their software risk and build resilience into every release." With application risk accumulating across government systems, federal, state, and local agencies must balance mission-critical service delivery with effective cybersecurity risk management. Veracode's comprehensive application risk management platform helps agencies navigate these competing demands through accelerated risk remediation, data-driven vulnerability prioritization, and automated risk assessment capabilities that build organizational resilience against evolving threats. This is especially important as AI-generated code and open-source dependencies introduce new complexity into software development processes. The complete Public Sector State of Software Security 2025 report is available to download on the Veracode website. About Veracode Veracode is a global leader in Application Risk Management for the AI era. Powered by trillions of lines of code scans and a proprietary AI-assisted remediation engine, the Veracode platform is trusted by organizations worldwide to build and maintain secure software from code creation to cloud deployment. Thousands of the world's leading development and security teams use Veracode every second of every day to get accurate, actionable visibility of exploitable risk, achieve real-time vulnerability remediation, and reduce their security debt at scale. Veracode is a multi-award-winning company offering capabilities to secure the entire software development life cycle, including Veracode Fix, Static Analysis, Dynamic Analysis, Software Composition Analysis, Container Security, Application Security Posture Management, Malicious Package Detection, and Penetration Testing. Learn more at on the Veracode blog, and on LinkedIn and X. Copyright © 2025 Veracode, Inc. All rights reserved. Veracode is a registered trademark of Veracode, Inc. in the United States and may be registered in certain other jurisdictions. All other product names, brands, or logos belong to their respective holders. All other trademarks cited herein are property of their respective owners. View source version on Contacts Press and Media: Katy GwilliamHead of Global Communications, Veracodekgwilliam@


Business Wire
9 hours ago
- Business Wire
Public Sector Application Risk Accumulates as Security Debt Grows Across Government Systems
BURLINGTON, Mass.--(BUSINESS WIRE)-- Veracode, a global leader in application risk management, today released its Public Sector State of Software Security 2025 report, revealing alarming trends in software security across government organizations. Drawing from an extensive analysis of 1.3 million unique applications and 126.4 million raw findings, the research shows 78 percent of public sector organizations are operating with significant security debt—flaws left unaddressed for more than a year. Moreover, 55 percent are burdened with 'critical' security debt, representing long-standing vulnerabilities with severe risk potential. Veracode Public Sector State of Software Security 2025 report reveals alarming trends in software security. 78% of government organizations are operating with significant security debt, while 55% are burdened with 'critical' security debt. Share Public Sector Security Debt Exceeds Industry Average In an era where public trust and digital infrastructure security are paramount, the public sector continues to struggle with timely vulnerability remediation. The research reveals that public sector entities require an average of 315 days to fix half their software vulnerabilities—significantly higher than the overall average of 252 days. This 63-day delay creates substantial windows of opportunity for potential application-layer attacks and data breaches. The data further reveals that even after two years, one-third of security flaws in government applications remain unresolved, with 15 percent persisting for more than five years. This prolonged remediation (depicted in the survival curve in Fig. 1) illustrates how unaddressed vulnerabilities accumulate into widespread security debt. 'Many government organizations are facing growing challenges in keeping up with vulnerability remediation, potentially leaving critical systems and data that run essential government services exposed,' said Chris Wysopal, Chief Security Evangelist at Veracode. 'Our research highlights an urgent need for the public sector to modernize its security practices, especially when it comes to managing risk in open-source software.' Veracode collaborates directly with public sector agencies to tackle these cybersecurity challenges. Backed by findings from more than 360 trillion lines of code analyzed over two decades, the Veracode platform provides comprehensive risk visibility from design through deployment, enabling organizations to remediate vulnerabilities with speed and precision. Third-Party Code Presents Disproportionate Risk Profile A particularly concerning finding reveals that while third-party and open-source code comprise less than 10 percent of overall security debt, they account for a staggering 70 percent of critical security debt in government systems. Worse yet, these flaws take approximately 50 percent longer to fix compared to flaws in first-party software developed internally. Wysopal said, 'This disproportionate risk highlights the importance of securing software supply chains and carefully vetting open-source dependencies. Without extending visibility and remediation efforts beyond internal code, public sector entities risk leaving the most dangerous flaws unaddressed. As the use of AI-generated code increases across organizations, comprehensive open-source analysis is more essential than ever to prevent hidden flaws from slipping through.' Security Maturity Benchmarks Reveal Performance Disparities Despite overall concerning trends, Veracode's research reveals leading government agencies are successfully reducing security debt and resolving vulnerabilities nearly four times faster than others. These high-performing organizations demonstrate that meaningful improvement is achievable, offering a clear path forward for peers looking to strengthen their software security posture. The report identifies five key metrics that measure an organization's application security maturity and debt management capability, revealing distinct performance gaps between leading and lagging public sector organizations: Flaw Prevalence: Leading agencies have flaws in fewer than 33 percent of applications, while lagging agencies show flaws in 100 percent of their applications. Remediation Capacity: Leaders address more than nine percent of flaws monthly, compared to just 0.1 percent for laggards. Resolution Speed: Top performers resolve half of their flaws within 3.3 months, while bottom performers take more than 11 months for similar results. Security Debt Prevalence: Less than 26 percent of applications in leading agencies carry security debt, compared to more than 85 percent in lagging organizations. Open-Source Debt: Even among leaders, 84 percent of applications contain open-source critical debt, rising to 100 percent for lagging peers. 'The disparity between top- and bottom-performing government organizations is striking and raises important questions about the factors that make a material difference to security posture,' added Wysopal. 'This data provides public sector security teams with a clear framework to assess their maturity, identify gaps, and improve their performance based on the practices of top-performing agencies.' A Clear Call to Action As public sector organizations face mounting cyber threats and expanding regulatory compliance requirements, Veracode recommends two strategic shifts: Implement Risk-Based Prioritization: Deploy context-driven security posture management capabilities that correlate findings from multiple security tools and data sources. Advanced solutions like Veracode Risk Manager surface the most exploitable and urgent vulnerabilities, offering automated resolution. Enhance Comprehensive Visibility: Establish continuous scanning and developer enablement across the complete software development lifecycle. Proactive flaw identification before deployment remains the most cost-effective and impactful AppSec investment. Wysopal concluded, 'In today's threat landscape, security debt is no longer an acceptable risk. With the right focus, metrics, and automation, public sector agencies can take control of their software risk and build resilience into every release.' With application risk accumulating across government systems, federal, state, and local agencies must balance mission-critical service delivery with effective cybersecurity risk management. Veracode's comprehensive application risk management platform helps agencies navigate these competing demands through accelerated risk remediation, data-driven vulnerability prioritization, and automated risk assessment capabilities that build organizational resilience against evolving threats. This is especially important as AI-generated code and open-source dependencies introduce new complexity into software development processes. The complete Public Sector State of Software Security 2025 report is available to download on the Veracode website. About Veracode Veracode is a global leader in Application Risk Management for the AI era. Powered by trillions of lines of code scans and a proprietary AI-assisted remediation engine, the Veracode platform is trusted by organizations worldwide to build and maintain secure software from code creation to cloud deployment. Thousands of the world's leading development and security teams use Veracode every second of every day to get accurate, actionable visibility of exploitable risk, achieve real-time vulnerability remediation, and reduce their security debt at scale. Veracode is a multi-award-winning company offering capabilities to secure the entire software development life cycle, including Veracode Fix, Static Analysis, Dynamic Analysis, Software Composition Analysis, Container Security, Application Security Posture Management, Malicious Package Detection, and Penetration Testing. Learn more at on the Veracode blog, and on LinkedIn and X. Copyright © 2025 Veracode, Inc. All rights reserved. Veracode is a registered trademark of Veracode, Inc. in the United States and may be registered in certain other jurisdictions. All other product names, brands, or logos belong to their respective holders. All other trademarks cited herein are property of their respective owners.
Yahoo
9 hours ago
- Yahoo
Public Sector Application Risk Accumulates as Security Debt Grows Across Government Systems
Veracode's Public Sector State of Software Security 2025 Report Reveals 78% of Government Organizations Operate with Unaddressed Security Flaws, with Critical Vulnerabilities Persisting for Years BURLINGTON, Mass., June 11, 2025--(BUSINESS WIRE)--Veracode, a global leader in application risk management, today released its Public Sector State of Software Security 2025 report, revealing alarming trends in software security across government organizations. Drawing from an extensive analysis of 1.3 million unique applications and 126.4 million raw findings, the research shows 78 percent of public sector organizations are operating with significant security debt—flaws left unaddressed for more than a year. Moreover, 55 percent are burdened with 'critical' security debt, representing long-standing vulnerabilities with severe risk potential. Public Sector Security Debt Exceeds Industry Average In an era where public trust and digital infrastructure security are paramount, the public sector continues to struggle with timely vulnerability remediation. The research reveals that public sector entities require an average of 315 days to fix half their software vulnerabilities—significantly higher than the overall average of 252 days. This 63-day delay creates substantial windows of opportunity for potential application-layer attacks and data breaches. The data further reveals that even after two years, one-third of security flaws in government applications remain unresolved, with 15 percent persisting for more than five years. This prolonged remediation (depicted in the survival curve in Fig. 1) illustrates how unaddressed vulnerabilities accumulate into widespread security debt. "Many government organizations are facing growing challenges in keeping up with vulnerability remediation, potentially leaving critical systems and data that run essential government services exposed," said Chris Wysopal, Chief Security Evangelist at Veracode. "Our research highlights an urgent need for the public sector to modernize its security practices, especially when it comes to managing risk in open-source software." Veracode collaborates directly with public sector agencies to tackle these cybersecurity challenges. Backed by findings from more than 360 trillion lines of code analyzed over two decades, the Veracode platform provides comprehensive risk visibility from design through deployment, enabling organizations to remediate vulnerabilities with speed and precision. Third-Party Code Presents Disproportionate Risk Profile A particularly concerning finding reveals that while third-party and open-source code comprise less than 10 percent of overall security debt, they account for a staggering 70 percent of critical security debt in government systems. Worse yet, these flaws take approximately 50 percent longer to fix compared to flaws in first-party software developed internally. Wysopal said, "This disproportionate risk highlights the importance of securing software supply chains and carefully vetting open-source dependencies. Without extending visibility and remediation efforts beyond internal code, public sector entities risk leaving the most dangerous flaws unaddressed. As the use of AI-generated code increases across organizations, comprehensive open-source analysis is more essential than ever to prevent hidden flaws from slipping through." Security Maturity Benchmarks Reveal Performance Disparities Despite overall concerning trends, Veracode's research reveals leading government agencies are successfully reducing security debt and resolving vulnerabilities nearly four times faster than others. These high-performing organizations demonstrate that meaningful improvement is achievable, offering a clear path forward for peers looking to strengthen their software security posture. The report identifies five key metrics that measure an organization's application security maturity and debt management capability, revealing distinct performance gaps between leading and lagging public sector organizations: Flaw Prevalence: Leading agencies have flaws in fewer than 33 percent of applications, while lagging agencies show flaws in 100 percent of their applications. Remediation Capacity: Leaders address more than nine percent of flaws monthly, compared to just 0.1 percent for laggards. Resolution Speed: Top performers resolve half of their flaws within 3.3 months, while bottom performers take more than 11 months for similar results. Security Debt Prevalence: Less than 26 percent of applications in leading agencies carry security debt, compared to more than 85 percent in lagging organizations. Open-Source Debt: Even among leaders, 84 percent of applications contain open-source critical debt, rising to 100 percent for lagging peers. "The disparity between top- and bottom-performing government organizations is striking and raises important questions about the factors that make a material difference to security posture," added Wysopal. "This data provides public sector security teams with a clear framework to assess their maturity, identify gaps, and improve their performance based on the practices of top-performing agencies." A Clear Call to Action As public sector organizations face mounting cyber threats and expanding regulatory compliance requirements, Veracode recommends two strategic shifts: Implement Risk-Based Prioritization: Deploy context-driven security posture management capabilities that correlate findings from multiple security tools and data sources. Advanced solutions like Veracode Risk Manager surface the most exploitable and urgent vulnerabilities, offering automated resolution. Enhance Comprehensive Visibility: Establish continuous scanning and developer enablement across the complete software development lifecycle. Proactive flaw identification before deployment remains the most cost-effective and impactful AppSec investment. Wysopal concluded, "In today's threat landscape, security debt is no longer an acceptable risk. With the right focus, metrics, and automation, public sector agencies can take control of their software risk and build resilience into every release." With application risk accumulating across government systems, federal, state, and local agencies must balance mission-critical service delivery with effective cybersecurity risk management. Veracode's comprehensive application risk management platform helps agencies navigate these competing demands through accelerated risk remediation, data-driven vulnerability prioritization, and automated risk assessment capabilities that build organizational resilience against evolving threats. This is especially important as AI-generated code and open-source dependencies introduce new complexity into software development processes. The complete Public Sector State of Software Security 2025 report is available to download on the Veracode website. About Veracode Veracode is a global leader in Application Risk Management for the AI era. Powered by trillions of lines of code scans and a proprietary AI-assisted remediation engine, the Veracode platform is trusted by organizations worldwide to build and maintain secure software from code creation to cloud deployment. Thousands of the world's leading development and security teams use Veracode every second of every day to get accurate, actionable visibility of exploitable risk, achieve real-time vulnerability remediation, and reduce their security debt at scale. Veracode is a multi-award-winning company offering capabilities to secure the entire software development life cycle, including Veracode Fix, Static Analysis, Dynamic Analysis, Software Composition Analysis, Container Security, Application Security Posture Management, Malicious Package Detection, and Penetration Testing. Learn more at on the Veracode blog, and on LinkedIn and X. Copyright © 2025 Veracode, Inc. All rights reserved. Veracode is a registered trademark of Veracode, Inc. in the United States and may be registered in certain other jurisdictions. All other product names, brands, or logos belong to their respective holders. All other trademarks cited herein are property of their respective owners. View source version on Contacts Press and Media: Katy GwilliamHead of Global Communications, Veracodekgwilliam@ Error in retrieving data Sign in to access your portfolio Error in retrieving data Error in retrieving data Error in retrieving data Error in retrieving data