Acquisition Will Deliver Speed and Security from App Development to Production, Bridges CA Security Business with its Broad DevOps Portfolio
CA Technologies (NASDAQ:CA) today announced it has signed a definitive agreement to acquire Veracode, a leader in securing web, mobile and third-party applications across the software development lifecycle, for approximately $614 million in cash. The transaction is expected to close in the first quarter of fiscal year 2018, and is subject to customary closing conditions, including regulatory approvals.
The combination of CA’s portfolio with privately-held Veracode will establish CA Technologies as a leader in the Secure DevOps market through the automation and scaling of application security testing (AST) to develop and deploy applications faster with fewer defects. With Veracode, CA Technologies bridges its Security business with its broad DevOps portfolio and adds to its growing SaaS business. Veracode extends CA’s go-to-market strategy into midsize enterprise customers while CA accelerates Veracode‘s global reach into larger enterprise customers.
“Security testing is growing faster than any other security market, as AST solutions adapt to new development methodologies and increased application complexity. Security and risk management leaders must integrate AST into their application security programs.”* Increased deployment of web and cloud-based business applications has further propelled the market growth. “By 2019, more than 50 percent of enterprise DevOps initiatives will have incorporated application security testing for custom code, up from less than 10% in 2016.”
“Software is at the heart of every company’s digital transformation. Therefore, it’s increasingly important for them to integrate security at the start of their development processes, so they can respond to market opportunities in a secure manner,” said Ayman Sayed, President and Chief Product Officer, CA Technologies. “This acquisition will unify CA’s Security and DevOps portfolios with a SaaS-based platform that seamlessly integrates security into the software development process. Looking holistically at our portfolio, now with Veracode and Automic, we have accelerated the growth profile of our broad set of solutions. We now expect that the size of our growing solutions within our Enterprise Solutions portfolio will eclipse the more mature part of the Enterprise Solutions portfolio in FY19.”
The ability to deliver Identity and Access Management, DevOps tools and automation capabilities with SaaS-based application security, allows CA to offer enterprises of all sizes a faster time-to-value from their software investments.
Digital transformation requires an integrated and agile approach to security. Code-vulnerability risk is mitigated and time spent identifying and fixing security issues in production is reduced when security testing is shifted earlier into the application development process. According to data from the National Institute of Standards and Technology, “it’s 30x more expensive to fix a vulnerability during post-production than during the design, requirement identification and architecture stage.”
Named a leader in the Gartner Magic Quadrant for Application Security Testing***, Veracode’s solution enables automated, on-demand application security testing starting at the earliest phases of the development lifecycle to improve testing speed, address security concerns in production, and eliminate risk. In addition to dynamic application testing, the SaaS-based application security testing software and solutions also perform static testing to detect potential vulnerabilities in custom code, third party applications and open-source components.
“We provide over 1400 small and large enterprise customers the security they need to confidently innovate with the web and mobile applications they build, buy and assemble, as well as the components they integrate into their environments,” said Bob Brennan, CEO, Veracode. “By joining forces with CA Technologies, we will continue to better address growing security concerns, and enable them to accelerate delivery of secure software applications that can create new business value.”