• Home
  • News
  • Coins2Day 500
  • Tech
  • Finance
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechCybersecurity

Exclusive: CA Technologies Is Buying a Startup to Bolster App Security

Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
April 9, 2018, 10:44 AM ET
Day Two Of The World Economic Forum (WEF) 2018
Mike Gregoire, chief executive officer of CA Technologies Inc., gestures as he speaks during a Bloomberg panel session on day two of the World Economic Forum (WEF) in Davos, Switzerland, on Wednesday, Jan. 24, 2018. World leaders, influential executives, bankers and policy makers attend the 48th annual meeting of the World Economic Forum in Davos from Jan. 23 - 26. Photographer: Jason Alden/Bloomberg via Getty ImagesJason Alden—Bloomberg via Getty Images

CA Technologies is buying SourceClear, a startup that helps developers build safer software by scanning for security vulnerabilities in code.

Founded in Seattle in 2013 and now based in San Francisco, SourceClear has raised a total of $11.5 million in two rounds of funding to date. The startup was conceived by Mark Curphey, a British cybersecurity veteran who created the so-called Open Web Application Security Project, or OWASP, a nonprofit organization devoted to improving the security of software.

CA and SourceClear declined to disclose the terms of the deal.

“There is a lot of inherent risk in leveraging open source libraries to assemble software,” said Sam King, general manager for CA Technologies’ Veracode unit, SourceClear’s new home which specializes in application security, in a statement emailed to Coins2Day. One recent consequence of that risk: last year’s Equifax data breach, which was caused by the big three credit bureau using a vulnerable version of Apache Struts, a popular open source software project.

Veracode, bought by CA for $614 million in cash a year ago, plans to bolster its existing so-called software composition analysis offering with SourceClear’s tools. “We had an incredible roadmap ahead of us for our current SCA [software composition analysis] solution, but we realized that we could bring these features (and more) to market faster by acquiring a company like SourceClear,” King said .

A recent, yet unreleased survey of 400 application developers across the U.S., UK and Germany, found that only about half—52%—said they update their coding components when new security vulnerabilities come to light. Failing to patch bugs leaves holes in software that hackers can exploit to nefarious ends. Veracode shared a preview of that research, conducted by Vanson Bourne, a market research firm, with Coins2Day ahead of its publication, slated for this week.

Curphey is set to become vice president of business unit strategy in CA’s Veracode division, reporting to King.

About the Author
Robert Hackett
By Robert Hackett
Instagram iconLinkedIn iconTwitter icon
See full bioRight Arrow Button Icon
Rankings
  • 100 Best Companies
  • Coins2Day 500
  • Global 500
  • Coins2Day 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Coins2Day Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Coins2Day Brand Studio
  • Coins2Day Analytics
  • Coins2Day Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Coins2Day
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

© 2025 Coins2Day Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Coins2Day Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.