Products

Problems
we solve

We can help your business

Request a Free Demo / trial

Insights

Insights
23 July, 2025

Will Businesses Ever Take Performance and Security Testing Seriously?

Performance & Security

Are performance and security testing still treated as tick boxes to tag on to the end of a project when all the development is done? In my experience, neither performance nor security is taken seriously by enough companies.

‘Twas ever thus, you might say. And you’d be right. But these are different times, with different expectations, different threats, and different consequences.

These days, performance and security failures can bring down businesses. So, why does it still feel like most companies don’t take the related testing phases seriously?

A Personal Story

Once upon a time, I was involved in launching a web security testing service. To get things started, we offered customers a free health check, and one particular financial company jumped at the chance.

We quickly got to work and shortly identified two severe security defects, both of which could have resulted in data theft. We notified them immediately and continued on.

Our final report, which they sincerely thanked us for, included an additional 20 medium-priority security defects.

When I asked what they planned to do, I was shocked by their answer. They told me, matter-of-factly, that they would do nothing about the defects, as they had not budgeted for additional effort.

Granted, this was some time ago, and I’d love to say they would handle this news differently today, but my experience fills me with doubt.

A Tougher Landscape and Sky-High Expectations

The simple fact is, though, the stakes have never been higher. It’s no longer enough for software to be functionally adequate or for severe performance and security defects to be knowingly accepted into live solutions.

On the one hand, the threat landscape is more complex than ever, with new vulnerabilities and attack vectors cropping up daily. High-profile cyberattacks are commonplace in modern news cycles.

At the same time, customers expect lightning-fast performance. Anything less — a sluggish checkout page, or an app that crashes under load — and you risk losing more than just that user.

These days, ‘working’ must also include robust performance and rock-solid security. The funny thing is, businesses know this. Stakeholders absolutely know that security and performance are fundamental to success, yet they still cut corners and therefore don’t take their testing seriously.

Why Are Security and Performance Testing Still Regarded as Second-Class Citizens?

So why are security and performance often only tested at the very end of the development cycle, if at all?

I can think of a few reasons:

  • Misconceptions: Teams often think you can’t do performance or security testing before you have a finished product. In fact, there are lightweight, iterative approaches that identify problems early, saving costly rework and failures.  
  • Project Pressures: Fast deadlines, tight budgets, and pressure to deliver minimum viable products (MVPs) can lead teams to cut corners. Testing is often seen as a way to reduce time, and performance and security are prime candidates for the squeeze.
  • Underestimating Risk: If past releases didn’t have problems (or you didn’t detect them), there’s a false sense of security that it will be the same next time.
  • Lack of Expertise or Tooling: Many teams lack in-house specialists or the necessary tools to conduct meaningful tests early. Without champions to advocate for it, testing gets pushed back.

The more I think about it, the more I think it’s simply down to basic human nature. Functional issues must be addressed immediately, but performance and security concerns can often be put off until tomorrow.

In many organisations, functional testing has become part of the DevOps culture. It’s planned early, automated where possible, and viewed as a core part of the development process.

Meanwhile, performance and security testing are left lingering at the back of the queue, if at all. All too often, they’re squeezed into the last sprint or pushed until the week before go-live. After all, as long as a solution is functionally adequate, we can ship it and deal with any fall out.

Even When Testing Is Done, It’s Often Done Half-Heartedly

Sure, some teams run a basic load test or click a few checkboxes for compliance, but without time to analyse the results or act on them, these tests do little to improve the actual quality of the product.

To make matters worse, many test teams are being encouraged to move away from robust, enterprise-grade tooling to “free” or lower-cost alternatives. While budgets matter, the business often doesn’t realise these tools don’t deliver the same quality of insight, and the subsequent risk increase is all too real.

For example, I once worked with a company that replaced a proven enterprise performance testing tool (LoadRunner) with a cheaper solution. The migration required weeks of script rework, and ultimately, the tool was unable to simulate real-world traffic properly. The delays and post-launch firefighting quickly wiped out any savings.

Often, they are being encouraged to do this by external consultants. Have you ever wondered why? Two main reasons:

  • They are more interested in diverting your budget to their fees and away from tools
  • Most free or low-cost tools require more effort to achieve results, so more consultancy days sold

A win-win for them.

Will More Businesses Ever Take Performance and Security Testing Seriously?

Despite increasing media coverage and general awareness of the issues, many businesses are stuck in old habits. This begs the question: Will businesses ever take this seriously?

What needs to happen to wake people up to the consequences of short-term thinking?

Performance and security can’t just be checkboxes. We’ve all seen the consequences when they aren’t taken seriously. They must be integrated into development from the beginning — with the right mindsets, the right expertise, and serious, professional tools like LoadRunner Cloud, LoadRunner Professional and Fortify.

But do you think this will ever happen?

Stephen Davis
by Stephen Davis

Stephen Davis is the founder of Calleo Software, a OpenText (formerly Micro Focus) Gold Partner. His passion is to help test professionals improve the efficiency and effectiveness of software testing.

To view Stephen's LinkedIn profile and connect 

Stephen Davis LinkedIn profile

23rd July 2025
Adding More Testers Makes Quality Worse

When Adding More Testers Makes Quality Worse!

You’re deep into a project, go-live is rapidly approaching, but there is a mountain of testing to get through. Then, a key stakeholder chimes in, “Let’s just pull more people into testing.” It sounds logical: bigger effort, higher quality. But doubling down on resources can easily lead to chaos, confusion, and worse software quality.

Is Open Source Trustworthy

Do You Trust Open-Source Tools for Enterprise Testing?

Open-source testing tools like JMeter and Selenium have obvious appeal—no licensing fees, endless customisation, and a community to lean on. But, if you’re using open-source for mission-critical testing, you need to ask—is it really worth the risk?

Should testers be allowed to block releases?

Should Testers Be Allowed to Block Releases?

Your testers find a critical bug the night before a major release. Should they have the power to stop the launch?

Testers provide essential insights into software quality and risk. Their analysis is critical for decision-makers, so would it make sense to give them the power to veto releases?

Bug seeding

Bebugging: Would You Plant Defects to Test Testers?

Would you intentionally plant defects to test your test team? Bebugging, as it’s known, is a technique where software flaws are purposely introduced to gauge testing effectiveness. Are there times and places where bebugging is a valid way to help improve processes, tighten up testing, or root out a potential weak link?

Unethical Test Tool Marketing

Exposed: Are You Being Conned By Test Tool Marketing?

We have all witnessed an alarming rise in deceptive marketing practices that undermine customer decision-making and market integrity, with tool vendors increasingly comparing their tools to industry leaders using deliberately misleading information.

Flaky Automated Tests

Are Flaky Automated Tests Better Than None at All?

Is flaky automation better than no automation at all? Does it help accelerate projects and reduce timelines, or does it end up causing more problems than it solves? And are the questions moot when, with modern AI-powered tools, there’s no excuse for flaky tests?

Software Testing Concepts

Software QA Mythbusting: 5 Misunderstood Testing Concepts

We’ve all been there—sitting in a meeting, nodding along, confident that everyone shares the same understanding, only to discover later that our ideas were built on shaky ground, based on false assumptions and an incomplete grasp of a complex situation. In the world of software development, nowhere is this more common, or more consequential, than with software testing.

LoadRunner v JMeter

LoadRunner: Cheaper & Easier Than JMeter?

Four years ago, I wrote about how LoadRunner Cloud was debunking the myth that open-source is cheaper. At the time, LoadRunner Cloud’s pay-as-you-go pricing, bundled infrastructure, and rapid setup were already making it a compelling alternative to JMeter and similar tools.

Model Based Testing

How to Bridge the Gap Between Business and Testing

MBT can transform software QA processes through enhanced collaboration between testers and subject matter experts (SMEs). It offers enhanced capabilities for businesses seeking efficient, comprehensive testing solutions in an increasingly complex software landscape.

Time to Ditch Jira

Is it Time to Ditch Jira? (… For Test Management)

Are you sick of Jira test management solutions? You’re not alone. I speak to dozens of businesses monthly across all different sectors. Many have been forced to use Jira for test management. The more positive people I talk to say it is okay at best.

Insights

Search

Related Articles

InsightsTrending

To get other software testing insights, like this, direct to you inbox join the Calleo mailing list.

You can, of course, unsubscribe 

at any time!

By signing up you consent to receiving regular emails from Calleo with updates, tips and ideas on software testing along with the occasional promotion for software testing products. You can, of course, unsubscribe at any time. Click here for the privacy policy.

Sign up to receive the latest, Software Testing Insights, news and to join the Calleo mailing list.

You can, of course, unsubscribe at any time!

By signing up you consent to receiving regular emails from Calleo with updates, tips and ideas on software testing along with the occasional promotion for software testing products. You can, of course, unsubscribe at any time. Click here for the privacy policy.