Products

Problems
we solve

We can help your business

Request a Free Demo / trial

Insights

Insights
23 July, 2025

Will Businesses Ever Take Performance and Security Testing Seriously?

Performance & Security

Are performance and security testing still treated as tick boxes to tag on to the end of a project when all the development is done? In my experience, neither performance nor security is taken seriously by enough companies.

‘Twas ever thus, you might say. And you’d be right. But these are different times, with different expectations, different threats, and different consequences.

These days, performance and security failures can bring down businesses. So, why does it still feel like most companies don’t take the related testing phases seriously?

A Personal Story

Once upon a time, I was involved in launching a web security testing service. To get things started, we offered customers a free health check, and one particular financial company jumped at the chance.

We quickly got to work and shortly identified two severe security defects, both of which could have resulted in data theft. We notified them immediately and continued on.

Our final report, which they sincerely thanked us for, included an additional 20 medium-priority security defects.

When I asked what they planned to do, I was shocked by their answer. They told me, matter-of-factly, that they would do nothing about the defects, as they had not budgeted for additional effort.

Granted, this was some time ago, and I’d love to say they would handle this news differently today, but my experience fills me with doubt.

A Tougher Landscape and Sky-High Expectations

The simple fact is, though, the stakes have never been higher. It’s no longer enough for software to be functionally adequate or for severe performance and security defects to be knowingly accepted into live solutions.

On the one hand, the threat landscape is more complex than ever, with new vulnerabilities and attack vectors cropping up daily. High-profile cyberattacks are commonplace in modern news cycles.

At the same time, customers expect lightning-fast performance. Anything less — a sluggish checkout page, or an app that crashes under load — and you risk losing more than just that user.

These days, ‘working’ must also include robust performance and rock-solid security. The funny thing is, businesses know this. Stakeholders absolutely know that security and performance are fundamental to success, yet they still cut corners and therefore don’t take their testing seriously.

Why Are Security and Performance Testing Still Regarded as Second-Class Citizens?

So why are security and performance often only tested at the very end of the development cycle, if at all?

I can think of a few reasons:

  • Misconceptions: Teams often think you can’t do performance or security testing before you have a finished product. In fact, there are lightweight, iterative approaches that identify problems early, saving costly rework and failures.  
  • Project Pressures: Fast deadlines, tight budgets, and pressure to deliver minimum viable products (MVPs) can lead teams to cut corners. Testing is often seen as a way to reduce time, and performance and security are prime candidates for the squeeze.
  • Underestimating Risk: If past releases didn’t have problems (or you didn’t detect them), there’s a false sense of security that it will be the same next time.
  • Lack of Expertise or Tooling: Many teams lack in-house specialists or the necessary tools to conduct meaningful tests early. Without champions to advocate for it, testing gets pushed back.

The more I think about it, the more I think it’s simply down to basic human nature. Functional issues must be addressed immediately, but performance and security concerns can often be put off until tomorrow.

In many organisations, functional testing has become part of the DevOps culture. It’s planned early, automated where possible, and viewed as a core part of the development process.

Meanwhile, performance and security testing are left lingering at the back of the queue, if at all. All too often, they’re squeezed into the last sprint or pushed until the week before go-live. After all, as long as a solution is functionally adequate, we can ship it and deal with any fall out.

Even When Testing Is Done, It’s Often Done Half-Heartedly

Sure, some teams run a basic load test or click a few checkboxes for compliance, but without time to analyse the results or act on them, these tests do little to improve the actual quality of the product.

To make matters worse, many test teams are being encouraged to move away from robust, enterprise-grade tooling to “free” or lower-cost alternatives. While budgets matter, the business often doesn’t realise these tools don’t deliver the same quality of insight, and the subsequent risk increase is all too real.

For example, I once worked with a company that replaced a proven enterprise performance testing tool (LoadRunner) with a cheaper solution. The migration required weeks of script rework, and ultimately, the tool was unable to simulate real-world traffic properly. The delays and post-launch firefighting quickly wiped out any savings.

Often, they are being encouraged to do this by external consultants. Have you ever wondered why? Two main reasons:

  • They are more interested in diverting your budget to their fees and away from tools
  • Most free or low-cost tools require more effort to achieve results, so more consultancy days sold

A win-win for them.

Will More Businesses Ever Take Performance and Security Testing Seriously?

Despite increasing media coverage and general awareness of the issues, many businesses are stuck in old habits. This begs the question: Will businesses ever take this seriously?

What needs to happen to wake people up to the consequences of short-term thinking?

Performance and security can’t just be checkboxes. We’ve all seen the consequences when they aren’t taken seriously. They must be integrated into development from the beginning — with the right mindsets, the right expertise, and serious, professional tools like LoadRunner Cloud, LoadRunner Professional and Fortify.

But do you think this will ever happen?

Stephen Davis
by Stephen Davis

Stephen Davis is the founder of Calleo Software, a OpenText (formerly Micro Focus) Gold Partner. His passion is to help test professionals improve the efficiency and effectiveness of software testing.

To view Stephen's LinkedIn profile and connect 

Stephen Davis LinkedIn profile

23rd July 2025
AI for Test Data

How to Implement AI for Test Data: 10 Considerations

Test data has always been one of the slowest, least glamorous parts of software testing. It is rarely strategic work, but it holds everything up. No matter how good your test plan is, weak data can make the whole exercise unreliable.

Choosing Performance

How to Choose a Performance Testing Tool

If you’re looking for a new performance tool or new to performance testing, it can be a tough subject to get your head around. I’ve been involved in the industry for 3 decades, and during that time, it has evolved massively. Increasingly, I talk to people at companies who’ve never

DevWeb is better than JMeter

5 Ways DevWeb Is Better Than JMeter

JMeter often becomes the default because it looks free. There is no license fee, and it appears flexible enough to do almost anything. But JMeter’s ease is often a myth. In reality, it is rarely the most sensible or low-cost choice.

Testing is Vital

Seriously Though, Five Reasons Testing is Vital

In the last main Testing Times edition (April fools day), I argued, quite ludicrously, that testing is a waste of time. That it slows releases, costs money, and ruins everyone’s fun. Judging by the comments, a few readers took it a bit too literally. So let’s be serious for a minute.

Aviator Testing AI

DevOps Aviator: AI Made For Testers

DevOps Aviator brings generative AI into software delivery to help test teams move sooner, reduce manual effort, and get answers faster. It is part of the broader Aviator suite: a set of AI capabilities embedded across OpenText products.

Testing is a waste of time

5 Reasons Testing is a Waste of Time

Let’s be honest, testing is what teams do when they don’t trust their developers. It’s a tax on speed, a relic from waterfall days, and a crutch for people afraid to ship. It just slows down releases, kills creativity, and wastes budget that could be better spent on another sprint.

OpenText Summit 2026

OpenText Summit: Why This Free Event Is Worth Your Time

You walk into a room where people are talking about the exact problems you wrestle with: tricky deployments, clunky processes, and how to test faster. Sometimes, the right conversation with the right person is enough to unlock a solution or a possibility you hadn’t even considered.

Python

Functional Testing 26.1: Adds Python, Cloud Testing, and more AI

With 26.1, OpenText is giving you something concrete: Python‑based automation, AI‑assisted verification, and cloud labs that fit into your existing CI/CD. This turns functional testing from a separate QA activity into a shared capability that developers, SDETs, and testers can all contribute to.

LoadRunner AI

LoadRunner 26.1: A New Direction in Performance Testing?

OpenText’s version 26.1 is a clear statement of where the Performance Engineering (LoadRunner) family is heading: AI-assisted, simplifying complex tasks and enabling your team to be more productive. This creates a very practical question: how do you buy and deploy these new capabilities in a way that actually moves the needle on risk, cost, and delivery speed?

Insights

Search

Related Articles

To get other software testing insights, like this, direct to you inbox join the Calleo mailing list.

You can, of course, unsubscribe 

at any time!

By signing up you consent to receiving regular emails from Calleo with updates, tips and ideas on software testing along with the occasional promotion for software testing products. You can, of course, unsubscribe at any time. Click here for the privacy policy.

Sign up to receive the latest, Software Testing Insights, news and to join the Calleo mailing list.

You can, of course, unsubscribe at any time!

By signing up you consent to receiving regular emails from Calleo with updates, tips and ideas on software testing along with the occasional promotion for software testing products. You can, of course, unsubscribe at any time. Click here for the privacy policy.