Risks in software projects

Detection and Mitigation of Risks in Software Projects

The main question for every team involved in digital product development is how we can prevent the risk of finding defects in a production environment, or in other words, how we can detect potential defects before they take effect
See the 4 workstreams
Trusted by
Risk assessment
Risk assessment of a software project
10X Cost of a defect in production
No sensitive data exposed
10X in production
Cost of a defect

Compared to the cost of finding it during the analysis phase.

99%
Security incidents

As a root cause of risk in software projects.

80%
Analysis

Analysis concentrates a large share of the risk detected.

6%
Sensitive data

Exposure of credentials and sensitive data in code.

Fewer defects translate into shorter delivery times and savings in resources. A defect in production carries an exponentially higher cost.

Methodology

Risk reduction for software projects

Four workstreams that address the origin of risk: the product concept, the requirements, code security and project execution.

01
Concept and strategy

Digital product definition

Finding the competitive values and the integral value concept. The most efficient route is to start with concept and strategy before technology.

Competitive values Integral value concept Strategy before technology
01
Digital product definition
Concept before technology
02
Technical analysis

Requirements gathering and analysis

Ehecatl methodology for technical analysis: requirements are gathered, analyzed and documented under a formal process.

Ehecatl methodology Technical analysis Formal process
02
Requirements gathering and analysis
Ehecatl methodology
03
Security

Assessment of security flaws or credentials exposed in code

We identify vulnerabilities and poor security practices that could compromise the application, including credentials, access keys, tokens and other sensitive data exposed in the code.

Security flaws Credentials in code Preventing sensitive data exposure
03
Assessment of security flaws and credentials in code
Sensitive data protected
04
Comprehensive assessment

Digital project assessment

We analyze the key elements that influence the quality, continuity and reliability of a digital project: architecture, partners and vendors, team training and quality testing. We identify potential risks and areas for improvement before they impact operations.

Architecture Partners Vendors Training Quality testing
04
Digital project assessment
Architecture and vendors
INFORMATION

Cost of defects in code

10X in production

The cost of a defect found in production is 10X the cost of finding it during the analysis phase. Every phase that goes by without detecting it multiplies the effort, the rework and the impact on operations.

Relative cost of a defect by phase
Init → Analysis → Design → Development → Testing → Production
Exponential growth
Cost of defects in code by project phase Early detection Late detection 12 10 8 6 4 2 0 1X 10X Init Analysis Design Development Testing Production
A defect in production carries an exponentially higher cost.

We anticipate risks and prevent failures before they affect your operations.

Consulting

Consulting to improve and assess software quality

Three questions frame the conversation with your team and define the real value of a quality assessment.

What is the real benefit?

A clearer understanding of the expected benefit allows us to align better with expectations.

It is possible to shorten delivery times

Fewer defects translate into shorter delivery times and savings in resources. A defect in production carries an exponentially higher cost.

The main question for every team involved in digital product development is how we can prevent the risk of finding defects in a production environment, or in other words, how we can detect potential defects before they take effect.

Improving service quality

Improving our awareness of the unknown allows us to improve service quality.

Statistics

Main root causes of defects in code

Findings from private research conducted by Servicios de Software Ehecatl.

1
No formal process to gather or define software requirements
2
Technical / logic errors
3
Platform variability
4
Undefined or low-quality validation process
5
Poor level of communication among "stakeholders" or low motivation
Risks in software projects
99%
Security incidents
80%
Analysis
6%
Sensitive data
39%
Unclear or changing requirements
75%
Unrealistic estimates
29%
Lack of resources or skills
50%
Scope creep
35%
Low user involvement/adoption
Exposed sensitive data

According to the State of Secrets Sprawl 2025 (GitGuardian) report

23.8 M New secrets
23.8 million new secrets were exposed in public GitHub repositories in 2024 alone.
+39 M Leaked secrets
More than 39 million leaked secrets were detected on GitHub during 2024.
≈6.4 % Leak rate
Repositories using GitHub Copilot show a ≈6.4% secret leak rate.
Source: State of Secrets Sprawl 2025 — GitGuardian Preventing sensitive data exposure
Exposed
Document with exposed credentials and sensitive data
Next step: risk assessment

How much risk does your software project carry?

Let us assess your project to identify risks across product definition, requirements, architecture, security and execution, and turn them into concrete decisions that let you build more secure and reliable software.

Talk to our team and find out which risks you can prevent today.

Clients who trust Ehecatl

Organizations across industry, healthcare, tourism, manufacturing and services that have built their digital capability with us.