ETFOptimize | High-performance ETF-based Investment Strategies

Quantitative strategies, Wall Street-caliber research, and insightful market analysis since 1998.


ETFOptimize | HOME
Close Window

New Research Reveals Critical Gaps in Web App and API Security as Attack Complexity Grows

Despite widespread security adoption, organizations struggle to keep pace with rapid API expansion, multi-cloud challenges, and increasingly sophisticated cyberattacks, highlighting the pressing need for consolidated and automated defense solutions.

Fastly, Inc. (NYSE: FSLY), a leader in global edge cloud platforms, in partnership with Informa TechTarget’s Enterprise Strategy Group (ESG), released a new study today revealing significant challenges for cybersecurity professionals as they combat the rapidly evolving application security landscape. The report, “Balancing Requirements for Application Protection,” based on insights from 383 cybersecurity and IT professionals in North America, underscores the escalating difficulties in securing rapidly expanding web applications and APIs amid growing cyber threats.

With organizations increasingly dependent on applications and APIs to generate revenue, the digital landscape is expanding at an unprecedented rate. On average, the surveyed experts project a 39% increase in the number of web applications and websites within the next two years, rising from an average of 145 to 201 per organization. Furthermore, API usage is expected to surge, with the percentage of respondents anticipating that more than half of their applications will use APIs increasing from 32% to 80% in the same period. As a result, security teams are grappling with agile development cycles and the widespread adoption of cloud infrastructure, making it increasingly challenging to maintain robust defenses.

As application security becomes critical, the risks have also increased. According to the study, 57% of midmarket and enterprise organizations have experienced web application and/or API attacks exploiting lesser-known vulnerabilities in the last 24 months.

Despite 92% of organizations implementing at least one web application firewall (WAF), 67% rely on multiple WAFs from different vendors. This fragmentation is largely due to multi-cloud complexities and feature-specific requirements, signaling a critical need for consolidated, next-generation security solutions capable of covering diverse environments, from cloud to on-premises and hybrid infrastructures.

"The rapid growth of APIs has fundamentally changed application environments and introduced significant security and governance challenges, from misconfigurations to API injection and volumetric DDoS attacks. Yet as organizations have layered multiple WAFs and bot management tools to address these risks, complexity has grown," said John Grady, principal analyst at TechTarget’s Enterprise Strategy Group. "We’ve reached a tipping point where adding different security tools provides diminishing returns. Cybersecurity and IT teams should be looking at ways to simplify operations and improve security by consolidating solutions that offer both automation and specialized protection from a wide range of threats."

The research also highlights a troubling trend: 45% of organizations that experienced a DDoS attack reported it as part of a diversion tactic in a larger, more coordinated assault. Shockingly, 70% of these diversions succeeded, resulting in significant operational disruptions and data loss. As attackers continue to innovate, organizations are increasingly turning toward automated solutions to counter these evolving threats. However, concerns remain—59% of IT professionals believe that cyber adversaries have the upper hand in leveraging AI for attacks.

"Speed is critical in application security, and automated attacks demand equally fast automated defenses to ensure privacy and security regulations are met and user information is protected," said Fernando Medrano, Deputy Chief Information Security Officer at Fastly. "As web applications and APIs continue to grow in prominence, organizations need to consider integrating security into the product development process early on rather than treat it as an afterthought."

To access the full report and explore how businesses are consolidating tools and shifting spending in response to high-profile cybersecurity incidents, click here. For additional insights from Fastly about the report findings and strategies for strengthening security, visit our blog.

About the Research

ESG surveyed 383 cybersecurity and IT professionals involved in securing their organizations' web applications in both midmarket and enterprise organizations across the United States and Canada. The interviews were conducted via an online survey between Nov. 1 and Nov. 14, 2024.

About Fastly, Inc.

Fastly’s powerful and programmable edge cloud platform helps the world’s top brands deliver online experiences that are fast, safe, and engaging through edge compute, delivery, security, and observability offerings that improve site performance, enhance security, and empower innovation at global scale. Compared to other providers, Fastly’s powerful, high-performance, and modern platform architecture empowers developers to deliver secure websites and apps with rapid time-to-market and demonstrated, industry-leading cost savings. Organizations around the world trust Fastly to help them upgrade the internet experience, including Reddit, Neiman Marcus, Universal Music Group, and SeatGeek. Learn more about Fastly at https://www.fastly.com, and follow us @fastly.

Source: Fastly, Inc.

"Cybersecurity and IT teams should be looking at ways to simplify operations and improve security by consolidating solutions that offer both automation and specialized protection from a wide range of threats."

Contacts

Recent Quotes

View More
Symbol Price Change (%)
AMZN  254.00
+9.78 (4.00%)
AAPL  269.05
-1.32 (-0.49%)
AMD  259.65
+3.53 (1.38%)
BAC  53.56
+0.11 (0.21%)
GOOG  284.12
+2.30 (0.82%)
META  637.71
-10.64 (-1.64%)
MSFT  517.03
-0.78 (-0.15%)
NVDA  206.88
+4.39 (2.17%)
ORCL  257.85
-4.76 (-1.81%)
TSLA  468.37
+11.81 (2.59%)
Stock Quote API & Stock News API supplied by www.cloudquote.io
Quotes delayed at least 20 minutes.
By accessing this page, you agree to the Privacy Policy and Terms Of Service.


 

IntelligentValue Home
Close Window

DISCLAIMER

All content herein is issued solely for informational purposes and is not to be construed as an offer to sell or the solicitation of an offer to buy, nor should it be interpreted as a recommendation to buy, hold or sell (short or otherwise) any security.  All opinions, analyses, and information included herein are based on sources believed to be reliable, but no representation or warranty of any kind, expressed or implied, is made including but not limited to any representation or warranty concerning accuracy, completeness, correctness, timeliness or appropriateness. We undertake no obligation to update such opinions, analysis or information. You should independently verify all information contained on this website. Some information is based on analysis of past performance or hypothetical performance results, which have inherent limitations. We make no representation that any particular equity or strategy will or is likely to achieve profits or losses similar to those shown. Shareholders, employees, writers, contractors, and affiliates associated with ETFOptimize.com may have ownership positions in the securities that are mentioned. If you are not sure if ETFs, algorithmic investing, or a particular investment is right for you, you are urged to consult with a Registered Investment Advisor (RIA). Neither this website nor anyone associated with producing its content are Registered Investment Advisors, and no attempt is made herein to substitute for personalized, professional investment advice. Neither ETFOptimize.com, Global Alpha Investments, Inc., nor its employees, service providers, associates, or affiliates are responsible for any investment losses you may incur as a result of using the information provided herein. Remember that past investment returns may not be indicative of future returns.

Copyright © 1998-2017 ETFOptimize.com, a publication of Optimized Investments, Inc. All rights reserved.