Application Security Is Falling Behind: What Radware’s New Report Reveals


Radware’s latest research, conducted with Osterman Research, paints a sobering picture of the current state of application security. The 2025 Cyber Survey shows that while organizations are accelerating digital innovation, their defenses are falling behind, especially when it comes to AI threats, API vulnerabilities, and business logic risks.

One of the most concerning findings is the growing gap between the threat of AI and how prepared organizations are. While 70% of respondents are highly concerned about hackers using AI to enhance attack tools, create larger attack volumes, and launch zero-day exploits, only 8% are currently using AI-based security solutions. That is despite the fact that 81% plan to adopt such tools within the next year.

API ecosystems are also expanding rapidly. API usage is up 42% from 2023, with more than 12% of organizations updating APIs multiple times per day. Yet only 6% have full documentation for all their APIs, and nearly half of respondents admit they do not know what third-party code is running in their applications. This lack of visibility creates a serious risk of exposure to data leakage, unauthorized access, and hidden backdoors.

Business logic attacks are becoming a top concern. These attacks exploit the intended behavior of applications to perform malicious actions like stealing data or abusing discounts. While 81% of respondents agree that real-time protection is essential, only 51% have runtime logic defenses in place. Even more concerning, just 29% of security teams are fully trained to recognize and stop these types of threats.

The use of third-party APIs is nearly universal, with 99% of organizations embedding them into applications. On average, 19 third-party APIs are used per app, up from 16 in 2023. However, only 16% of respondents feel confident in their ability to prevent data breaches tied to these services. Meanwhile, 65% are very concerned about payment data theft and supply chain exploits.

In addition to growing attack sophistication, the cost of downtime is rising fast. A successful application DDoS attack now costs an average of $6,106 per minute. For industries like financial services and healthcare, these disruptions can translate into major revenue losses, brand damage, and even life-threatening consequences.

This report is a wake-up call. Cyber attackers are moving faster and getting smarter, using AI to scale and diversify their methods. Organizations must invest in greater visibility, real-time protection, and staff training to stay ahead. Otherwise, they risk exposing their data, customers, and brand to growing levels of harm.

Analyst Report

Read the full report here

Read Report

Dan Schnour

Dan Schnour

At Radware, Dan leads various product marketing initiatives for cloud application protection services, DDoS protection solutions, and application delivery products. He brings a wealth of experience in product management and marketing from industry leaders such as Meta and Cisco Systems, where he focused on networking and identity security products. With an MBA from Cornell University and a B.Sc. in Electrical Engineering from the Technion, along with his industry experience, Dan is uniquely equipped to translate complex technical concepts into compelling marketing strategies and impactful business plans.

Related Articles

Account Takeover: What do we need to know to prevent these attacks? Application Protection Account Takeover: What do we need to know to prevent these attacks? In the evolving digital landscape, user account security has always been of critical concern for businesses and end users. Account Takeover (ATO) attacks have started to become extremely prevalent these days and these attacks end up costing companies millions of dollars and end up severely damaging customer trust. In this blog, we will explore what Account Takeover Attack is, what are the different categories into which we can demarcate this, what are the implications for businesses, and how a strategic approach to bot management can safeguard user accounts. We will also cover how Radware Bot Manager solution takes a holistic approach towards proactive detection and mitigation of Account Takeover attacks. Karthik Raju |October 16, 2024

Contact Radware Sales

Our experts will answer your questions, assess your needs, and help you understand which products are best for your business.

Already a Customer?

We’re ready to help, whether you need support, additional services, or answers to your questions about our products and solutions.

Locations
Get Answers Now from KnowledgeBase
Get Free Online Product Training
Engage with Radware Technical Support
Join the Radware Customer Program

Get Social

Connect with experts and join the conversation about Radware technologies.

Blog
Security Research Center
CyberPedia