83% of organizations widely use GenAI or LLMs, while only 17% have full
visibility into AI agents and AI-driven processes
Radware® (NASDAQ: RDWR), a global leader in AI and application
security and delivery solutions for multi-cloud environments, today released
its
2026 Cyber Survey: New Trends in AI, API and Application Security. Based on a global survey conducted by Osterman Research on behalf of
Radware, the survey found that organizations are adopting AI faster than they
are implementing the security controls needed to protect their environments.
Security professionals are accustomed to security models aligned with
traditional layers of the technology environment, including the network,
application and data layers. The emerging AI layer presents a new set of
challenges. As enterprises expand their use of generative AI, large language
models (LLMs), AI agents and autonomous workflows, the survey indicates that
threat actors are using AI to discover vulnerabilities, evade defenses and
accelerate attacks. The survey found many organizations lack the visibility
and governance needed to effectively secure AI, applications and APIs.
"The emerging AI layer presents a new set of security challenges that may not
be addressed with isolated point solutions," said Connie Stack, chief growth
officer, Radware. "Organizations need visibility across AI, applications and
APIs to identify and respond to emerging threats faster."
Among the survey's key findings:
-
Organizations are deploying AI faster than they can protect it. 83% of
organizations are making widespread use of GenAI or LLM functionality, and
96% expect to implement AI agents or autonomous workflows within 12 months.
Yet only 17% have full visibility into AI agents or AI-driven processes.
-
AI traffic is creating a new access-control challenge. Only 14% of
organizations have full visibility into AI crawler traffic, while 76% have
experienced a negative impact from AI crawler traffic or AI agents.
-
Application development continues to outpace API security. Nearly half (48%)
of organizations update APIs for production use daily or more frequently.
Yet only 19% have a fully automated and continuously updated API inventory,
and just 24% conduct comprehensive API security testing across the full
lifecycle.
-
The business impact of application attacks continues to grow. 71% of
organizations experience application-layer or API-targeted DDoS attacks
monthly or more often. The average cost of downtime from an
application-layer DDoS attack increased 23% year over year to $7,530 per
minute, or approximately $451,800 per hour.
-
Security operations are not moving fast enough. Only 21% of organizations
report the highest level of readiness to manage application security
incidents, while the average resolution time for significant API, bot or
DDoS-related incidents is 2.8 hours.
The survey’s findings underscore the growing need for organizations to
strengthen visibility, governance and coordinated security across AI,
applications and APIs as they prepare for increasingly sophisticated AI-driven
threats.
The 2026 Cyber Survey: New Trends in AI, API and Application Security is based
on research conducted by Osterman Research among 377 organizations worldwide.
Download the survey here.
Webinar
Radware will also host a webinar on July 30 at 11:00 AM EDT, highlighting the
survey's key findings, emerging trends and recommendations for strengthening
AI, application and API security.
Register for the webinar
here.
About Radware
Radware® (NASDAQ: RDWR) is a global leader in application security and
delivery solutions for multi-cloud environments. The company’s cloud
application, infrastructure, API, and AI security solutions use AI-driven
algorithms for precise, behavior-based, real-time protection against
sophisticated web, application, and DDoS attacks, API abuse, business logic
threats, and malicious bots. Radware delivers end-to-end API security,
including discovery, posture management, testing, and runtime protection,
along with advanced protection for AI agents and models. Enterprises and
carriers worldwide rely on Radware to address evolving cyberthreats, protect
their brands and business operations, and reduce costs. For more information,
please visit the Radware website.
Radware encourages you to join our community and follow us on:
Facebook,
LinkedIn,
Radware Blog,
X, and
YouTube.
©2026 Radware Ltd. All rights reserved. Any Radware products and solutions
mentioned in this press release are protected by trademarks, patents, and
pending patent applications of Radware in the U.S. and other countries. For
more details, please see:
https://www.radware.com/LegalNotice/. All other trademarks and names are property of their respective owners.
Radware believes the information in this document is accurate in all material
respects as of its publication date. However, the information is provided
without any express, statutory, or implied warranties and is subject to change
without notice.
The contents of any website or hyperlinks mentioned in this press release are
for informational purposes and the contents thereof are not part of this press
release.
Safe Harbor Statement
This press release contains “forward-looking statements” within the
meaning of the Private Securities Litigation Reform Act of 1995 and other
U.S. securities laws. Any forward-looking statements made herein that are
not statements of historical fact, including statements about Radware’s
plans, objectives, expectations, beliefs, projections, future financial
performance, business strategies, market opportunities, and developments
in our industry, are forward-looking statements. In some cases,
forward-looking statements can be identified by words such as “believe,”
“expect,” “anticipate,” “intend,” “estimate,” “plan,” “project,”
“forecast,” “target,” and similar expressions, as well as future or
conditional verbs such as “will,” “should,” “would,” “may,” and “could.”
For example, when we say in this press release that the new Cloud Web DDoS
Protection for DefensePro X enables organizations to improve detection of
sophisticated application-layer DDoS attacks using AI-powered cloud
algorithms while keeping traffic inspection and TLS private keys on
premises, we are using forward-looking statements.
Because such statements deal with future events, they are subject to
various risks and uncertainties that could cause actual results to differ
materially from those expressed or implied in such forward-looking
statements. Factors that could cause or contribute to such differences
include, but are not limited to: the impact of global market and economic
conditions; our dependence on independent distributors; disruptions in our
supply chain, including shortages of components or manufacturing capacity;
our reliance on a limited number of vendors; our ability to attract, train
and retain qualified personnel; intense competition in the cybersecurity
and application delivery markets; our ability to develop new solutions and
enhance existing solutions; risks related to defects, vulnerabilities or
failures in our products or services, including cybersecurity incidents
affecting our systems or those of our customers; risks associated with the
use of artificial intelligence technologies, including evolving regulatory
frameworks, litigation exposure and reputational considerations; risks
related to our information technology systems, including failures,
disruptions or security breaches; outages, interruptions, or delays in
hosting or cloud-based services; risks related to the interoperability of
our products; risks associated with our global operations; and
geopolitical risks, including instability in the Middle East and
Israel.
These factors are not exhaustive. For a more detailed description of the
risks and uncertainties affecting Radware, please refer to Radware’s
Annual Report on Form 20-F and other reports filed with or furnished to
the Securities and Exchange Commission (SEC) from time to time.
Forward-looking statements speak only as of the date on which they are
made, and, except as required by applicable law, Radware undertakes no
obligation to update or revise any forward-looking statements to reflect
events or circumstances after the date of such statements. Radware’s
public filings are available from the SEC’s website at
www.sec.gov or on
Radware’s website at www.radware.com.