Fortinet’s 2025 Web Application Security Report shows that organizations are struggling with visibility, API security, and cloud misconfigurations while facing rising breaches, bot activity, and AI-driven attacks. The report highlights a shift toward AI, automation, and tool consolidation as companies try to close security gaps and improve readiness across hybrid and multi-cloud environments. #Fortinet #Optus #MGMResorts #Snowflake #LeviStrauss #MOVEit #Cloudflare #Google #Mirai
Keypoints
- Annual web application security reports typically begin with an executive summary and introduction that explain why web apps are high-value targets, then present survey methodology, respondent demographics, and a concise list of headline findings.
- They usually follow with thematic sections covering confidence in security posture, top concerns, cloud and API challenges, breach frequency, attack vectors, detection tools, AI adoption, budget trends, and future investment priorities.
- This report is based on a survey of 651 IT and cybersecurity professionals across industries such as technology, financial services, healthcare, government, and manufacturing, providing a broad view of current application security maturity.
- Only 42% of respondents are confident in their application security posture, while 58% are not, and confidence has declined from 53% the year before, suggesting growing concern and persistent security gaps.
- Data protection is now the top concern for 63% of respondents, up sharply from 43% last year, showing that breach risk and regulatory pressure are pushing data security to the forefront.
- Cloud application security concerns rose to 54%, while threat and breach detection remained critical at 50%, reflecting the continued move toward cloud-native architectures and the need for faster detection.
- Misconfigurations in cloud infrastructure were the biggest cloud security challenge at 63%, followed by limited visibility into workloads at 60% and API security at 58%, reinforcing that cloud complexity and poor observability remain major weaknesses.
- Compliance complexity affected 51% of respondents and lack of staff expertise affected 45%, showing that operational and human constraints still slow effective security management.
- 56% of organizations experienced an application breach or compromise in the last 12 months, up from 50% previously, and 21% were unsure whether they had been breached, indicating detection and visibility problems.
- Among attack vectors, malware injection led at 34%, stolen credentials rose to 30%, software vulnerability exploits reached 29%, and application misconfiguration exploits stayed high at 26%, underscoring the continued impact of credential abuse and poor hardening.
- DDoS attacks accounted for 19% of reported attack types but became the top bot-related concern at 49%, showing that disruption is increasingly seen as a major operational risk.
- API visibility remains weak: only 14% are very confident they know all applications and APIs in use, while 57% express uncertainty, highlighting shadow IT and undocumented endpoints as ongoing exposure points.
- Preparedness against human-like bots is low, with 62% lacking confidence, which aligns with growing concerns about credential stuffing, scraping, and other automated abuse that mimics legitimate users.
- AI-driven attacks are another major worry: 66% lack confidence in defending against them, and the report notes that attackers are using AI for convincing phishing, deepfakes, and faster exploit creation.
- Organizations are responding with layered detection: 71% use vulnerability scanners, 67% use real-time monitoring, 60% use threat intelligence feeds, and 58% use penetration testing.
- AI is already being used defensively by 61% for threat detection and response, 57% for anomaly detection, 50% for behavioral analysis, and 42% for automated remediation, showing strong momentum toward machine-assisted security operations.
- Tool sprawl is a recurring theme: 43% plan to consolidate application security tools in 2025, aiming to reduce complexity, improve integration, and eliminate redundant controls.
- When choosing tools, ease of use ranks first, followed by pricing/licensing, comprehensiveness, accuracy, scalability, and integration, indicating that teams want practical solutions that are effective but not overly complex.
- Budget outlook is positive, with 58% planning to increase application security spending over the next 12 months, while only 7% expect cuts, signaling that application risk is becoming a higher investment priority.
- Top investment areas are security automation at 50%, staff training at 47%, AI-driven security solutions at 45%, threat intelligence at 40%, and compliance management at 37%, reflecting a balanced focus on technology, process, and people.
- The report’s main takeaway is that modern web application security depends on better visibility, stronger API protection, bot mitigation, AI-assisted detection, and simplified security operations across hybrid and multi-cloud environments.
Source: Awesome Annual Security Reports - The reports in this collection are limited to content which does not require a paid subscription, membership, or service contract. (https://github.com/jacobdjwilson/awesome-annual-security-reports/)