2026 Cyber survey – on AI, API, and application security

Image for Radware's 2026 cyber survey

Osterman Research announces the availability of a new white paper – 2026 Cyber Survey: New Trends in AI, API and Application Security. Radware commissioned this white paper – it’s the fourth year we’ve worked with the Radware team on this research. Please get your copy from Radware’s website.

The report focuses on AI, API, and application security, and notes the increasing threats of autonomous frontier AI models, low visibility at organizations into threats across multiple security domains, and low readiness by security operations to manage application security incidents, among others. 

The key findings from this research are:

  • Organizations are deploying AI faster than they can protect it. 83% of organizations are making widespread use of GenAI or LLM functionality, and 96% expect to implement AI agents or autonomous workflows within 12 months. Yet only 17% have full visibility into AI agents or AI-driven processes.
  • AI traffic is creating a new access-control challenge. Only 14% of organizations have full visibility into AI crawler traffic, while 76% have experienced a negative impact from AI crawler traffic or AI agents.
  • Application development continues to outpace API security. Nearly half (48%) of organizations update APIs for production use daily or more frequently. Yet only 19% have a fully automated and continuously updated API inventory, and just 24% conduct comprehensive API security testing across the full lifecycle.
  • The business impact of application attacks continues to grow. 71% of organizations experience application-layer or API-targeted DDoS attacks monthly or more often. The average cost of downtime from an application-layer DDoS attack increased 23% year over year to $7,530 per minute, or approximately $451,800 per hour.
  • Security operations are not moving fast enough. Only 21% of organizations report the highest level of readiness to manage application security incidents, while the average resolution time for significant API, bot or DDoS-related incidents is 2.8 hours.

The report is 16 pages. Please get your copy from the Radware website

Webinar is next week

I will be presenting the research findings in conjunction with Radware’s Dan Schnour on July 30. Please register to attend.

Discover more from Osterman Research

Subscribe now to keep reading and get access to the full archive.

Continue reading