15 cloud WAAP security providers ranked
SecureIQLab, a provider of cloud security validation solutions, has shared the results of its 2025 Cloud Web Application Firewall and API Protection (WAAP) validation study.
SecureIQLab, known for its cloud cybersecurity validation, leveraged its proprietary SocX, an AI-powered validation platform, to validate cloud WAAP solutions against the OWASP Top:2023 critical security risks.
The validation study that was conducted from January through April 2025 attempted to evaluate over 15 leading enterprise-class cloud WAAP providers. The study focused on overall security efficacy use-cases targeted around 15 distinct attack vectors and 1,360 attack techniques. The results also exposed key operational gaps around efficiently deploying and managing these solutions, as highlighted in the 60 or more operational scenarios that were evaluated as a part of the study.
"Today's sophisticated cyberthreats require equally sophisticated defence mechanisms," said David Ellis, VP Corporate Relations & Research at SecureIQLab.
"Our validation methodology sets the standard for how organisations should evaluate their web security posture while leveraging the full capabilities of our SocX AI-powered platform around key OWASP top-10 security risks in today's rapidly evolving threat landscape."
Research highlights included:
- The advanced AI-Powered SocX Platform helped demonstrate a 40% increase in validation efficacy on OWASP Top 10 security risks.
- The average OWASP Top 10 security score was pegged at 89.5%, which was close to ~2% more than the last year.
- Only two of the 11 security vendors tested received SecureIQLab's badge of honour on Secure by Design and Secure by Default.
- The cloud WAAP security vendors had an average security efficacy score of 74.50% and an operational efficiency score of 86.9%.
- Overall OWASP API security scores were significantly lower, with the average being 55.0%.
"While securing enterprise cloud applications, what you don't validate today becomes tomorrow's vulnerability," explained Cameron Camp, Senior Security Researcher at SecureIQLab.
"Specifically, without comprehensive validation of cloud WAF API security against today's sophisticated threats, businesses risk not only data breaches but damage to customer trust and their bottom line."
Explore
Access SecureIQLab's 2025 Cloud WAAP CyberRisk Ripple at https://secureiqlab.wpcomstaging.com/publications/
Comments
Post a Comment