Radware’s 2025 Cyber Survey: Application Security at a Breaking Point provides a sobering snapshot of the way that organizations are falling behind in the AI cyber-race.
According to the report, the use of AI to improve and intensify hacking tradecraft is the top cyber concern for organizations:
- 70% of respondents are concerned that AI is being used to create and improve hacking tools.
- 67% fear that AI is being used to generate a larger volume of cyber attacks.
- 66% believe that AI will help attackers launch new zero-day attack vectors.
Despite these concerns, only 8% of organizations are currently using AI-based solutions for defences. Four out of five organizations are planning to implement AI-based cyber security solutions within the next 12 months, but in reality, that is too slow. The threat is here and real, and the gap between attackers and defenders is becoming an increasing chasm.
Another area highlighted by the report is web applications and APIs. Organizations are increasing their use of APIs even while they remain ill-protected:
- In 2025, API usage is up 42% compared to the highest rate of usage in 2023, with multiple daily updates to APIs surging six-fold during the same time frame.
- Widespread third-party usage: on average, organizations are using 19 third-party APIs per application, which introduces new types of threats around data compromise that cannot be mitigated at a coding level.
- Poor business logic attack mitigation: business logic attacks, a common form of API attacks, represent a threat area of rapidly growing concern. While 81% of respondents say it is very or extremely important to have real-time protection measures in place:
- Just half have deployed runtime business logic protections.
- Only 29% have security staff fully trained to detect and mitigate these attacks.
- Lack of preparedness:
- On average, only 6% of respondents have full documentation for all their APIs.
- Half of respondents don’t know what third-party code is being used by their web applications, which data is being leaked to third-party services, or when malicious scripts and services are introduced.
“The weaponization of AI by malicious actors is intensifying cyber security threats and drawing even more attention to areas where companies are simply ill-protected,” said Shira Sagiv, Radware’s vice president of product portfolio. “Internal alarms should be sounding. Companies openly admit to major concerns about gaps in cyber protection and lack of readiness, especially around web applications and APIs, yet their usage continues to climb creating even more risk and exposure.”
Resilience issues rise
Survey respondents expressed a lack of confidence in the effectiveness of their defensive posture against growing threats.
- Third-party breaches: only 16% of respondents are confident in their current protection against data breach attempts through third-party services code running on their web applications.
- Costly DDoS disruptions: downtime caused by an application DDoS attack averages $6,100 per minute, or $366,000 per hour.
- High compliance pressures: an average of 54% of respondents express high or extreme concern about compliance with a range of regulations, including NIS2, HIPAA, SEC, PCI DSS 4, GDPR, DORA, and SOX.
Methodology
The survey, which was conducted with Osterman Research, includes responses from compliance, chief risk, and data privacy officers; vice presidents of research and development; senior network security administrators; senior DevOps and DevSecOps administrators; cloud security specialists; and API architects, among other titles. The survey was conducted in nine countries across North America, EMEA, APAC, and LATAM.






