SecureIQLab finds cloud WAAP tools strong on legacy attacks but uneven on APIs
SecureIQLab’s latest Cloud WAAP validation shows 12 vendors have nearly closed the gap on long-tested web attacks, but many still struggle with newer API and AI surfaces. The report matters because enterprises are adding those surfaces fastest, while false positives and compliance results remain highly uneven.
Why it matters: - Cloud WAAP products are converging on mature threats, but security gaps remain on the newer attack surfaces enterprises are deploying most quickly. - The report shows a nearly 10-point split between web security and API security, underscoring where protection is strongest and where risk is still rising. - False positives and compliance vary widely, which can translate into more alert noise, blocked legitimate traffic, and uneven governance coverage.
What happened: - SecureIQLab published the Cloud WAAP v5.0 CyberRisk Validation Comparative Report covering 12 cloud Web Application and API Protection solutions. - The group average Complete Security Score reached 86.80 percent, up about 12.3 percentage points from the v4.0 validation group average. - The comparison reflects broader market progress, not a like-for-like retest of the same products, because the vendor cohorts changed between evaluations. - The report measured each product against the same evidence base: 1,608 attack payloads and 1,487 benign requests under controlled lab conditions. - The methodology maps outcomes to MITRE ATT&CK, OWASP Top 10 (2025), OWASP API Security Top 10 (2023), OWASP LLM Top 10, and AMTSO. - The report says it is the first WAAP methodology to include large language model security testing and the first to use AI-enhanced attack payloads against AI-defended products. - The validation is AMTSO-compliant under Testing Protocol Standard v1.3, AMTSO Test ID AMTSO-LS1-TP169. - SecureIQLab also named 12 vendors in the report and placed all solutions into four ranking tiers: Leader, Contender, Visionary, or Upcomer.
The details: - OWASP Web Application Security averaged 89.96 percent across the group. - OWASP API Security averaged 80.3 percent, leaving a close-to-10-point gap versus web security. - SecureIQLab says Compliance and OWASP API Security showed the greatest variability across the 12 solutions. - Security Efficacy covered seven tested areas: OWASP Web Application Security, OWASP API Security, Bot Attacks, AI-Assisted Bot Attacks, Layer 7 DoS and DDoS Attacks, Security Resiliency, and WAAP Vulnerability Assessment. - The report used six validation pillars: Security Efficacy, Operational Efficiency, AI Application Security & Operational Efficiency, Secure-by-Design & Secure-by-Default, False Positive Avoidance, and Compliance. - On legacy attack surfaces, the group scored 97.9 percent on Layer 7 DoS attacks, with 11 of 12 products at 100 percent. - WAAP Vulnerability Assessment averaged 99.7 percent. - Authentication-failure detection under OWASP Top 10 (2025) averaged 99.5 percent. - On newer API surfaces, six of the 12 products scored zero on WebSocket API protection. - That WebSocket result included products that did not support the protocol and products that supported it but did not defend it. - API privilege escalation, including Broken Object Level Authorization, split the field: six products scored 100 percent, four scored zero, and the category average was 58.3 percent. - Prompt Injection defense scores ranged from 100 percent to 35 percent, with nine products at 100 percent. - Improper Output Handling averaged 99.4 percent. - Under AI-assisted bot attacks, most of the field scored 100 percent, while two products that scored perfectly against traditional bot attacks fell short against the AI-assisted version. - The OWASP LLM security results are scored separately and are not included in the Complete Security Score or the overall Operational Efficiency score. - Gen AI and LLM Operational Efficiency results ranged from 100 percent to zero. - In the false-positive test, each product received 1,452 benign requests, with 35 LLM benign cases scored separately. - Four of the 12 products produced zero false positives. - The group median was 9 false positives. - The highest false-positive count was 275, equal to an 18.9 percent false-positive rate on the identical benign traffic. - Compliance scores ranged from 47.8 percent to 87.0 percent and averaged 63.95 percent. - Six of the 12 solutions scored above the Compliance average. - Operational Efficiency averaged 94.1 percent across nine evaluated categories, and 10 of the 12 products scored above 90 percent. - Support and Documentation and Visibility and Analytics each scored above 90 percent for every solution. - Ease of Deployment ranged from 66.7 percent to 100 percent. - Ease of Management ranged from 72.7 percent to 100 percent. - Secure by Design requires scores of at least 85 percent on Secure by Design criteria plus a perfect 100 percent on the WAAP Vulnerability Assessment. - Secure by Default uses the same thresholds, applied to the first two principles and 13 criteria. - Five of the 12 products earned both badges. - The report says it publishes each product’s overall Security Efficacy and Operational Efficiency scores, CyberRisk Ripple tier, Operational Efficiency category results, Matthews correlation coefficient, precision and recall, category-level group averages, score ranges, false-positive avoidance rates, and Compliance results. - The full report is available as the full Cloud WAAP v5.0 CyberRisk Validation Comparative Report.
Between the lines: - The strongest results cluster around attack classes the industry has tested for years, which suggests the market has learned how to block familiar threats. - The weaker results cluster around APIs, WebSockets, and AI-related surfaces, which are newer, more complex, and closer to where application teams are adding functionality. - SecureIQLab’s separation of AI security results from the main score means a product can look strong overall while still showing major gaps in emerging AI-specific defenses. - The wide false-positive spread suggests that product effectiveness alone is not enough; operational burden can differ sharply from one platform to another. - The compliance spread shows that audit, logging, and governance maturity still trails pure detection performance.
What's next: - SecureIQLab says individual vendor reports will publish detail below the group-level data. - Security teams are expected to inventory whether WebSocket APIs, API authorization logic, and LLM integrations exist in their environments, then test deployed protections against those specific surfaces. - Enterprises will likely use the report to compare measured protection, operational load, and compliance coverage rather than rely on datasheet claims.
The bottom line: - Cloud WAAP protection is nearing the ceiling on legacy web attacks, but the next wave of risk is still open on APIs, WebSockets, and AI-driven traffic.
Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.
Sign up for:
Earth Matters Journal
The daily local news briefing you can trust. Every day. Subscribe now.
Check Your Email!
We sent a one-time activation link to: .
Confirm it's you by clicking the email link.
If the email is not in your inbox, check spam or try again.
Welcome back!
is already signed up. Check your inbox for updates.