The biggest cybersecurity issues that businesses face, from false positives to outages

According to Fastly’s report, UK businesses spend over £356,406 a year on web applications and API security tools, but nearly half of all security alerts are still false positives.

Fastly, a global edge cloud platform provider has released new research that uncovers a crucial need for a unified, modern and simplified approach to security. Based on insights from information security and IT professionals from 250 UK companies and 500 global companies, the research revealed growing concerns around adequately securing the rapidly rising number of mission-critical cloud services and API-centric applications that enterprise businesses are relying on. Outdated offerings, false positives, and ineffective blocking are among the main causes driving this global concern.

The research highlighted that, on average, UK businesses use 11 web applications and API security tools and spend close to £356,000 on them but that 40% of all security alerts are still false positives. In addition, security is becoming more complex and costly for organisations as they are increasingly required to protect traditional architectures, in addition to new architectures and cloud environments.

1 in 4 (23%) UK businesses have suffered a loss of revenue in the past 12 months as a result (at least in part) of false positives from web applications and API security tools, with an average revenue loss of 12%. Due to these false positives, the downtime frequently causes similar vulnerability to actual attacks, which suggests that current security tools may be causing more problems than they solve. 

The research demonstrated that more than half of organisations believe most, if not all, of their applications will use APIs in the next two years.

Despite an anticipated increase in API implementation, half of the organisations stated that web application and API security are more difficult than two years ago and indicated struggles to maintain adequate security across new application architectures. Driving these difficulties is the shift to public cloud and API-centric applications without a modern security solution to support those innovations.

Perhaps most strikingly of all, 47% of UK businesses run tools in log or monitoring mode and only switch to blocking mode when they are confident detections are accurate due to the occurrence of false positives. The global report also shows that businesses are running their web application and API security tools in blocking mode a mere 9% of the time. As a result, current tools frequently block harmless traffic, impeding business and impacting their bottom line.

“One of the biggest security challenges we are seeing today is that technologies are rapidly evolving to better serve the growing demand for digital experiences, but the security offerings that protect those technologies are not experiencing that same level of transformation — and often erode the benefits of modern technology stacks,” said Kelly Shortridge, Senior Principal Technologist at Fastly.

“Security tools should fuel innovation, actively support service resilience, and minimise disruption to software delivery workflows, rather than slowing build cycles and producing disjointed, unactionable, or irrelevant data.”

“The responsibility for protecting enterprise assets, data, and users from cyber threats no longer falls solely on the security organisation, even as the threat landscape becomes increasingly complex. Application security in particular, is a team sport that requires input and cross-functional collaboration across many parts of an organisation,” said John Grady, Senior Analyst at ESG.

“As a result, security professionals have become frustrated with the complex and siloed nature of traditional application security solutions that fail to address these issues. Modern businesses require uniform tools and approaches that can minimise vulnerabilities between their public cloud infrastructure, microservices-based architecture, and legacy applications while supporting a variety of personas.”

ESG Methodology (global data)

To gather data for this report, ESG conducted a comprehensive online survey of information security and IT professionals who know about their organisation’s application development practices and are involved in security purchase processes (61%). The survey also included developers, engineering, and DevOps leaders who build and deliver applications for their organisation (39%). Respondents were distributed across North America (41%), Europe (30%), and the Asia Pacific and Japan (29%). Respondents were employed at organisations with 10 or more employees. Specifically, 10% were employed at small organisations (i.e., those with 10 to 499 employees), 15% at midmarket organisations (i.e., those with 500 to 999 employees), and 75% at enterprises (i.e., organisations with 1,000 or more employees). Respondents represented numerous industry and government segments, with the largest participation coming from manufacturing (23%), financial services (14%), retail/wholesale (14%), technology (11%), healthcare (8%), and communications (8%). The survey was fielded between March 17, 2021, and March 31, 2021.

Sapio Methodology (UK data)

The survey was conducted among 251 Information technology (IT)/Information security or Application development/Software engineering in 500+ UK companies. The interviews were conducted online by Sapio Research in July 2021 using an email invitation and an online survey. Results of any sample are subject to sampling variation. The magnitude of the variation is measurable and is affected by the number of interviews and the level of the percentages expressing the results. In this particular study, the chances are 95 in 100 that a survey result does not vary, plus or minus, by more than 6.2 percentage points from the result that would be obtained if interviews had been conducted with all persons in the universe represented by the sample. 

READ MORE:

About Fastly

Fastly helps people stay better connected with the things they love. Fastly’s edge cloud platform enables customers to create great digital experiences quickly, securely, and reliably by processing, serving, and securing our customers’ applications as close to their end-users as possible — at the edge of the internet. Fastly’s platform is designed to take advantage of the modern internet, be programmable, and support agile software development with unmatched visibility and minimal latency, empowering developers to innovate with performance and security. Fastly’s customers include many of the world’s most prominent companies, including Pinterest, The New York Times, and GitHub.

About ESG

Enterprise Strategy Group is an IT analyst, research, validation, and strategy firm that provides market intelligence and actionable insight to the global IT community.

For more news from Top Business Tech, don’t forget to subscribe to our daily bulletin!

Follow us on LinkedIn and Twitter

Amber Donovan-Stevens

Amber is a Content Editor at Top Business Tech

Birmingham Unveils the UK’s Best Emerging HealthTech Advances

Kosta Mavroulakis • 03rd April 2025

The National HealthTech Series hosted its latest event in Birmingham this month, showcasing innovative startups driving advanced health technology, including AI-assisted diagnostics, wearable devices and revolutionary educational tools for healthcare professionals. Health stakeholders drawn from the NHS, universities, industry and front-line patient care met with new and emerging businesses to define the future trajectory of...

Why DEIB is Imperative to Tech’s Future

Hadas Almog from AppsFlyer • 17th March 2025

We’ve been seeing Diversity, Equity, Inclusion, and Belonging (DEIB) initiatives being cut time and time again throughout the tech industry. DEIB dedicated roles have been eliminated, employee resource groups have lost funding, and initiatives once considered crucial have been deprioritised in favour of “more immediate business needs.” The justification for these cuts is often the...

The need to eradicate platform dependence

Sue Azari • 10th March 2025

The advertising industry is undergoing a seismic shift. Connected TV (CTV), Retail Media Networks (RMNs), and omnichannel strategies are rapidly redefining how brands engage with consumers. As digital privacy regulations evolve and platform dynamics shift, advertisers must recognise a fundamental truth. You cannot build a sustainable business on borrowed ground. The recent uncertainty surrounding TikTok...

The need to clean data for effective insight

David Sheldrake • 05th March 2025

There is more data today than ever before. In fact, the total amount of data created, captured, copied, and consumed globally has now reached an incredible 149 zettabytes. The growth of the big mountain is not expected to slow down, either, with it expected to reach almost 400 zettabytes within the next three years. Whilst...

What can be done to democratize VDI?

Dennis Damen • 05th March 2025

Virtual Desktop Infrastructure (VDI) offers businesses enhanced security, scalability, and compliance, yet it remains a niche technology. One of the biggest barriers to widespread adoption is a severe talent gap. Many IT professionals lack hands-on VDI experience, as their careers begin with physical machines and increasingly shift toward cloud-based services. This shortage has created a...

Tech and Business Outlook: US Confident, European Sentiment Mixed

Viva Technology • 11th February 2025

The VivaTech Confidence Barometer, now in its second edition, reveals strong confidence among tech executives regarding the impact of emerging technologies on business competitiveness, particularly AI, which is expected to have the most significant impact in the near future. Surveying tech leaders from Europe and North America, 81% recognize their companies as competitive internationally, with...