As web applications and APIs power everything from e-commerce to online banking, the need for advanced protection has never been greater. Traditional WAFs can no longer address the complexity of today’s API-driven environments. This webinar will explore why WAAP has become the new standard for web application and API security. You will learn what WAAP is, why organizations are adopting it, and how it addresses critical challenges such as bot attacks, DDoS threats, and API vulnerabilities. We will also present findings from our recent Leadership Compass, including analysis of market leaders, innovative capabilities, and emerging trends. Join us to discover how organizations are leveraging WAAP to reduce risk, ensure resilience, and protect their systems.
Osman Celik, Research Analyst at KuppingerCole, will share insights from his latest Leadership Compass on WAAP and its growing importance in modern cybersecurity strategies. He will discuss the transition from WAF to WAAP, the essential capabilities, and the latest updates from the market. The session will also cover vendor differentiators and innovations shaping the WAAP market.
Who should attend?
Don’t miss this webinar if you’re a security leader, CISO, DevSecOps professional, product innovator, or compliance officer who wants to stay ahead of evolving web application and API threats, learn from market insights, and discover how WAAP protects web applications and APIs against attacks, abuse, and downtime.
Welcome to our webinar today. We are here with you for the webinar around the web application and firewalls and API protection tools.
Last year, in the 2000s, we released the first report. Back then we called it the web application, when breaking into two separate applications, API protection. When I was working on the report, I noticed that most of the WAAP tools that are defining themselves as WAAP tools are becoming very obsolete, and then they are becoming legacy tools, and then they offer only the core capabilities we expect from a modern WAAP solution, and some of them were renaming them as Next Gen WAAP or WAAP 2.0, and so on. When I was working with vendors, I noticed that there is a need for renaming the market.
So for those of you who are following KuppingerCole's WAAP reports from back in 2021 to 2024, this year we renamed the report to WAAP, WAAP in longer version, web application and API protection. So that's why the name of the webinar today is Breaking the Firewall, and actually breaking into two pieces, let's say. But before we start and then go into details, let me do some housekeeping here. So for those of you participating, we have a very easy to use user interface for our webinar.
In the below, you'll see that there are buttons for applications, links, people's polls and questions and chat, and you can interact with us there. And throughout the webinar, you can send us your questions, or you can also answer the questions over there and also participate in the poll questions. You don't have to mute yourself. You are automatically muted. So whenever you want to contribute to the webinar with your question, please use the chat or the question button.
And for those of you who are not here with us today, the slide decks and then the recording of the webinar will be available after we are done. So quickly, I'll go through the agenda of today. I related 12 vendors recently, and we published the report at the end of August. And this was the second time I was working on the market after 2024, as I mentioned. And we got some good feedback. And today I will share with you my insight from the market, from the WAP market, and how we conducted this leadership compass. Before we start, our first poll question for those who want to answer.
Does your organization have a WAP solution in place today? Actively deployed in evaluation proof of concept space or no? Please take your time to answer the question. If you have time at the end of the webinar, I will share the results with you. So before we begin about what WAP is and then what does it do, we should first try to understand why is it there and what are the challenges that are motivating us or encouraging us to obtain or acquire WAP solution? So first of all, WAP solutions are not only addressing, let's say, conventional web application threats.
They are not addressing only API protection as well. But if you think about the vendors out there, when I did my initial research, I first noticed that most of the solutions at least offer web application protection, API protection, bot management and DDoS protection. So these four main pillars, I would say the main challenges or the main threat areas that web application and API protection solutions are trying to mitigate and address. So the challenges are malicious bots that are becoming more and more advanced. API security, I will get back to this point.
Maybe we should not really think about API security, but I wanted to use this term here because we also need to make sure that people understand what we mean by API security in terms of web application and API protection. I am more inclined to use the API protection and discovery because that is more lightweight rather than hardcore API security tools out there.
Third one, DDoS attacks, not only layer three and four attacks, but also the more modern solutions are also addressing layer seven attacks. Known and unknown vulnerabilities, at least they should cover some, they should have some coverage on OWASP top 10 for web app and API protection. Based using AI cybercriminals now, criminals have now more sophisticated attack vectors and then we need more modern tools addressing those, not the legacy solutions. And we have now broader supply chain partners and business contracts that also forces us to take care of our third party risks.
And as always, we also need to watch out for regulatory compliance and we need to have tools that are helping with us with the compliance issues. So, how does WAP work and why do you need it? Before I go into the details of how each of what we expect from WAP and what it delivers, I want to make sure that people understand what are some core WAP capabilities and some more advanced or let's say more innovative capabilities.
Because when I was looking, when I was analyzing the market, one of the point is that not every vendor is approaching to the WAP in the same way, because now, now that we renamed the market from WAP to WAP, there is definitely something going on in the market, right? So there is a more focus on the API protection and discovery side, but it will be unfair to the vendors that are already bringing some much like major core API protection to the table and not focusing too much on the API protection side.
So that's why I had to make sure that we at least determine what are the core WAP capabilities and then see what other capabilities are offered, if they are innovative or not. And thirdly, this is something I wanted to mention separately, the role of cyber threat intelligence. As an analyst, I'm working with different sorts of proactive cybersecurity solutions, and I always mention the importance of cyber threat intelligence. Find a solution, whether it is native, let it be providing native CTI or providing at least integrations to good CTI feeds or third party CTI tools.
So this is very important. And this is, again, a critical part of WAP solutions. I'm not saying that we have to have a solution that is providing, we need to have a WAP solution that is providing CTI, but at least it has to integrate with some third party solutions because that's really a game changer. And then you have a better context and you have a better understanding of your attack vectors that are targeting you and also the API attack service management that I will discuss shortly.
And why, as I said, the four main pillars now are very important. Verification protection, API protection and discovery, DDoS protection and both management. And in here you see that they are covered here and you also need to make sure that your data is protected. Your sensitive data is not at risk and you comply with the regulations. So from here on, I will go deeper into what we should expect from a WAP solution.
So in the surface level, I would say this core capabilities should be must have if you're searching for a solution and you should check if your checklist has these capabilities and then if the vendor is providing them. What are they? DDoS and DDoS protection, at least signature and rule based detection in the basic level.
They should definitely provide an understanding and also a control group, if possible, for OWASP 10 and they should provide some logging and reporting and reporting of like if it's going to help you with your audit sessions, if you're going to perform any forensics activity or if you're going through a compliance check, so on. So the reporting should help you with that.
And you might want to look for a centralized management solution offering centralized management, a single pane dashboard, for example, that way you can see all the threats and then the API traffic and all the policies you have, the custom and the pre-configured ones and the attack trends or the actions that are taken by your internal teams, internal security teams. And another important point is advanced bot management here, this is an upgrade from the last year. Last year for us, a bot management, the entry level bot management was maybe enough.
But from this year on, the attackers are utilizing AI so much and they are mostly affecting the bot management's capability of, they are, sorry, the utilization of AI for the attacks is addressed, should be addressed by the bot management tools or the models of the web solutions. And then they have to reach to a certain level if they cannot be only addressing basic level at bot management capabilities anymore. And comprehensive API inventory and runtime protection here, I am a bit flexible, to be honest. Expecting a full lifecycle API security is not realistic.
And I am not sure if we should then call these solutions a WAP solution anymore, then they are becoming, again, a hardcore API security solution. And we have to kind of separate these two markets. And so what you should expect from this WAP tools, then maybe automatic API discovery, at least the schema validation, and maybe some sort of protection against some API abuse, which is again linked to the advanced bot management here. Some orchestration or integration with some known CM and SOAR solutions. Advanced rate limiting that is useful for protecting against API abuse and DDoS attacks.
And zero attack protection and DevOps integration and CDN are the other ones that we think that are must have. The advanced capabilities, on the other hand, are, I call it innovative capabilities in this sense. They are not found in every vendor, but I think that now the direction and the roadmap of the vendors should be in this direction. So what they should do is they should support from now on, like, of course, the hybrid IT environments that they should not be only available as SaaS, or they should be supporting Kubernetes on the microservice environments.
They should provide more and more out-of-the-box integration with third-party security solutions. So they should not be limited with CM and SOAR, but also maybe threat intelligence or other analytic tools, fraud detection services, or XDR or NDR, whatever is more necessary for the organization. So they should have some policy management where they can actually have some granular policy enforcement and real-time updates to those, and also some rule adaptation as well. Compliance enforcement is something that I personally think that is very important.
This is very useful for organizations that are operating in some regulated verticals. Some solutions have control groups that are automatically mapped, and then you can check whether you are on the good way to comply with this certain regulation or standard. Data loss protection, virtual protection, and mobile app protection are some other innovative capabilities.
Actually, in the left right-hand side, we can say all these are innovative capabilities that we barely see in the market, but that means that only a couple of vendors are offering these capabilities as of today, but this should be what we should expect to see more and more from the other vendors in the market as well. Some market analysis here. I am not only going to talk about the solutions, but also the state of the market here.
The web threats are becoming more sophisticated, and API attacks are expanding, so that's why we should always check if the WAF solution is also bringing some protection against APIs, because they are everywhere. Organizations utilize it everywhere, so please make sure that it's not only a traditional WAF that you're acquiring, and we need to have a proactive cybersecurity mentality because this is why you should be already checking for WAF. You need to have your protection before you get hit or damaged by the cyber threats. Some highlights.
I would like to read these parts because they are, I think, very important. The traditional WAF is no longer enough, and they are no longer sufficient to address our modern needs, and then the WAF extends this traditional coverage to API protection. They utilize ML-driven bot management, and then now we see almost all WAF solutions also addressing layer 7 DDoS mitigation, whereas some WAF solutions are only addressing L3 and L4 level layer DDoS attacks.
WAF provides runtime API protection but lacks full lifecycle coverage, which means that they are not going to help you as much as a hardcore API security tool. In case if you need one, then you should maybe consider both of these solutions instead of looking one only, so it really depends on what your organization needs. WAF solutions adopt intelligent mechanisms, and then they include anomaly detection, policy automation, like we discussed, and also DevSecOps integrations. Speaking of the markets, there are a couple of vendors that are still doing acquisitions. There are some recent ones.
You can check out them. I'm not going to name them, but you can check out some recent WAF acquisitions, and the big players are still dominating the market, so therefore the startups are having high entry barriers. We also covered a couple of startup-level or, let's say, smaller vendors, so-called, but they are doing a good job focusing on some niche capabilities, such as lightweight deployment and API discovery I mentioned here, but some of them are also, like I know, they also provide tools around agentic AI.
They are trying at least something to do, and they also provide CDN capabilities, which I'm going to ask a question about later on. Overall, the market is mature, and the baseline features are standardized. How do I know this?
Because, again, this is the second time I'm working on this market, and I see most of the vendors are offering more or less the same solution, only making a couple of additions to their tools, so, of course, the use of AI is affecting all the vendors out there, so even if it's the sake of doing something, they are integrating AI tools, but, yes, the market is mature, and to be honest, I haven't seen that much of vendors really utilizing gen AI or agenting AI for automation purposes or for making WAP looking, let's say, future proof, so I think this is still in the development era, and some vendors are, as I mentioned earlier, are pushing to innovate in certain areas and capabilities.
Before we move to the key findings of the overall leadership compass, I would like to ask you my second poll question. How has your organization's cybersecurity budget changed this year compared to last year?
So, you can think of 2025 kind of ending, so maybe you can, if you have roughly an idea, how is this compared to last year, 2020? 2024.
So, my key findings, again, I would like to read this part a bit so that we don't miss any critical part. These are key findings section is the summary of my leadership compass, which was around 90 pages long, if I'm not wrong.
So, unlike traditional WAP, WAP takes a broader security approach addressing advanced risks related to APIs. I think this should be the core message of this webinar today, that why WAP differs from the traditional WAF, and why we renamed the leadership compass this year, and why you should look for solutions that are providing somewhat API protection and discovery, at least as of 2025. The many main capabilities of WAP include WAF, web application protection, basically, API discovery and protection, bot management and DDoS protection.
I think these four pillars should be something that all organizations should be aware and looking for when acquiring a WAP solution today. Effective bot management within WAP requires a mail-driven detection model, so they have to be somehow advanced level. Solutions utilize a combination of static signatures, heuristic analysis, contextual behavior detection, and supervised and unsupervised ML for threat mitigation.
So, this is more on the engine level, so you should be checking what their AI and ML engines are performing or providing. Capture, passive biometrics, fingerprinting, JavaScript challenges, and silent or invisible challenges are used to validate traffic, authenticity, and mitigate bots.
Here, I only mention what are the options, challenge of bot management, challenge options are available there. To be honest, this is really up to the organization and the end user, which one they are more comfortable with. Some people don't want to have capture, but some people find it more secure, so it's really up to that.
For me, as an analyst, I would like to see when there's given options to the organization, so they can choose whichever they are more comfortable with. I see also that more and more vendors switching to default, silent, or invisible challenges in their solutions. Web acceleration and CDN support appear as a differentiator among vendors.
Again, I will come to CDN in a couple of minutes. Some WAP vendors have begun integrating agentic AI into their platforms, but again, this is still in the development phase, something in the development phase yet. WAP solutions are offered through various delivery models, SaaS, on-premises, hybrid, edge-based, container-native, and fully managed service. The market is mature. WAP is adopted by organizations of all sizes.
Here, I have to say that no matter where you are industry you operate, WAP is always useful to have, and when I was going through the customer base of the vendors, to be honest, I got lost in the field. I can say that the coverage is very broad. There is no vertical focus almost on any vendor. I wouldn't name any vendor focusing on one particular industry. Let's put it that way. Industries such as finance, healthcare, e-commerce, insurance, and government are particularly dependent on WAP, and this is because of compliance issues and compliance requirements.
This is, again, a very important finding. The WAP market features global cloud providers like AWS, Google, and CDN and edge vendors like Fastly, Ekamai, traditional security vendors like Fortinet, Checkpoint, and focused startups like Propase and SenseDefense.
Here, some of the vendors I mentioned here are from the vendors to watch list, so you will not have the opportunity to see the detailed analysis of every vendor I mentioned here. The vendor landscape includes legacy WAP providers expanding into WAP, cloud native entrants, and startups focusing again.
Here, I wanted to show that in the first year, in the first time I worked in the WAP report, almost half of the vendors were similar to this year, so we have new additions, some new entrants, and also some new startups this year in the report. Entry barriers for startups are high due to complexity and breadth of the WAP functionality. If you ask me, yes, and this is also because of the bigger vendors, the giants are not allowing other vendors.
So, before we move on to our leadership complex methodology and how we conducted the analysis, I would like to ask my third poll question, and then this is why I was also bragging about the CDN. This will be very important if you answer me this poll question because I got this feedback from a couple of vendors and also end users whether CDN should be considered as one of the main pillars of WAP. If you remember, when I was talking about the four main pillars, I mentioned web application protection, API protection and discovery, DDoS protection, and bot management.
I did not include CDN, but I see that many vendors are now offering CDN next to their WAP solution, maybe under a unified solution or as a separate model. So, I would like to see what end users think about that. If CDN functionality really influences your organization's decision when acquiring a WAP solution.
So, please let us know if you really care if a WAP solution has a CDN functionality or not, and if you care about it, if it's important to you or if it's somewhat important to you. This would also help us understand and also work better next year with better understanding in the next years.
So, yes. All right.
So, from here on, I will basically summarize how we conduct leadership compasses. This is not only limited to the WAP market.
Obviously, as analysts, we cover different research areas. Personally, I cover attack surface management, brand protection, network detection and response, extended detection and response, and also WAP.
So, when we start our research, we first identify the vendors and we create a list of vendors that we would like to, sorry, get in touch and see if they would like to participate in our upcoming leadership compass. And we let them know that these are the capabilities we are looking for, the core advanced ones and also innovative ones, as we discussed earlier.
So, they have the ability to check if our understanding of WAP or the market aligns with their understanding of the market. So, they will have the full documentation from us and also the questionnaire that I prepare. These questionnaires are long questionnaires that are like around like 300 to 500 questions, but most of them are yes to no question. And we give one month to these vendors giving consent to participation to answer all these questions.
So, once they give their consent and answer the question and send us back the answers, I have one hour long briefings with them and I see their corporate overview, product overview, and almost half an hour of live demo where I ask my questions if I don't understand something, and then they tell us, they show us their workflows and also their user interface, so on. And also, I check their documentations and also their collaterals whenever it's necessary.
So, these are the information stack I would say that I am using, that I'm benefiting from to write my reports. And when I'm writing the report, I use the questionnaires and also the vendor documentation as a search, but I also double check if they are providing the right answer, if they are being objective with their solution.
If not, then I am being critical and I am providing the real answers or summarizing what the challenges are around their solution. So, after I finish the first draft, we give another chance to vendors to check if the vendor analysis is correct for them.
So, we might make mistakes. And then there are also some things that are patched during this period of writing because, as you see here, from research to fact check period, sometimes the duration is around three to four months.
So, if we highlight or list a challenge for a specific vendor, within that time period, sometimes they patch or they address the issue. So, they tell us, oh, this is no longer an issue for us, so could you please remove it? Or they say that we have a new major upcoming release that will be published before the publication of the report. Could you please include this in the report as well? So on.
So, they will have chance, they have chance to add and remove sections or give, suggest us, sorry, suggest us to add and remove the sections. And I check again what their feedbacks are and then I do necessary adjustments. And afterwards, we publish the report.
So, this whole cycle is around like six months. So, this is a heavy job that we are conducting here as Kupinger co-analysts and also vendors are also putting lots of effort to support us whenever we need their help.
So, in this page, you see the vendors that are being analyzed and rated in the last LC. If you remember, I was discussing, when I was discussing the key findings, I told you that not all the vendors I mentioned here are analyzed in the report.
So, these ones you see here are all analyzed. They have, they're analyzed in terms of what they provide, which, what capabilities they provide, and what are the challenges, what are the challenges associated to these vendors, and what are their strengths. And we also provide a spider graph for each of them. And it is something like this.
So, these are the eight main pillars that we think that a cybersecurity solution, in this sense, a WAP solution should have. If you remember the four main pillars, DDoS protection, the web application protection, API protection, and bot management, here you see also some other pillars like threat intelligence, centralized management and reporting, web performance, or CDN, or also the admin and DevOps support.
So, we would like to highlight more about the solution, not only focusing on the WAP side of it, but also in terms of cybersecurity, the product safety, social security, and product functionality, ease of use, the reporting capabilities, and so on. So, here is more like a better representation of a solution, I would say, than just focusing on the market itself.
And here, like I mentioned, the KMAI or the which one was it? SenseDefense.
Yes, KMAI and SenseDefense. So, these vendors here, you see, are not analyzed in depth, but these are the vendors that you should be also aware that they are in the market. Some of them did not want to work with us in this report. Some of them, we couldn't reach out to the right person, maybe, so we didn't get feedback. And with some of them, we already worked in the previous years, like, for example, Ubica, or Ergon, or Fortinet, or Fortra, Cloudflare as well.
So, some of them, we already worked, but this year, they did not give consent to participation. But we still include these vendors to show that we are aware of the market.
And also, we try to be fair with everyone in the market. We are not trying to highlight whoever gives consent to participation in our report, but also to other vendors. But of course, if they don't give the consent to the participation, so that means that they don't ask for the questionnaire, so I don't have time and resources enough to go and make a deeper analysis. But here are the vendors that you should be also watching out. And in our reports, we have basically three leadership categories, the product, market, and innovation leadership.
And here, we list the vendors based on their scores. And the combination of these three, we have the overall leadership chart. I think that this is the most interesting part of this long report, and I think everyone wants to see it, and everyone is more concerned about where the placement as vendor and also as customers, as users, you also want to see if you could afford or if you could work with the best solution out there. And these are the charts that affecting definitely the procurement and also the analysis of end users.
So here is our overall leadership chart from WAP 2025 leadership compass. I will briefly tell them the name from the best to the last one in the chart, F5, Impairbar, Radware, Google, AWS, Astley are the leaders. Checkpoint, Cisco, Link11, Propace, Valarman, Curators are the vendors in our report this year, in total, 12 vendors. So this is it from my end. If you have any question, we still have around like five to 10 minutes. We can discuss it. I have a couple of questions I see. But before that, maybe we can see if there is anything interesting to share from the poll questions.
So starting with the first one, half of our audience here has actively deployed WAP solution. That's good. And half of it, almost half of it doesn't have it. And 10% of it is still in the evaluation and proof of concept phase. So I hope that this webinar will be somewhat helpful to your journey of acquiring a WAP solution. Or if you already have one, maybe it will help you understand the market better. And if you should maybe think about what to prioritize in the upcoming years and check what other vendors out there and providing what. The second question was about your cybersecurity budgets.
40% of people said that their budget grew slightly. 40% said it remains stable. And a 20% said that it grew significantly, which is more than 20%. And no one said that our cybersecurity budget decreased this year. So that's good to see. And this kind of aligns with other data we have. And the most important question, I think that I was also curious to see what is the answer to this one. To what extent does CDN functionality influence your organization's decision when acquiring a WAP solution? So 40% of the people said that somewhat important. And 30% said very important. And 20%.
Okay, we got a last minute one as well. So only 20% said not important. So what I could say that if only 20% of the people participating today said no. So we did a good job because we covered the CDN as one of the main pillars under the web acceleration performance, web performance pillar. And we highlighted this capability in vendor analysis section, and also provide some detail and then how it works and why you should care.
Because I was thinking if I should consider putting this in my upcoming research next year, because sometimes people think this is kind of becoming irrelevant to the WAP market and creating its own market. So let's see if we have any solutions. So starting with the Pedro, would it make sense to explore a WAP solution instead of an API security solution? So this actually, I would like to say that I mentioned throughout the webinar a couple of times that even at Coppinger Call, we have two separate leadership compasses. My colleague, Alexey Balaganski, is working on API security tools.
And he has a separate coverage for the market. And his criteria for the vendors are much more API centric than my report, obviously. But when I was working on the report last year, when it was called web application firewalls only, I noticed that many vendors are stepping into API protection. So I think the naming kind of summarizes what should be careful about. So if we need somewhat API protection, so WAP solutions should be enough.
But if our organization are kind of utilizing API whenever it's necessary, and if we have no control over them, then maybe we should have a hard core API security solution out there. And we have a separate report for that. Please go and check our website. Or if you can just make your own, you can also make your own research and then try to understand the difference WAP and API security tools. Another question from Pedro again, are customers asking for bundled WAP API security DDoS solutions or preferring best of breed?
So what I understand from this question is that if customers are looking for some bundled solutions that are offering everything in a unified solution, or they are searching these solutions one by one. To be honest, I don't have a concrete answer to this. But I would like to hear your answers to this. What would be your solution? This is a question that you should be asking to a vendor, not to an analyst company.
Yes, we contact with end users, but I think that the better answer you would get from what vendors are offering out there. If you go and look at their website, the packages, their pricing sections, they always show what is included in the WAP. And I believe my observation, this is not based on any empirical data, of course, but I think that people prefer bundled solutions, because this is what I saw in my research. But some people might be only needing DDoS protection. So I cannot really say which one is better.
And another question from Ilia Neagao, what about API protection, especially business logic protection? So if you could maybe elaborate on your question, Ilia, I would maybe try to answer this. So business logic protection is, as far as I understood, you try to understand if this is relevant to your business, or let me understand it better. I think that we covered as much as possible. And I tried to highlight what is changing in the market. And as I said, this year, the market is a bit different than the 2024 landscape. But the market itself is mature.
So the solutions and the vendors are trying to play niche in the market. And they are trying to implement AI and agentic AI in their solutions in the experimental phase, let's say. So please be careful that your WAP solution is not becoming a legacy tool anymore, and addressing the sophisticated attack vectors is up to date and answering your needs today. So thank you very much for joining us. And I look forward to seeing you in our upcoming webinars. So thank you.
See All Locations
See All Locations