Frost and Sullivan World Applications Security Products Study

Network security is steadily gaining prominence as Web applications are emerging as vital components for business-to-customer organizations, according to Frost & Sullivan. The application security market encompasses products that scan for security weaknesses in Web applications, custom in-house applications and applications in development. Application security vendors have evolved from providing strictly consulting services to now offering strong stand-alone products.

New analysis from Frost & Sullivan, World Application Security Products Markets, finds that the market earned revenues of over $165 million in 2007 and estimates this to reach $596 million in 2014.

According to the analysis, Web applications offer innumerable benefits to enterprises because they are easy to deploy and update, operating system-independent and do not require client disk space. While necessary for any organization with a Web site, these applications remain available to the public at all times while staying connected with sensitive, critical backend systems. Web applications are not subject to testing as much as more ubiquitous applications, which can lead to a potentially dangerous situation.

"The security industry has long been centered on network security, but the security focus is shifting," explains Frost & Sullivan Research Analyst Chris Rodriguez. "Organizations are recognizing Web applications and other custom applications are not secure and represent a dangerous point of attack."

Furthermore, most organizations that have secured their network perimeter now turn to application security products to identify software security flaws and prioritize remediation efforts; however, the faltering world economy presents a major challenge for this burgeoning market. Security software is still not quite considered mission critical technology. While there is little that vendors can do to counter this directly, they can focus on improving competitive factors to expand their market share. This demands focus on increasing the availability, affordability and ease of implementation of solutions.

For now, the market is seeing increasing consolidation. Strong growth in 2006 and 2007, when revenues touched an estimated $127 million and $165.3 million respectively, enticed large multinational vendors such as IBM and HP to venture into this space. The dynamic testing segment witnessed decreased growth due to the acquisition of two leading vendors, Watchfire and SPI Dynamics. When these companies achieve complete integration with their parent companies, they are expected to contribute more to the growth of the market. In comparison, static source-code analysis vendors were responsible for a larger share of revenues than those of vendors offering dynamic testing solutions, according to the study's data.

"The recent success of static testing vendors is indicative of the eventual goal of security, which will become an integral part of the software development lifecycle," explains Rodriguez. "Customers are realizing that application security must go beyond dynamic testing and incorporate static testing in order to establish a firm foothold in the market."

Participants can improve their likelihood of success by broadening their product lines and enhancing functionality and features to offer a tandem of dynamic and static testing capabilities.

World Application Security Products Markets is part of the Network Security Growth Partnership Service program, which also includes research in the following markets: vulnerability management, network access control, data leakage prevention and endpoint security. All research services included in subscriptions provide detailed market opportunities and industry trends that have been evaluated following extensive interviews with market participants.

Featured

  • Report: 47 Percent of Security Service Providers Are Not Yet Using AI or Automation Tools

    Trackforce, a provider of security workforce management platforms, today announced the launch of its 2025 Physical Security Operations Benchmark Report, an industry-first study that benchmarks both private security service providers and corporate security teams side by side. Based on a survey of over 300 security professionals across the globe, the report provides a comprehensive look at the state of physical security operations. Read Now

    • Guard Services
  • Identity Governance at the Crossroads of Complexity and Scale

    Modern enterprises are grappling with an increasing number of identities, both human and machine, across an ever-growing number of systems. They must also deal with increased operational demands, including faster onboarding, more scalable models, and tighter security enforcement. Navigating these ever-growing challenges with speed and accuracy requires a new approach to identity governance that is built for the future enterprise. Read Now

  • Eagle Eye Networks Launches AI Camera Gun Detection

    Eagle Eye Networks, a provider of cloud video surveillance, recently introduced Eagle Eye Gun Detection, a new layer of protection for schools and businesses that works with existing security cameras and infrastructure. Eagle Eye Networks is the first to build gun detection into its platform. Read Now

  • Report: AI is Supercharging Old-School Cybercriminal Tactics

    AI isn’t just transforming how we work. It’s reshaping how cybercriminals attack, with threat actors exploiting AI to mass produce malicious code loaders, steal browser credentials and accelerate cloud attacks, according to a new report from Elastic. Read Now

  • Pragmatism, Productivity, and the Push for Accountability in 2025-2026

    Every year, the security industry debates whether artificial intelligence is a disruption, an enabler, or a distraction. By 2025, that conversation matured, where AI became a working dimension in physical identity and access management (PIAM) programs. Observations from 2025 highlight this turning point in AI’s role in access control and define how security leaders are being distinguished based on how they apply it. Read Now

New Products

  • FEP GameChanger

    FEP GameChanger

    Paige Datacom Solutions Introduces Important and Innovative Cabling Products GameChanger Cable, a proven and patented solution that significantly exceeds the reach of traditional category cable will now have a FEP/FEP construction.

  • Unified VMS

    AxxonSoft introduces version 2.0 of the Axxon One VMS. The new release features integrations with various physical security systems, making Axxon One a unified VMS. Other enhancements include new AI video analytics and intelligent search functions, hardened cybersecurity, usability and performance improvements, and expanded cloud capabilities

  • Camden CV-7600 High Security Card Readers

    Camden CV-7600 High Security Card Readers

    Camden Door Controls has relaunched its CV-7600 card readers in response to growing market demand for a more secure alternative to standard proximity credentials that can be easily cloned. CV-7600 readers support MIFARE DESFire EV1 & EV2 encryption technology credentials, making them virtually clone-proof and highly secure.