Frost and Sullivan World Applications Security Products Study

Network security is steadily gaining prominence as Web applications are emerging as vital components for business-to-customer organizations, according to Frost & Sullivan. The application security market encompasses products that scan for security weaknesses in Web applications, custom in-house applications and applications in development. Application security vendors have evolved from providing strictly consulting services to now offering strong stand-alone products.

New analysis from Frost & Sullivan, World Application Security Products Markets, finds that the market earned revenues of over $165 million in 2007 and estimates this to reach $596 million in 2014.

According to the analysis, Web applications offer innumerable benefits to enterprises because they are easy to deploy and update, operating system-independent and do not require client disk space. While necessary for any organization with a Web site, these applications remain available to the public at all times while staying connected with sensitive, critical backend systems. Web applications are not subject to testing as much as more ubiquitous applications, which can lead to a potentially dangerous situation.

"The security industry has long been centered on network security, but the security focus is shifting," explains Frost & Sullivan Research Analyst Chris Rodriguez. "Organizations are recognizing Web applications and other custom applications are not secure and represent a dangerous point of attack."

Furthermore, most organizations that have secured their network perimeter now turn to application security products to identify software security flaws and prioritize remediation efforts; however, the faltering world economy presents a major challenge for this burgeoning market. Security software is still not quite considered mission critical technology. While there is little that vendors can do to counter this directly, they can focus on improving competitive factors to expand their market share. This demands focus on increasing the availability, affordability and ease of implementation of solutions.

For now, the market is seeing increasing consolidation. Strong growth in 2006 and 2007, when revenues touched an estimated $127 million and $165.3 million respectively, enticed large multinational vendors such as IBM and HP to venture into this space. The dynamic testing segment witnessed decreased growth due to the acquisition of two leading vendors, Watchfire and SPI Dynamics. When these companies achieve complete integration with their parent companies, they are expected to contribute more to the growth of the market. In comparison, static source-code analysis vendors were responsible for a larger share of revenues than those of vendors offering dynamic testing solutions, according to the study's data.

"The recent success of static testing vendors is indicative of the eventual goal of security, which will become an integral part of the software development lifecycle," explains Rodriguez. "Customers are realizing that application security must go beyond dynamic testing and incorporate static testing in order to establish a firm foothold in the market."

Participants can improve their likelihood of success by broadening their product lines and enhancing functionality and features to offer a tandem of dynamic and static testing capabilities.

World Application Security Products Markets is part of the Network Security Growth Partnership Service program, which also includes research in the following markets: vulnerability management, network access control, data leakage prevention and endpoint security. All research services included in subscriptions provide detailed market opportunities and industry trends that have been evaluated following extensive interviews with market participants.

Featured

  • Security Today Announces 2025 CyberSecured Award Winners

    Security Today is pleased to announce the 2025 CyberSecured Awards winners. Sixteen companies are being recognized this year for their network products and other cybersecurity initiatives that secure our world today. Read Now

  • Empowering and Securing a Mobile Workforce

    What happens when technology lets you work anywhere – but exposes you to security threats everywhere? This is the reality of modern work. No longer tethered to desks, work happens everywhere – in the office, from home, on the road, and in countless locations in between. Read Now

  • TSA Introduces New $45 Fee Option for Travelers Without REAL ID Starting February 1

    The Transportation Security Administration (TSA) announced today that it will refer all passengers who do not present an acceptable form of ID and still want to fly an option to pay a $45 fee to use a modernized alternative identity verification system, TSA Confirm.ID, to establish identity at security checkpoints beginning on February 1, 2026. Read Now

  • The Evolution of IP Camera Intelligence

    As the 30th anniversary of the IP camera approaches in 2026, it is worth reflecting on how far we have come. The first network camera, launched in 1996, delivered one frame every 17 seconds—not impressive by today’s standards, but groundbreaking at the time. It did something that no analog system could: transmit video over a standard IP network. Read Now

  • From Surveillance to Intelligence

    Years ago, it would have been significantly more expensive to run an analytic like that — requiring a custom-built solution with burdensome infrastructure demands — but modern edge devices have made it accessible to everyone. It also saves time, which is a critical factor if a missing child is involved. Video compression technology has played a critical role as well. Over the years, significant advancements have been made in video coding standards — including H.263, MPEG formats, and H.264—alongside compression optimization technologies developed by IP video manufacturers to improve efficiency without sacrificing quality. The open-source AV1 codec developed by the Alliance for Open Media—a consortium including Google, Netflix, Microsoft, Amazon and others — is already the preferred decoder for cloud-based applications, and is quickly becoming the standard for video compression of all types. Read Now

New Products

  • EasyGate SPT and SPD

    EasyGate SPT SPD

    Security solutions do not have to be ordinary, let alone unattractive. Having renewed their best-selling speed gates, Cominfo has once again demonstrated their Art of Security philosophy in practice — and confirmed their position as an industry-leading manufacturers of premium speed gates and turnstiles.

  • Luma x20

    Luma x20

    Snap One has announced its popular Luma x20 family of surveillance products now offers even greater security and privacy for home and business owners across the globe by giving them full control over integrators’ system access to view live and recorded video. According to Snap One Product Manager Derek Webb, the new “customer handoff” feature provides enhanced user control after initial installation, allowing the owners to have total privacy while also making it easy to reinstate integrator access when maintenance or assistance is required. This new feature is now available to all Luma x20 users globally. “The Luma x20 family of surveillance solutions provides excellent image and audio capture, and with the new customer handoff feature, it now offers absolute privacy for camera feeds and recordings,” Webb said. “With notifications and integrator access controlled through the powerful OvrC remote system management platform, it’s easy for integrators to give their clients full control of their footage and then to get temporary access from the client for any troubleshooting needs.”

  • 4K Video Decoder

    3xLOGIC’s VH-DECODER-4K is perfect for use in organizations of all sizes in diverse vertical sectors such as retail, leisure and hospitality, education and commercial premises.