Skip to main content

Fastly Global Security Report 2026-v2

Page 1

Global Security Research Report

Hurtling towards a cybersecurity crisis Why businesses are unknowingly putting themselves at risk - and what to do about it


Table of Contents 01

Executive Summary

03 The AI-first Paradox 03

AI creates its own attack surface

04

How AI scrapers hit the bottom line

04

WAAP becomes essential

05 When bugs beat breaches 05

Software bugs actually triggered

06 A silver lining in incident recovery 06

Investment in response capabilities pays off

07 Investment priorities: where security dollars are really going 07

With mounting risks, it’s no wonder that data protection and privacy lead investment priorities at 37%

08 CISOs have more responsibility but hollow support 08

Policy changes miss the point

08

Nobody knows who’s in charge

09 Solving the skills strain 09

Alternatives to external recruitment

10

How threats vary by sector

11

The path forward: security by design in an AI-accelerated world

11

The automation ceiling

11

Two problems, one solution

12

How to fix security before you start

13

About the research

Hurtling towards a cybersecurity crisis


Executive Summary Businesses are hurtling towards a cybersecurity crisis

Here’s what emerged:

of their own making because of the massive scale of

Businesses are paying a steep AI tax.

adoption of AI within organizations. By embracing AI innovation without thinking through how to reinforce their security and putting a strategic plan in place to implement holistic solutions, companies racing to call themselves “AI-first” are discovering that shiny new functionality without infrastructure defense creates more problems than it solves.

More than 75% of businesses that identify as AI-first (meaning they’ve integrated AI into core processes from the outset, either publicly or informally) take an average of 80 days longer to recover from security incidents than their peers. It takes 6.8 months on average across all regions for AI-first organizations to recover, and 3.9 months for everyone else.

To understand what companies are experiencing in the real world, beginning in September 2025 Fastly partnered with research agency Sapio to survey 2,000 IT decision makers across 21 regions who are involved with cybersecurity. The findings reveal an uncomfortable truth: the organizations most aggressive about AI adoption are the ones struggling the most with security incidents.

The financial impact is also more painful for AI businesses: incidents cost AI-first organizations 135% more than their counterparts, consuming 3.13% of annual revenue compared to 1.33% for non-AI-first companies -representing billions of lost revenue. Almost half (44%) report that AI was directly exploited in their most recent incident.

continued on next page

The expanding attack surface: AI is expanding faster than security can follow AI directly exploited in 44% of incidents

64% say AI scraping is a material cost centre 34% AI caused security oversight

$350k+ average annual scraping cost

43% report rising infrastructure expenses 31% higher shadow AI usage

51% businesses remain unclear on incident ownership

Hurtling towards a cybersecurity crisis

1


The infrastructure footprint is expanding faster than

There is a bright spot in the data. Overall incident

defenses can keep up. Shadow AI also jumped in the

volume for all businesses held steady at an average of

past 12 months. More than a third (34%) of AI-first

41 incidents per organization, and recovery capabilities

organizations say direct exploitation of AI contributed

improved. Average recovery time dropped more than

to their last incident, with another 30% saying that AI

a month from last year’s 7.34 months to 6.08 months.

use led to an oversight that contributed to the incident.

Revenue losses from incidents fell to 2.68% of annual

Meanwhile, AI scraping has become a material cost

income, down from 2.98%. Organizations that invested

center for more than two-thirds (64%) of businesses,

in post-incident reviews (52%) and response automation

with average annual infrastructure costs rising by almost

(43%) are likely among those seeing positive results.

$350,000. Further, 43% of respondents reported surging infrastructure expenses. It isn’t just a financial issue: 40% also faced operational disruption and 29% reported degraded customer experiences.

Investment priorities are shifting to address AIspecific risks. Agentic discoverability tools lead security spending on agentic AI infrastructure at 56%, followed by API security (55%) and web application firewalls (54%).

Nobody knows who’s actually responsible when

Three-quarters (75%) worry about DDoS attacks targeting

things go wrong. Half of AI-first businesses (51%)

AI agents, while 53% acknowledge they lack AI-specific

report confusion over who handles incident response,

security expertise.

compared to 23% of non-AI-first organizations. Traditional accountability is rapidly deteriorating because teams can now include humans and self-thinking, self-learning, and self acting AI agents.

The path forward requires a mindset shift. Enterprises must monitor AI crawler activity, anticipate shadow AI adoption, and strengthen perimeter defenses before expanding the attack surface. It’s also prompting a rethink of web application and API protection (WAAP) solutions; companies are starting to view them as business-critical infrastructure rather than niche solutions.

AI-first companies tend to suffer from AI-related compromises

17%

25%

0% - No known attacks involved AI

1-10%

27%

17%

11-25%

26-50%

6%

6%

4%

More than 50%

We don’t have the visibility to determine this

We have not experienced an attack where AI was involved

Hurtling towards a cybersecurity crisis

2


The AI-first paradox AI is a potential productivity booster, but as with any

One apparent cause traces back to what security

enabling technology, it requires a strategic balance

teams can’t see. Shadow AI (unauthorized tools that

between innovation and security. Organizations that

employees adopt without IT approval) runs 31% higher

brand themselves as “AI-first” and race to integrate

among a quarter of employees at AI-first organizations,

artificial intelligence must find this balance to truly apply

presumably because the culture encourages innovation

AI’s benefits. At the moment, these businesses take an

with AI. But for Marshall Erwin, CISO at Fastly, sanctioned

average of 6.8 months to recover from cybersecurity

AI tools are at least as much of an issue as shadow AI.

incidents, which is 80 days longer than their non-AI-first peers, who recover in just about 4 months. They have some work to do.

Approved AI tools often receive extensive automated permissions, and companies already struggling with identity and access management in a pre-AI world are watching that problem explode. “These tools are going

“The AI tools themselves are going to be privileged parts of your infrastructure, and that’s what’s going to create the risk.”

to expand potential access risks,” Erwin warns. “The AI

— Marshall Irwin, CISO at Fastly

security oversights that contributed to their last breach.

tools themselves are going to be privileged parts of your infrastructure, and that’s what’s going to create the risk.” The numbers support this conclusion. Over a third (34%) of AI-first organizations cite AI usage as a factor in That compares to 20% in traditional organizations.

Innovation is a critical business advantage, but

Think of AI tools as machine entities requiring their

organizations that create robust security measures to

own identity governance. Automated privileges allow

protect AI data, infrastructure, and processes will be

automated attacks. The more agentic these tools get

better positioned to innovate than those who don’t.

(meaning the more complex their autonomous tasks) the

Incidents cost AI-first businesses 135% more than non-AI-

bigger that risk will become.

first organizations. The recovery gap translates directly

(44%) of AI-first organizations report that AI was directly exploited in their most recent security incident, compared

70 60 50 40

45%

30

1

29%

20

21% 6%

10 0

Ye a n s ‚ fo d p rm ub ally lic ly

to a mere 6% among non-AI-first businesses.

74%

80

Ye s

infrastructure that companies must protect. Almost half

90

%

AI introduces more complexity, more code, and more

100

ar No A I e ex ‚ b u t i nt p l w eg ori e ra ng tio n a r N o‚ A I e ex b u t i nt p l w eg ori e ra ng tio n

AI creates its own attack surface

AI-first organizations took longer to recover from security incidents than non-AI-first ones

Y i nf es, or bu ma t lly

reputational damage.

percentage of people who agree

into lost revenue, extended downtime, and prolonged

(employees using unsanctioned AI tools)

Hurtling towards a cybersecurity crisis

3


How AI scrapers hit the bottom line

WAAP becomes essential

Shadow AI invites accidental misuse of AI inside

These realities are changing how organizations think

an organization, but there are also risks from third

about their security stacks. WAAP might once have been

parties using AI. These malicious actors can target an

lower on the list of security tools for some companies, but

organization’s content using scraper bots. AI scraping

it’s now becoming part of their core infrastructure. It’s the

is costing companies serious cash as it puts their

control layer for managing costs and securing the APIs

infrastructure under strain.

that underpin modern digital services from those both

Approximately two thirds of businesses (64%) say

inside and outside a company.

AI scraping has become a material cost center, with

Enterprises are voting with their wallets. When they invest

expenses soaring over $348,000 annually on average.

in protecting agentic infrastructure, organizations are

That’s hitting infrastructure bills and operational budgets

prioritizing agentic discoverability (56%), API security

hard. More than four in ten companies have watched

(55%), and web application firewalls (WAFs, at 54%).

infrastructure expenses climb as AI activity ramps up.

These non-traditional security categories are direct

Another 40% report operational disruption, while 29%

responses to architectural patterns that barely existed

are dealing with user experience problems. Sluggish load

two years ago.

times, broken functionality, and degraded performance are the kinds of problems that send customers elsewhere if they persist. Old-school external attack techniques can do serious damage to AI infrastructure. Three quarters of respondents to Fastly’s survey worry about DDoS attacks hitting AI agents. What this means is that even companies who don’t use AI internally should be mindful of how others might use it to exploit them. None of these risks should stop companies from embracing AI, but the winners will be those who innovate while also adjusting their security postures accordingly. That means either finding the skills to do so (53% admit their security teams lack the AI specific expertise to deal with these threats) or working with a third-party partner to help manage the risks.

Hurtling towards a cybersecurity crisis

4


When bugs beat breaches Our research showed that in 2025, the number of security incidents stayed flat. Organizations faced an average of 41 known incidents, up just one from 2024. But the headline number tells you almost nothing. What’s actually breaking tells a more realistic story. Software bugs actually triggered 40% of incidents, up from 33% in 2024, moving it from second place to the top slot, knocking the incumbent top cause (external attackers) down to second place at 39%. Misconfigurations took third place, up to 29% from fourth place at 25% last year. More than ever, companies are wrestling with security failures that have nothing to do with sophisticated threat actors and everything to do with how they write their code or configure their infrastructure (which is increasingly also done with code).

Software bugs actually triggered 40% of incidents, up from 33% in 2024. Ninety percent of organizations suffered at least one cybersecurity incident, but it’s clear that these stem from development problems, process problems, and maybe cultural problems in the enterprise. Clearly organizations cannot take their eyes off the perimeter, but it’s time for them to elevate their focus on budget allocation and team structure rather than organizing purely around external threats. Scale amplifies all these issues. Large enterprises with 10,000+ employees averaged 57 incidents, nearly 40% above the mean of 40. Sprawling attack surfaces and tangled development pipelines create more opportunities for things to break. Smaller organizations deal with the same issues at a smaller scale, which helps but doesn’t eliminate the problem.

Hurtling towards a cybersecurity crisis

5


A silver lining in incident recovery The Fastly survey revealed some genuinely good news: organizations are getting better at bouncing back from attacks. Average recovery time dropped to 6.08 months

Investment in response capabilities pays off

in 2025 from 7.34 months the previous year. That’s more

Organizations are putting money where it matters.

than a month off the recovery timeline, representing a

Over half (52%) invested in post-incident reviews,

meaningful improvement when every day of downtime

systematically analyzing what went wrong and how to

costs money and erodes customer trust.

prevent it next time. Another 43% have implemented

The gap between expectations and reality is closing too. Organizations now expect recovery to take 5.89 months, and the actual timeline of 6.08 months is remarkably

response automation, using technology to speed up containment and recovery steps that previously required manual intervention.

close. This alignment suggests that companies are

But there are significant caveats buried in these positive

developing more realistic incident response plans based

trends. Despite the improvements, 30% of organizations

on actual experience rather than wishful thinking.

still lack regularly tested incident response playbooks.

Financial impacts are also trending in the right direction.

The pressure is on to squeeze real recovery times further.

Revenue losses averaged 2.68% of annual income, down

And while companies might recover quickly, lighting

from 2.98% last year. While that’s still painful (a mid-sized

frequently strikes twice or even more. Two thirds (66%)

company losing nearly 3% of revenue is taking a serious

of organizations suffered repeat incidents within three

hit), the trajectory matters. Organizations are containing the

months, as underlying problems might still exist.

damage more effectively than they did twelve months ago. Lastly, customers seem to be more forgiving once they see a company making efforts to fix its cybersecurity problems. Reputational recovery averages 4.73 months, faster than the 6.08 months needed to fully restore systems and operations. Managing the crisis narrative and maintaining customer communication can rebuild trust even while technical teams are still cleaning up the mess.

Recovery expectations are getting more realistic 2025

2024 Expected recovery time 50

Actual recovery time

Expected recovery time 50

44%

40

45% 41%

40

34%

30

Actual recovery time

30

5%7

%

rs Ye a

nt mo

2+

hs

hs -2 4 19

-18

mo

nt

16

mo -15 13

mo -12

nt

hs

hs nt

hs nt 10

mo 79

6m

on

th

s

hs

Hurtling towards a cybersecurity crisis

W e e d ma xp e id n ke c t o t r e a to co fu ve l l ry

2%2% 1% 1% 1% 1% 1% 0%

0 nt

rs

W e e d ma xp e id n ke c t o t r e a to co fu ve l l ry

nt mo

Ye a

hs

hs -2 4 19

-18

mo

nt

16

mo -15 13

mo -12

nt

hs

hs nt

hs 10

mo

nt

s 79

th on 6m 4-

1-3

mo

nt

hs

0

5% % 2% 1% 3 1% 2 % 1% 1% 2+

5%6%

11% 14%13% 11%

10

mo

13%12% 12% 11%

10

21% 21%

20

1-3

20

4-

19% 19%

6


Investment priorities: where security dollars are really going Ask security teams what keeps them up at night and data

Cyber insurance was the second most popular

breaches naturally top the list at 45%. Social engineering

investment category at 34%, followed by API security

comes in second at 40%. That makes sense, given

at 33%. Cyber insurance’s runner-up status is a sign of

that phishing emails remain the launch point for most

acceptance. Organizations realize that a perfect defense

successful attacks. Fancy technology still won’t stop a

is impossible, so they’re transferring risk. Can’t prevent

harried employee from clicking a convincing link late on a

every breach? At least make sure you’re not absorbing

Friday afternoon.

the entire financial hit when one lands.

Ransomware (often launched using these social engineering attacks) ranks highly at 28%, after generative AI and a lack of technical skill. After years of headlines, that shouldn’t surprise anyone, companies are still falling victim to it. Just because the playbook is well understood

With mounting risks, it’s no wonder that data protection and privacy lead investment priorities at 37%.

by now doesn’t make it easier to stop. These risks don’t exist in isolation. Account takeover (19% cite this as a worry) also usually starts with phishing.

The API security investments make sense when you consider that every new mobile app, third-party integration, and microservice creates another potential

However, the third-party risks deserve particular

entry point. APIs used to be internal plumbing. Now

attention. September’s attack on the npm software

they’re exposed to the internet and attackers have

repository showed how a single attack can infect

noticed.

hundreds of packages, trickling malware into countless user environments. When your security depends partly on someone else’s, you’re adding risk you can’t directly control.

The real investment shift shows up in AI. The survey found that organizations are preparing for agentic infrastructure threats. Among those investing in this area, agentic discoverability tops the list at 56%,

With mounting risks, it’s no wonder that data protection

followed by API security at 55% and WAFs at 54%. These

and privacy lead investment priorities at 37%. The shift

non-traditional security categories are responses to

toward data protection reflects mounting regulatory

architectural patterns that barely existed two years ago.

pressure and the realization that data breaches carry consequences beyond immediate technical remediation. Compliance violations, customer lawsuits, and brand damage all stem from mishandled data.

Three quarters of companies are worried about DDoS attacks targeting AI agents, and over half admit their teams lack the AI specific expertise to handle these threats. Yet DDoS protection ranks just fifth as an investment priority at 30%. There’s a disconnect between stated concerns and actual spending that suggests either misplaced priorities or constrained budgets forcing uncomfortable tradeoffs.

1

2

“ Widespread Supply Chain Compromise Impacting Npm Ecosystem | CISA.” Cybersecurity and Infrastructure Security Agency CISA, 23 Sept. 2025, www.cisa.gov/news-events/alerts/2025/09/23/widespread-supply-chain-compromise-impacting-npm-ecosystem

Hurtling towards a cybersecurity crisis

7


CISOs have more responsibility but hollow support The CISO’s chair is getting hotter. Nearly three quarters

(in other words, reading the rules properly). Of

(73%) of organizations now say the CISO is ultimately

respondents surveyed, 45% are now offering more legal

responsible when breaches occur. Regulatory pressure

support for cybersecurity staff.

is increasingly showing that security leaders can face personal liability for failures. For example, The EU’s 2022 NIS2 Directive allows temporary suspensions of executives deemed incapable of fulfilling their cybersecurity responsibilities, along with damages to be levied against general managers and CEOs.

with 82% reporting active participation and 74% seeing increased CISO engagement over the past year. On paper, this looks like security getting the executive attention it deserves. In practice, the response has been less impressive.

finally giving the CISO a seat at the table for strategic decisions (that ties almost joint first with additional legal support and resources for cybersecurity teams, which each come in at 45%). That’s at least giving them some kind of voice, but that alone isn’t enough to stop the rot. Security leaders need the authority and resources

Nobody knows who’s in charge

64%

60

The confusion extends beyond technical vulnerabilities

50

into organizational structure. Over half of AI-first

40

businesses report a lack of clarity over who is responsible

36% 26%

30

24%

for incident response, compared to just 23% of non-

24%

18%

20 10

AI-first organizations. Yet when breaches occur, blame 1%

Pro ma n du c tio n agem e nt N res p o s ha r e o it ’s c ns ib il it y d e ntr a lize – d

O ps D ev

P e n g inlat fo r m e e r in g

E xe c lea d u tive e (C I S r s h ip O et c) Le g a l a com p li a n n d ce

cu r it erse C yb

e r at IT op

y

0

io ns

% of responsibility by department

improving your security posture.”

responsibility when things go wrong.

Policy changes miss the point

1

self-preservation,” says Erwin. “Those aren’t actually

to implement necessary security measures, not just the

When it comes to cybersecurity, everyone has a part to play 69%

policies’. “These measures are nice, but little more than

One of the most common measures, cited by 44%, is

CISO involvement in incident response has also jumped,

70

These are colloquially known as ‘CYA (cover your ass)

flows uphill, with 79% of AI-first businesses reporting the CISO is ultimately held responsible versus 57% among traditional organizations. As AI-first organizations create new risks faster than they can manage them, this issue will take center stage for security leaders. They will shoulder the blame as the inevitable breaches follow those risks.

Most organizations (94%) made policy changes in

Confusion doesn’t just cause problems at the top. Our

response to growing CISO accountability. But dig into

research shows that 43% of people within enterprises feel

what those changes actually entail and the picture gets

there’s clarity around who’s responsible for incidents – the

murky. Many measures are defensive, with 42% promising

same percentage feel there isn’t (with the remainder on

increased scrutiny of security disclosure documentation

the fence).

3

ricewaterhouseCoopers. “What You Need to Know about NIS2 - PwC.” PwC, 2023, www.pwc.de/en/cyber-security/european-nis2P directive-implications-for-businesses-and-institutions.html.

Hurtling towards a cybersecurity crisis

8


Solving the skills strain The talent problem is getting worse, not better. More than half (53%) of security teams lack the AI specific expertise needed to respond to emerging threats. This isn’t just about general cybersecurity skills anymore. The rapid adoption of AI infrastructure has created demand for specialized knowledge that the market can’t supply.

Alternatives to external recruitment Perhaps companies should look inwards instead. Several options deserve consideration. Upskilling existing staff for new responsibilities means they’re already aligned with your culture and at least partly fluent in your specific systems and processes. These people understand the business context, which matters as much as technical capability when making security decisions under pressure. Mentoring provides on-the-job training from experienced staff, cementing junior employees’ skills and shaping them for success. It’s slower than hiring someone with 10 years of experience, but those experienced candidates are increasingly hard to find and expensive to recruit. Cross-functional collaboration between security and other teams like IT, compliance, support, and product development can create well-rounded employees with

AI first organizations are especially hungry for talent. They’re moving fast and building new systems. They’re

a strong sense of how security fits into other functions. There are opportunities for secondments here.

also discovering that traditional security expertise

Sourcing talent from within, especially across different

doesn’t translate cleanly to protecting AI agents,

functions, carries several advantages. It promotes the

managing agentic infrastructure, or defending against

idea that everyone is responsible for security. It also

AI powered attacks. The skills shortage has become a

supports digital transformation efforts by embedding

bottleneck limiting how quickly they can secure their

security expertise throughout the organization rather

expanding technology footprints.

than concentrating it in a single team that becomes a

Fresh cybersecurity graduates face a steep learning

bottleneck.

curve. They must learn technical skills specific to a company’s toolset and workflow, plus organizational cultural nuances. It takes substantial time and effort before a raw recruit becomes productive. As companies scale, this challenge intensifies, particularly when working in larger, constantly evolving environments.

Hurtling towards a cybersecurity crisis

9


How threats vary by sector The aggregate data tells one story, but drilling down

Government

into individual sectors reveals how unevenly the

Nation-state attacks are understandably the

cybersecurity burden falls across different industries.

big issue for government respondents, worrying

Some face existential threats to their core business

21% of security teams (markedly more than the

models, while others grapple with geopolitical risks

percentage in commercial sectors). The percentage

or the operational chaos of securing sprawling digital

fretting about data breaches tops out at 52%, the

estates. Here’s how the threat landscape breaks

highest anywhere.

down sector by sector.

Retail

Finance

Retailers seem to get hammered from every

Finance averages 54 breaches a year.

direction. DDoS attacks are a concern for 25% of

Phishing still worries 39% of organizations, and

them, (the highest rate across all sectors), while

data breaches concern 42%, but the killer statistic

ransomware worries among retailers match those in

is $442,232. That’s the average increased annual

the finance community at 32%. And a sector-high

infrastructure cost from AI scraping alone, and it’s

32% skills gap means payment systems and customer

the highest across all sectors. Perhaps that’s why

data aren’t properly defended.

generative AI worries 41% of financial institutions. Only tech companies are more anxious about it.

Media and entertainment

Sectors may have differences that cause them to score differently in various aspects of cybersecurity, but one thing is universal: they all pay an AI tax

This sector breaks the mold entirely. It

now. Scraping costs run from nearly $300k-$450k

shoulders the lowest number of breaches across

annually across named sectors. The traditional

all sectors, at 24. However, content scraping is a

threats such as identity attacks and data breaches

business model threat, with one in five of these

haven’t gone away, but AI has added mandatory new

companies identifying it as a major concern, versus

costs to running digital operations.

5-16% elsewhere. That shows up in the 51% of media companies suffering elevated infrastructure costs from AI scraping, the 47% encountering operational disruption, and the 39% reporting customer experience issues – all of which are cross-sector highs. Just 11% report no impact. Financial organizations lost the most on average from their single biggest security incident in 2025

Mean % of revenue loss

5 4 3 2 1

3.24% Finance / Accounting

2.14% Government / Public Sector

2.92% Healthcare / Life Sciences

0

Hurtling towards a cybersecurity crisis

1.86% Media / Entertainment / Travel & Tourism

2.79% Retail / Wholesale (including e-commerce)

10


The path forward: security by design in an AI-accelerated world With internal mistakes now causing as many breaches as external attacks and software bugs triggering 40%

Two problems, one solution

of incidents, you’d think this would spark a fundamental

AI creates both external and internal security challenges.

rethink of how organizations build software. But it hasn’t.

On one side sits the operational cost problem from external AI threats. AI scraping bleeds infrastructure

“I can’t wait for someone to come to me for approval, because if that’s happening, then I probably already failed.” — Marshall Irwin, CISO at Fastly

budgets so badly that 64% of organizations now consider it a material cost center. That’s because bots are crawling their sites, consuming bandwidth, degrading performance, and increasing their cloud bills (not to mention misappropriating valuable intellectual property). On the other side sits the attack surface problem facing

Only 37% have shifted security responsibility to platform

companies’ own AI infrastructure. Agentic infrastructure

engineering or DevOps teams.

and privileged AI tools create new vectors for attackers.

Participating in conversations before architecture decisions are made is crucial. “I can’t wait for someone

These highly privileged tools can give attackers deep access to infrastructure if exploited.

to come to me for approval, because if that’s happening,

Both problems converge at the same point: web

then I probably already failed,” Erwin says.

applications and APIs. WAAP solutions defend both

DevOps automation helps, but only with tactical problems. Your continuous integration/ continuous delivery (CI/CD) pipeline won’t catch architectural mistakes like giving an AI agent excessive privileges that open your infrastructure to attack. Those require human judgment during design.

fronts. The same layer that throttles scrapers burning through your infrastructure budget also protects the APIs underpinning agentic systems. Web application firewalls that block layer-seven attacks work whether the target is traditional infrastructure or AI agents. Organizations investing in agentic security get this.

The automation ceiling Automation is an important part of the security equation,

company in the tech space today,” notes Erwin. Combine

“The volume of potential vulnerabilities that you need to look at and get ahead of is high for just about any mature company in the tech space today.”

high volume with high false positive rates and automation

— Marshall Irwin, CISO at Fastly

because it helps to bridge the talent gap. However, even companies committed to automation hit limits. “The volume of potential vulnerabilities that you need to look at and get ahead of is high for just about any mature

only gets you so far. Erwin advises automation for managing less serious issues and keeping expert humans for serious incidents. Let the machines handle routine vulnerabilities. Save human expertise for the tricky stuff that requires context and judgment. Hurtling towards a cybersecurity crisis

11


How to fix security before you start

AI is rewriting business operations at a pace that makes

AI-first businesses must learn the value of measured

leisurely. Companies building that new infrastructure

movement. So if they move fast and break things, it

without security architects in the room from the first

takes them longer to pick up the pieces. That’s why AI

conversation are going to join the large community of AI-

organizations are increasing security spending yet feel

first organizations that saw AI directly exploited in their

more vulnerable.

most recent breach.

It’s also why security by design has moved from an

There will be a demarcation line between those who

aspirational goal to a survival requirement. The 81%

embedded security into their AI strategy and those who

who say resilience investments safely accelerated their

bolted it on afterward. The good news is that you control

innovation have already figured this out.

which side you stand on.

the economy’s decade-long migration to the cloud look

Security architecture built into systems from the beginning remove uncertainty, enabling teams to move faster with confidence. The alternative is what we’re seeing now: organizations spending more, recovering slower, and wondering why buying more tools didn’t fix anything. It’s no coincidence that 72% of organizations prioritize speed-to-market over building resilience into systems.

Security benefits of implementing AI fro the start

Early implementation AI development

$

Security by design Efficiency

Cost savings

Robust system

Mid-stream implementation Delays AI development

Security implementation Vulnerabilities and retrofitting

$ increased costs

Hurtling towards a cybersecurity crisis

Patchwork

12


About the research

About Fastly, Inc.

This research surveyed 2,000 key IT decision makers

Fastly’s powerful and programmable edge cloud platform

with an influence in cybersecurity, in large organizations

helps the world’s top brands deliver online experiences

spanning multiple industries across North, Central and

that are fast, safe, and engaging through edge compute,

South America, Europe, Asia-Pacific, and Japan. The

delivery, security, and observability offerings that

interviews were conducted online by Sapio Research in

improve site performance, enhance security, and

Q4 2025 using an email invitation and an online survey.

empower innovation at global scale. Compared to other

Results of any sample are subject to sampling variation.

providers, Fastly’s powerful, high-performance, and modern platform architecture empowers developers to

The magnitude of the variation is measurable and is

deliver secure websites and apps with rapid time-to-

affected by the number of interviews and the level

market and demonstrated, industry-leading cost savings.

of the percentages expressing the results. In this

Organizations around the world trust Fastly to help

particular study, the chances are 95 in 100 that a survey

them upgrade the internet experience, including Reddit,

result does not vary, plus or minus, by more than 2.6

Neiman Marcus, Universal Music Group, and SeatGeek.

percentage points from the result that would be obtained

Learn more about Fastly at https://www.fastly.com, and

if interviews had been conducted with all persons in the

follow us @fastly.

universe represented by the sample.

About Sapio Best new agency finalist, Sapio is adept at opinion polling (we have access to 80 million people internationally), focus groups, face-to-face interviews, telephone interviews, online research, desk research and statistical modelling to mention just a few techniques. We love B2B research and consultancy. Our business is based on partnership principles inspired by social enterprise.

Hurtling towards a cybersecurity crisis

13


Turn static files into dynamic content formats.

Create a flipbook
Fastly Global Security Report 2026-v2 by walkerdesign - Issuu