Global Security Research Report
Hurtling towards a cybersecurity crisis Why businesses are unknowingly putting themselves at risk - and what to do about it
Table of Contents 01
Executive Summary
03 The AI-first Paradox 03
AI creates its own attack surface
04
How AI scrapers hit the bottom line
04
WAAP becomes essential
05 When bugs beat breaches 05
Software bugs actually triggered
06 A silver lining in incident recovery 06
Investment in response capabilities pays off
07 Investment priorities: where security dollars are really going 07
With mounting risks, it’s no wonder that data protection and privacy lead investment priorities at 37%
08 CISOs have more responsibility but hollow support 08
Policy changes miss the point
08
Nobody knows who’s in charge
09 Solving the skills strain 09
Alternatives to external recruitment
10
How threats vary by sector
11
The path forward: security by design in an AI-accelerated world
11
The automation ceiling
11
Two problems, one solution
12
How to fix security before you start
13
About the research
Hurtling towards a cybersecurity crisis
Executive Summary Businesses are hurtling towards a cybersecurity crisis
Here’s what emerged:
of their own making because of the massive scale of
Businesses are paying a steep AI tax.
adoption of AI within organizations. By embracing AI innovation without thinking through how to reinforce their security and putting a strategic plan in place to implement holistic solutions, companies racing to call themselves “AI-first” are discovering that shiny new functionality without infrastructure defense creates more problems than it solves.
More than 75% of businesses that identify as AI-first (meaning they’ve integrated AI into core processes from the outset, either publicly or informally) take an average of 80 days longer to recover from security incidents than their peers. It takes 6.8 months on average across all regions for AI-first organizations to recover, and 3.9 months for everyone else.
To understand what companies are experiencing in the real world, beginning in September 2025 Fastly partnered with research agency Sapio to survey 2,000 IT decision makers across 21 regions who are involved with cybersecurity. The findings reveal an uncomfortable truth: the organizations most aggressive about AI adoption are the ones struggling the most with security incidents.
The financial impact is also more painful for AI businesses: incidents cost AI-first organizations 135% more than their counterparts, consuming 3.13% of annual revenue compared to 1.33% for non-AI-first companies -representing billions of lost revenue. Almost half (44%) report that AI was directly exploited in their most recent incident.
continued on next page
The expanding attack surface: AI is expanding faster than security can follow AI directly exploited in 44% of incidents
64% say AI scraping is a material cost centre 34% AI caused security oversight
$350k+ average annual scraping cost
43% report rising infrastructure expenses 31% higher shadow AI usage
51% businesses remain unclear on incident ownership
Hurtling towards a cybersecurity crisis
1
The infrastructure footprint is expanding faster than
There is a bright spot in the data. Overall incident
defenses can keep up. Shadow AI also jumped in the
volume for all businesses held steady at an average of
past 12 months. More than a third (34%) of AI-first
41 incidents per organization, and recovery capabilities
organizations say direct exploitation of AI contributed
improved. Average recovery time dropped more than
to their last incident, with another 30% saying that AI
a month from last year’s 7.34 months to 6.08 months.
use led to an oversight that contributed to the incident.
Revenue losses from incidents fell to 2.68% of annual
Meanwhile, AI scraping has become a material cost
income, down from 2.98%. Organizations that invested
center for more than two-thirds (64%) of businesses,
in post-incident reviews (52%) and response automation
with average annual infrastructure costs rising by almost
(43%) are likely among those seeing positive results.
$350,000. Further, 43% of respondents reported surging infrastructure expenses. It isn’t just a financial issue: 40% also faced operational disruption and 29% reported degraded customer experiences.
Investment priorities are shifting to address AIspecific risks. Agentic discoverability tools lead security spending on agentic AI infrastructure at 56%, followed by API security (55%) and web application firewalls (54%).
Nobody knows who’s actually responsible when
Three-quarters (75%) worry about DDoS attacks targeting
things go wrong. Half of AI-first businesses (51%)
AI agents, while 53% acknowledge they lack AI-specific
report confusion over who handles incident response,
security expertise.
compared to 23% of non-AI-first organizations. Traditional accountability is rapidly deteriorating because teams can now include humans and self-thinking, self-learning, and self acting AI agents.
The path forward requires a mindset shift. Enterprises must monitor AI crawler activity, anticipate shadow AI adoption, and strengthen perimeter defenses before expanding the attack surface. It’s also prompting a rethink of web application and API protection (WAAP) solutions; companies are starting to view them as business-critical infrastructure rather than niche solutions.
AI-first companies tend to suffer from AI-related compromises
17%
25%
0% - No known attacks involved AI
1-10%
27%
17%
11-25%
26-50%
6%
6%
4%
More than 50%
We don’t have the visibility to determine this
We have not experienced an attack where AI was involved
Hurtling towards a cybersecurity crisis
2
The AI-first paradox AI is a potential productivity booster, but as with any
One apparent cause traces back to what security
enabling technology, it requires a strategic balance
teams can’t see. Shadow AI (unauthorized tools that
between innovation and security. Organizations that
employees adopt without IT approval) runs 31% higher
brand themselves as “AI-first” and race to integrate
among a quarter of employees at AI-first organizations,
artificial intelligence must find this balance to truly apply
presumably because the culture encourages innovation
AI’s benefits. At the moment, these businesses take an
with AI. But for Marshall Erwin, CISO at Fastly, sanctioned
average of 6.8 months to recover from cybersecurity
AI tools are at least as much of an issue as shadow AI.
incidents, which is 80 days longer than their non-AI-first peers, who recover in just about 4 months. They have some work to do.
Approved AI tools often receive extensive automated permissions, and companies already struggling with identity and access management in a pre-AI world are watching that problem explode. “These tools are going
“The AI tools themselves are going to be privileged parts of your infrastructure, and that’s what’s going to create the risk.”
to expand potential access risks,” Erwin warns. “The AI
— Marshall Irwin, CISO at Fastly
security oversights that contributed to their last breach.
tools themselves are going to be privileged parts of your infrastructure, and that’s what’s going to create the risk.” The numbers support this conclusion. Over a third (34%) of AI-first organizations cite AI usage as a factor in That compares to 20% in traditional organizations.
Innovation is a critical business advantage, but
Think of AI tools as machine entities requiring their
organizations that create robust security measures to
own identity governance. Automated privileges allow
protect AI data, infrastructure, and processes will be
automated attacks. The more agentic these tools get
better positioned to innovate than those who don’t.
(meaning the more complex their autonomous tasks) the
Incidents cost AI-first businesses 135% more than non-AI-
bigger that risk will become.
first organizations. The recovery gap translates directly
(44%) of AI-first organizations report that AI was directly exploited in their most recent security incident, compared
70 60 50 40
45%
30
1
29%
20
21% 6%
10 0
Ye a n s ‚ fo d p rm ub ally lic ly
to a mere 6% among non-AI-first businesses.
74%
80
Ye s
infrastructure that companies must protect. Almost half
90
%
AI introduces more complexity, more code, and more
100
ar No A I e ex ‚ b u t i nt p l w eg ori e ra ng tio n a r N o‚ A I e ex b u t i nt p l w eg ori e ra ng tio n
AI creates its own attack surface
AI-first organizations took longer to recover from security incidents than non-AI-first ones
Y i nf es, or bu ma t lly
reputational damage.
percentage of people who agree
into lost revenue, extended downtime, and prolonged
(employees using unsanctioned AI tools)
Hurtling towards a cybersecurity crisis
3
How AI scrapers hit the bottom line
WAAP becomes essential
Shadow AI invites accidental misuse of AI inside
These realities are changing how organizations think
an organization, but there are also risks from third
about their security stacks. WAAP might once have been
parties using AI. These malicious actors can target an
lower on the list of security tools for some companies, but
organization’s content using scraper bots. AI scraping
it’s now becoming part of their core infrastructure. It’s the
is costing companies serious cash as it puts their
control layer for managing costs and securing the APIs
infrastructure under strain.
that underpin modern digital services from those both
Approximately two thirds of businesses (64%) say
inside and outside a company.
AI scraping has become a material cost center, with
Enterprises are voting with their wallets. When they invest
expenses soaring over $348,000 annually on average.
in protecting agentic infrastructure, organizations are
That’s hitting infrastructure bills and operational budgets
prioritizing agentic discoverability (56%), API security
hard. More than four in ten companies have watched
(55%), and web application firewalls (WAFs, at 54%).
infrastructure expenses climb as AI activity ramps up.
These non-traditional security categories are direct
Another 40% report operational disruption, while 29%
responses to architectural patterns that barely existed
are dealing with user experience problems. Sluggish load
two years ago.
times, broken functionality, and degraded performance are the kinds of problems that send customers elsewhere if they persist. Old-school external attack techniques can do serious damage to AI infrastructure. Three quarters of respondents to Fastly’s survey worry about DDoS attacks hitting AI agents. What this means is that even companies who don’t use AI internally should be mindful of how others might use it to exploit them. None of these risks should stop companies from embracing AI, but the winners will be those who innovate while also adjusting their security postures accordingly. That means either finding the skills to do so (53% admit their security teams lack the AI specific expertise to deal with these threats) or working with a third-party partner to help manage the risks.
Hurtling towards a cybersecurity crisis
4
When bugs beat breaches Our research showed that in 2025, the number of security incidents stayed flat. Organizations faced an average of 41 known incidents, up just one from 2024. But the headline number tells you almost nothing. What’s actually breaking tells a more realistic story. Software bugs actually triggered 40% of incidents, up from 33% in 2024, moving it from second place to the top slot, knocking the incumbent top cause (external attackers) down to second place at 39%. Misconfigurations took third place, up to 29% from fourth place at 25% last year. More than ever, companies are wrestling with security failures that have nothing to do with sophisticated threat actors and everything to do with how they write their code or configure their infrastructure (which is increasingly also done with code).
Software bugs actually triggered 40% of incidents, up from 33% in 2024. Ninety percent of organizations suffered at least one cybersecurity incident, but it’s clear that these stem from development problems, process problems, and maybe cultural problems in the enterprise. Clearly organizations cannot take their eyes off the perimeter, but it’s time for them to elevate their focus on budget allocation and team structure rather than organizing purely around external threats. Scale amplifies all these issues. Large enterprises with 10,000+ employees averaged 57 incidents, nearly 40% above the mean of 40. Sprawling attack surfaces and tangled development pipelines create more opportunities for things to break. Smaller organizations deal with the same issues at a smaller scale, which helps but doesn’t eliminate the problem.
Hurtling towards a cybersecurity crisis
5
A silver lining in incident recovery The Fastly survey revealed some genuinely good news: organizations are getting better at bouncing back from attacks. Average recovery time dropped to 6.08 months
Investment in response capabilities pays off
in 2025 from 7.34 months the previous year. That’s more
Organizations are putting money where it matters.
than a month off the recovery timeline, representing a
Over half (52%) invested in post-incident reviews,
meaningful improvement when every day of downtime
systematically analyzing what went wrong and how to
costs money and erodes customer trust.
prevent it next time. Another 43% have implemented
The gap between expectations and reality is closing too. Organizations now expect recovery to take 5.89 months, and the actual timeline of 6.08 months is remarkably
response automation, using technology to speed up containment and recovery steps that previously required manual intervention.
close. This alignment suggests that companies are
But there are significant caveats buried in these positive
developing more realistic incident response plans based
trends. Despite the improvements, 30% of organizations
on actual experience rather than wishful thinking.
still lack regularly tested incident response playbooks.
Financial impacts are also trending in the right direction.
The pressure is on to squeeze real recovery times further.
Revenue losses averaged 2.68% of annual income, down
And while companies might recover quickly, lighting
from 2.98% last year. While that’s still painful (a mid-sized
frequently strikes twice or even more. Two thirds (66%)
company losing nearly 3% of revenue is taking a serious
of organizations suffered repeat incidents within three
hit), the trajectory matters. Organizations are containing the
months, as underlying problems might still exist.
damage more effectively than they did twelve months ago. Lastly, customers seem to be more forgiving once they see a company making efforts to fix its cybersecurity problems. Reputational recovery averages 4.73 months, faster than the 6.08 months needed to fully restore systems and operations. Managing the crisis narrative and maintaining customer communication can rebuild trust even while technical teams are still cleaning up the mess.
Recovery expectations are getting more realistic 2025
2024 Expected recovery time 50
Actual recovery time
Expected recovery time 50
44%
40
45% 41%
40
34%
30
Actual recovery time
30
5%7
%
rs Ye a
nt mo
2+
hs
hs -2 4 19
-18
mo
nt
16
mo -15 13
mo -12
nt
hs
hs nt
hs nt 10
mo 79
6m
on
th
s
hs
Hurtling towards a cybersecurity crisis
W e e d ma xp e id n ke c t o t r e a to co fu ve l l ry
2%2% 1% 1% 1% 1% 1% 0%
0 nt
rs
W e e d ma xp e id n ke c t o t r e a to co fu ve l l ry
nt mo
Ye a
hs
hs -2 4 19
-18
mo
nt
16
mo -15 13
mo -12
nt
hs
hs nt
hs 10
mo
nt
s 79
th on 6m 4-
1-3
mo
nt
hs
0
5% % 2% 1% 3 1% 2 % 1% 1% 2+
5%6%
11% 14%13% 11%
10
mo
13%12% 12% 11%
10
21% 21%
20
1-3
20
4-
19% 19%
6
Investment priorities: where security dollars are really going Ask security teams what keeps them up at night and data
Cyber insurance was the second most popular
breaches naturally top the list at 45%. Social engineering
investment category at 34%, followed by API security
comes in second at 40%. That makes sense, given
at 33%. Cyber insurance’s runner-up status is a sign of
that phishing emails remain the launch point for most
acceptance. Organizations realize that a perfect defense
successful attacks. Fancy technology still won’t stop a
is impossible, so they’re transferring risk. Can’t prevent
harried employee from clicking a convincing link late on a
every breach? At least make sure you’re not absorbing
Friday afternoon.
the entire financial hit when one lands.
Ransomware (often launched using these social engineering attacks) ranks highly at 28%, after generative AI and a lack of technical skill. After years of headlines, that shouldn’t surprise anyone, companies are still falling victim to it. Just because the playbook is well understood
With mounting risks, it’s no wonder that data protection and privacy lead investment priorities at 37%.
by now doesn’t make it easier to stop. These risks don’t exist in isolation. Account takeover (19% cite this as a worry) also usually starts with phishing.
The API security investments make sense when you consider that every new mobile app, third-party integration, and microservice creates another potential
However, the third-party risks deserve particular
entry point. APIs used to be internal plumbing. Now
attention. September’s attack on the npm software
they’re exposed to the internet and attackers have
repository showed how a single attack can infect
noticed.
hundreds of packages, trickling malware into countless user environments. When your security depends partly on someone else’s, you’re adding risk you can’t directly control.
The real investment shift shows up in AI. The survey found that organizations are preparing for agentic infrastructure threats. Among those investing in this area, agentic discoverability tops the list at 56%,
With mounting risks, it’s no wonder that data protection
followed by API security at 55% and WAFs at 54%. These
and privacy lead investment priorities at 37%. The shift
non-traditional security categories are responses to
toward data protection reflects mounting regulatory
architectural patterns that barely existed two years ago.
pressure and the realization that data breaches carry consequences beyond immediate technical remediation. Compliance violations, customer lawsuits, and brand damage all stem from mishandled data.
Three quarters of companies are worried about DDoS attacks targeting AI agents, and over half admit their teams lack the AI specific expertise to handle these threats. Yet DDoS protection ranks just fifth as an investment priority at 30%. There’s a disconnect between stated concerns and actual spending that suggests either misplaced priorities or constrained budgets forcing uncomfortable tradeoffs.
1
2
“ Widespread Supply Chain Compromise Impacting Npm Ecosystem | CISA.” Cybersecurity and Infrastructure Security Agency CISA, 23 Sept. 2025, www.cisa.gov/news-events/alerts/2025/09/23/widespread-supply-chain-compromise-impacting-npm-ecosystem
Hurtling towards a cybersecurity crisis
7
CISOs have more responsibility but hollow support The CISO’s chair is getting hotter. Nearly three quarters
(in other words, reading the rules properly). Of
(73%) of organizations now say the CISO is ultimately
respondents surveyed, 45% are now offering more legal
responsible when breaches occur. Regulatory pressure
support for cybersecurity staff.
is increasingly showing that security leaders can face personal liability for failures. For example, The EU’s 2022 NIS2 Directive allows temporary suspensions of executives deemed incapable of fulfilling their cybersecurity responsibilities, along with damages to be levied against general managers and CEOs.
with 82% reporting active participation and 74% seeing increased CISO engagement over the past year. On paper, this looks like security getting the executive attention it deserves. In practice, the response has been less impressive.
finally giving the CISO a seat at the table for strategic decisions (that ties almost joint first with additional legal support and resources for cybersecurity teams, which each come in at 45%). That’s at least giving them some kind of voice, but that alone isn’t enough to stop the rot. Security leaders need the authority and resources
Nobody knows who’s in charge
64%
60
The confusion extends beyond technical vulnerabilities
50
into organizational structure. Over half of AI-first
40
businesses report a lack of clarity over who is responsible
36% 26%
30
24%
for incident response, compared to just 23% of non-
24%
18%
20 10
AI-first organizations. Yet when breaches occur, blame 1%
Pro ma n du c tio n agem e nt N res p o s ha r e o it ’s c ns ib il it y d e ntr a lize – d
O ps D ev
P e n g inlat fo r m e e r in g
E xe c lea d u tive e (C I S r s h ip O et c) Le g a l a com p li a n n d ce
cu r it erse C yb
e r at IT op
y
0
io ns
% of responsibility by department
improving your security posture.”
responsibility when things go wrong.
Policy changes miss the point
1
self-preservation,” says Erwin. “Those aren’t actually
to implement necessary security measures, not just the
When it comes to cybersecurity, everyone has a part to play 69%
policies’. “These measures are nice, but little more than
One of the most common measures, cited by 44%, is
CISO involvement in incident response has also jumped,
70
These are colloquially known as ‘CYA (cover your ass)
flows uphill, with 79% of AI-first businesses reporting the CISO is ultimately held responsible versus 57% among traditional organizations. As AI-first organizations create new risks faster than they can manage them, this issue will take center stage for security leaders. They will shoulder the blame as the inevitable breaches follow those risks.
Most organizations (94%) made policy changes in
Confusion doesn’t just cause problems at the top. Our
response to growing CISO accountability. But dig into
research shows that 43% of people within enterprises feel
what those changes actually entail and the picture gets
there’s clarity around who’s responsible for incidents – the
murky. Many measures are defensive, with 42% promising
same percentage feel there isn’t (with the remainder on
increased scrutiny of security disclosure documentation
the fence).
3
ricewaterhouseCoopers. “What You Need to Know about NIS2 - PwC.” PwC, 2023, www.pwc.de/en/cyber-security/european-nis2P directive-implications-for-businesses-and-institutions.html.
Hurtling towards a cybersecurity crisis
8
Solving the skills strain The talent problem is getting worse, not better. More than half (53%) of security teams lack the AI specific expertise needed to respond to emerging threats. This isn’t just about general cybersecurity skills anymore. The rapid adoption of AI infrastructure has created demand for specialized knowledge that the market can’t supply.
Alternatives to external recruitment Perhaps companies should look inwards instead. Several options deserve consideration. Upskilling existing staff for new responsibilities means they’re already aligned with your culture and at least partly fluent in your specific systems and processes. These people understand the business context, which matters as much as technical capability when making security decisions under pressure. Mentoring provides on-the-job training from experienced staff, cementing junior employees’ skills and shaping them for success. It’s slower than hiring someone with 10 years of experience, but those experienced candidates are increasingly hard to find and expensive to recruit. Cross-functional collaboration between security and other teams like IT, compliance, support, and product development can create well-rounded employees with
AI first organizations are especially hungry for talent. They’re moving fast and building new systems. They’re
a strong sense of how security fits into other functions. There are opportunities for secondments here.
also discovering that traditional security expertise
Sourcing talent from within, especially across different
doesn’t translate cleanly to protecting AI agents,
functions, carries several advantages. It promotes the
managing agentic infrastructure, or defending against
idea that everyone is responsible for security. It also
AI powered attacks. The skills shortage has become a
supports digital transformation efforts by embedding
bottleneck limiting how quickly they can secure their
security expertise throughout the organization rather
expanding technology footprints.
than concentrating it in a single team that becomes a
Fresh cybersecurity graduates face a steep learning
bottleneck.
curve. They must learn technical skills specific to a company’s toolset and workflow, plus organizational cultural nuances. It takes substantial time and effort before a raw recruit becomes productive. As companies scale, this challenge intensifies, particularly when working in larger, constantly evolving environments.
Hurtling towards a cybersecurity crisis
9
How threats vary by sector The aggregate data tells one story, but drilling down
Government
into individual sectors reveals how unevenly the
Nation-state attacks are understandably the
cybersecurity burden falls across different industries.
big issue for government respondents, worrying
Some face existential threats to their core business
21% of security teams (markedly more than the
models, while others grapple with geopolitical risks
percentage in commercial sectors). The percentage
or the operational chaos of securing sprawling digital
fretting about data breaches tops out at 52%, the
estates. Here’s how the threat landscape breaks
highest anywhere.
down sector by sector.
Retail
Finance
Retailers seem to get hammered from every
Finance averages 54 breaches a year.
direction. DDoS attacks are a concern for 25% of
Phishing still worries 39% of organizations, and
them, (the highest rate across all sectors), while
data breaches concern 42%, but the killer statistic
ransomware worries among retailers match those in
is $442,232. That’s the average increased annual
the finance community at 32%. And a sector-high
infrastructure cost from AI scraping alone, and it’s
32% skills gap means payment systems and customer
the highest across all sectors. Perhaps that’s why
data aren’t properly defended.
generative AI worries 41% of financial institutions. Only tech companies are more anxious about it.
Media and entertainment
Sectors may have differences that cause them to score differently in various aspects of cybersecurity, but one thing is universal: they all pay an AI tax
This sector breaks the mold entirely. It
now. Scraping costs run from nearly $300k-$450k
shoulders the lowest number of breaches across
annually across named sectors. The traditional
all sectors, at 24. However, content scraping is a
threats such as identity attacks and data breaches
business model threat, with one in five of these
haven’t gone away, but AI has added mandatory new
companies identifying it as a major concern, versus
costs to running digital operations.
5-16% elsewhere. That shows up in the 51% of media companies suffering elevated infrastructure costs from AI scraping, the 47% encountering operational disruption, and the 39% reporting customer experience issues – all of which are cross-sector highs. Just 11% report no impact. Financial organizations lost the most on average from their single biggest security incident in 2025
Mean % of revenue loss
5 4 3 2 1
3.24% Finance / Accounting
2.14% Government / Public Sector
2.92% Healthcare / Life Sciences
0
Hurtling towards a cybersecurity crisis
1.86% Media / Entertainment / Travel & Tourism
2.79% Retail / Wholesale (including e-commerce)
10
The path forward: security by design in an AI-accelerated world With internal mistakes now causing as many breaches as external attacks and software bugs triggering 40%
Two problems, one solution
of incidents, you’d think this would spark a fundamental
AI creates both external and internal security challenges.
rethink of how organizations build software. But it hasn’t.
On one side sits the operational cost problem from external AI threats. AI scraping bleeds infrastructure
“I can’t wait for someone to come to me for approval, because if that’s happening, then I probably already failed.” — Marshall Irwin, CISO at Fastly
budgets so badly that 64% of organizations now consider it a material cost center. That’s because bots are crawling their sites, consuming bandwidth, degrading performance, and increasing their cloud bills (not to mention misappropriating valuable intellectual property). On the other side sits the attack surface problem facing
Only 37% have shifted security responsibility to platform
companies’ own AI infrastructure. Agentic infrastructure
engineering or DevOps teams.
and privileged AI tools create new vectors for attackers.
Participating in conversations before architecture decisions are made is crucial. “I can’t wait for someone
These highly privileged tools can give attackers deep access to infrastructure if exploited.
to come to me for approval, because if that’s happening,
Both problems converge at the same point: web
then I probably already failed,” Erwin says.
applications and APIs. WAAP solutions defend both
DevOps automation helps, but only with tactical problems. Your continuous integration/ continuous delivery (CI/CD) pipeline won’t catch architectural mistakes like giving an AI agent excessive privileges that open your infrastructure to attack. Those require human judgment during design.
fronts. The same layer that throttles scrapers burning through your infrastructure budget also protects the APIs underpinning agentic systems. Web application firewalls that block layer-seven attacks work whether the target is traditional infrastructure or AI agents. Organizations investing in agentic security get this.
The automation ceiling Automation is an important part of the security equation,
company in the tech space today,” notes Erwin. Combine
“The volume of potential vulnerabilities that you need to look at and get ahead of is high for just about any mature company in the tech space today.”
high volume with high false positive rates and automation
— Marshall Irwin, CISO at Fastly
because it helps to bridge the talent gap. However, even companies committed to automation hit limits. “The volume of potential vulnerabilities that you need to look at and get ahead of is high for just about any mature
only gets you so far. Erwin advises automation for managing less serious issues and keeping expert humans for serious incidents. Let the machines handle routine vulnerabilities. Save human expertise for the tricky stuff that requires context and judgment. Hurtling towards a cybersecurity crisis
11
How to fix security before you start
AI is rewriting business operations at a pace that makes
AI-first businesses must learn the value of measured
leisurely. Companies building that new infrastructure
movement. So if they move fast and break things, it
without security architects in the room from the first
takes them longer to pick up the pieces. That’s why AI
conversation are going to join the large community of AI-
organizations are increasing security spending yet feel
first organizations that saw AI directly exploited in their
more vulnerable.
most recent breach.
It’s also why security by design has moved from an
There will be a demarcation line between those who
aspirational goal to a survival requirement. The 81%
embedded security into their AI strategy and those who
who say resilience investments safely accelerated their
bolted it on afterward. The good news is that you control
innovation have already figured this out.
which side you stand on.
the economy’s decade-long migration to the cloud look
Security architecture built into systems from the beginning remove uncertainty, enabling teams to move faster with confidence. The alternative is what we’re seeing now: organizations spending more, recovering slower, and wondering why buying more tools didn’t fix anything. It’s no coincidence that 72% of organizations prioritize speed-to-market over building resilience into systems.
Security benefits of implementing AI fro the start
Early implementation AI development
$
Security by design Efficiency
Cost savings
Robust system
Mid-stream implementation Delays AI development
Security implementation Vulnerabilities and retrofitting
$ increased costs
Hurtling towards a cybersecurity crisis
Patchwork
12
About the research
About Fastly, Inc.
This research surveyed 2,000 key IT decision makers
Fastly’s powerful and programmable edge cloud platform
with an influence in cybersecurity, in large organizations
helps the world’s top brands deliver online experiences
spanning multiple industries across North, Central and
that are fast, safe, and engaging through edge compute,
South America, Europe, Asia-Pacific, and Japan. The
delivery, security, and observability offerings that
interviews were conducted online by Sapio Research in
improve site performance, enhance security, and
Q4 2025 using an email invitation and an online survey.
empower innovation at global scale. Compared to other
Results of any sample are subject to sampling variation.
providers, Fastly’s powerful, high-performance, and modern platform architecture empowers developers to
The magnitude of the variation is measurable and is
deliver secure websites and apps with rapid time-to-
affected by the number of interviews and the level
market and demonstrated, industry-leading cost savings.
of the percentages expressing the results. In this
Organizations around the world trust Fastly to help
particular study, the chances are 95 in 100 that a survey
them upgrade the internet experience, including Reddit,
result does not vary, plus or minus, by more than 2.6
Neiman Marcus, Universal Music Group, and SeatGeek.
percentage points from the result that would be obtained
Learn more about Fastly at https://www.fastly.com, and
if interviews had been conducted with all persons in the
follow us @fastly.
universe represented by the sample.
About Sapio Best new agency finalist, Sapio is adept at opinion polling (we have access to 80 million people internationally), focus groups, face-to-face interviews, telephone interviews, online research, desk research and statistical modelling to mention just a few techniques. We love B2B research and consultancy. Our business is based on partnership principles inspired by social enterprise.
Hurtling towards a cybersecurity crisis
13