WAAP v5.0 Comparative Report

WAAP CyberRisk Validation 5.0 Comparative Report — SecureIQLab

See Where the Field Splits on APIs

The Cloud WAAP CyberRisk Validation v5.0 Comparative Report measures 12 leading cloud WAAP solutions against an identical evidence base, providing independent data on WAF, API, advanced threats protection and AI security capabilities that extend beyond vendor claims.
Download the Report
Cover of the SecureIQLab WAAP CyberRisk Validation v5.0 Comparative Report evaluating 12 cloud WAAP solutions

The Problem

Enterprises test for the attacks they have always tested for. A decade of shared testing experience has pushed the whole WAAP market toward near-ceiling performance on legacy attack classes: Layer 7 denial of service, WAF vulnerability assessment, and the familiar OWASP web categories.

Attackers have moved on, and the evidence has not kept pace. APIs, WebSocket channels, and LLM integrations are now first-class parts of production environments, but protection for them is inconsistent and largely unmeasured. Vendor documentation describes coverage in language buyers cannot verify, and no independent comparative had put these newer surfaces on the same instrumented footing as the legacy ones.

The WAAP CyberRisk Validation v5.0 comparative report closes that gap. It replaces vendor-rated specifications with measured performance across traditional web application security, API security, and AI-enabled application security, so security teams can see exactly where deployed protection holds and where it breaks.

What You’ll Learn

How a two-speed industry shows up in the data

Across 12 leading cloud WAAP solutions, group averages reached 97.9 percent on Layer 7 DoS attacks and 99.7 percent on WAF vulnerability assessments, the attack classes enterprises have been testing for more than a decade. On the surfaces this methodology measured first, the same products averaged 48.3 percent on WebSocket API protection and 58.3 percent against API privilege escalation. The report shows the gap category by category.

Where API protection breaks down today

Six of the 12 products scored zero on WebSocket API protection. Privilege-escalation attempts against APIs, the Broken Object Level Authorization category, succeeded against a third of the field entirely.

What AI-enhanced testing revealed about AI-defended products

This is the first WAAP methodology to include LLM security testing and the first to validate AI-defended products with AI-enhanced payloads. Prompt Injection (LLM01:2025) defense ranged from 100 percent down to 35 percent, while Improper Output Handling (LLM05:2025) averaged 99.4 percent, evidence that the exposure is technique-specific rather than a general AI weakness.

Why false-positive spread is an operations problem, not a footnote

On 1,452 identical benign requests, four of the 12 products produced zero false positives, the group median was 9, and the highest count was 275, an 18.9 percent false-positive rate on the same traffic other products passed untouched. For security operations teams, that spread is a direct measure of alert-triage workload and blocked legitimate transactions.

What the Compliance pillar measured

The Compliance pillar covers regulatory, audit, logging, and governance validation across web and API workloads, organized into five evaluation layers. The report publishes no per-layer breakdown, so no individual layer can be named highest or lowest. Group scores spanned 47.8 percent to 87.0 percent and averaged 63.95 percent, with six of the 12 above the group average, evidence that compliance evidence generation lags well behind detection capability.

Report Preview

What’s Inside the Comparative Report

  • The CyberRisk Ripple placement for each of the 12 solutions, derived from overall Security Efficacy and Operational Efficiency scores, with every solution named and placed
  • Results across all 7 test categories and 6 validation pillars: Security Efficacy, Operational Efficiency, AI Application Security & Operational Efficiency, Secure-by-Design & Secure-by-Default, False Positive Avoidance, and Compliance
  • Category-level score ranges across the seven security-efficacy areas the report scores, from OWASP Top 10 (2025) web threats to API security, with OWASP LLM and GenAI results reported independently
  • Group averages by category and false-positive avoidance scores on the combined benign traffic base
  • The Compliance results, covering regulatory, audit, logging, and governance validation across web and API workloads
  • Operational Efficiency findings, the industry’s strongest pillar, validated across 9 areas and 57 features and functions, where 10 of the 12 products scored above 90 percent on the overall Operational Efficiency rating
  • The statistical appendix, with Matthews Correlation Coefficient, Precision, and Recall reported per solution against cohort averages of 0.90, 0.96, and 0.94

The 12 Vendors Evaluated

The public comparative evaluated 12 leading cloud WAAP solutions, listed alphabetically: Akamai, AWS, Check Point, Cloudflare, F5, Fortinet, Gcore, Harness (formerly Traceable), Imperva, Microsoft, Prophaze, and UBIKA. Every product faced an identical evidence base and scoring rubric.

Validation Approach

Element Detail
Methodology Cloud WAAP CyberRisk Validation v5.0 Methodology (Last Revision: March 12, 2026)
AMTSO Test ID AMTSO-LS1-TP169 (Testing Protocol Standard v1.3)
Frameworks aligned MITRE ATT&CK, OWASP Top 10 (2025), OWASP API Security Top 10 (2023), OWASP LLM Top 10
Pillars in scope 6 validation pillars: Security Efficacy, Operational Efficiency, AI Application Security & Operational Efficiency, Secure-by-Design & Secure-by-Default, False Positive Avoidance, and Compliance
Attack payloads per vendor 1,608
Benign requests per vendor 1,487
API protocols tested REST, SOAP, GraphQL, gRPC, WebSocket
New evaluation areas introduced 3 (AI-assisted bot attacks, API gateway operational efficiency, LLM/GenAI security)
AMTSO attestation signed by David Ellis, VP of Research and Corporate Relations at SecureIQLab, AMTSO Board of Directors

What Makes WAAP CyberRisk Validation v5.0 Different

WAAP v5.0 introduced three brand-new evaluation areas and used AI-enhanced payload qualities for more sophisticated attack simulation. It is the first WAAP methodology to include LLM security testing, covering the Prompt Injection and Improper Output Handling risk categories from the OWASP LLM Top 10.

What SecureIQLab Says

“The industry has mastered the attacks it has spent a decade testing. The gaps this validation measured sit exactly where attackers are moving next. Those surfaces are API session logic, WebSocket channels, and prompt injection. Enterprises deserve measured evidence of protection for them, rather than datasheet claims.”

— David Ellis, VP of Research and Corporate Relations at SecureIQLab

Source Credibility

Independent and Unbiased

SecureIQLab is an independent cloud security validation laboratory. Every product in the comparative was tested under identical conditions, with the same attack payloads, the same benign traffic, and the same scoring rubric. No vendor or buyer can influence results, and no vendor can prevent publication. Findings are presented as verified performance metrics, not ratings or endorsements.

Standards-Governed Methodology

The methodology complies with the Anti-Malware Testing Standards Organization (AMTSO) Testing Protocol Standard v1.3 and is registered as AMTSO Test ID AMTSO-LS1-TP169. AMTSO compliance requires transparency in payload selection, scoring-rubric publication, and formal vendor-dispute procedures. The AMTSO attestation is signed by David Ellis, VP of Research and Corporate Relations at SecureIQLab, who serves on the AMTSO Board of Directors. The methodology is published in full so anyone can examine the process.

Aligned With Recognized Frameworks

The methodology maps outcomes to MITRE ATT&CK, OWASP Top 10 (2025), OWASP API Security Top 10 (2023), and the OWASP LLM Top 10. SecureIQLab is a principal member of Mplify (formerly MEF) and a member of the Anti-Malware Testing Standards Organization (AMTSO), AVAR, and NetSecOPEN.