Web application security incidents have become far too common. Fifty-one percent of respondents reported
having at least one such incident (see Figure 1). It’s worth noting that within this group, 13% reported that they
experienced five or more incidents. Forrester suspects that many of those who reported that they have had no
breaches may have indeed suffered a breach — they just don’t know it. Today’s cybercriminals target their attacks
and do everything in their power to conceal their activity — it’s not unusual for an attack to go undetected for an
extended period of time. These statistics should be a wakeup call to the entire industry: if 51% or more of
randomly surveyed organizations have experienced at least one web app security incident in less than 24 months,
it’s clear that application security is in a dismal state.