Fastly, Inc. released new research in partnership with Enterprise Strategy Group (ESG) that uncovers a crucial need for a unified, modern, and simplified approach to security. The study, based on insights from information security and IT professionals representing hundreds of organizations globally, revealed growing concerns around adequately securing the rapidly rising number of mission-critical cloud services and API-centric applications. Outdated offerings, false positives, and ineffective blocking are among the main causes driving this global concern. As organizations around the world are faced with the task to digitally transform, many of the traditional tools and services no longer support the modern needs and architectures of the digitized world. While the increased need for flexibility, agility, and speed continues to drive the evolution of application development and increased deployment of microservice-based architectures, many organizations have not updated their security tooling and continue to rely on traditional web application and API security tools to protect their business. Research from the study concludes: On average, organizations use 11 web application and API security tools and spend close to $3 million dollars annually. Security is becoming more complex and costly as organizations are required to protect traditional architectures, in addition to new architectures and cloud environments. Traditional security tools are ineffective and impede business growth. Current security tools frequently block harmless business traffic, impacting the organization’s bottom line. As a result, 91% of organizations run tools in log or monitoring mode, or shut them off entirely. Nearly half of all security alerts are false positives. False positive downtime frequently causes similar downtime to actual attacks, suggesting current security tools are causing more problems than they solve for. More than half of organizations believe most or all of their applications will use APIs in the next two years. Despite an anticipated increase in API implementation, half of organizations stated that web application and API security is more difficult than two years ago and indicated struggles to maintain adequate security across new application architectures. Driving these difficulties is the shift to public cloud and API-centric applications without a modern security solution to support those innovations.