Cypress Data Defense and TechStudio released its 2025 State of Application Security Report, revealing a growing crisis in software security. The findings reveal a concerning trend: 62% of organizations knowingly release insecure code to meet delivery deadlines. Furthermore, as cyber threats escalate, security teams face burnout, insufficient resources, and a disconnect between investment and actual risk.
Conducted in partnership with TechStudio, the survey gathered insights from 250 senior IT and security leaders across North America. It outlines a critical disconnect between AppSec investment and the scale of risk. While the average cost of a breach in the U.S. has reached $9.48 million, nearly 90% of teams allocate just 11-20% of their security budgets to application security.
“False positives, talent shortages, and late-stage vulnerability detection are creating a perfect storm for application security teams,” said Aaron Cure, Co-Founder and Director of Cyber Security at Cypress Data Defense. “Organizations urgently need proactive AppSec strategies and managed services to keep pace with modern threats.
Key Findings:
Security Delays Threaten Software Releases
- 60% say security issues are more likely to delay product launches than feature bugs.
- Only 36% involve security at the planning stage; 57% wait until just before deployment.
Security Teams Under Intense Pressure
- 62% admit to pushing insecure code to production under deadline pressure.
- 58% report frequent false positives from security scanners; 11% say they occur constantly.
- 51% of teams have fully addressed OWASP Top 10 threats-leaving nearly half exposed to foundational risks.
AppSec Budgets Misaligned with Rising Risk
- Despite application layer attacks accounting for 43% of breaches, 36% of companies spend more on network security than AppSec.
- Nearly 90% allocate only 11-20% of their security budgets to application security.
- Just 1% invest more than 20% of their total security budget into AppSec.
Outsourcing Emerges as a Key Trend
- 83% are considering outsourcing AppSec functions.
- 8 in 10 AppSec professionals are open to outside help due to limited staffing, talent shortages, and constant development cycles.
The report underscores a clear crisis in morale and capacity. Burnout is rampant, and 62% of security professionals fear being fired following a breach. 17% believe termination is likely.
“Automated scanners generate alerts-but real security comes from expert validation and prioritization,” said Steve Kosten, Co-Founder and Director of Application Security at Cypress Data Defense. “Our State of Application Security report shows why managed AppSec services are becoming essential for modern development teams.”
Cypress’s hybrid AppSec model-including its EASy managed service-helps teams shift security left without slowing development. Its services include expert-led validation, secure code review, and scalable remediation support.
For a detailed look into the findings, download the 2025 State of Application Security Report.





