Gartner® Hype Cycle™ for Application Security, 2025

Explore essential app security innovations shaping 2025 in the latest Gartner Hype Cycle.
Topic
AI & the future of cybersecurity
Updated
5 Sep 2025

Download report

Explore essential app security innovations shaping 2025 in latest Gartner Hype Cycle. Gain insights into application shielding, securing AI-driven applications, and addressing emerging threats in mobile security.

Stay ahead of evolving cybersecurity threats and secure your organization's critical applications.

What we find interesting in the 2025 Gartner® Hype Cycle™ for Application Security:

    • Application shielding protects an enterprise’s software and applications when running on untrusted devices from cloning, information leakage, fraud, intellectual property (IP) theft and other forms of abuse. . Application shielding is on the Slope of Enlightenment in the Gartner Hype Cycle, which we feel is reflecting its growing understanding and broader adoption.
    • How AI-driven development introduces new vulnerabilities and why Gartner expects AI coding practices ("vibe coding") to account for 30% of application security exposures by 2027.
    • Through 2029, over 50% of successful cybersecurity attacks against AI agents will exploit access control issues, using direct or indirect prompt injection as an attack vector.

“Mobile applications move software logic and place sensitive data on the user devices. These applications expose functionality that, unless shielded, can lead to attacks such as data exfiltration from the app or its back end, and fraud against the user or the application. Application shielding is an important security measure when applications convey or store sensitive data or enable payments.”

Gartner, Hype Cycle™ for Application Security, 2025, Dionisio Zumerle, 22 July 2025

 

Disclaimer

Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.

GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally, HYPE CYCLE is a registered trademark of Gartner, Inc. and/or its affiliates and is used herein with permission. All rights reserved.

This graphic was published by Gartner, Inc. as part of a larger research document and should be evaluated in the context of the entire document. The Gartner document is available upon request from Promon.

 

Highlights from the report

Application security innovations are rapidly evolving to tackle new AI-related threats, the convergence of security tooling, and increasing DevSecOps maturity. Learn how leading organizations adopt these trends to secure their mobile apps and sensitive data.
30%
By 2027, at least 30% of application security exposures will result from usage of vibe coding practices.
40%
By 2026, at least 40% of organizations will default to their application security testing vendors for AI-based autoremediation of vulnerable code.
50%
Through 2029, over 50% of successful cybersecurity attacks against AI agents will exploit access control issues, using direct or indirect prompt injection as an attack vector.
file_copy
Download the Gartner® Hype Cycle™ for Application Security, 2025
Download
Want to stay in touch? Follow us on LinkedIn or Instagram.

Promon

Promon is the leader in proactive mobile app security. We exist to make the world a little bit safer, one app at a time.

Get the latest from Promon

Get expert insights, best practices, and the latest updates on mobile app protection straight to your inbox. Subscribe to the Promon blog today!
Subscribe