In the August 2026 SecureIQLab Cloud WAAP v5.0 CyberRisk Validation Comparative Report, Harness Web Application & API Protection (WAAP) was named a Leader. The analysis involves actual lab testing across 12 leading Cloud WAAP vendors and shows scores for each criterion evaluated — and we're thrilled to be one of just six vendors to earn Leader status, and one of only five to meet both of SecureIQLab's "Secure by Design" and "Secure by Default" criteria.

In the August 2026 SecureIQLab Cloud WAAP v5.0 CyberRisk Validation Comparative Report, Harness Web Application & API Protection (WAAP) was named a Leader. The analysis involves actual lab testing across 12 leading Cloud WAAP vendors and shows scores for each criterion evaluated — and we're thrilled to be one of just six vendors to earn Leader status, and one of only five to meet both of SecureIQLab's "Secure by Design" and "Secure by Default" criteria.
Figure 1: SecureIQLab 2026 WAAP v5.0 CyberRisk Ripple

Source: SecureIQLab, WAAP v5.0 CyberRisk Validation Report, August 2026
Independent testing conducted by SecureIQLab Inc. under the Cloud Web Application and API Protection CyberRisk Methodology v5.0.
The Numbers We're Proud Of
A few results from the report stand out to us:
- 100% effectiveness against the OWASP API Top 10. The agentic future runs on APIs. How well you protect your APIs is how well you protect your business. The group average for this category was 80.3%
- 100% coverage for advanced threats. SecureIQLab defines advanced threats as bot attacks, AI-assisted bot attacks, Layer 7 DoS and DDoS attacks, resiliency, and WAAP vulnerability assessment. Many of these bot attacks especially are business abuse rather than vulnerability exploits, which makes it essential to know your provider delivers strong efficacy here too, not just against classic exploits.
- 100% for ease of deployment and 100% for ease of management. A security solution can't protect your organization if your team can't actually implement and run it. This score reflects that Harness customers don't trade effectiveness for complexity.
- 100% False Positive Avoidance. Strong blocking only matters if it doesn't come at the cost of legitimate traffic. Harness caught the attacks without getting in the way of real users.
- A perfect 100% GenAI & LLM Operational Efficiency score — tied for the top score among all vendors tested, well above the 73% group average. As organizations race to operationalize AI, this reflects genuine enterprise readiness to deploy, manage, and govern AI security at scale, not just lab-condition detection. This is the first time the methodology included AI testing. The GenAI and LLM scores were rated independently and did not feed into the overall WAAP Operational Efficiency score.
Source: SecureIQLab, WAAP v5.0 CyberRisk Validation Report, August 2026
Independent testing conducted by SecureIQLab Inc. under the Cloud Web Application and API Protection CyberRisk Methodology v5.0.
How the Evaluation Worked
SecureIQLab evaluated WAAP vendors using its Cloud WAAP v5.0 CyberRisk Validation Methodology, assessing both security efficacy and operational effectiveness. Harness achieved a 99.8% Security Efficacy score and a 98.2% Operational Efficiency score, reflecting strong protection across modern web application, API, and AI security scenarios — placing Harness in the Leader segment of the CyberRisk Ripple.
Committed To A Security Landscape Rewritten By AI
The report focused on a specific set of AI protection capabilities, with tests covering OWASP LLM01 and LLM05. Harness sees that at the beginning of readiness for organizations as AI rewrites the security landscape. Harness continues to innovate to protect our customers as they face an environment where:
- Agents are being deployed at lightning speed. Many organizations don't even have full visibility into the agents and AI components already running in their environments. Harness can discover, test, and protect agentic operations across the entire lifecycle.
- AI is accelerating vulnerability discovery faster than most teams can keep pace with. Attackers are chaining together multiple low-risk vulnerabilities to create novel attacks. Detecting and blocking attacks that target vulnerabilities like those described in the OWASP Top 10 isn't optional — it's critical.
- The AI arms race has moved from LLMs to agents. Protecting apps built on LLMs was cutting-edge a year ago. It isn't nearly enough today. Organizations now need visibility and protection spanning agents, LLMs, MCPs, tool calls, and the broader set of AI components powering modern applications.
We invite you to read the report here, and call your Harness contact for a deeper conversation.


