F5 Hardened Release 1 is available. Staying current is one of the most important steps you can take to protect your environment.Learn more

SecureIQLab’s independent multi-vendor testing puts F5 in the Leader tier for security and operational efficiency

F5 ADSP | August 03, 2026

Modern applications are expanding faster than traditional security approaches can keep up. APIs, distributed architectures, and AI-powered workflows create new opportunities for innovation but also introduce greater complexity and significantly escalate threat risk. With frontier AI uncovering countless numbers of vulnerabilities in deployed software stacks simply waiting to be exploited before they are even publicly announced, the threat landscape has increased exponentially.

Organizations need security platforms that can stop the growing volume of advanced attacks without increasing operational burden. Especially in this time of AI-powered vulnerabilities, organizations also require a security platform that can identify and stop risks before they become exploits. They also need to enable virtual patching of vulnerabilities as a shield against exploits, affording themselves time to develop, test, and deploy patches. SecureIQLab's 2026 Cloud WAAP v5.0 CyberRisk Validation Comparative Report demonstrates that F5 addresses both, earning top-tier results across security effectiveness, resiliency, and operational efficiency.

F5’s perfect scores in advanced threat protection, and false positive avoidance, and our recognition as ‘Secure-by-Design’ and ‘Secure-by-Default’ affirm our position as a leader in security.

This new report from SecureIQLab, an independent, third-party cybersecurity solution validation and advisory provider, placed F5 Distributed Cloud Web Application and API Protection (WAAP) in the Leader tier, delivering elite security efficacy and operational excellence to address these dynamically evolving challenges.

F5 is placed in the Leader tier of the 2026 SecureIQLab Cloud WAAP v5.0 CyberRisk Validation Comparative Report.

Independent validation of F5’s performance

SecureIQLab’s rigorous testing highlighted F5’s exceptional capability to mitigate modern threats, while delivering out-of-the-box reliability and uncompromising defense. Part of F5’s uncompromising defense includes F5’s AI-powered web application firewall (WAF), F5 Distributed Cloud WAF, which evaluates multiple signals and attack indicators to assign an AI-generated risk score to suspicious traffic. F5 Distributed Cloud WAF integrates neural networking, a continuously trained shared ML model, and heuristic rules to improve threat detection and enable faster threat identification and blocking, while reducing false positives and policy configurations.

F5 Distributed Cloud WAAP delivered top security and operational scores in demanding tests by SecureIQLab, including:

  • 92.7% security efficacy and 94.7% operational efficiency scores, both above group averages.
  • Perfect 100% scores in protecting against advanced threat categories, including bot attacks, AI-assisted bot attacks, Layer 7 DoS & DDoS attacks, resiliency, and WAAP vulnerability assessment.
  • 100% false positive avoidance, ensuring seamless legitimate traffic flow without disruption to – and even enhancing – business operations.

These results underscore F5’s ability to proactively address risks, while minimizing complexity and friction in modern application security.

Secure by design and by default

F5’s distinction as “Secure-by-Design” and “Secure-by-Default” further validates its enterprise-grade capabilities and commitment to minimizing risk for organizations. These certifications are awarded to solutions that effectively preserve the security integrity of the environments they protect, ensuring they do not expand the attack surface or require extensive configuration and tuning to deliver meaningful protection.

SecureIQLab’s evaluation assessed solutions across 16 vulnerability categories. F5 demonstrated exceptional performance with embedded security controls integrated directly into its system architecture, earning a perfect WAAP vulnerability assessment score. This underscores F5’s proactive approach to reducing attack surfaces, safeguarding applications from exploitation, and enabling organizations to counter modern threats with confidence.

Platform resiliency to real-world attacks

Beyond its superior security efficacy, F5 Distributed Cloud WAAP excelled in testing scenarios that simulated real-world attacks designed to stress the platform under pressure. SecureIQLab subjected F5 Distributed Cloud WAAP to 133 resiliency test cases across eight unique attack vectors, where F5 tied as a top performer among evaluated vendors.

The solution achieved an impressive 100% block rate in mitigating these attacks, proving its ability to withstand and neutralize diverse attempts aimed at disrupting services or impacting customers negatively.

Streamlined operational efficiency

Operational efficiency and inherent security are equally critical for enterprises seeking agile and versatile solutions to protect their applications. F5 demonstrated exceptional performance across more than 50 tested features spanning deployment, management, risk oversight, logging, analytics, and geolocation-based security capabilities.

SecureIQLab validated F5 Distributed Cloud WAAP’s ability to streamline workflows, while optimizing security performance, making it an ideal choice for organizations aiming to maintain seamless operations without compromising protection.

Further enhancing its appeal, F5 Distributed Cloud WAAP’s “Secure-by-Default” designation means the solution ensures robust protection against the most prevalent threats and vulnerabilities without requiring extensive manual configuration. With default configurations already hardened, F5 helps to ensure that even newly deployed applications are shielded from vulnerabilities, allowing enterprises to scale securely and efficiently.

The F5 advantage in today’s threat landscape

F5 ultimately placed as one of six Leader tier vendors in SecureIQLab’s 2026 CyberRisk Validation Comparative Report, due to our industry-leading performance across security and operational benchmarks. With this new, independent validation from SecureIQLab, F5 Distributed Cloud WAAP continues to prove its ability to deliver robust defense against the increasingly complex and AI-enhanced cybersecurity threats and exploits shaping today’s application environments.

As organizations grapple with expanding attack surfaces driven by APIs, microservices, and AI-enabled workflows, as well as adversaries leveraging AI to escalate their attacks, F5’s perfect scores in advanced threat protection and false positive avoidance, and our recognition as “Secure-by-Design” and “Secure-by-Default” affirm our position as a security leader.

With independently validated protection, proven resiliency, and industry-leading operational efficiency, F5 empowers enterprises to innovate, grow, and protect their digital assets with confidence in the face of an ever-evolving threat landscape.

To learn more about how F5 can enhance your cybersecurity posture, download the SecureIQLab report or contact us today. Also, be sure to read our press release.

Share

About the Author

Nirav Shah
Nirav ShahSVP, Product and Solution Marketing | F5

Nirav Shah is the Senior Vice President and Head of Products and Solution Marketing at F5, where he leads the strategic direction for Application Security and AI Security. Before joining F5, he spent eleven years at Fortinet in several leadership positions, most notably heading the AI-Powered SASE, SOC, and Secure Networking solutions. His extensive background also includes significant roles at Cisco Systems, where he spearheaded major initiatives for SD-WAN. With more than two decades of experience in the cybersecurity sector, he has an established record of launching market-defining products and building high-performance teams that align product development with sales and marketing for maximum impact. As a thought leader and USC alumnus, he is a frequent speaker at industry conferences and a regular contributor to leading publications on the intersection of AI and cybersecurity, while remaining dedicated to mentoring emerging cybersecurity professionals.

More blogs by Nirav Shah

Related Blog Posts

Securing F5 NGINX in the age of AI
F5 ADSP | 07/08/2026

Securing F5 NGINX in the age of AI

How F5 is applying AI-driven security practices across the F5 NGINX portfolio to help deliver safer, more resilient software.

From dashboard fatigue to operational excellence: Why XOps needs F5 Insight for ADSP
F5 ADSP | 03/26/2026

From dashboard fatigue to operational excellence: Why XOps needs F5 Insight for ADSP

Learn how F5 Insight for ADSP lays the visibility foundation for XOps—turning fragmented signals across applications and infrastructure into actionable intelligence.

The hidden cost of unmanaged AI infrastructure
F5 ADSP | 01/20/2026

The hidden cost of unmanaged AI infrastructure

AI platforms don’t lose value because of models. They lose value because of instability. See how intelligent traffic management improves token throughput while protecting expensive GPU infrastructure.

Govern your AI present and anticipate your AI future
F5 ADSP | 12/18/2025

Govern your AI present and anticipate your AI future

Learn from our field CISO, Chuck Herrin, how to prepare for the new challenge of securing AI models and agents.

F5 recognized as one of the Emerging Visionaries in the Emerging Market Quadrant of the 2025 Gartner® Innovation Guide for Generative AI Engineering
F5 ADSP | 11/25/2025

F5 recognized as one of the Emerging Visionaries in the Emerging Market Quadrant of the 2025 Gartner® Innovation Guide for Generative AI Engineering

We’re excited to share that F5 has been recognized in 2025 Gartner Emerging Market Quadrant(eMQ) for Generative AI Engineering.

Self-Hosting vs. Models-as-a-Service: The Runtime Security Tradeoff
F5 ADSP | 05/01/2025

Self-Hosting vs. Models-as-a-Service: The Runtime Security Tradeoff

As GenAI systems continue to move from experimental pilots to enterprise-wide deployments, one architectural choice carries significant weight: how will your organization deploy runtime-based capabilities?