Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Application security is expanding beyond code scanning into APIs, secure development, DevSecOps, and software-supply-chain protection. For investors, the opportunity is not simply a larger list of tools: the UK evidence points to a market where differentiated products, efficient scaling, and recurring revenue can matter, while investment totals remain sensitive to a few unusually large rounds.

AppSec now covers more than code scanning

“Application security” describes a widening set of software-security capabilities, not one uniform product category. The UK government’s software-security taxonomy includes testing and tooling, secure-development lifecycle solutions, software-vulnerability assessment, DevSecOps implementation, code and API security, and container and software-supply-chain security. It also distinguishes specialist software-security providers from broader cybersecurity firms that include these capabilities in a wider portfolio. The UK software-security market analysis maps that landscape from 2019 to 2024.

That breadth creates different kinds of businesses for investors to assess: a focused testing platform is not the same business as a company implementing DevSecOps or a broader cyber provider with software-security offerings. Comparing them as though they sold interchangeable products can obscure both their technical scope and their commercial model.

What is changing in application security

Gartner’s public abstract for its Hype Cycle for Application Security, 2025 frames current change around AI-related challenges, the evolution of DevSecOps, and tool convergence. Gartner’s concise summary is: “Application security innovations continue to emerge in response to new AI challenges, the evolution of DevSecOps and the need for convergence of application security tools.” The abstract, published 22 July 2025, does not establish detailed adoption rankings or the maturity of individual products. Gartner’s public report page

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For buyers and investors, the convergence point is significant as a market question: organizations may value products that fit into existing development and security workflows rather than add another disconnected alert source. That is an interpretation of the stated convergence pressure, not a reported Gartner adoption finding.

What the UK investment figures do—and do not—show

The UK government’s Cyber security sectoral analysis 2025 reports that dedicated UK cybersecurity firms raised £206 million in 2024, down from £271 million in 2023, a 24% decline. The same report counts 59 dedicated-sector deals in 2024 and 71 in 2023. These figures describe the UK cybersecurity sector overall, not global AppSec funding or software-security investment alone. The report also cautions that a small number of very large investments can materially shift annual and quarterly totals. UK Department for Science, Innovation and Technology, Cyber security sectoral analysis 2025

A narrower UK software-security analysis identified £828 million across 42 deals involving 15 specialist firms over 2019–2024. That total is highly concentrated: about £400 million of the £432 million recorded in 2021 was associated with Snyk’s individual fundraising. Deal volume was roughly six to seven deals annually in 2019–2021, then moderated in more recent years as investment focus shifted toward established firms, according to the analysis. The concentration means the total should not be read as a smooth measure of underlying market growth. UK Department for Science, Innovation and Technology and Perspective Economics, AI and software cyber security market analysis

What the company examples illustrate

The UK market analysis names investments in businesses with distinct software-security propositions. These examples help show the category’s range; they are not a ranking and do not establish that one subcategory is more attractive to investors.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • PortSwigger: £88 million in growth investment in June 2024 to expand its web-security testing platform.
  • OnSecurity: More than £5.5 million in seed funding in 2024 to grow its penetration-testing platform and team.
  • Panaseer: Funding for its continuous-controls-monitoring platform, an adjacent security-controls business.

The cited analysis does not provide comparable valuations or company-level performance measures for these examples, so the rounds cannot support a direct comparison of company quality or returns. UK Department for Science, Innovation and Technology and Perspective Economics

What investors say they value

Late-2024 consultations reported in the UK government’s sector analysis point to interest in cybersecurity’s growth potential amid digitization and emerging technologies, including AI and quantum computing. Consultees emphasized differentiated products and efficient scaling. The report also says some venture capital and seed investors strongly require recurring revenue before investing.

Rank #4
Sale
The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws
  • Comes with secure packaging
  • It can be a gift item
  • Easy to read text

These are themes from five consultations, not a representative survey or universal checklist for venture capital. They are best treated as signals about questions a company may need to answer: what is distinct about its product, how can it grow without costs rising at the same pace, and does it have evidence of recurring revenue? UK Department for Science, Innovation and Technology, Cyber security sectoral analysis 2025

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

A practical framework for comparing AppSec companies

When assessing an AppSec business through an investor lens, separate five dimensions rather than relying on a broad “cybersecurity” label:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Technical scope: Identify whether the product focuses on code or API security, testing, secure development, DevSecOps, cloud and container security, supply-chain security, or adjacent controls monitoring.
  2. Specialist focus: Establish whether software security is the company’s core business or one offering within a broader cybersecurity portfolio.
  3. Demand evidence: Look for evidence of customer uptake and product-market fit. The UK analysis describes growth funding for established providers, but does not report comparable company valuations or performance metrics.
  4. Investor readiness: Consider product differentiation, efficient scaling, and recurring-revenue evidence as consultation themes—not as guaranteed requirements for every investor.
  5. Technology fit: Evaluate how the product relates to AI-related security challenges, evolving DevSecOps practices, and the drive toward tool convergence highlighted in Gartner’s 2025 abstract.

How global context fits

Silicon Valley Bank counted 13 active non-US cybersecurity unicorns in its 2025 private-market report. That is global cybersecurity context, not an AppSec company count, and it cannot be combined with the UK funding totals to produce an AppSec investment estimate. Silicon Valley Bank, State of the Markets 2025

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.