Does your org incorporate input from development teams before deciding which AppSec tool to purchase?
Yes, always32%
Sometimes58%
No9%
Unsure1%
81 PARTICIPANTS
Yes, always32%
Sometimes58%
No9%
Unsure1%
Yes - by a LOT24%
Yes - somewhat52%
Minimal improvements, still more to do18%
Nope4%
Other/don't know
SaaS discovery solution (like Netskope or Cisco Umbrella) 30%
CASB tool 46%
Packet sniffing (deep packet inspection) tool 28%
EDR tool/platform 18%
Something else (please share in a comment) 15%
N/A — we’re not currently using any tools to track shadow AI6%
No selling.
No recruiting.
No self promotion.
Rules of EngagementFAQsPrivacy
© 2026 Gartner, Inc. and/or its affiliates. All rights reserved.
I feel it's important to discuss an applications impact with any areas of IT, it makes a more effective team that pulls together to address cybersecurity issues and needs.