# IDOR test B gadgets Market Research Report - Europe

**Generated on:** 2026-08-09 17:35:46.961483  
**Industry:** IDOR test B gadgets  
**Geography:** Europe  
**Details:** authorized security test B

---

# Europe's Authorized IDOR/BOLA Testing Market and Buyer Playbook

## Executive Summary

**Scope note:** I interpret "IDOR test B gadgets" and "authorized security test B" as software tools and services for authorized testing of Insecure Direct Object Reference, also called Broken Object Level Authorization in API security. This is not a hardware-gadget market. If "test B" denotes a specific product class, standard, or device, that term needs clarification.

- **Category Reality**: IDOR/BOLA is an authorization-testing capability inside web penetration testing, DAST, API-security platforms, and proxy extensions, not a separately measured product market -> size the opportunity through adjacent categories and never present a standalone IDOR TAM as fact.
- **Demand Signal**: Broken Access Control remains OWASP's top application-risk category; in its contributed test data, every tested application had some form of broken access control, with a **3.74% average incidence rate** and **32,654 mapped CVEs** [2] -> make object-level authorization a release gate for API-heavy applications.
- **European Exposure**: **21.5% of EU enterprises** experienced an ICT security incident with consequences in 2023 [17], while **52.74%** used paid cloud services in 2025 [18] -> prioritize cloud-native, multi-tenant, and regulated buyers.
- **Growth Envelope**: A commercial estimate projects Europe's broad penetration-testing market from **$1.11B in 2026 to $2.66B in 2034**, an **11.63% CAGR** [28] -> use this only as an adjacent-market ceiling, not an IDOR revenue forecast.
- **Human Context Wins**: OWASP recommends at least two users, often more, with different objects and privileges when testing IDOR [3] -> automation should execute a tester-defined entitlement matrix rather than blindly mutate identifiers.
- **Regulation Pull**: NIS2 covers vulnerability handling, access control, supply-chain security, and effectiveness assessment [9], while DORA requires yearly testing of critical ICT systems and risk-selected TLPT at least every three years [10] -> sell auditable evidence, regression tests, and remediation verification.
- **Legal Boundary**: UK Computer Misuse Act analysis turns on whether intended access is unauthorized and whether the tester knows it is unauthorized [4] -> require signed scope, named assets, permitted identities, rate limits, data rules, and stop conditions before testing.
- **Layered Stack**: Burp Suite plus Autorize or AuthMatrix suits expert testers; ZAP supplies role-rule testing; 42Crunch and commercial DAST platforms support repeatable API checks [11][14][12][13] -> buy by workflow maturity and evidence quality, not vulnerability-count claims.
- **Consolidation Trend**: Snyk acquired Portugal-based Probely in November 2024 [23], while PortSwigger, Detectify, Invicti, and Escape received strategic or growth capital [22][19][21][20] -> expect authorization testing to become a feature of larger AppSec platforms.
- **Safe Operating Model**: NCSC disclosure guidance prohibits destructive scanning, unnecessary data access, data modification, and service disruption [7] -> train in labs, test staging first, and use minimal production evidence only when explicitly authorized.

## Market Definition: IDOR Is a Capability, Not a Standalone Category

IDOR occurs when an application uses user-controlled object references without sufficient authorization checks, allowing a user to access resources such as another user's database record or file [3]. BOLA is the API-focused formulation: an endpoint receives an object identifier but fails to verify that the authenticated user may perform the requested action on that object [5]. Identifiers may appear in URL paths, query parameters, headers, JSON bodies, GraphQL variables, UUIDs, or ordinary strings [5].

The commercial category therefore sits at the intersection of four markets:

| Adjacent category | What the buyer purchases | IDOR/BOLA role | Market-sizing caution |
|---|---|---|---|
| Manual web/API penetration testing | Expert time, proof of exploitability, and remediation advice | High, because testers model users, tenants, objects, and business rules | Service revenue includes many vulnerabilities unrelated to IDOR |
| DAST and application-security testing | Recurring automated scans, CI/CD integration, dashboards | Medium unless the platform supports multiple identities and expected access rules | Product forecasts include web, API, and other test types |
| API security testing | API discovery, contract testing, authentication, authorization, and runtime context | High for tools explicitly supporting BOLA/BFLA | API-security estimates often include runtime protection, not just testing |
| Proxy extensions and open-source tools | Tester-controlled request replay and role comparison | High capability at low software cost, but labor intensive | Seat or free-tool adoption is not equivalent to market revenue |

Published forecasts illustrate the envelope, not the addressable IDOR submarket. One source projects global penetration testing from **$1.98B in 2025 to $4.39B in 2031**, a **14.2% CAGR** [26]. Another projects global application-security testing from **$1.83B to $7.60B** over the same years, a **26.7% CAGR** [24]. The large difference indicates that definitions, included products, and assumptions vary substantially. These figures should not be added together.

**Decision-ready insight:** Europe offers a real and growing authorization-testing opportunity, but the defensible commercial model is a share of broader AppSec, API-security, and pentesting budgets. A vendor should report authorization-specific revenue, targets under management, tested entitlement cells, and validated findings rather than inventing an "IDOR gadgets" TAM.

## European Demand: APIs, Incidents, and Regulation Expand the Budget Pool

European demand is driven by digitization, incident exposure, regulation, and scarce specialist labor. In 2025, **52.74% of EU enterprises with at least 10 workers** bought cloud services, up **7.42 percentage points** from 2023 [18]. Of cloud-buying enterprises, **96.44%** used at least one SaaS service, **77.25%** used IaaS, and **26.08%** used PaaS [18]. Cloud use does not prove API use, but it is a useful demand proxy because SaaS, mobile, partner, and multi-tenant services commonly expose object-oriented interfaces.

The risk signal is material. **21.5% of EU enterprises** experienced an ICT incident with operational or data consequences in 2023 [17]. The highest reported sector rates included electricity and gas at **28.8%**, information and communications at **27.9%**, professional and technical activities at **26.8%**, real estate at **25.0%**, and water and waste services at **24.1%** [17]. IDOR is not responsible for all those incidents, so the figures support security-testing demand rather than vulnerability attribution.

OWASP provides the authorization-specific signal. Broken Access Control remains its number-one application category, while BOLA is described as easy to exploit, widespread, and capable of causing unauthorized disclosure, deletion, modification, or account takeover [5]. Its 2025 dataset reports a **20.15% maximum incidence rate**, **3.74% average incidence**, and **32,654 CVEs** for the broad Broken Access Control category [2]. These are contributed test-data statistics, not a representative survey of every European application.

### Priority European buyer segments

| Segment | Demand mechanism | Recommended offer |
|---|---|---|
| Banks, insurers, payments, and market infrastructure | DORA testing and TLPT, complex customer objects, high transaction impact | Authenticated API testing, expert business-logic review, immutable evidence, live-system safeguards |
| Energy, transport, health, water, cloud, and digital infrastructure | NIS2 risk management, supply-chain exposure, critical service availability | Continuous DAST plus scheduled manual testing and supplier/API inventory |
| Software and connected-product manufacturers | CRA secure-development and vulnerability-handling obligations | Pre-release authorization regression, API inventory, support-period testing evidence |
| SaaS and marketplaces | Multi-tenancy creates horizontal authorization risk | Tenant-isolation matrices, CI/CD regression, bug-bounty intake |
| Government and critical national infrastructure | High assurance and formal procurement requirements | Accredited providers, explicit rules of engagement, low-impact production validation |
| SMEs | Limited specialist staffing and price sensitivity | Managed scanning, clear remediation instructions, fixed-scope expert reviews |

**Decision-ready insight:** The strongest early market is not "all European companies." It is organizations where APIs expose customer, financial, clinical, operational, or tenant-specific objects and where regulation requires repeatable evidence.

## Authorized Testing Workflow: Two Identities Beat Blind Mutation

An effective authorized test begins with permission, not scanning. The rules of engagement should identify the legal owner, exact domains and APIs, permitted environments, source IPs, dates, identities, allowed actions, rate limits, excluded records, evidence-retention period, emergency contacts, and stop conditions. Third-party hosting and shared platforms require separate confirmation that the customer may authorize the planned activity.

The technical method should then proceed as follows:

1. **Inventory objects and actions.** Map endpoints that read, create, modify, export, approve, or delete customer records, files, orders, vehicles, messages, invoices, and administrative resources.
2. **Create controlled identities.** Use at least two users with separate objects, plus relevant roles such as support agent, manager, tenant administrator, and platform administrator. OWASP explicitly recommends two or more users and different privilege levels [3].
3. **Capture valid baselines.** Record authorized requests for each identity and object-action pair.
4. **Build an entitlement matrix.** For every identity, mark each request as Allow, Deny, or Unknown. Include horizontal tests between peers, vertical tests between roles, cross-tenant tests, and unauthenticated tests.
5. **Substitute controlled references.** Change identifiers in paths, queries, headers, bodies, and GraphQL variables. Test both reads and state-changing operations.
6. **Validate effects, not only status codes.** A `200` response can be harmless if the body is generic; a `404` can still conceal a state change. Compare content, length, semantic fields, database or audit effects, and follow-up reads.
7. **Minimize evidence.** Prove access with synthetic records or the smallest permitted sample. Do not enumerate real customer data.
8. **Fix server-side policy.** OWASP says checks must run in trusted server-side code, deny by default, and enforce record ownership [2]. Random identifiers may reduce guessability but do not replace authorization [5].
9. **Convert the proof into regression tests.** A fixed issue should fail closed across every affected role, tenant, endpoint, and method before deployment.

### Case study: Three OWASP scenarios reveal one control failure

In OWASP's e-commerce scenario, an attacker changes the shop name in `/shops/{shopName}/revenue_data.json` and accesses sales data for thousands of stores [5]. In its vehicle scenario, an API accepts a VIN without checking whether the vehicle belongs to the logged-in user, exposing remote start, stop, lock, and unlock functions [5]. In a GraphQL scenario, a deletion mutation accepts a document ID without a permission check, allowing one user to delete another's document [5].

The formats and impacts differ, but the mechanism is identical: a validly authenticated user reaches a legitimate function and changes the target object. An unauthenticated scanner, single test account, or check that only confirms endpoint access can miss all three. The corrective principle is object-action authorization on every request, not merely login validation or unpredictable IDs [5].

**Decision-ready insight:** Measure authorization coverage as tested cells in an identity x object x action matrix. Request volume is a poor proxy for assurance.

## Competitive Landscape: Proxy Tools, API Platforms, DAST, and Services

The European market is fragmented by workflow rather than vulnerability name. PortSwigger is the expert-testing anchor; OWASP ZAP is the open tooling option; 42Crunch and Escape represent API-native approaches; Snyk/Probely, Invicti/Acunetix, Detectify, and Edgescan compete in broader DAST and exposure-management budgets; consultancies address logic-heavy or regulated engagements.

| Player or stack | Core authorization mechanism | Automation and deployment | Public price signal | Best fit | Main caveat |
|---|---|---|---|---|---|
| PortSwigger Burp Suite Professional plus Autorize | Replays privileged traffic with low-privilege or unauthenticated credentials and compares responses [14] | Tester-led proxy workflow | **$499 per user/year**; every user needs a subscription [25] | Skilled pentesters and AppSec teams | Third-party extension; requires credentials and enforcement patterns |
| Burp plus AuthMatrix | Tester defines users, roles, requests, and expected outcomes in a color-coded matrix [11] | Semi-automated, reusable regression configuration | Burp license plus extension | Complex role and tenant matrices | Jython setup and significant model-building; PortSwigger provides no warranty [11] |
| OWASP ZAP Access Control Testing | Runs known URLs from every configured user's perspective against Allow, Deny, or Unknown rules [13] | Automated after authentication, exploration, and rule setup | No price stated in the cited documentation | Budget-conscious teams and repeatable role checks | Discovery and expected-access rules remain user responsibilities |
| 42Crunch | Uses an OpenAPI contract, tokens, and variable substitution to test BOLA and BFLA [12] | Local, platform, or CI/CD API scanning | Free and paid activation paths; exact enterprise price not established here | API-first development teams | Contract quality, test data, and tokens constrain coverage |
| Snyk/Probely | Developer-first DAST for web applications and APIs | CI/CD-oriented recurring scans | Free plan includes **five scan hours/month**; paid plans offer a **14-day trial** [29] | Agile engineering teams wanting integrated DAST | Acquisition integration and deep business-logic coverage should be validated in a proof of concept |
| Escape | Vendor positions its agents around discovery, business-logic-aware DAST, testing, and remediation [20] | AI-led continuous offensive testing | Quote-led in this research | API-heavy buyers testing emerging agentic workflows | Claims require independent testing against the buyer's own entitlement matrix |
| Invicti/Acunetix, Detectify, Edgescan | Broader DAST, attack-surface, API, or human-validated testing | Enterprise platform and managed-service models | Typically quote-led | Large portfolios needing inventory, dashboards, and integrations | Do not assume generic authenticated scanning equals BOLA coverage |
| Specialist consultancy or accredited provider | Human threat modeling and business-logic exploitation | Project, retainer, or managed testing | Scope-based | DORA, critical infrastructure, complex approvals | Higher cost and lower continuous coverage unless tests become regression assets |

### Case study: PortSwigger's extension ecosystem separates engine from policy

Autorize automates differential replay, while AuthMatrix makes the expected policy explicit. Neither removes the need for a tester to supply identities, sessions, target requests, and enforcement logic [11][14]. This architecture exposes the key market truth: request automation is commoditizing, but entitlement modeling remains scarce expertise.

For buyers, the right proof of concept is not "find as many vulnerabilities as possible." Give each vendor the same staging API, four roles, two tenants, seeded objects, and a hidden set of known authorization defects. Score discovery, validated true positives, missed policy violations, evidence quality, setup time, safe throttling, and retest automation.

**Decision-ready insight:** A layered stack usually outperforms a single platform: broad recurring DAST for coverage, an authorization matrix tool for regression, and periodic expert testing for business logic.

## Regulation and Safe Harbor: Scope Is a Product Requirement

European regulation increases demand but does not create blanket permission to test. An organization may need vulnerability assessment and still require carefully bounded authorization for every tester, endpoint, identity, and action.

| Framework | Relevant requirement | IDOR-testing implication | Important limit |
|---|---|---|---|
| NIS2 | Management approves and oversees cyber-risk measures [9]; controls include supply-chain security, vulnerability handling, secure development, effectiveness assessment, and access control [9] | Maintain approved test policy, supplier scope, findings, fixes, and effectiveness metrics | An IDOR scan alone does not demonstrate full NIS2 compliance |
| DORA | Non-microenterprise financial entities need risk-based testing, with yearly tests on critical systems [10] | Include authenticated web/API authorization in the annual program | DORA includes many resilience tests beyond application authorization |
| DORA TLPT | Selected entities conduct TLPT at least every three years; scope can cover live production and must be validated by authorities [10] | Production IDOR checks need exceptional safeguards, low-impact proofs, and coordination | Realism raises outage and data-exposure risk |
| Cyber Resilience Act | Connected products must meet essential cybersecurity requirements and manufacturers must maintain vulnerability-handling processes [8] | Convert object-level authorization tests into release and support-period regression evidence | Most provisions apply from **11 December 2027**; specified reporting duties apply from **11 September 2026** [8] |
| UK Computer Misuse Act | Liability focuses on unauthorized access and knowledge that access is unauthorized [4] | Signed rules of engagement and clearly defined limits are essential | A vulnerability-disclosure policy is not unlimited permission |
| NCSC disclosure guidance | Researchers should not access excessive data, modify data, use destructive scanning, or disrupt services [7] | Build these restrictions directly into test tooling and contracts | The guidance states that its policy does not authorize unlawful conduct [7] |

### Case study: DORA creates a realism-versus-safety tension

DORA allows vulnerability scans, source-code review, scenario testing, end-to-end tests, and penetration tests, and requires at least yearly testing of critical ICT systems [10]. For selected entities, TLPT reaches live production systems and several critical or important functions [10]. This increases the value of credible authorization testing because staging environments may not reproduce real identities, data relationships, or gateways.

The same realism magnifies harm. A delete, transfer, approval, vehicle-control, or patient-record proof can create a real incident. A financial institution should therefore use synthetic accounts, pre-seeded records, read-only proofs where possible, transaction reversibility, low request rates, live monitoring, and an immediate kill switch. Compliance supplies the reason to test, not permission to test carelessly.

**Decision-ready insight:** Treat scope control, evidence minimization, and emergency stopping as product capabilities. They should appear in procurement scoring alongside vulnerability detection.

## Economics and Go-To-Market: Consolidation Absorbs Point Features

Public pricing shows two ends of the market. Burp Suite Professional offers a clear expert-seat anchor at **$499 per user per year** [25]. Probely offers five free scan hours monthly and a 14-day paid-plan trial [29], while enterprise DAST, API-security, and managed-testing platforms generally require quotes. The total cost of ownership is therefore driven less by license price than by identity setup, API inventory, test-data maintenance, triage, remediation, retesting, and audit reporting.

Investment and acquisition activity supports a platform-consolidation thesis:

| Event | Verified detail | Strategic implication |
|---|---|---|
| PortSwigger investment, June 2024 | Brighton Park Capital became a minority shareholder; amount undisclosed [22] | Capital supports product development, research, hiring, and US expansion [22] |
| Detectify funding, September 2022 | **$10M** follow-on round led by Insight Partners [19] | Funding targeted Surface Monitoring and Application Scanning [19] |
| Snyk acquisition of Probely, November 2024 | Snyk acquired the Porto-based DAST provider; price undisclosed [23] | DAST and API testing move into a broader developer-security platform |
| Invicti investment, October 2021 | **$625M** led by Summit Partners with Turn/River Capital [21] | Large-scale growth capital raises competitive pressure on smaller DAST vendors |
| Escape Series A, March 2026 | Vendor announced **$18M**, led by Balderton Capital [20] | Capital is flowing toward AI-assisted, business-logic-aware testing claims |

### Case study: Snyk plus Probely shows where the category is going

Snyk described the Probely acquisition as adding API and DAST capabilities across the software-development lifecycle [23]. The mechanism is commercial as much as technical: developer platforms already own repository, CI/CD, issue-tracking, and policy workflows, so adding dynamic authorization findings reduces procurement and integration friction.

The opportunity for specialists remains in areas platforms find hard to standardize: tenant data models, role hierarchies, stateful approvals, nonproduction test data, and proof quality. A specialist should expose APIs and exportable regression assets so it can become the authorization engine inside a larger platform rather than compete only as another dashboard.

**Decision-ready insight:** The winning go-to-market model combines a low-friction developer entry point, enterprise governance, and expert services. A pure scanner seat is vulnerable to bundling.

## Risks and Failure Cases: Automation Misses Business Context

| Risk | Mechanism | Consequence | Control |
|---|---|---|---|
| False negatives | Scanner has one identity or no expected entitlement model | High-impact cross-user or cross-tenant defects remain invisible | Require at least two identities and a role-object-action matrix [3] |
| False positives | Similar responses are treated as successful bypasses without semantic or state validation | Developer fatigue and lost trust | Validate body fields, side effects, audit events, and follow-up reads |
| Production harm | Automated writes, deletes, exports, or high-rate enumeration alter or disrupt services | Incident, outage, or customer harm | Synthetic records, operation allowlists, throttling, monitoring, and kill switch; NCSC discourages destructive scanning [7] |
| Legal overreach | Tester follows a discovered link or object beyond written scope | Potential unauthorized-access exposure | Asset-level authorization, named accounts, source IPs, time window, and escalation contact [4] |
| Privacy spill | Proof captures unrelated customer records | Data-protection breach and reporting burden | Stop at first minimal proof, encrypt evidence, restrict access, and delete promptly; NCSC calls for deletion when no longer required or within one month after resolution [7] |
| Session and test-data drift | Tokens expire, role assignments change, or seeded objects are deleted | Inconsistent tests and misleading trends | Automated account health checks and deterministic test-data reset |
| Vendor lock-in | Findings, test definitions, or evidence cannot be exported | High migration cost after consolidation | Require APIs, SARIF/JSON export, reproducible HTTP evidence, and ownership of test definitions |
| AI overclaim | Agent produces plausible labels without a reliable entitlement oracle | Unverified findings or missed logic paths | Hidden-defect benchmark, human confirmation, and separate vendor-claim reporting |

### Failure case: A responsible-disclosure policy is not broad consent

NCSC's model language tells researchers not to access excessive data, modify data, use destructive scanners, or disrupt systems [7]. It also says the policy does not permit conduct inconsistent with law [7]. A tester who enumerates thousands of records after proving one unauthorized access may turn a valid finding into unnecessary exposure.

The commercial implication is important: "autonomous pentesting" must include restraint. Buyers should demand request ceilings, operation allowlists, proof minimization, evidence redaction, replay logs, and an emergency stop. A product that only maximizes exploit count is poorly aligned with authorized European testing.

**Decision-ready insight:** The best authorization-testing platform is not the most aggressive one. It is the platform that proves defects with the least data access and converts each proof into a reliable regression check.

## 2026-2030 Outlook and Buyer Playbook

The adjacent market forecasts support continued growth, but a precise IDOR revenue forecast would be false precision. The likely direction is clearer than the magnitude: authorization testing will move from episodic expert work toward continuously executed policy tests, while experts remain necessary to define policy and interpret business state.

| Scenario | Mechanism | Market outcome | Buyer response |
|---|---|---|---|
| Base case: regulated convergence | NIS2, DORA, and CRA pull testing evidence into governance programs | DAST platforms add deeper identity features; consultancies productize regression packs | Standardize an entitlement-test schema and integrate it with CI/CD and audit systems |
| Upside: policy-as-code | Identity, tenant, object, and action expectations become machine-readable | Authorization tests run on every release with lower setup cost | Invest in reusable test identities, seeded data, and API contracts now |
| Downside: automation without context | Vendors race to market with AI mutation engines but weak entitlement oracles | Noise rises, trust falls, and expert validation remains the bottleneck | Benchmark on hidden known defects and measure validated recall, not raw findings |
| Consolidation case | Large AppSec vendors acquire DAST and API specialists | Procurement simplifies, but pricing and lock-in increase | Require exportable test definitions and separate renewal pricing for targets, seats, and scan volume |
| Enforcement case | A destructive or out-of-scope automated test causes a material incident | Insurers and regulators demand stronger authorization controls | Make safe-execution telemetry and signed scope technically enforceable |

### Recommended 90-day implementation

**Days 1-30:** Inventory applications and APIs, identify regulated services, define object classes, select two representative applications, create test accounts across roles and tenants, and approve rules of engagement.

**Days 31-60:** Run a controlled proof of concept with one expert proxy workflow and one recurring platform. Seed known authorization defects in staging. Score setup time, matrix coverage, true findings, misses, evidence quality, integration effort, and safety controls.

**Days 61-90:** Remediate server-side checks, convert verified findings into CI/CD regression tests, add production-safe monitoring, and define quarterly manual business-logic review. Expand only after the test-data and identity lifecycle is stable.

### Proposed operating metrics

| Metric | Definition | Initial decision use |
|---|---|---|
| API inventory coverage | Tested in-scope endpoints / discovered endpoints | Reveals blind spots |
| Authorization-matrix coverage | Executed identity-object-action cells / planned cells | Core assurance KPI |
| Validated violation rate | Confirmed defects / candidate findings | Measures noise |
| High-risk remediation time | Median days from confirmation to verified fix | Tracks operational response |
| Regression pass rate | Passing fixed authorization tests / all fixed tests | Detects recurrence |
| Cross-tenant test coverage | Tested tenant boundaries / identified boundaries | Measures SaaS isolation assurance |
| Evidence spill count | Tests retrieving more data than minimally required | Safety and privacy KPI |
| Automated-to-manual escalation rate | Findings needing expert logic review / candidates | Exposes automation limits |

**Decision-ready insight:** Start with coverage and proof quality, not a fleet-wide tool purchase. Scale when accounts, test data, entitlement rules, and evidence handling are repeatable.

## Synthesis

| Approach | Mechanism | Scope | Evidence quality | Trade-off | Time horizon |
|---|---|---|---|---|---|
| Manual Burp-based testing | Human models business policy; extensions replay and compare | Deep but application-specific | Highest when an expert confirms state and impact | Labor intensive and difficult to scale | Best for design reviews, releases, and complex workflows |
| ZAP or matrix-based regression | User supplies identities and expected access rules | Repeatable known paths | Strong for previously modeled policy | Coverage depends on exploration and rule maintenance | Every build or scheduled regression |
| API-native scanning | Contract, tokens, and generated tests exercise endpoints | Broad across documented APIs | Good for discoverable, machine-expressible rules | Misses undocumented state and ambiguous entitlement | CI/CD and continuous testing |
| Broad DAST platform | Portfolio inventory, authenticated scanning, dashboards | Wide web/API estate | Useful operational evidence, variable logic depth | Can create a false sense of authorization coverage | Continuous portfolio hygiene |
| Expert service or TLPT | Threat-led, scenario-based human testing | Selected critical functions | Strongest contextual proof | Higher cost and production risk | Annual, three-year, or major-change cycle |

Three tensions define the market. First, automation lowers marginal test cost, but IDOR depends on business context that automation does not inherently possess. Second, regulation pushes testing toward live and critical systems, while responsible authorization demands minimal impact. Third, platform consolidation simplifies procurement but can weaken tool portability and pricing transparency.

These tensions converge on one strategy: **separate policy from execution**. The buyer should own the entitlement model, identities, test data, and expected outcomes. Tools may then execute that policy through proxy replay, DAST, API contracts, or expert testing. This also makes vendors replaceable and findings comparable.

The market opportunity is therefore larger than a niche IDOR scanner but narrower than the full European security-testing market. The durable value pool is authorization assurance: discovering APIs, modeling who may do what to which object, executing that policy safely, proving failures minimally, and preserving tests after remediation. Vendors that can operationalize that lifecycle will capture a meaningful share of European AppSec budgets; products that only mutate IDs will be commoditized.

## References

1. *ICT security in enterprises - Statistics Explained - Eurostat*. https://ec.europa.eu/eurostat/statistics-explained/index.php?title=ICT_security_in_enterprises
2. *A01 Broken Access Control - OWASP Top 10:2025*. https://owasp.org/Top10/2025/A01_2025-Broken_Access_Control/
3. *WSTG - Latest | OWASP Foundation*. https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/05-Authorization_Testing/04-Testing_for_Insecure_Direct_Object_References
4. *Computer Misuse Act | The Crown Prosecution Service*. https://www.cps.gov.uk/prosecution-guidance/computer-misuse-act
5. *API1:2023 Broken Object Level Authorization - OWASP API Security Top 10*. https://owasp.org/API-Security/editions/2023/en/0xa1-broken-object-level-authorization/
6. *Review of the Computer Misuse Act 1990: consultation and response to call for information (accessible) - GOV.UK*. https://www.gov.uk/government/consultations/review-of-the-computer-misuse-act-1990/review-of-the-computer-misuse-act-1990-consultation-and-response-to-call-for-information-accessible
7. *NCSC Vulnerability Disclosure Toolkit V2*. https://www.ncsc.gov.uk/files/NCSC-Vulnerability-disclosure-Toolkit-v2.pdf
8. *L_202402847EN.000101.fmx.xml*. https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ%3AL_202402847
9. *L_2022333EN.01008001.xml*. https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A32022L2555
10. *L_2022333EN.01000101.xml*. https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A32022R2554
11. *AuthMatrix - PortSwigger*. https://portswigger.net/bappstore/30d8ee9f40c041b0bfec67441aad158e
12. *API Security and Conformance Scan on the OpenAPI (Swagger) Editor Extension for VS Code *. https://42crunch.com/tutorial-security-conformance-scan-openapi-swagger-extension-vs-code/
13. *ZAP – Access Control Testing*. https://www.zaproxy.org/docs/desktop/addons/access-control-testing/
14. *Autorize - PortSwigger*. https://portswigger.net/bappstore/f9bbac8c4acf4aefa4d7dc92a991af2f
15. *Broken Object Level Authorization (BOLA) Vulnerability*. https://escape.tech/blog/understanding-broken-object-level-authorization/
16. *NIS Investments 2024 | ENISA*. https://www.enisa.europa.eu/publications/nis-investments-2024
17. *21.5% of EU enterprises had ICT security incidents in 2023 - News articles - Eurostat*. https://ec.europa.eu/eurostat/web/products-eurostat-news/w/ddn-20251008-1
18. *Cloud computing - statistics on the use by enterprises - Statistics Explained - Eurostat*. https://ec.europa.eu/eurostat/statistics-explained/index.php?title=Cloud_computing_-_statistics_on_the_use_by_enterprises
19. *Detectify $10M in Follow-On Funding - Blog Detectify*. https://blog.detectify.com/news/detectify-raises-10m-in-follow-on-funding-to-accelerate-external-attack-surface-management-powered-by-elite-ethical-hackers/
20. *Escape raises $18M Series A to replace legacy scanners with AI agent-driven discovery, pentesting, and remediation*. https://escape.tech/blog/escape-raises-18m-series-a/
21. *Invicti Security announces $625 million growth investment led by Summit Partners | Acunetix*. https://www.acunetix.com/blog/news/invicti-security-announces-625-million-growth-investment-led-by-summit-partners/
22. *Investing to deliver more | Blog - PortSwigger*. https://portswigger.net/blog/investing-to-deliver-more
23. *Snyk Acquires Developer-First DAST Provider Probely | Snyk*. https://snyk.io/news/snyk-acquires-developer-first-dast-provider-probely/
24. *Application Security Testing Market Report 2025-2030, by ...*. https://www.marketsandmarkets.com/Market-Reports/application-security-testing-market-147329639.html
25. *Subscribe to Burp Suite Professional*. https://portswigger.net/buy/pro
26. *Penetration Testing Market Report 2025-2031, by ...*. https://www.marketsandmarkets.com/Market-Reports/penetration-testing-market-13422019.html
27. *Regulation - 2016/679 - EN - gdpr - EUR-Lex - European Union*. https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng
28. *Europe Penetration Testing Market Size & Analysis, 2034*. https://www.marketdataforecast.com/market-reports/europe-penetration-testing-market
29. *Pricing*. https://probely.com/pricing/
30. *Penetration testing*. https://www.ncsc.gov.uk/guidance/penetration-testing
31. *Business logic vulnerability*. https://owasp.org/www-community/vulnerabilities/Business_logic_vulnerability

