Security Risks Multiply as Copilots and Low-Code Apps Spread
As enterprises rush to empower business teams with copilot tools and low-code platforms, the scale of new software is staggering—and so are the risks. According to Zenity, 62% of these rapidly built applications harbor security vulnerabilities, exposing organizations to threats that too often go unnoticed until it’s too late.
When Anyone Can Build, Everyone Is Exposed
Large companies now find themselves with an average of 80,000 internally created applications, a testament to how quickly low-code development has changed the landscape. These tools let non-developers spin up workflows with drag-and-drop ease or natural language instructions. It’s a productivity dream—and a security department’s recurring nightmare. Each new app potentially opens another door to sensitive data, and few are built with robust defenses in mind.
Blind Spots in Fast-Track Development
Most organizations don’t have strong guardrails for security or threat detection when business users build their own solutions. This lack of oversight creates more ways for attackers to slip in, especially as the number of apps balloons. Without coordinated policies and monitoring, every “quick fix” tool can become another weak point in the company’s digital armor.
Zenity’s Data: What’s Actually Going Wrong?
The latest report from Zenity sheds light on the scale and specifics of these challenges:
- Unchecked App Growth: As businesses churn out apps at breakneck speed, vulnerabilities pile up. Some organizations now face more than 50,000 separate security issues within their internal app portfolios.
- AI Adds New Layers of Risk: Many low-code tools now include AI copilots, but their output is frequently overshared. The result: more avenues for prompt injection attacks or leaks of sensitive information if access isn’t tightly controlled.
- Guest Access: An Open Invitation: When guest accounts aren’t monitored or restricted, attackers can exploit these pathways to obtain broad privileges—sometimes without raising alarms.
- The Open-Source Trap: Developers rely on open-source libraries to build quickly, but malicious code can ride along for the journey. A single infected component can put entire ecosystems at risk.
A CEO’s Warning on Business-Led Development
Ben Kliger, Zenity’s co-founder and CEO, doesn’t mince words: the drive for speed and autonomy is admirable, but organizations can’t afford to ignore the dangers that come with it. He argues that IT teams must keep tabs on what business users are building—and what potential threats they’re unintentionally bringing into the fold.
How Zenity Tries to Close the Gaps
Founded in 2021, Zenity describes itself as the first platform tailored specifically to safeguard enterprise copilots and low-code projects. The company’s approach centers on continuous vulnerability scanning and centralized risk assessment—providing IT with a live map of potential trouble spots as new apps appear. By automating oversight and enforcing security policies across sprawling portfolios, Zenity aims to keep compliance and continuity intact even as business-led development accelerates.
Your Questions on Low-Code Security Answered
Which vulnerabilities turn up most often in Zenity’s findings?
The report highlights that a majority of low-code apps contain vulnerabilities—especially those built without a clear focus on security from the outset. Rushed projects tend to skip basic safeguards.
How does letting anyone build apps affect overall security?
If not monitored, low-code projects can expose confidential data or widen attack surfaces dramatically. Without standardized practices, each app becomes a potential liability—particularly as their numbers grow unchecked.
Does AI make things safer or more dangerous?
AI-powered development can speed up productivity but also introduces fresh risks. When AI-generated apps are widely shared or poorly managed, they’re prone to prompt injection attacks and inadvertent data leaks.
What’s the danger in letting guests access these platforms?
Poorly controlled guest accounts open up powerful features to outsiders who may abuse them for lateral movement or data theft. Tight access controls and monitoring are essential safeguards here.
What does Zenity do to manage these risks?
The platform offers real-time scanning for vulnerabilities, helps prioritize which threats need urgent attention, and sets automated guardrails that block common attack vectors—giving IT teams a fighting chance against the chaos of rapid app creation.
The bottom line: speed shouldn’t come at the cost of security. As more employees turn into software creators overnight, every organization faces the same question—how fast is too fast when your data is on the line?