• About
  • Subscribe
  • Contact
Monday, July 7, 2025
    Login
FutureCISO
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
No Result
View All Result
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
No Result
View All Result
FutureCISO
No Result
View All Result
Home Process Compliance and Governance

Sensitive data exposed: Calling for API protections

FutureCISO Editors by FutureCISO Editors
July 7, 2025
Sensitive data exposed: Calling for API protections

Photo by Antoni Shkraba Studio: https://www.pexels.com/photo/person-using-macbook-air-on-table-5475779/

Share on FacebookShare on Twitter

A recent report from Raidiam has revealed a significant API security crisis, with 84% of enterprises operating outside regulated frameworks lacking adequate protections for sensitive data.

This alarming statistic highlights a critical vulnerability, particularly for organisations in sectors such as fintech, SaaS, and payments.

Source: Radiam 2025

The report, titled "Helping Enterprises Recognize and Address Critical Risk," is based on a security profiling exercise involving 68 organisations. It found that while 85% of these firms handle sensitive or high-value personal and financial data, the majority rely on outdated security mechanisms, such as static API keys and basic OAuth secrets, without additional safeguards.

David Oppenheim

Emphasised the severity of the issue, David Oppenheim, head of Enterprise Strategy at Raidiam stated: “The gap between the sensitivity of data and the strength of controls is a board-level risk – not just a technical issue.”

Key findings from the report include the concerning fact that 84% of organisations were placed in the "Act Urgently" category, exposing sensitive APIs with inadequate security measures.

Alarmingly, only one organisation met the benchmark for modern, cryptographic API protection. Furthermore, 57 out of 68 organisations still depend on bare API keys or basic OAuth credentials, despite their known vulnerabilities. Less than half of the surveyed entities conduct regular API-specific penetration testing or runtime anomaly monitoring, which leaves them blind to potential attacks.

The report also notes that real-world breaches, such as the Dell partner API hack in 2023, illustrate how weak API protections are being exploited.

The report introduces a Security vs Sensitivity Matrix, which clearly shows a misalignment between the level of API protection and the sensitivity of the data exposed.

Related:  FortiAppSec Cloud to enhance web application security

“In regulated environments like Open Banking, stronger controls like mutual TLS and certificate-bound tokens are standard,” Oppenheim pointed out. “Outside those frameworks, there’s a gaping hole.”

Concerns over API risks are growing, as seen in an open letter from JPMorgan Chase’s CISO, who highlighted the need for prioritising security over speed in development roadmaps. According to Gartner, API breaches can leak up to ten times more data than traditional attacks, making this a pressing concern for enterprises.

To address these vulnerabilities, the report outlines a four-step roadmap for improvement:

  1. Elevate API security to a board-level priority.
  2. Modernise controls using cryptographic techniques like mTLS.
  3. Invest in developer awareness and security testing.
  4. Engage trusted partners to adopt proven standards.
Source: Radiam 2025

With the threat landscape evolving, organisations must take immediate action to secure their APIs and protect sensitive data from emerging vulnerabilities.

Tags: API securityRadiam
FutureCISO Editors

FutureCISO Editors

No Result
View All Result

Recent Posts

  • Sensitive data exposed: Calling for API protections
  • AI spending displaces traditional security budgets in APAC
  • AI revolutionises threat detection for MDR
  • Cohesity enhances MongoDB data protection
  • Logistics sector faces network security crisis

Categories

  • Blogs
  • Compliance and Governance
  • Culture and Behaviour
  • Cybersecurity careers
  • Data Protection
  • Endpoint Security
  • Incident Response
  • Network Security
  • People
  • Process
  • Resources
  • Risk Management
  • Technology
  • Training and awarenes
  • Videos
  • Webinars and PodChats
  • White Papers

Strategic Insights for Chief Information Officers

FutureCISO serves the interests of the Chief Information Security Officer (CISO) and the information security profession. Its purpose is to provide relevant and timely industry insights around all things important to security professionals and organisations that recognize and value the importance of protecting the organisation’s data and its customers’ privacy.

Cxociety Media Brands

  • FutureIoT
  • FutureCFO
  • FutureCIO

Categories

  • Privacy Policy
  • Terms of Use
  • Cookie Policy

Copyright © 2024 Cxociety Pte Ltd | Designed by Pixl

Login to your account below

or

Not a member yet? Register here

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
Login

Copyright © 2024 Cxociety Pte Ltd | Designed by Pixl