• About
  • Subscribe
  • Contact
Friday, May 9, 2025
    Login
FutureCISO
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
No Result
View All Result
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
No Result
View All Result
FutureCISO
No Result
View All Result
Home Technology Endpoint Security

Urgent gaps in API security exposed

FutureCISO Editors by FutureCISO Editors
October 8, 2024
Urgent gaps in API security exposed

Photo by Vitaliy Mitrofanenko: https://www.pexels.com/photo/person-holding-on-black-metal-fence-9510438/

Share on FacebookShare on Twitter

F5’s 2024 State of Application Strategy Report: API Security reveals alarming deficiencies in API protection, highlighting critical vulnerabilities that could endanger enterprise security. Released on October 3, 2024, the report emphasizes the rapid growth of APIs in the digital landscape, with less than 70% of customer-facing APIs secured using HTTPS. This leaves nearly one-third of these APIs vulnerable, contrasting sharply with the 90% of web pages currently utilizing HTTPS.

Lori MacVittie, a distinguished engineer at F5, notes that while APIs are essential for digital transformation, many organizations are failing to meet the necessary security standards, particularly in light of emerging AI threats. The report identifies several key issues:

  • API Proliferation: Organizations typically manage around 421 APIs, primarily hosted in public cloud environments. However, many customer-facing APIs remain unprotected.
  • Evolving Security Needs: As APIs increasingly interface with AI services, security measures must adapt to protect both inbound and outbound traffic. Current practices tend to focus predominantly on incoming traffic, leaving outbound calls at risk.
  • Fragmented Security Responsibility: The responsibility for API security is often divided within organizations, with 53% managing it under application security and 31% through API management platforms. This division can create inconsistencies and gaps in security coverage.
  • Demand for Programmable Security: Survey respondents highlighted the importance of programmability in API security solutions, indicating a need for real-time inspection and response to threats.

To mitigate these vulnerabilities, the report advises organizations to adopt comprehensive security strategies covering the entire API lifecycle—from design to deployment. Integrating API security into both the development and operational phases is crucial for safeguarding digital assets against an increasing array of threats. The findings serve as a call to action for organizations to reassess their API security frameworks to ensure safe and effective operation in the AI-driven era.

Related:  Security leaders elevating API security concerns and strategies

Tags: API securityF5
FutureCISO Editors

FutureCISO Editors

No Result
View All Result

Recent Posts

  • DDoS attacks surge in Asia Pacific, claims Cloudflare
  • Reimagining security for the AI Era
  • PodChats for FutureCISO: Articulating the business value of security in 2025
  • New standard for cybersecurity at the storage layer
  • Cybersecurity challenges persist despite improved defenses

Categories

  • Blogs
  • Compliance and Governance
  • Culture and Behaviour
  • Cybersecurity careers
  • Data Protection
  • Endpoint Security
  • Incident Response
  • Network Security
  • People
  • Process
  • Resources
  • Risk Management
  • Technology
  • Training and awarenes
  • Videos
  • Webinars and PodChats
  • White Papers

Strategic Insights for Chief Information Officers

FutureCISO serves the interests of the Chief Information Security Officer (CISO) and the information security profession. Its purpose is to provide relevant and timely industry insights around all things important to security professionals and organisations that recognize and value the importance of protecting the organisation’s data and its customers’ privacy.

Cxociety Media Brands

  • FutureIoT
  • FutureCFO
  • FutureCIO

Categories

  • Privacy Policy
  • Terms of Use
  • Cookie Policy

Copyright © 2024 Cxociety Pte Ltd | Designed by Pixl

Login to your account below

or

Not a member yet? Register here

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
Login

Copyright © 2024 Cxociety Pte Ltd | Designed by Pixl