Businesses disconnected from realities of API security | Computer Weekly
Summary
“The continuing increase in reported API security incidents over the past two years demonstrates that this is not a fleeting trend, but a pressing reality that organisations must deal with and prioritise,” he said. However, he continued, APIs are also a clear source of risk for several reasons – they are mission-critical to most large organisations; exist in a scattered environment across multiple public clouds, gateways and regions; and crucially, their use puts security teams and developers in conflict. • As developers build more complex applications, the widespread use of APIs is creating significant security challenges for organisations, according to a new survey from ESG. “Because modern API threats are so rooted in the business logic approach, WAFs and gateways, while they served a purpose, just weren’t built for these challenges. Happily, the report also found clear evidence that security leaders are making API security more of a priority than they did 12 months ago – 81% said this was the case (84% in the UK and 78% in the US) – and the data also clearly suggested the impact of the increased volume of API-linked incidents, such as loss of reputation and employee or customer churn, was hitting home.