CISOs urged to fix API risk before regulation forces their hand

CISOs Warn of Growing API Security Risks and Lack of Protections Across Industries
Photo: Help Net Security

CISOs Warn of Growing API Security Risks and Lack of Protections Across Industries

A recent report by Raidiam, titled ‘API Security at a Turning Point’, sheds light on alarming gaps in API security practices across industries. The research, based on an assessment of 68 organizations, highlights that over 80% of organizations handle sensitive data like personal and payment information through APIs but employ weak security measures such as static API keys and shared secrets. Only one company in the study implemented what is considered a modern security stack, including mutual TLS and client certificate authentication. This lack of robust security measures leaves APIs vulnerable to attacks and exposes sensitive data to potential misuse. The report stresses that organizations, particularly those not under regulatory pressure, must take urgent steps to improve their API security practices. The use of mutual TLS, certificate-bound tokens, and other advanced security methods, as seen in financial-grade APIs, could dramatically reduce security risks. Despite the proven effectiveness of these practices in regulated industries, most organizations outside these sectors continue to rely on outdated security methods. The report urges businesses to adopt these practices to safeguard their APIs, emphasizing the importance of board-level oversight and monitoring API security improvements over time.

Leave a Reply

Your email address will not be published. Required fields are marked *