ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Building bridges: defining and maintaining good APIs

Nick Rago at Salt Security explains why API security is rising towards the top as one of the key challenges for CISOs

 

The importance of defining a "good" Application Programming Interface (API) can not be underestimated in today’s interconnected world, which is literally driven by tens of millions of APIs - the proverbial on-ramps to the digital world.

 

Consider, for a moment, the motorway system without bridges; it is universally acknowledged that bridges are essential components of an efficient ground transportation network with features like clear signage, suitable driving surface, and proper lighting.

 

Similar to bridges, APIs play a pivotal role in today’s applications, facilitating critical connections in transformation projects, microservice-driven app modernisations, AI-powered systems and more.

 

However, unlike bridges, there isn’t a consensus on what makes a "good" API, and this lack of clarity poses significant risks to enterprises relying on these interfaces.

 

APIs and security challenges

As APIs have proliferated across enterprises, they’ve introduced major security concerns. From incidents like the Optus data breach, which cost the telecoms company in Australia an estimated $140AUD due to an unauthenticated API, to DropBox, JumpCloud and Twitter also experiencing high-profile security incidents - all because of API-related security issues.  

 

Compounding matters, the attempts to address API security by augmenting existing tools have proven insufficient because they lack the context over time to be able to identify API threats. Traditional security solutions including WAFs, API gateways, API management tools, and identity and access management (IAM) tools weren’t designed to prevent attacks on APIs. 

 

Historically, organisations have relied on testing to spot security flaws before deploying an application. However, the widespread adoption of agile development methodologies and the issue of API sprawl have made testing for every single API vulnerability simply impossible. While standard pre-production testing can find some gaps in API security best practices, they won’t uncover vulnerabilities rooted in API business logic gaps — which are precisely the flaws that today’s attackers will aim to exploit.

 

Additionally, it is not realistic to expect any developer to write fully secure code every time, so the only way to detect and stop API threats is to have runtime protection in place.

 

Organisations now face challenges such as risky API security postures, misconfigurations and logic-based vulnerabilities, leaving them susceptible to threats. The root of the problem lies not in inadequate security tools but in the absence of a comprehensive API security strategy.

 

Anticipating API growth and risks

The use of APIs is set to surge in 2024. And this will be particularly true as the adoption of AI-driven processes and solutions grows. As APIs become conduits for critical and sensitive data, organisations must address the risks associated with this potential API sprawl, before it becomes unmanageable.

 

Put simply, those innovating, cutting-edge organisations who are seeking to drive business efficiencies with AI, will also need to build comprehensive API strategies with security at the heart to avoid opening themselves to new threats. 

 

Another consideration is that the emergence of generative intelligence to develop APIs introduces a new set of potential regulatory challenges, emphasising the need for corporate standards on what constitutes a "good" API from a security standpoint.

 

Failure to control or set standards when it comes to APIs could become a huge risk for organisations, not only in terms of potential data loss and theft, but also API manipulation which could amount to monetary losses.

 

Defining "good" and sharing standards

To effectively reduce API-related risks, organisations must implement a strategy that spans from design to deployment. Establishing an API security posture governance programme is crucial, beginning with an understanding of existing API assets, their potential attack surface and capturing contextual intelligence. With this information, organisations can better define their standards, policies and best practices, creating a source of truth that aligns and guides all API stakeholders.

 

In order to be able to assess effectiveness comprehensively, a successful API posture governance programme should not only set the policies but in addition, continuously evaluate compliance with corporate standards, best practices and regulatory requirements. Prioritising and swiftly remediating non-compliance is essential to avoid compounding and repeating mistakes. 

 

It is well known that many API attacks are logic attacks, and the behaviours associated with these attacks typically evade traditional web defenses in use by many organisations. Therefore, API behavioural anomaly detection needs to be viewed almost as a specialist discipline, instead of trying to lump it in with other forms of threat intelligence.

 

Because of the “low and slow” tactics typically associated with API security threats, it takes a tonne of data and a myriad of cloud compute power to effectively and accurately identify anomalous behaviour. 

 

Having said that, it doesn’t have to require infinitely more resources to defend against API security threats. An efficient API posture governance programme provides the foundation for a successful behavioural threat protection programme by supplying it with the context rich API intelligence needed to help distinguish between benign anomalies and malicious intent.

 

This intelligence also helps security teams triage, prioritise, contain, and remediate production threats and vulnerabilities uncovered at runtime more effectively.

 

API security essentials

When looking into requirements for an API security solution, there are some key features to look out for that will help ensure optimal protection for organisations. For example, a good API security platform should foremostly be able to discover all new and changed APIs, along with the sensitive data they expose; detect and stop attacks on APIs during a reconnaissance phase; and eliminate vulnerabilities in the build phase by providing actionable advice to development teams.  

 

A complete API security solution should also be able to collect, store and analyse hundreds of attributes across millions of users and API calls and, more importantly, leverage artificial intelligence (AI) and machine learning (ML) to correlate them over time to learn from these behaviours. Gaining this breadth of context requires cloud-scale big data, as server or virtual machine-based approaches won’t have a broad enough data set over time to identify today’s sophisticated, low and slow API attacks.

 

More sophisticated approaches include total API posture governance, giving organisations the ability to comprehensively author and assess compliance with corporate standards, best practices and regulatory requirements. 

 

API security will rise towards the top as one of the key challenges for CISOs in 2024. The proliferation of AI-enabled everything is set to compound security concerns further, with APIs acting as the bridges to new innovative products and services in the digital world. Organisations need to ensure these bridges are built and maintained securely to forge a safer future. 

 


 

Nick Rago is field CTO at Salt Security

 

Main image courtesy of iStockPhoto.com


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543