
Chuck Herrin at F5 Security explains how to augment API discovery and protection capabilities
Application programming interfaces (APIs) are the hidden central nervous system of our digital lives.
All day, every day, APIs power the apps we use to purchase our first coffee from our favourite shops, badge into the door at the office, grab a rideshare to get lunch with a colleague, check the weather, and finally sit down at the end of a long day to stream a TV show. Nearly every organisation that we interact with each day relies on APIs to drive their digital business, whether they think of it that way or not.
The rise of API-first software development and delivery has changed the world for the better in countless ways. But there’s a problem—when your applications and architectures change, so does your attack surface.
Traditional security measures like WAF, DDoS, and bot protection remain essential, but they fall short in fully safeguarding these APIs. They were built for the attack surfaces of the day, unable to predict the future attack surface and changes brought about by the rapid adoption of APIs in the last few years.
Research found that over 90% of web-based cyber-attacks target API endpoints, attempting to exploit newer, less understood vulnerabilities, often exposed by APIs not actively monitored by security teams.
As attacks and attack surfaces change, your defence must adapt as well. The industry’s current focus on generative AI is also spurring rapid growth in the volume of apps and APIs to support artificial intelligence and machine learning (AI/ML) models, adding further complexity.
Modern businesses need a dynamic defence strategy, focusing on discovering and mitigating risks before they escalate into expensive, embarrassing, and often preventable breaches.
The pace of these rapid changes has made securing critical APIs a significant challenge for organisations of all types. Already-stretched teams of developers and defenders often do not even know how many APIs their companies use, where they are, or the compliance and other risks associated with the critical data and business processes these interfaces support.
While technology is always changing, the API security phenomenon underscores the bedrock principles of cyber-security. There’s a reason major control frameworks like NIST almost always start with “Identify”. Simply put, you can’t protect what you can’t see, and it’s impossible to effectively manage the risk of an attack surface you do not understand.
API blind spots have become a fundamental problem. Gartner and other industry analysts have been predicting since at least 2019 that APIs would become the number one attack vector; and our data supports that assertion, with no sign of slowing.
The cyber-security industry has responded so far mostly with point solutions geared toward one aspect of API development or another. Such products offer diverse but limited capabilities, like API discovery to find APIs known to be in use, or scanning and testing tools to help find vulnerabilities and attempt to close these gaps.
But the future of API security is not a set of point solutions you cobble together and try to integrate yourself. Enter a cyber-security partner.
To build the future of your company, you must equip it for the future.
Industry leaders in distributed computing and application security saw this essential emphasis on APIs coming, and many have already started building a game-changing suite of capabilities aimed at tackling the latest issues.
Today’s AI-powered apps rely on a distributed arrangement of data sources, models, and services across on-premises, cloud, and edge deployments, joined together by a rapidly increasing number of APIs.
To help customers navigate these intertwined challenges and opportunities, cyber-security companies are bringing advanced API code testing and telemetry analysis to create a comprehensive and AI-ready API security solution. They are also adding capabilities such as vulnerability detection and observability to application development processes, which helps their customers identify risks and implement policies before APIs even enter production.
Much like the future of API security, any cyber-security partner built for the future of all enterprise computing, will have these essential attributes:
Many cyber-security businesses already offer robust API discovery and protection services that illuminate API risks with actionable insights, leverage AI/ML to mitigate complex API attacks, and more. Moving forward, the onus should be on shifting left in order to address the full API lifecycle.
Here are some of the capabilities you should look to enhance: augmenting the current API discovery and protection capabilities with:
With true visibility and security from code to cloud, you can securely run every app and every API. Everywhere.
Chuck Herrin is Senior Principal Product Manager – Security at F5
Main image courtesy of iStockPhoto.com and BlackJack3D
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543