Widespread API Use Heightens Cybersecurity Risks
February 05, 2018

Tami Casey
Imperva

IT professionals show a heightened concern for cybersecurity risk related to API use, according to a new survey conducted by Imperva.

Specifically, 63 percent of respondents are most worried about DDoS threats, bot attacks, and authentication enforcement for APIs.

APIs power the interactive digital experiences users love and are fundamental to an organization’s digital transformation. However, they also provide a window into an application that presents a heightened cybersecurity risk. The survey shows that more than two-thirds (69 percent) of organizations are exposing APIs to the public and their partners and that organizations are on average managing 363 different APIs.

Public-facing APIs are a key security concern because they are a direct vector to the sensitive data behind applications. 80 percent of organizations use a public cloud service to protect the data behind their APIs with most people using the combination of API gateways (63.2 percent) and web application firewalls (63.2 percent).


“APIs represent a growing security risk because they expose multiple avenues for hackers to try to access a company’s data,” said Terry Ray, CTO for Imperva. “To close the door on security risks and protect their customers, companies need to treat APIs with the same level of protection that they provide for their business-critical web applications.”

92 percent of IT professionals believe that DevSecOps, the combination of development, security and operations, will play a part in the future of application development. This highlights an increased desire from many organizations for security to be built in from the very beginning of software development rather than as an after-thought.

“It is very encouraging that the majority of respondents to our survey expect DevSecOps to be involved in the future of application development. Cybercrime is pervasive, and it is vital that organizations keep their applications safe from hackers. Embracing DevSecOps provides organizations with the building blocks needed for defense against some of the most serious cybersecurity threats,” Ray concluded.

Tami Casey is Director of Public Relations at Imperva
Share this

Industry News

September 19, 2019

DevOps Institute has entered into a fundraising partnership with the global Teach For All network in conjunction with the 2020 Upskilling: Enterprise DevOps Skills Survey.

September 19, 2019

Idera announced an agreement to acquire the software assets and related entities of WhereScape Software LTD., a provider of data infrastructure automation software.

September 19, 2019

Automox announced the launch of Automox Alive, a community for IT and security practitioners that facilitates the sharing of extensible Automox Worklets, to improve cyber hygiene.

September 18, 2019

Parasoft SOAtest API and UI functional testing solution has won a 2019 API Award in the Best in Microservices Infrastructure category.

September 18, 2019

Micro Focus announced the general availability of Vertica in Eon Mode for Pure Storage.

September 18, 2019

Mindtree announced a new service, InnoApp for Kubernetes, enabling enterprises to deploy containerized cloud applications on Microsoft Azure, accelerating application setup and innovation.

September 17, 2019

Redgate launched SQL Change Automation 4.0, extending its database change management automation tool to the free Microsoft SQL Server Management Studio (SSMS) development environment for the first time.

September 17, 2019

Oracle and VMware announced an expanded partnership to help customers leverage the companies’ enterprise software and cloud solutions to make the move to the cloud.

September 17, 2019

FireMon announced the introduction of FireMon Automation, a comprehensive set of policy automation management solutions designed to chart the course to smart security process automation.

September 16, 2019

Oracle announced the general availability of Java SE 13 (JDK 13).

September 16, 2019

Data Intensity launched its Automation-as-a-Service offering.

September 16, 2019

Mobile Labs launched the final addition to its mobile device cloud suite: GigaFox Red and GigaFox Silver.

September 12, 2019

Rafay Systems announced the general availability of its turnkey, SaaS-based offering designed to confront a complex set of ongoing challenges enterprises and service providers face when modernizing their applications.

September 12, 2019

StackRox announced the availability of the StackRox App for the Sumo Logic Continuous Intelligence Platform.

September 12, 2019

Lacework is receiving $42 million from Sutter Hill Ventures and Liberty Global Ventures.