Research highlights rapidly growing API ecosystems, rising attack activity, and lack of API security maturity
PALO ALTO, Calif., June 18, 2024 — Salt Security, the leading API security company, today unveiled the findings from the Salt Labs State of API Security Report, 2024. The research, which analyzed survey responses from 250 IT and security professionals, combined with anonymized empirical data from Salt customers, highlights a lack of API security maturity and posture governance across organizations, leading to a rise in API security incidents and attack traffic.
The research found that almost all (95%) survey respondents experienced security problems in production APIs, with 23% suffering breaches as a result of API security inadequacies. The volume of APIs within organizations is also accelerating, with Salt customer data showing a 167% increase in API counts over the past 12 months, and nearly two-thirds (66%) of survey respondents indicating that they are managing more than 100 APIs. With increased API usage, comes an expanded API attack surface putting malicious activity on the rise.
The 2024 report also highlights the ongoing lack of API security maturity. Only 7.5% of organizations consider their API security programs to be ‘advanced’ and alarmingly, over one-third (37%) of the respondents, who have APIs running in production, do not have an active API security strategy in place. Despite this, nearly half (46%) of respondents stated that API security is a c-level discussion within their organization.
According to the research, API posture governance strategies, which provide a structured framework for managing and securing the entire API ecosystem from design to deployment, also remain a relatively new phenomenon. Only 10% of organizations currently have an API posture governance strategy in place. However, realizing its critical importance, almost half (47%) plan to implement such a strategy within the next 12 months. By deploying and implementing a robust API posture governance engine, organizations can gain complete visibility into their API landscape, eliminate blind spots, and establish corporate-wide security standards and regulations across their entire API ecosystem.
“The volume of APIs within organizations are showing no sign of decline, and security teams are struggling to keep pace with the sheer breadth and depth of modern API ecosystems,” said Roey Eliyahu, co-founder and CEO, Salt Security. “As illustrated by the findings of our research, attackers are continuing to take advantage of this, leveraging weak spots within APIs to execute malicious attacks and gain access to company and customer data. With bad actors constantly refining their tactics to discreetly launch API attacks, often through legitimate means, it requires organizations to take a more sophisticated approach to securing APIs. One that encompasses strong API discovery capabilities, a posture governance strategy, and the ability to quickly and efficiently detect active threats and malicious API traffic.”
The research revealed that API security incidents are on the rise.
Respondents expressed high levels of concern about the potential risks associated with "Zombie" APIs -he outdated, forgotten APIs within ecosystems.
API discovery was highlighted as an ongoing hurdle for many organizations.
The rapid change of APIs, combined with the increasing use of AI-generated APIs, has rendered traditional documentation methods obsolete.
A large percentage of API attacks target well-known security weaknesses outlined in the OWASP API Security Top 10 list.
The State of API Security Report, 2024, was compiled by researchers from Salt Labs, the research division of Salt Security, utilizing survey data from nearly 250 respondents across a range of job responsibilities, industries, and company sizes, globally. 20% of respondents were executive-level security or IT leaders, and another 18% within platform or DevOps teams. Technology and financial services companies—widely viewed as the forefront of API usage —comprised 37% of respondents. Companies large and small were evenly represented. The report also includes real-world API attack attempt data from the Salt Security API Protection Platform. This customer data is anonymized, aggregated, and then analyzed by Salt’s researchers to identify critical trends that can help educate the broader security industry.
To download a copy of the full report, please visit: https://content.salt.security/state-api-report.html
A comprehensive blog exploring the findings also be found here: https://salt.security/blog/increasing-api-traffic-proliferating-attack-activity-and-lack-of-maturity-key-findings-from-salt-securitys-2024-state-of-api-security-report