90% of businesses experienced API security vulnerabilities in 2020

Report finds that more than a quarter of organizations haven't yet launched an API security strategy

Nine in ten organizations suffered a security incident with their application programming interfaces (APIs) last year, according to a report from security company Salt Security.

An API is a tool that software uses to field queries over the internet, including other cloud-based and mobile apps. They can also make browser-based applications more responsive and fluid. APIs are becoming increasingly popular, with Akamai stating that API queries comprise 83% of web traffic.

However, poorly crafted APIs can be a security risk, allowing people to query information they shouldn't. Examples in the past include a flaw an ethical hacker discovered in a GitLab API that could have exposed private group information. In 2018, an API bug at Google exposed 52.5 million private users’ data, and another at the US Postal Service made near real-time data on 60 million users public.

The report's findings don't mean 90% of people have experienced breaches via APIs. The incidents it described range from the discovery of vulnerabilities (54% of companies found those in production systems) to authentication problems (46%). However, the number of attacks on APIs was still a concern.

One in five companies experienced bot scrapers, and almost the same proportion experienced denial of service attacks via their APIs. Account misuse via APIs plagued 14% of respondents, while 9% saw an API-based data breach.

Related Resource

IBM Maximo 8.0: Moving to an integrated suite of applications

A report on the business benefits of the new Maximo solution

What are the benefits of Maximo 8.0 - integrated suite of applications - whitepaper from IBMDownload now

The respondents surveyed across all company sizes and various sectors revealed a lack of knowledge and strategy around API security. Of those surveyed, 5% had no API security strategy, and 22% were in the planning stages for API security. It's no surprise, then, that 83% of them lacked confidence in the APIs they were using, and 8% had no confidence at all. Companies had not documented their APIs properly because their tools relied on human interaction.

API blindness is a problem when it comes to version control. Outdated ”zombie” APIs that should have been retired long ago are often left exposed. According to Salt, there were anywhere from 40% to 800% more APIs in its clients' infrastructures than employees had documented.

This lack of visibility makes APIs a critical attack point. Salt's software found that 91% of its clients' APIs exposed personal or otherwise sensitive data.

Companies are aware of these security issues and see them as a significant risk and, according to the report, these concerns have delayed 66% of API deployments. There is too much of a focus on pre-production API threat-hunting, it warned, adding that too many people rely on developers and DevOps teams to catch API security issues. Companies must increase collaboration between their security and development teams, it warned.

Featured Resources

2021 Thales cloud security study

The challenges of cloud data protection and access management in a hybrid and multi cloud world

Free download

IDC agility assessment

The competitive advantage in adaptability

Free Download

Digital transformation insights from CIOs for CIOs

Transformation pilotes, co-pilots, and engineers

Free download

What ITDMs did next - and what they should be doing now

Enable continued collaboration and communication for hybrid workers


Hackers publish Vestas data following cyber attack
cyber attacks

Hackers publish Vestas data following cyber attack

9 Dec 2021
Google files lawsuit against Russian botnet operators

Google files lawsuit against Russian botnet operators

8 Dec 2021
Trend Micro Worry-Free Business Security review: Great cloud-managed malware protection
endpoint security

Trend Micro Worry-Free Business Security review: Great cloud-managed malware protection

7 Dec 2021
BitMart suspends withdrawals following hack

BitMart suspends withdrawals following hack

6 Dec 2021

Most Popular

What are the pros and cons of AI?
machine learning

What are the pros and cons of AI?

30 Nov 2021
How to move Microsoft's Windows 11 from a hard drive to an SSD
Microsoft Windows

How to move Microsoft's Windows 11 from a hard drive to an SSD

24 Nov 2021
What is single sign-on (SSO)?
single sign-on (SSO)

What is single sign-on (SSO)?

2 Dec 2021