The Noname Security study also shows that 74% of cybersecurity professionals do not have a complete API inventory or know which APIs return sensitive data.
Shay Levy, chief technology officer and co-founder of Noname Security says:Our research has highlighted the disconnect between large incidents, low levels of visibility, effective monitoring and testing of the API environment, and misplaced confidence that existing tools prevent attacks. This underscores the need for more training for the security, AppSec and development teams on the realities of API security testing.“
Among other findings, 71% of respondents expressed confidence and satisfaction that they had adequate API protection. Less than half of the respondents (48%) had a view of the security status of APIs enabled.
Only 11% of respondents test APIs for signs of abuse in real time, and 39% test them less than once a day and even once a week. 67% of respondents are confident that their DAST and SAST tools are capable of testing APIs.
There are some interesting geographical differences: UK respondents (28%) are more likely to have a full inventory of APIs and know which ones expose sensitive data, compared to the US (24%). However, in the US, 44% have visibility into their entire inventory of APIs, but don’t know which ones are showing sensitive data, compared to 38% in the UK. This tends to indicate that US organizations care more about API-driven growth than they are about securing existing APIs.
There are also differences between the teams: 81% of CISOs reported having experienced an API-related security incident, compared to just 53% of AppSec professionals. Additionally, 58% of CIOs say it’s easy to scale API security solutions, while nearly a third (29%) of AppSec respondents say it’s difficult.
source : Aman without a name
And you?
Do you find this study relevant?
How about inside your company?
See also:
“Hardcore beer fanatic. Falls down a lot. Professional coffee fan. Music ninja.”
More Stories
SALES / PHOTO SALES – Nikon D850 “5 Star” Bare Body Photo Body at €2,539.00
Discovering a new turning point under the Antarctic ice sheet! What are the consequences?
Record number for an insect!