Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

API security gaps and zombie endpoints: are your controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: 37% of respondents experienced an API security incident in the past 12 months, while only 58% have an established discovery process and just 7.5% run dedicated API testing and threat modelling, according to Salt’s 2024 State of API Security Report. The signal is clear: API sprawl is now a governance problem, not just a development problem.

NHIMG editorial — based on content published by Salt: the 2024 State of API Security Report preview

By the numbers:

Questions worth separating out

Q: What breaks when API discovery is incomplete?

A: When discovery is incomplete, security teams miss shadow APIs, forgotten integrations, and endpoints that no longer have an obvious owner.

Q: Why do APIs create identity governance risk across machine and human access?

A: APIs often carry the real access decision for service accounts, tokens, and human sessions.

Q: What do security teams get wrong about API posture governance?

A: They often treat it as a late-stage scan rather than an operating model.

Practitioner guidance

  • Implement continuous API discovery Link discovery to gateways, source control, and runtime traffic so new or changed endpoints are detected before they become blind spots.
  • Bind machine credentials to workload context Replace broad, reusable API secrets with scoped credentials that are tied to a specific workload, environment, or service purpose.
  • Add security gates to API lifecycle events Require design review, threat modelling, authentication checks, and retirement validation at release and decommissioning stages.

What's in the full report

Salt's full State of API Security Report covers the operational detail this post intentionally leaves for the source:

  • Survey breakdowns showing how API incidents vary across organisation size and maturity.
  • The in the wild vulnerability research behind the report’s discovery findings.
  • The full set of remediation priorities for teams building API posture programmes.
  • Benchmark context that helps security leaders compare their own API governance maturity.

👉 Read Salt’s State of API Security Report on API growth, incidents, and governance gaps →

API security gaps and zombie endpoints: are your controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

API sprawl is now an identity problem, not just a development problem. The report’s data shows that discovery, authentication, and posture management are lagging behind growth, which means governance is being asked to manage interfaces it cannot reliably see. For NHIs, that is especially important because APIs are often reached with service accounts, tokens, and workload credentials that sit outside traditional human IAM processes. Practitioners should treat API inventory as a living identity map, not a static catalogue.

A question worth separating out:

Q: Who is accountable when a public API leaks data through valid access?

A: Accountability usually spans application owners, IAM or platform teams, and security leadership, because the failure is shared between access design, endpoint logic, and monitoring. In regulated environments, the organisation must also be able to show that access controls and logging were proportionate to the sensitivity of the data involved.

👉 Read our full editorial: API security gaps widen as inventories, testing lag behind



   
ReplyQuote
Share: