Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

API security strategy gaps: are your controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: A survey of 300 security leaders finds 73% of CISOs rate API security as top or critical, yet only 17% say they have a comprehensive implemented strategy, while 74% are surprised by new undocumented APIs and 16% feel adequately staffed to triage alerts, according to Salt. The gap is operational, not aspirational, and it leaves shadow APIs, legacy tooling, and business logic abuse outside practical governance.

NHIMG editorial — based on content published by Salt: API security strategy gaps and the visibility crisis

By the numbers:

Questions worth separating out

Q: What breaks when API discovery is missing from the security programme?

A: Security teams lose the ability to prove coverage.

Q: What problem does ownership attribution solve for service accounts and API keys?

A: It closes the gap between exposure detection and accountable remediation.

Q: How can security teams tell whether API risk controls are actually working?

A: Look for reduced abuse volume, fewer successful automated attacks, and clearer visibility into which non-human clients are making requests and why.

Practitioner guidance

  • Establish continuous API discovery Inventory every internal, external, managed, and unmanaged API on a cadence that matches release velocity, then reconcile ownership, authentication method, and data sensitivity after each change window.
  • Tie API review to identity and secrets governance Map each API to the service accounts, tokens, and API keys it depends on, then verify rotation, offboarding, and scope reduction whenever an endpoint changes.
  • Measure unowned and undocumented API exposure Track the number of APIs with no named owner, no recent review, or no documented data flow, and treat growth in that metric as a governance exception requiring escalation.

What's in the full article

Salt's full analysis covers the operational detail this post intentionally leaves for the source:

  • Detailed breakdown of Salt Illuminate's discovery workflow for internal, external, managed, and unmanaged APIs.
  • Examples of how the platform maps data flows and attack signals across API relationships.
  • Policy Hub coverage showing how the vendor frames OWASP and PCI alignment at the point of access.
  • Context-rich alerting examples for business logic abuse and data exfiltration scenarios.

👉 Read Salt's analysis of the API security strategy gap and shadow API risk →

API security strategy gaps: are your controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

API security is becoming an identity governance problem, not only an application security problem. APIs carry service identities, tokens, delegated permissions, and access paths that often outlive the change records that created them. When teams cannot reconcile API inventories with credential ownership and authorisation scope, the real control gap sits in access governance. Practitioners should treat undocumented APIs as unmanaged identities with data reach.

A question worth separating out:

Q: Which frameworks help teams align API discovery with security governance?

A: NIST Cybersecurity Framework 2.0 and NIST SP 800-53 Rev 5 are useful starting points because they connect asset visibility, access control, and continuous monitoring. For API-heavy estates, map discovery outputs to those controls so inventory, authentication, and testing are managed as one process.

👉 Read our full editorial: API security strategy is lagging behind discovery and response needs



   
ReplyQuote
Share: