ETFOptimize | High-performance ETF-based Investment Strategies

Quantitative strategies, Wall Street-caliber research, and insightful market analysis since 1998.


ETFOptimize | HOME
Close Window

Shining a Light on Hackers’ New Favorite Target: Expert Panel Shares Eye-Opening Security Insights to Risks and Blind Spots of APIs

Sensedia Sponsors Informative Discussion on Critical API Security and Governance

Sensedia, the global leader in delivering API and microservice solutions, presents an expert panel discussion, 5 Reasons Why API Security and Governance Matter. This free and informative session is available to stream on-demand here. Industry analysts warn that APIs will become the most commonly targeted attack vector in the enterprise if they aren't already. API security is now a C-suite level discussion.

Filipe Torqueto, Head of Solutions at Sensedia, USA, Chuck Herrin, CTO and Board Director at Wib, and Zoe Strickland, Senior Fellow at Future of Privacy Forum, joined moderator Paul Wilke, CEO of Upright Position Communications, to discuss the importance of ensuring APIs are secure and governed. The panel reviewed five areas on which leaders should focus:

  • Scalable and Consistent Execution
  • Cost-Effectiveness
  • Risk Mitigation and Trust
  • Compliance
  • Collaboration

As technology teams increase delivery speed to market, APIs are an ideal solution. When technology expands within organizations, APIs can be a blind spot. Many companies don't know exactly how many APIs they have within their platforms accessing their data. Having scalability and consistent execution is critical for companies to stay secure.

"The technology teams need to accelerate delivery. A great way to do that is by embracing APIs and microservices that use them, which changes your architecture, which naturally changes your attack surface. So the attackers adapt," says Herrin. "This puts security and governance teams behind the curve, and we typically and often see our clients underestimate 2X, 5X, how many APIs they actually have. APIs are so much easier to expose and publish than they are to understand and govern. I see this getting worse before it starts to get better."

Torqueto adds, "We don't have a one-size fits all solution. The secret word here is adaptive. We need to know what we're doing, for whom we're doing it, and the risk around it. We're thinking about frameworks, architectures, APIs, everywhere, and we must also discuss the management, the governance, and the security."

Understanding and implementing strong API security and governance saves businesses money and builds trust. According to Strickland, "Costs themselves can be substantial. If you do have an incident, you'll likely need to hire consultants to help you figure out what happened because you've got to get on it right away. I can't even tell you the sense of urgency that needs to happen. You might need to hire lawyers too, depending on how serious the incident is and how much hot water you're in."

During the insightful one-hour webinar, the speakers delved into the relationship between risk mitigation and compliance, sharing that proper risk management supports compliance, and according to Torqueto, we need to understand that regulations are there to protect us and regulators are the good guys, not the bad guys. "We need to detach this regulation and compliance word from the killers of agility," he states.

Collaboration emerged as a key theme in the panel’s discourse. One critical point Herrin makes is how few of our technology problems are actually technology problems. "The security team may not even be aware of what's going on in the development shop. And those internal silos and blind spots wind up manifesting as a weak exterior attack surface." He continues, "Ongoing collaboration internally is critical. And it starts with a little bit of empathy and a little bit of understanding your business and technology goals."

The security experts share many more insights throughout the session. With APIs now the major attack surface for the outside world, it's essential to listen to what they have to say, so leaders can take action and keep their businesses and customers secure.

ABOUT SENSEDIA

Sensedia supports companies to become more digital, connected and open through a technology platform and expertise in APIs and Microservices. Whether aiming to integrate channels, enable partner ecosystems or create modern multi-cloud/hybrid architectures, innovative enterprises rely on Sensedia as a partner in API Management, Microservices, Service-Mesh, Open Banking and enabling rapid legacy integration. More at www.sensedia.com.

Contacts

Stock Quote API & Stock News API supplied by www.cloudquote.io
Quotes delayed at least 20 minutes.
By accessing this page, you agree to the following
Privacy Policy and Terms Of Service.


 

IntelligentValue Home
Close Window

DISCLAIMER

All content herein is issued solely for informational purposes and is not to be construed as an offer to sell or the solicitation of an offer to buy, nor should it be interpreted as a recommendation to buy, hold or sell (short or otherwise) any security.  All opinions, analyses, and information included herein are based on sources believed to be reliable, but no representation or warranty of any kind, expressed or implied, is made including but not limited to any representation or warranty concerning accuracy, completeness, correctness, timeliness or appropriateness. We undertake no obligation to update such opinions, analysis or information. You should independently verify all information contained on this website. Some information is based on analysis of past performance or hypothetical performance results, which have inherent limitations. We make no representation that any particular equity or strategy will or is likely to achieve profits or losses similar to those shown. Shareholders, employees, writers, contractors, and affiliates associated with ETFOptimize.com may have ownership positions in the securities that are mentioned. If you are not sure if ETFs, algorithmic investing, or a particular investment is right for you, you are urged to consult with a Registered Investment Advisor (RIA). Neither this website nor anyone associated with producing its content are Registered Investment Advisors, and no attempt is made herein to substitute for personalized, professional investment advice. Neither ETFOptimize.com, Global Alpha Investments, Inc., nor its employees, service providers, associates, or affiliates are responsible for any investment losses you may incur as a result of using the information provided herein. Remember that past investment returns may not be indicative of future returns.

Copyright © 1998-2017 ETFOptimize.com, a publication of Optimized Investments, Inc. All rights reserved.