A new survey-based report by Salt Security has found that the majority of CISOs struggle when it comes to API security, with only 17% having a fully developed strategy in place. Additionally, the majority of CISOs do not have full visibility over their API environments, despite recognition of the growing API attack surface.
The 2025 Salt Security CISO Report – API Blindspots and Breakthroughs: How CISOs are approaching API risk – found that while 73% of CISOs rank API security as a high or critical priority for the next 12 months, only 17% reported having a comprehensive and implemented API security strategy, highlighting the growing gap between awareness and action when it comes to API security.
The report also revealed that only 19% of CISOs globally have full visibility and confidence in tracking APIs across their organization. Among large enterprises, only 27% report full oversight. For smaller organizations, the number shrinks to 12%. This general lack of visibility poses a persistent and growing security risk to organizations, with many easily exploitable shadow APIs potentially lurking within an environment.
Highlighting this risk, 74% of CISOs admit to constantly uncovering APIs that they did not know existed. A further 9 in 10 CISOs can’t confirm that they’re free of unmanaged APIs, highlighting widespread uncertainty and visibility gaps in API environments.
Protection and tools
The research found that legacy tools are the primary line of defence for most CISOs. To secure APIs, 76% of CISOs rely on WAFs, and 72% on API gateways.
“There is an evident overconfidence in legacy tooling to protect against uniquely modern and complex threats,” said Michael Callahan, Chief Marketing Officer of Salt Security. “These tools were not built with the threats faced by organizations today in mind, especially as the threat landscape has evolved so quickly and unpredictably in recent years. Legacy tech paired with a lack of visibility over the entire API ecosystem presents a worrying picture for CISOs aiming to secure their organization effectively. Modern issues need modern solutions that are scalable, efficient and effective.”
Methodology
The research for API Blindspots and Breakthroughs: How CISOs are approaching API risk was conducted by Global Surveyz Research and features insights from 300 CISOs from France, Germany, Italy, the United Kingdom and the United States, all of whom work at companies with more than 1,000 employees. The CISOs surveyed work across a number of industries including financial services, healthcare, transportation, retail, and software.






