Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Managing resilience»Technology»Are we misunderstanding API risk and how to control it? (Page 14)
Technology

Are we misunderstanding API risk and how to control it?

Mohammad Ismail says that businesses must stop regarding API security as simply a matter of discovery.
September 26, 20256 Mins Read
API concept.

Application Programming Interfaces (APIs) now underpin much of the digital services we consume, but many businesses have rolled them out in such numbers and at such speed that they’ve struggled to document them. The APIs then become ready targets for attackers who are able to study and subvert them to gain access to the valuable data they gatekeep.

The answer to governing this API footprint, according to the security industry, is to carry out discovery to net those APIs that have been operating off-radar and to decrease the attack surface.

Discovery can be used to reveal shadow APIs (those the business didn’t know about), zombie APIs (those that have persisted and which may or may not serve a purpose), and those deemed non-compliant (missing specifications). But the process can vary in its thoroughness. It may not seek to create an inventory of internal, external, and third-party APIs, for example, or may not operate on a continuous runtime basis, thereby governing APIs throughout their lifecycle.

However, discovery shouldn’t be regarded as a means of managing risk in and of itself. Once you have documentation, you need to look at those APIs and assess the risk they represent. This can be difficult because, if the business is going it alone and trying to adhere to a framework like the OWASP API Security Top 10, it’s going to struggle to identify which threats to prioritise. Knowing whether account takeover (ATO) or broken object level authorisation (BOLA) is more pressing is hard; and giving equal weight to too many attack types negates the purpose of the exercise, which is to appropriately and proportionately apply security.

Of course, in many ways determining the risk an API poses will only become known once it is deployed and comes under attack. Theory will only get you so far, but by that time it’s too late, which is why relying on a discovery-based approach is flawed. Focusing on discovery can see the business fail to monitor what’s happening in the API traffic and to spot any changes in the calls being made to APIs, which could be indicative of an attack. Blindsided, the business is then caught in a reactive state.

Early detection is therefore key, but what do you do if you suspect an attack? The general approach has been to offload enforcement to the SOC or development team, or to use Content Delivery Networks (CDNs) or Web Application Firewalls (WAFs) for enforcement. The problem here is that these solutions are not designed to handle API attacks. They struggle to detect and deal with business logic abuse, for instance, which sees the functionality of the API used against it.

A far more logical solution is to handle detection and mitigation natively in line with the API, which allows policies to be customised and response workflows created. This can allow attacks to be stopped in flight using a variety of tactics, from rate limiting to blocking, or deception, whereby the attacker is sent down blind alleyways to frustrate them or to max out their resources.

In addition, it’s advisable to adopt a ‘shield right and shift left’ approach. This involves both stopping the attack in its tracks while simultaneously working cross-functionally with security and development teams to get any API issues resolved. In this way it becomes possible to minimise the window for attackers to do anything harmful while simultaneously improving the attack surface.

One tier-one telecom operator adopting this approach was able to do precisely that. The operator started with continuous runtime discovery and inventory, capturing over 30,000 API endpoints. It then determined which had serious vulnerabilities, such as APIs that did not require authorisation, those that were transmitting sensitive data inappropriately, or those containing known vulnerabilities. By shielding right and shifting left, the operator was then able not just to block access attempts but also to carry out virtual patching of its API base to prevent access to its APIs with outdated authentication algorithms.

Such use cases attest to the value that going beyond the discovery phase can confer. But there’s also another very pressing need for organizations to bolster their API defences; and that is AI.

AI and APIs

Both generative AI and agentic AI use APIs to retrieve information and tools. In the case of agentic AI, which is able to function autonomously, the agent has a two-sided exchange. A set of inbound APIs is used to perceive the world around it, to understand the task at hand, and to collect the data needed to complete the task, with additional APIs used to rationalise the problem and come up with possible solutions. A second set of outbound APIs is then used to test those solutions in a real-world context, measure their success, and learn from the outcomes. This creates two sides to the same coin and significantly raises the risk of compromise.

The dependency of AI on APIs to facilitate these learning journeys makes those APIs a key target for attackers. Stopping those attacks will require much better visibility over both the APIs calling the AI agent and those the agent is consulting for answers. That means we need to know not just that those APIs exist but also how effectively they are protected in terms of the level of authorisation required to access them. At the present time, many APIs have little to no authentication built in, or are using outdated methods. It’s also very difficult to determine the authentication and access controls present in third-party APIs, which means securing AI interactions is going to be challenging.

It’s for these reasons that businesses must stop regarding API security as simply a matter of discovery. Discovery, inventory, and compliance are undoubtedly important, but these are baseline activities that fail to equip the business with the means to monitor, detect suspicious activity, and defend their APIs. It’s only by embracing runtime visibility, native protection, and real-time mitigation that we can meet these dynamic attacks with the necessary dynamic response and ensure these APIs don’t scupper AI.

The author

Mohammad Ismail is VP of EMEA, Cequence Security

Africa Asia Asia Pacific Australasia Europe Middle East North America UK
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleCyber and data attacks are seen as by far the biggest threats to organizations in 2026
Next Article From threat to operational resilience: understanding and managing open source risks in your organizational software

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
Multiracial people in a city wearing face masks.

UK Government publishes Pandemic Preparedness Strategy

March 26, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?