API MythBusters: The Five Myths Putting You at Risk

preview_player
Показать описание
Any company developing applications today is running more – and more critical – APIs than ever. Those APIs are essential for connecting customers and partners to critical data and services.

Hackers fully realize that APIs map the route to a company’s crown jewels, making them well worth the time and effort to attack. We get news of API-based breaches several times a month. But too many organizations haven’t woken up to the scope of this threat yet. They’re hanging onto old ways of thinking about API security – wrong notions that keep them vulnerable.

Listen to our discussion on the five most persistent myths surrounding API security. You’ll hear first hand how one CISO got his wake-up call, and you’ll get rich insights into the pitfalls to avoid and the hyped security tactics that can’t really help in protecting APIs.

Key takeaways:
- The impact trends such as zero trust, cloud migration, containerization, and shift-left are having on API security
- The role of traditional security controls in API security – what they deliver and where they fall short
- The value of a full lifecycle approach in grappling with API security
- How to deploy dedicated API security that fits today’s automated, agile, and cloud-first environments

Speakers: Curtis Simpson (CISO, Armis), Michael Isbitski (Salt), Michelle McLean (Salt)
Рекомендации по теме
Комментарии
Автор

Great presentation - just trying to get my head around how API flows might disclose business logic flaws in a TLS (1.2 or 1.3) session - I understand most state is kept at client side but still...

rikherlaar
Автор

Great information.
The foundations of cybersecurity are very rapidly changing.



Would Salt Security's API protect small tax preparation offices that fully depend on external cloud-based services such as Intuit's ProConnect tax, Intuit Link for file sharing and Google Workspace office apps?



OR



Is Salt Security more directed at companies like Intuit itself to help Intuit secure its APIs.





Another question:
If we are using Google's AppSheet no-code system to create new API-based apps, are those apps automatically fully secured against all of the threats mentioned in your video?

Should we / can we integrate Salt's API security into our AppSheet created programs for full spectrum API security?
Can Salt's API security system even be integrated into these no-code, click-n-build app programs?

mikepallcynac