New Study Finds 84% of Security Professionals Experienced an API Security Incident in the Past Year
Rhea-AI Summary
Akamai Technologies released its third annual API Security Impact Study, revealing concerning trends in API security. 84% of respondents experienced API security incidents in the past year, up from 78% in 2023. The study, surveying 1,207 security leaders across the US, UK, and Germany, found that only 27% of participants have a full API inventory and know which APIs exchange sensitive data, down from 40% in 2023.
The average cost to remediate API incidents was $591,404 in the US, rising to $832,801 in financial services. Energy/utilities reported the highest incident rate (91%), while retail/ecommerce had the lowest (68%). CISOs ranked addressing generative AI threats (25.5%) and securing APIs (24.8%) as top priorities.
Positive
- Retail/ecommerce sector shows lowest API incident rate at 68%
- API security ranks as second-highest priority for CISOs (24.8%)
Negative
- 84% of respondents experienced API security incidents, up from 78% in 2023
- Only 27% of participants have full API inventory visibility, down from 40% in 2023
- High remediation costs: $591,404 average in US, $832,801 in financial services
- Real-time API testing decreased from 18% to 13% in US and UK
- 91% incident rate in energy/utilities sector despite low priority ranking
News Market Reaction 1 Alert
On the day this news was published, AKAM declined 1.48%, reflecting a mild negative market reaction.
Data tracked by StockTitan Argus on the day of publication.
Only
The study finds that
Although API incursions are up, the percentage of participants who have a full API inventory and know which APIs exchange sensitive data dropped from an already low
The API Security Impact Study surveyed security leaders from the following industries: financial services, retail/ecommerce, healthcare, government/public sector, manufacturing, energy/utilities, automotive, and insurance. Energy/utilities reported the highest number of API security incidents (
Other findings of the survey include:
- The average cost to remediate API incidents was
in$591,404 the United States In sectors such as financial services, the average rose to .$832,801 - There is general consensus among all roles in all regions that the greatest impacts of API security incidents fall on security staff. Participants ranked the levels of stress and/or pressure on their teams from API security to be slightly higher than those from remediation costs and regulatory fines.
- The top-ranked security priorities for CISOs over the next 12 months are addressing generative AI–fueled threats (
25.5% ) and securing APIs (24.8% ). - In 2023,
18% ofU.S. andU.K. respondents said they tested APIs in real time. Among the same cohort in 2024, that figure fell to13% . Many of the causes for API incidents that were cited by survey takers are exactly the types of issues real-time testing can help address. - Top-ranked causes of API incidents include vulnerabilities cited in the OWASP Top 10 API Security Risks and a candid admission that commonly used API tools did not catch the issues.
"Our research shows that API security has yet to become a key element in a comprehensive security strategy," said Rupesh Chokshi, Senior Vice President and General Manager, Application Security, Akamai. "Organizations mostly treat API threats as emerging, when the attack data — as well as the financial impact and stress on security teams — shows they keep growing. We believe that the API Security Impact Study will help companies to better assess API protections and improve them where needed."
The study offers not only insights about survey findings but also recommendations that security teams can use to enhance their API security strategies. This includes undertaking a full inventory of APIs, regular testing to ensure APIs are coded correctly, and implementing runtime detection to differentiate between "normal" and "abnormal" API activity.
The API Security Impact survey was conducted by Opinion Matters between June 12, 2023, and July 7, 2024.
About Akamai
Akamai is the cybersecurity and cloud computing company that powers and protects business online. Our market-leading security solutions, superior threat intelligence, and global operations team provide defense-in-depth to safeguard enterprise data and applications everywhere. Akamai's full-stack cloud computing solutions deliver performance and affordability on the world's most distributed platform. Global enterprises trust Akamai to provide the industry-leading reliability, scale, and expertise they need to grow their business with confidence. Learn more at akamai.com and akamai.com/blog, or follow Akamai Technologies on X and LinkedIn.
Contact
Jim Lubinskas
Akamai Media Relations
703.907.9103
jlubinsk@akamai.com
View original content to download multimedia:https://www.prnewswire.com/news-releases/new-study-finds-84-of-security-professionals-experienced-an-api-security-incident-in-the-past-year-302303810.html
SOURCE Akamai Technologies, Inc.