This is according to Traceable’s State of API Security 2023 Global Findings, which surveyed 1,629 respondents across 32 countries from over six major industries, including financial services, insurance, retail, healthcare, SAAS, and high technology and software.
APIs, or application programming interface, are the intermediary software allowing two different applications to communicate. They are vital for the functioning of most webpages and interfaces, and underscore the foundation of web applications.
57% of organisations surveyed by Traceable said APIs were critically important to their digital transformation journey, underscoring their vitality.
Further, nearly a quarter (23%) of organisations use 251 to 500 APIs, with a fifth using 1,001 to 2,500 APIs, showing their growing importance in tech.
Being able to keep these streams of communication secure is therefore crucial to keeping data secure as it moves between interfaces.
That being said, Traceable’s findings were anything but comforting – 60% of organisations surveyed experienced an API-related data breach in the past two years, and nearly three-quarters (74%) experienced at least three of these events.
Shockingly, just over a third (34%) reported experiencing three to four breaches, and 40% suffered five or more breaches. Over one in ten (11%) respondents reported seven breaches, highlighting a chronic cybersecurity issue.
Distributed-denial-of-service (DDoS) attacks were the most common API attack method according to 38% of respondents. Fraud and known attacks were both cited by nearly a third (29%) of participants as a top cause of data breaches.
A concerning 57% of respondents say that traditional security solutions are simply not effective enough in detecting legitimate versus fraudulent activity at the API layer.
Respondents are even confused on their own organisation’s API morphology, with 56% saying that the increasing amount and complexity of APIs make it difficult to keep track of how many APIs exist, where they are, and what they do.
Adding to the security concerns are third parties – the report found that an average of 127 third parties are connected to an organisation’s APIs, but only a third of organisations say they are prepared to mitigate risks associated with third party access.
In relation to this, just over a third (35%) of organisations claim to be able to identify and reduce risks associated with APIs outside of their own organisation, with 40% saying they are capable of the same within their organisation.
According to Traceable, these issues arise from organisation’s lack of knowledge surrounding the actual amount of data being transmitted through their APIs.
All these issues lead to a negative outlook over the coming two years, with 61% of organisations anticipating API risks are set to increase or significantly increase. In contrast, only 15% of those surveyed think the associated risks will decrease.
Recommended reading
- Reddit Blackout: Subreddits Go Dark in Protest of API Policy
- New Gartner Research Identifies Top Cybersecurity Trends
- Aware but Not Prepared: Board Members Face Up to Cybersecurity Woes
APIs are unavoidable necessities, but the majority (58%) of respondents find that these only expand their attack surface across every layer of their technology sack, increasing security vulnerabilities.
Their vitality and accompanying security issues has created many top concerns for organisations. API sprawl is the top concern for nearly half (48%) of respondents, and this makes sense as the term encompasses some of the many issues arising from the indispensable nature of APIs.
API sprawl is the situation of having many APIs, in many locations, managed by many different teams. Essentially, APIs are ‘sprawled’ out across a company, regulated by different departments, affecting different systems, and ultimately, presenting various security vulnerabilities that are not managed by a unified system.
Akin to this challenge is maintaining an accurate inventory of APIs, which was cited by 39% of organisations, followed by managing third-party access, which was listed by about a third (30%) of companies as a top concern.
This all rounds out to the need for unified management of APIs and their security challenges.





