International Cyber Expo International Cyber Expo
  • About Us
Tuesday, 21 July, 2026
IT Security Guru
International Cyber Expo
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Giving API Security the spotlight

In conversation with Michelle McLean, VP of product marketing at Salt Security

by Guru Writer
July 13, 2022
in Featured, Features
Michelle McLean
Share on FacebookShare on Twitter

IT Security Guru recently sat down with Michelle McLean, VP of product marketing at Salt Security, to learn more about API security as its own discipline and how it supports cyber resiliency in large enterprises on their digital transformation journeys. 

Michelle started her career working as a technology journalist for almost a decade and has since held marketing leadership roles in a variety of enterprise security and software companies, as well as an advisory role at META Group. She’s recognised that the majority of businesses today, even more so since the pandemic happened, are fuelled by applications and these are built on Application Programming Interfaces (APIs) for the transmission and retrieval of data. This, she says has led attackers to get through more traditional security defences that typically protect applications, like web application firewalls, to attack the APIs themselves. 

“Those kinds of security devices see a single snapshot at a time and they look for known patterns of bad, so they can stop that known pattern of bad. But with APIs, bad actors attack differently,” she said. “They’re trying to figure out your API and they’re trying to look for a business logic gap. Maybe you ask for authentication at the beginning, but then in a later request you don’t ask for authentication, or you don’t ask for authorisation and so threat actor manipulates what they’re doing in the API call and they get data they shouldn’t have access to. Many well-known API attacks in the US such as those on Experian and Peloton were done via the API.” 

Detecting attacks on APIs is therefore far more nuanced and requires deep context and richer information to remediate. This is an area where Salt Security stands out because its architecture is built on cloud-scale big data that provides the whole picture needed to correlate an attacker’s reconnaissance efforts and say, “we have a problem”.  

“Salt is focused on applying really rich information and context across the API life cycle to protect APIs. We do full discovery: what are the APIs that are running? what sensitive data do they expose? We baseline what constitutes “normal” and so bad traffic always stands out even if it’s a tiny, tiny percentage. But you need to find the manipulations, as well as the reconnaissance activity of the bad actors to be able to find it. That’s where Salt really shines- at finding those run-time attacks,” Michelle explained. 

“We store data over days and weeks. API attacks unfold over a really long period of time, so if you only see a finite amount of data, you’re going to miss 95% of the attacks that happen in a given time period,” she continued. “You need to see way more data and have a very rich understanding of the whole picture. By knowing what a bad actor did an hour ago, a day ago, a week ago, along with being able to correlate it in real time is how you find these kinds of attacks.” 

Another focus area in security is “shift-left”, which describes the process of doing things better and more securely from the start in order to shorten the cyber kill chain. For Salt, this means helping customers write better APIs and making them more secure over time, something which is vital to large organisations in financial, retail, pharmaceutical and medical industries that process huge amounts of valuable data through APIs. 

As organisations continue to digitise at scale, Michelle encourages young people to join the cybersecurity industry, noting the well-known shortage of well-trained people.  

“I think it’s one of the most exciting and honestly one of the most inclusive and diverse communities in tech, which I find very promising. However, let’s have reasonable expectations around how we bring more people into the industry; rather than having a very high bar of university degree, and X number of experiences, bring people in and train them. We can absolutely do that.  

“There’s constant innovation. If you think about how bad actors keep evolving with their own creativity and how the industry in turn keeps evolving to keep up and stay ahead – I think the cycle of innovation is very exciting,” Michelle concluded. 

ShareTweet
Previous Post

Outpost24 acquired by Vitruvian Partners

Next Post

FTC to Crack Down on Illegal Sharing of Citizen’s data

Recent News

What Does the Cyber Industry Want to See From the New UK Government?

What Does the Cyber Industry Want to See From the New UK Government?

July 20, 2026
Purple Logo, capitalised letters: SALT.

Salt Security tackles AI governance challenge with 100 pre-built agentic security policies

July 20, 2026
New Continuous Runtime Security Validation service aims to strengthen fintech cyber resilience

New Continuous Runtime Security Validation service aims to strengthen fintech cyber resilience

July 20, 2026
Scams Now Drive Almost Half of All Malware Detections as Attackers Weaponise Everyday Trust

Scams Now Drive Almost Half of All Malware Detections as Attackers Weaponise Everyday Trust

July 20, 2026

Eskenzi PR banner ad

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol