Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Tuesday, 16 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Majority of CISOs Lack Full Visibility Over APIs

A new report by Salt Security found that the majority of CISOs struggle when it comes to API security, with only 17% having a fully developed strategy in place

by Guru Writer
July 22, 2025
in Editor's News, Featured, Features, News
Majority of CISOs Lack Full Visibility Over APIs
Share on FacebookShare on Twitter

New research by Salt Security has revealed that the majority of CISOs do not have full visibility over their API environments, despite recognition of the growing API attack surface. The 2025 Salt Security CISO Report found that while 73% of CISOs rank API security as a high or critical priority for the next 12 months, only 17% of CISOs reported having a comprehensive and implemented API security strategy, highlighting the growing gap between awareness and action when it comes to API security.

The 2025 research features insights from 300 CISOs from France, Germany, Italy, the United Kingdom and the United States, all of whom work at companies with more than 1,000 employees. 

Organisations are rapidly scaling their API environments to bolster innovation, accommodate growing customer demands and boost operational efficiency. Salt Security’s 2025 State of API report revealed that 30% of organisations reported a 51-100% growth in the number of APIs they manage over the past year, with 25% of respondents experiencing growth exceeding 100%. Evidently, APIs play a critical part in an organisation’s ability to innovate, especially in the era of AI; however, scale and pace of adoption can strain resources and complicate security efforts. This discrepancy is further underscored by the 2025 CISO report. 

Confidence and Visibility 

The report also revealed that only 19% of CISOs globally have full visibility and confidence in tracking APIs across their organisation. Among large enterprises, only 27% report full oversight. For smaller organisations, the number shrinks to 12%. This general lack of visibility poses a persistent and growing security risk to organisations, with many easily exploitable shadow APIs potentially lurking within an environment. 

What’s more, around three-quarters (74%) of CISOs admit to constantly uncovering APIs that they did not know existed. A further 9 in 10 CISOs can’t confirm that they’re free of unmanaged APIs, highlighting widespread uncertainty and visibility gaps in API environments. In smaller organisations, CISOs are nearly three times less likely to feel assured about their API inventories.

Innovation vs. Security

Similarly, the report uncovered a disparity between the pace of development, adoption and security, with modern development moving quickly. The research found that three-quarters (75%) of APIs are updated weekly or daily. However, two-thirds (66%) of organisations only audit for shadow or unmanaged APIs on a monthly or quarterly basis. This creates a dangerous window of 4 to 12 weeks of blindspots, allowing unmanaged changes to introduce risk. Only 34% of organisations globally have adopted continuous, automated auditing to close this visibility gap and match the speed of API change.

Protection and Tools

The research found that legacy tools are the primary line of defence for most CISOs. To secure APIs, 76% of CISOs rely on WAFs and 72% on API Gateways. Despite their limitations, 85% express confidence that these tools can block business logic attacks – threats that they weren’t designed to stop. These tools cannot prevent attacks that exploit legitimate, intended functionalities to access sensitive data; they only detect known signatures of malicious activity. Worryingly, only 39% of organisations are adopting best-of-breed API security solutions built for the changing threat landscape. 

Michael Callahan, Chief Marketing Officer at Salt Security, said “there is an evident overconfidence in legacy tooling to protect against uniquely modern and complex threats. These tools were not built with the threats faced by organisations today in mind, especially as the threat landscape has evolved so quickly and unpredictably in recent years. Legacy tech paired with a lack of visibility over the entire API ecosystem presents a worrying picture for CISOs aiming to secure their organisation effectively. Modern issues need modern solutions that are scalable, efficient, and effective.” 

The Future of API Security

The data shows that a strategic shift is essential to ensuring the security of all APIs. Organisations are under-resourced, revealing that only 16% of security leaders feel they are adequately staffed to triage and respond to the volume of API-related security alerts in real-time. Increasing personnel isn’t a scalable solution, rather bridging the gap requires a modern approach that addresses the core themes of speed, visibility and threat detection head-on.

 

ShareTweet
Previous Post

The password that sank a 158-year-old business

Next Post

Nearly Half of MSPs Have Dedicated Kitty For Ransomware Incidents

Recent News

Check Point Expands MSP Platform with AI Security Capabilities and Unified Bundles

From Playbooks to Adaptive Workflows: How MSSPs Are Evolving Security Operations with Agentic AI

June 15, 2026
Nagomi Control Brings CTEM Into Action

2 in 5 Organisations Experienced Cyber Incidents Tied to Suppliers in Past Year

June 12, 2026
Certes Research Warns Legacy Systems Are Biggest Barrier to Quantum Security Readiness

KnowBe4 Expands Gamified Training Library With Launch of “Spot the Vish” Game

June 12, 2026
Swan Song For Infosec’s Most Gripping Awareness Training Series: The Inside Man Goes Out With A Star-Studded Bang

Swan Song For Infosec’s Most Gripping Awareness Training Series: The Inside Man Goes Out With A Star-Studded Bang

June 12, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol