Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs

Wallarm: Go Beyond WAFs and Gateways – Manage API Risk, Resilience, and Response at Scale

Truth in IT
11/14/2025
1
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


From Discovery to Defense: Building a Mature API Security Program for CISOs

This webinar, hosted by Tim Erlin of Wallarm with insights from Graham Ludlow (HPE) and Ken Foster (Candescent), examines API security through a CISO’s lens. The session connects technology and business trends to concrete security requirements, highlighting where traditional controls fall short and how to build a resilient API program.

Why it matters: APIs are now the backbone of digital operations, AI integrations, and partner ecosystems. Their speed and ubiquity amplify business value—and risk. For IT and security leaders, aligning API protection with business logic, non-human identities, and third-party dependencies is now a core responsibility.

API Security in Context: What’s Driving the Risk

Digital and AI transformation expand attack surface

Enterprises have matured through digital transformation and now accelerate into AI-enabled operations. Both phases are API-intensive—modernizing integrations, enabling real-time services, and connecting to third parties. As Ludlow notes, even “non-software companies” now depend on APIs throughout their value chain. That ubiquity increases exposure: public, private, partner, and AI-facing APIs all become control points.

Velocity, complexity, and shadow ecosystems

Speed is the business mandate—batch jobs give way to real-time interactions. Foster highlights the proliferation of shadow APIs and now “shadow AI,” echoing past shadow IT patterns. The net effect is reduced visibility and accelerating risk if governance, inventory, and monitoring do not keep pace.

The Modern API Threat Landscape

Two primary risks: extortion and exposure

Ludlow frames threats in two buckets. First, malicious actors exploit APIs for disruption and extortion—denial of service at the endpoint (not just volumetric DDoS) and business logic abuse that can degrade operations. Second, inadvertent data exposure via misconfigured or overly permissive APIs triggers regulatory violations and privacy incidents—even without an “attack.”

AI-driven misuse and non-human identities

AI agents operate through APIs. That shifts problems from authentication to authorization: can you bind each API call’s scope to the initiating prompt and policy? Least privilege for agents, strong entitlement governance, and runtime monitoring become critical to prevent overreach and data leakage.

Lessons from Recent Incidents

AI chatbots, hiring data, and business logic gaps

In incidents involving Paradox AI/McDonald’s and Restaurant Brands International (RBI), researchers demonstrated how AI-assisted interactions and open or weakly validated APIs expose sensitive data or operational artifacts (e.g., drive-thru recordings used for analytics). Takeaway: security must validate intent vs. design—“using the API as designed, not as intended” enables business logic abuse. Traditional controls alone do not prevent these failure modes.

Payments abuse: when attackers want money, not data

The FlexPay case underscores that attackers often target direct financial outcomes. APIs that trigger payouts, credits, or irreversible actions require heightened authorization, rate limits aligned with business norms, and behavior-based anomaly detection.

From Maturity to Execution: Building an API Security Program

Start with policy, education, and governance

Ludlow advises beginning with policy and training across developers, IT, and business teams. Establish expectations for API design, data handling, and third-party usage. Then enforce through governance—embedding security in processes and automating checks as maturity grows.

Inventory and posture first

Discovery is foundational: maintain a real-time catalog of internal, partner, and COTS-exposed APIs. Add context—data classification, exposure (internet-facing vs. internal), auth method, business owner, expected rates/seasonality. Treat APIs as first-class assets/entities in your CMDB and risk registers.

Program Requirements by Function

Discover (and manage posture)

  • Automated discovery across internal and external surfaces, including third-party and product APIs.
  • Data-aware classification (PII/PCI/regulated), exposure level, and owner mapping.
  • Tie to third-party risk: require partners to document business flows, expected rates, and controls.

Protect (prevent and detect)

  • Strong authN/authZ for human and non-human identities; enforce least privilege and token scopes.
  • Gateway/WAF plus API-specific runtime protection for injection, abuse, and anomaly detection.
  • Business logic and behavior-based controls, informed by baselined volumes, bursts, and seasonality.
  • Lifecycle hygiene: versioning, deprecation, and blocking stale endpoints.

Respond (prepare for API-specific incidents)

  • Incorporate API scenarios into IR plans; practice playbooks and escalation for revenue-impacting endpoints.
  • Ensure real-time observability: logs, request metadata, client/agent attribution, IP intelligence.
  • Define authority to throttle or disable endpoints and pre-approve containment actions to avoid hesitation.

Test (shift-left and validate in runtime)

  • Integrate API security testing into CI/CD; include business logic, fuzzing, and negative tests.
  • Mirror production-level controls and data patterns in lower environments to avoid rollbacks that reintroduce risk.
  • Continuously test runtime protections and alert fidelity.

Key Takeaways

  • Treat APIs as assets/entities: maintain a live inventory with data classification, exposure, and ownership.
  • Pair strong authZ for non-human identities with runtime detection for business logic abuse.
  • Codify API-specific incident response, including who can throttle or shut down revenue APIs.
  • Integrate API security into CI/CD and test against business logic, not just protocol exploits.
  • Extend discovery and governance to third-party and product APIs; align rate limits to real business patterns.

Conclusion

API security is now a core competency for IT and security leaders, spanning digital, AI, and partner ecosystems. As the perimeter shifts to endpoint logic and machine-driven access, programs must evolve from generic controls to intent-aware authorization, runtime protection, and business-aligned monitoring. For CISOs, the path forward blends policy, posture management, and automation with pragmatic incident readiness—ensuring APIs enable growth without compromising resilience.

Categories:
  • » Webinar Library
  • » Webinar Library » Wallarm
  • » Cybersecurity Webinars » Data Security
  • » Cybersecurity Webinars » Application Security
  • » Cybersecurity Webinars » Identity & Access Management (IAM)
Channels:
News:
Events:
Tags:
  • a
  • cisos
  • guide
  • to
  • api
  • security
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Wallarm: Go Beyond WAFs and Gateways – Manage API Risk, Resilience, and Response at Scale

              Upcoming Webinar Calendar

              • 11/18/2025
                01:00 PM
                11/18/2025
                Microsoft Advanced Group Policy Management (AGPM) End of Life: Your Practical Migration Playbook
                https://www.truthinit.com/index.php/channel/1579/microsoft-advanced-group-policy-management-agpm-end-of-life-your-practical-migration-playbook/
              • 11/18/2025
                01:00 PM
                11/18/2025
                HUMAN Dialogue: Cultivating Trust Amidst the Rise of Agentic Commerce
                https://www.truthinit.com/index.php/channel/1582/human-dialogue-cultivating-trust-amidst-the-rise-of-agentic-commerce/
              • 11/20/2025
                05:00 AM
                11/20/2025
                Druva: Prove you can outsmart ransomware in this virtual cyber recovery simulation!
                https://www.truthinit.com/index.php/channel/1619/untitled-channel/
              • 11/20/2025
                11:00 AM
                11/20/2025
                Trend Micro Webinar: Smarter Decision Making via Network Intelligence
                https://www.truthinit.com/index.php/channel/1372/unlocking-network-intelligence-for-smarter-risk-decisions/
              • 11/20/2025
                12:00 PM
                11/20/2025
                CMMC Certification: Next Steps for Continuous Monitoring and Management
                https://www.truthinit.com/index.php/channel/1558/cmmc-certification-next-steps-for-continuous-monitoring-and-management/
              • 11/20/2025
                01:00 PM
                11/20/2025
                Rethinking Hybrid Access: Securing Users, Vendors, and Infrastructure in the Zero Trust Era
                https://www.truthinit.com/index.php/channel/1612/rethinking-hybrid-access-securing-users-vendors-and-infrastructure-in-the-zero-trust-era/
              • 12/02/2025
                01:00 PM
                12/02/2025
                The Invisible Threat: How Polymorphic Malware is Outsmarting Your Email Security
                https://www.truthinit.com/index.php/channel/1629/the-invisible-threat-how-polymorphic-malware-is-outsmarting-your-email-security/
              • 12/04/2025
                12:00 PM
                12/04/2025
                CMMC Level 2 Assessment Insights: Expectations from an OSC and C3PAO Assessor
                https://www.truthinit.com/index.php/channel/1557/cmmc-level-2-assessment-insights-expectations-from-an-osc-and-c3pao-assessor/
              • 12/09/2025
                01:00 PM
                12/09/2025
                Energize Your Connections with Netskope and Presidio Collaboration
                https://www.truthinit.com/index.php/channel/1553/energize-your-connections-with-netskope-and-presidio-collaboration/
              • 12/10/2025
                01:00 PM
                12/10/2025
                The Next Generation of Managed Data Security Services
                https://www.truthinit.com/index.php/channel/1620/cyera-the-next-generation-of-managed-data-security-services/
              • 12/10/2025
                01:00 PM
                12/10/2025
                HUMAN Dialogue: Uncovering True Insights to Safeguard Performance through Page-Level Intelligence
                https://www.truthinit.com/index.php/channel/1630/human-dialogue-uncovering-true-insights-to-safeguard-performance-through-page-level-intelligence/
              • 12/10/2025
                10:00 PM
                12/10/2025
                Enhancing Revenue Opportunities: Bridging Gaps with Druva’s Microsoft Expansion in APAC
                https://www.truthinit.com/index.php/channel/1624/enhancing-revenue-opportunities-bridging-gaps-with-druvas-microsoft-expansion-in-apac/
              • 12/11/2025
                05:00 AM
                12/11/2025
                Maximize Revenue Potential: Address Gaps with Druva’s Microsoft Expansion
                https://www.truthinit.com/index.php/channel/1625/maximize-revenue-potential-address-gaps-with-druvas-microsoft-expansion/
              • 12/11/2025
                12:00 PM
                12/11/2025
                Secureframe: Addressing the Top 5 Compliance Challenges for Startup Leaders and Solutions
                https://www.truthinit.com/index.php/channel/1526/addressing-the-top-5-compliance-challenges-for-startup-leaders-and-solutions/
              • 12/11/2025
                01:00 PM
                12/11/2025
                Enhance Revenue Streams: Address Gaps with Druva's Microsoft Expansion Solutions.
                https://www.truthinit.com/index.php/channel/1623/enhance-revenue-streams-address-gaps-with-druvas-microsoft-expansion-solutions/
              • 12/18/2025
                12:00 PM
                12/18/2025
                360View: 2026 IT Predictions & Emerging Trends
                https://www.truthinit.com/index.php/channel/933/360view-2026-it-predictions-emerging-trends/

              Upcoming Spotlight Events

              • Nov
                18

                Microsoft Advanced Group Policy Management (AGPM) End of Life: Your Practical Migration Playbook

                11/18/202501:00 PM ET
                • Nov
                  20

                  Rethinking Hybrid Access: Securing Users, Vendors, and Infrastructure in the Zero Trust Era

                  11/20/202501:00 PM ET
                  • Dec
                    02

                    The Invisible Threat: How Polymorphic Malware is Outsmarting Your Email Security

                    12/02/202501:00 PM ET
                    More events

                    Upcoming Industry Events

                    • Nov
                      18

                      HUMAN Dialogue: Cultivating Trust Amidst the Rise of Agentic Commerce

                      11/18/202501:00 PM ET
                      • Nov
                        20

                        Trend Micro Webinar: Smarter Decision Making via Network Intelligence

                        11/20/202511:00 AM ET
                        • Nov
                          20

                          CMMC Certification: Next Steps for Continuous Monitoring and Management

                          11/20/202512:00 PM ET
                          More events

                          Upcoming 360 View Events

                          • Dec
                            18

                            360View: 2026 IT Predictions & Emerging Trends

                            12/18/202512:00 PM ET
                            More events

                            Recent Spotlight Events

                            • Oct
                              22

                              Cut Ticket Resolution Time in Half with Smarter IT Documentation

                              10/22/202501:00 PM ET
                              • Oct
                                15

                                Managing Human Risk in an AI-Driven Threat Landscape: Are Your Defenses Evolving Fast Enough?

                                10/15/202501:00 PM ET
                                • Sep
                                  16

                                  KnowBe4: Beyond DMARC: Closing Critical Gaps in Your Email Security Shield

                                  09/16/202501:00 PM ET
                                  More events

                                  Recent Industry Events

                                  • Nov
                                    13

                                    Transforming AI Trends into Tangible Business Success with Druva

                                    11/13/202501:00 PM ET
                                    • Nov
                                      13

                                      Advancements in Click Fraud Prevention: Insights from LinkedIn and HUMAN

                                      11/13/202501:00 PM ET
                                      • Nov
                                        13

                                        Insights from a Certified CMMC Assessor: Sidestepping Common Assessment Pitfalls

                                        11/13/202512:30 PM ET
                                        More events
                                        Truth in IT
                                        • Sponsor
                                        • About Us
                                        • Terms of Service
                                        • Privacy Policy
                                        • Contact Us
                                        • Preference Management
                                        Desktop version
                                        Standard version