Prioritizing API Security Measures

No ratings

Presented at Snowfroc 2025 by

Securing APIs is paramount to protecting data from unauthorized access; however, it is often behind a long list of other tasks that are already in the long line of application security (web application issues, mobile security issues, threat modeling, etc.). If you are starting off your API security program, you may have 30 minutes a day to work on this, but maybe 30 minutes per week. This talk will discuss how to prioritize the essential security measures for API Security based on 200 data points. This abstract won’t outline the strategic approach to API security, as there are 10M+ vendor white papers that already exist, but rather the top 10 things I would do if I only have 30min/week to run my API Security program. The focus will be on high-impact actions that offer robust protection in order to prevent AppSec data breaches.