Douglas M. Vernon, MS, CIAM, CAMS’ Post

View profile for Douglas M. Vernon, MS, CIAM, CAMS, graphic

AVP, Engineering Info Sec Mgr

The SINET “Approaches to Protecting the Growing API Attack Surface” panelist discussion was enjoyable and thought-provoking. The event was moderated nicely by Robert Rodriguez and included expert IS, cyber and technology panelists. - one of which was my former colleague Alexander Abramov. Alex summarized the API attack surface as a target rich environment without a silver bullet to mitigate all attack surface exposures. He suggested creating API inventories, prioritizing API code reviews based on risk levels, and using ML and AI accessories as part of your API security efforts. The panelists recommended discovering APIs using scanning techniques, remediating APIs that are incorrectly externally exposed or have other security flaws, using WAFs to protect web applications and APIs from attacks, considering API gateways, and many other excellent suggestions. As an IAM professional, I recommend using strong authentication and authorization methods, conducting secure coding and security awareness training, and reinforcing Security 101 concepts to staff. Also, running API security testing tools and having a strong TDIR program. I look forward to future SINET webinars.

View profile for Alexander Abramov, graphic

Technology and Cyber Risk | Third Party Risk | Operational Risk & Resiliency | Business Information Security | Governance | Compliance | Leadership

Looking forward presenting at SINET panel “Approaches to Protecting the Growing API Attack Surface.”  The webinar is scheduled for Thursday May 30, 2024 at 8:30 AM – 9:30 AM PT / 11:30 AM – 12:30 PM ET. As API abuses become a more frequent attack vector, we will explore how security teams can protect this somewhat “invisible” attack surface, including types of risky API assets, why they are attractive to hackers, and models to detect and secure them.  I will be joined by an expert panel including Vinod Brahmapuram, MS, CISM, CISSP, MCSD, Senior Director, Security, Lumen Technologies, Juan Piacquadio, MBA, MSIT, CIO & VP, Information Technology, Phlow Corporation, Nitin Negi, Senior Manager, Cyber Security Engineering and Operations, Micron Technology, Rob N. Gurzeev, CEO and Co-Founder, CyCognito, and Allwyn Saldanha Saldanha, Head of Application & Cloud Security, CSC. The panel will be moderated by Robert Rodriguez, Chairman, SINET & Venture Partner, SYN Ventures. Learn more and register here. https://lnkd.in/eiap_K2A Heather Rodriguez Nicole Ostrow Ahsan Sheikh, CISM, CISA, CRISC, Series 99 Tim Mortimer Farid Abdelkader Eugene Levin Wei Tschang Sam Vohra, CISA CISM CDPSE Igor G. Goldberg James Basile, CISM Moriah Hara Steven Wallstedt Dr. Markus Sanio Sivan Tehila Parimal Parikh, CISA, CICA Fred Rica Ken Frantz Jennifer Bayuk Yossi Akselrud Yosef Levine ISACA New York Metropolitan Chapter Maharaj Mukherjee Archie Scott CRISC CISM

  • No alternative text description for this image
Alexander Abramov

Technology and Cyber Risk | Third Party Risk | Operational Risk & Resiliency | Business Information Security | Governance | Compliance | Leadership

1mo

Doug, thank you for your great summary and insights.

To view or add a comment, sign in

Explore topics