MENU
GET LISTED
GET LISTED
SHOW ALLPOPULAR CATEGORIES

APIs Among Top Threats to Cloud Computing—Here’s What You Can Do

Daniel Epstein
Daniel Epstein

News editor

June 9, 2022, 09:10
CSA threats to cloud computing

Source: pixabay

If you’re one of those developers who are constantly worried about your API security, you’re not alone. It turns out insecure interfaces and APIs are among the top threats to cloud computing as ranked by a recently published report from the Cloud Security Alliance (CSA).

The report titled, “Top Cloud Threats to Cloud Computing – Pandemic Eleven,” is a survey of more than 700 experts on security issues in the cloud industry. It revealed changes taking place in the community in terms of what security issues are seen as concerning. Based on respondents’ answers, traditional cloud security concerns such as CSP data loss, denial of service, shared technology vulnerabilities, and system vulnerabilities were rated very low and were no longer considered in the report. The low ratings were attributed to the confidence and apparent trust of clients in the cloud infrastructure.

The focus of security efforts has now shifted to configuration and authentication. These include identity and access management, configuration management, cryptography, coding practices, and strategic cloud direction.

Here are the top 11 concerns in order of significance:

  1. Insufficient identity, credential, access and key management
  2. Insecure interfaces and APIs
  3. Misconfiguration and inadequate change control
  4. Lack of cloud security architecture and strategy
  5. Insecure software development
  6. Unsecure third-party resources
  7. System vulnerabilities
  8. Accidental cloud data disclosure
  9. Misconfiguration and exploitation of serverless and container workloads
  10. Organized crime/hackers/APT
  11. Cloud storage data exfiltration

Jon-Michael C. Brook, co-chair of the Top Threats Working Group and one of the paper’s lead authors said, “Collectively, these security issues are a call to action for developing and enhancing cloud security awareness, configuration, and identity management. As cloud business models and security tactics evolve, there is an even greater need to address security issues that are situated higher up the technology stack and are the result of senior management decisions.”

Weighing the Risks of Open APIs

Organizations are adopting APIs for the end goals of agility and connectivity. But these benefits don’t come without risks. The same with SaaS misconfigurations that occur due to lack of visibility and too many departments with privileged access, APIs and microservices are also vulnerable to misconfiguration, inappropriate authorization, and poor coding practices.

Moreover, as more organizations implement multiple SaaS products and customize them to serve their requirements, it becomes harder for developers to regularly monitor, manage, and secure their overall API portfolio due to their rapid adoption. Oversights can leave interfaces open to attacks. Some of the most common circumstances of compromised interfaces that can lead to malicious activities include unauthenticated endpoints, disabled logging or monitoring, and disabled security controls. Unsecured APIs can lead to unintended exposure of sensitive data or data breaches that enable hackers to conduct exfiltration, deletion, and modification.

With that said, Open APIs do provide uncontested business and user benefits that we can’t just throw out the window. They are crucial for integration and data sharing between apps and IT systems for efficient workflows and delivery of services. SaaS vendors who want to offer open APIs will, therefore, need to pour more resources into providing regular updates and ensuring the security of their interfaces. With so many versions, access points, and errors that need to be monitored, doing so effectively will not be possible using manual methods. This is where automation and other technologies come into play. Developers need to employ these advanced tools that can continuously monitor anomalous API communication as part of their SaaS security strategy.

Daniel Epstein

By Daniel Epstein

Daniel Epstein is a senior financial research analyst at FinancesOnline and the architect behind our Fintech and ERP content division. His main areas of expertise are blockchain technologies, cryptocurrencies, and the use of biometrics in fintech solutions. His work has been frequently quoted by such publications as Forbes, USA Today, Entrepreneur, and LA Times. With more than 1,800 solutions scrutinized in the last 5 years spent on our team he always prioritized offering readers an unbiased perspective on modern financial technologies.

Popular news

Why Marketing Automation Should Be in Your 2023 Small Business Marketing Strategies

As 2022 comes to a close, economists and investors forecast a global economic slowdown in 2023. While top United Stat

APIs Among Top Threats to Cloud Computing—Here's What You Can Do

If you're one of those developers who are constantly worried about your API security, you're not alone. It turns out insecure interfaces and APIs are among the top threats to c

Contactless Payments to Reach $10 Trillion by 2027; Cash Transactions to Decline

During the early stages of the COVID-19 pandemic, everyone maintained a safe physical distance from others for fear of contracting the disease. This paved the way for contactle

Not so Fast, Tech Companies Aren't Recession Proof

When th

VR for Remote Work to Boost VR/AR Market Further?

In the future workplace, your typical day might start with putting on your VR headset to have a meeting with your colleague's avatar.

Leave a comment!

Add your comment below.

Be nice. Keep it clean. Stay on topic. No spam.

Why is FinancesOnline free? Why is FinancesOnline free?

FinancesOnline is available for free for all business professionals interested in an efficient way to find top-notch SaaS solutions. We are able to keep our service free of charge thanks to cooperation with some of the vendors, who are willing to pay us for traffic and sales opportunities provided by our website. Please note, that FinancesOnline lists all vendors, we’re not limited only to the ones that pay us, and all software providers have an equal opportunity to get featured in our rankings and comparisons, win awards, gather user reviews, all in our effort to give you reliable advice that will enable you to make well-informed purchase decisions.