Taliferro Group

API Security Neglect: A Wake-Up Call

92% of organizations hit an API security incident last year — not bad luck, but what happens when security stays an afterthought. Taliferro's API consulting exists to fund and act on what a security review actually finds, not just commission one.

Published: 30 Apr 2023 · Updated: 10 Aug 2026

By Tyrone Showers

Co-Founder Taliferro

Article

Introduction

The recent article by Venture Beat, titled "Report shows 92% of organizations experienced an API security incident last year", sheds light on the precarious state of API security across numerous organizations. The Enterprise Strategy Group survey of 397 respondents revealed that a staggering 92% of organizations encountered at least one API-related security incident in the past year. Furthermore, 57% of the surveyed organizations experienced multiple API security incidents, and 75% updated their APIs daily or weekly. This opinion piece posits that organizations frequently regard security as an afterthought, and the lack of governance or expertise exacerbates the situation. Moreover, even when organizations employ security experts, they often dismiss their valuable insights, resulting in a precarious security landscape.

The Neglect of Security

APIs are how software systems talk to each other, which makes them essential — and also makes securing them everyone's problem and nobody's priority. Protecting them routinely loses out to shipping features faster, which leaves APIs exposed to attack and sensitive data exposed to whoever's looking for it.

Most organizations simply haven't built the knowledge or process to secure APIs comprehensively, and weak governance compounds it. With 75% of surveyed organizations updating their APIs daily or weekly, the attack surface is moving faster than most security processes can track.

Disregarding Expertise

When organizations do employ security experts, they often ignore their recommendations, which makes the hire pointless. This happens for a few recurring reasons: organizational inertia, chasing short-term gains, and reluctance to fund the fixes security actually requires.

Organizational inertia is a formidable barrier to implementing comprehensive security measures. Many companies resist change, clinging to outdated practices and systems that leave their APIs vulnerable. This obstinate adherence to the status quo stifles the efforts of security experts to implement vital security enhancements.

Organizations frequently focus on accelerating product releases, neglecting security measures in favor of rapid development and deployment. This myopic approach undermines the efforts of security experts and exposes the organization to significant risks.

Moreover, prioritizing short-term gains often supersedes the long-term benefits of a robust security infrastructure.

Even where organizations do hire security experts, they often don't fund them properly — no budget, no tooling, no headroom to actually fix what they find. Hiring the expert without giving them the resources to act is functionally the same as not hiring one.

The Imperative of Security-Centricity

Organizations must adopt a security-centric approach to address these challenges and protect their APIs. This paradigm shift involves placing security at the forefront of the development process, embracing comprehensive governance, and valuing the expertise of security professionals. To adopt a security-centric approach, organizations should:

  • Foster a culture of security awareness, ensuring that employees at all levels understand the importance of API security and are equipped to mitigate risks.
  • Establish robust governance structures, including clearly defined security policies, procedures, and best practices that govern API development and management.
  • Invest in continuous security education and training, empowering security experts to stay abreast of emerging threats and equipping them with the knowledge to devise and implement effective defense strategies.
  • Allocate adequate resources to security initiatives, providing security experts with the necessary tools, budget, and personnel to safeguard the organization's APIs.
  • Encourage collaboration between security experts and other stakeholders, fostering a culture of open communication and shared responsibility in addressing API security concerns.

By adopting these strategies, organizations can cultivate a security-centric mindset, ensuring that API security is treated as a priority rather than an afterthought. This proactive approach mitigates the risk of security incidents and fosters a culture of vigilance and preparedness that is essential.

Conclusion

92% of organizations hitting an API security incident in one year isn't bad luck — it's what happens when security stays an afterthought and the people hired to prevent it get ignored or under-resourced. Fixing that means funding security experts properly and actually acting on what they find, not just hiring them for the org chart.

Tyrone Showers
Need momentum, not another patch?

Start with workflow execution support, connect it to the momentum system, or show us the drag point.

Want this fixed on your site?

Tell us your URL and what feels slow. We’ll point to the first thing to fix.

Explore Taliferro's free tools: Ask TODD · Find · Email Signature Builder · SayIt · Lead Vault · Meet Maya — or become an affiliate.