Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Are Your APIs Secure?

By Sean Lawless on July 3, 2018
Email this postTweet this postLike this postShare this post on LinkedIn

Application Programming Interface (API), provides a way for programmers and developers to allow systems to exchange data with one another. For instance, all of your company’s important employee data may be contained in Active Directory (AD), but it also needs to be contained in the firm’s CRM system. Instead of having to perform tedious manual data entry of all employee moves, adds or changes, developers could leverage the APIs in the contact relationship management (CRM) system to keep AD and the CRM system in sync.

As valuable as APIs are to customers, the business and programmers, however, they pose a fairly high risk as well. All sorts of potentially sensitive information could be exposed through a vulnerable API—client data, financial data, intellectual property, etc. APIs are available in almost all enterprise software platforms and cloud-based Software as a Service (SaaS) systems. Therefore, it is extremely important that you understand how to protect those APIs so they cannot be leveraged for nefarious purposes.

In fact, author Thorsten George of SecurityWeek reports that APIs are the next big cyber-attack vector according to security experts. As an example, George points to the Panera Bread breach where the company left an unauthenticated API endpoint exposed on its website. So, what might you do to secure your APIs?

  1. Approach API security the same way you would your overall security program—base it on an industry standard framework.
  2. Begin all projects with security in mind.
  3. Monitor, log and perform vulnerability scans against your APIs.
  4. Implement technology-based engineering controls like API gateways.
Photo of Sean Lawless Sean Lawless

Sean is Robinson+Cole’s Infrastructure & Security Manager, a member of the firm’s Data Privacy + Cybersecurity Team, and a non-attorney contributor to the Data Privacy + Cybersecurity Insider blog. He has spent more than a decade helping professional services organizations in various industries…

Sean is Robinson+Cole’s Infrastructure & Security Manager, a member of the firm’s Data Privacy + Cybersecurity Team, and a non-attorney contributor to the Data Privacy + Cybersecurity Insider blog. He has spent more than a decade helping professional services organizations in various industries, develop and implement practical information security programs based on industry standard frameworks. Sean holds a Bachelor of Science degree from the University of Connecticut and is a member of several cybersecurity professional organizations.

Read more about Sean LawlessEmail
Show more Show less
  • Posted in:
    Privacy and Cybersecurity, Technology and AI
  • Blog:
    Data Privacy + Cybersecurity Insider
  • Organization:
    Robinson & Cole LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo