API security is a pressing concern for industries undergoing digital transformation, and none more so than financial services and insurance. To shed light on their unique challenges, Salt undertook and today released its first industry-specific report on API security: the 2023 “State of API Security for Financial Services and Insurance.” Given their early adoption of digitalization, we wanted to learn how API threats and vulnerabilities specifically impact these sectors and how they differ from other markets.
We discovered that API attackers have become increasingly active in financial services and insurance. In fact, our findings reveal a staggering 244% increase in unique attackers in financial services and insurance between the first and second halves of last year.
Breaches not only threaten key business initiatives but also can result in costly fines and reputational damage. Just one potential security breach could pose a significant threat to the value of an organization’s digital transformation initiatives.
Also alarming is the finding that nearly 70% of financial services and insurance companies have delayed application rollouts due to API security issues – more than 10% higher than the overall industry average. Such delays can cost a business the loss of valuable time, resources, and customer confidence.
The report shows that 92% of financial/insurance respondents have faced significant security issues related to production APIs over the past year, and nearly one out of five have experienced an actual API security breach.
Yet, despite these growing attacks, more than 25% of the financial services/insurance organizations surveyed lack a proper API strategy, putting them at a higher risk of API breaches. Other notable findings include:
On the positive side, given the importance of digital services as a business driver in these industries, awareness of API security as a critical issue is growing, as highlighted by the following findings:
Here at Salt we have many customers in the financial services and insurance sectors – each with their own unique situation and requirements. All of them recognize that API security is essential to their success. By leveraging the Salt Security API Protection Platform, they can ensure the safety of their digital initiatives, maintain customer trust, and safeguard their reputation.
But don’t just take our word for it. In the following excerpts from anonymous Gartner Peer Insights reviews, read why financial services and insurance customers have adopted our purpose-built API security:
“As a financial company providing banking services, our clients rely on us to protect and secure their digital financial transactions… While a WAF protects us from “known” attacks and gives us limited insights and visibility to defend against API attacks, Salt has shown us potential risks where we previously had no insights and has found attacks that our security analysts could not spot.”
IT security and risk management role, banking industry, company size $3-10 billion
“As a bank, we’re a constant target, and no surprise we’re really focused on security. We looked at a few platforms, and Salt was the best solution for us. Salt shows us all our internal and third-party API endpoints, and we can see what data is going in and out. So, we have a better sense of our weaknesses and potential threats we need to mitigate. Salt has also helped us catch a lot of mistakes while we’re still building our APIs, so we can fix them before pushing those APIs into production.”
IT security and risk management role, banking industry, company size $500 million to $1 billion
“The Salt attacker timeline is very helpful for its ability to correlate all the attack information in one place. We can see the pattern of attempted attack so we can block it proactively. In addition, being a financial institution, we are always looking for solutions to stay in compliance with security regulations and Salt helps us stay ahead of the curve in regards to API security.”
IT role, banking industry, company size $50-250 million
“Attackers know that APIs make an easy target, in part because a lot of companies haven’t focused on protecting them. We knew we wanted a dedicated API solution to discover and protect our growing population of APIs. Deployment was easy, and Salt quickly enabled us to discover all of our APIs, including shadow (unknown) APIs.”
IT security and risk management role, finance (non-banking), company size $3-10 billion
We invite you to download your complimentary copy of the complete 2023 State of API Security for Financial Services and Insurance report and read all the findings. If you would like to experience for yourself how Salt can provide the deep visibility and adaptive intelligence needed to protect your critical APIs, please contact us or click here to arrange a customized demo.
Salt continues to receive accolades for the Salt Security API Protection Platform – all year round! This time we have been honored with the “Best API Security” award in the 2023 API Awards.
We’ve further strengthened our partnership with the new “better-together” story of Salt and the CrowdStrike Falcon® platform.