Unmasking the Invisible Threat: Defend Your APIs Before Attackers Do episode artwork

EPISODE · Mar 11, 2026 · 13 MIN

Unmasking the Invisible Threat: Defend Your APIs Before Attackers Do

from The Security Strategist

Podcast series: The Security StrategistGuest: Chip Witt, Principal Security Analyst at RadwareHost: Richard Stiennon, Chief Analyst Researcher at IT-HarvestWhen attackers target modern enterprises, they don’t break in; they log in. This insight came from the recent episode of The Security Strategist Podcast, where host Richard Stiennon, a cybersecurity analyst and Chief Analyst Researcher at IT-Harvest, speaks to Chip Witt, Principal Security Analyst at Radware.The conversation spotlights a critical issue faced by most enterprises – defending APIs as if they are just infrastructure while attackers exploit them as part of the business logic. That gap represents the real risk.What’s the Core Misunderstanding with APIs?As per Witt, enterprise teams often view APIs as technical plumbing instead of business products. Security programs focus on endpoints and authentication, believing that a locked front door means the house is safe.However, the true risk lies deeper — in authorisation logic, identity sprawl, and how applications change over time. Modern development methods lead to constant API drift. New routes appear, fields change, and versions multiply. In many organisations, security leaders cannot confidently state which APIs are live in production. The uncertainty to many is theoretical, but in reality, it’s an operational risk.Also Watch: How Do You Stop an Encrypted DDoS Attack? How to Overcome HTTPS ChallengesHow are Enterprises Shifting Towards Intent-Aware Protection?As enterprises speed up their use of serverless architectures, microservices, and AI-driven applications, API sprawl intensifies. With sprawl, the security model cannot remain unchanged while the application structure evolves.According to Witt, the future of API security must be intent-aware. Protection should assess whether a sequence of calls makes sense within its context for the user, system, or resource initiating them. Simply confirming identity is not enough; security also needs to validate behaviour.Zero trust principles have reshaped strategies for networks and identities. APIs now require similar scrutiny—not just at the perimeter, but within the workflow itself.APIs are no longer just back-end connectors; instead, they are now the visible surface of the enterprise. The most concerning attacks are not brute-force attempts. Most distressing attacks, in fact, are authenticated actions carried out with malicious intent.Organisations that continuously track their APIs, enforce strict authorisation, and identify workflow misuse in real time can significantly reduce their risk of breaches. More importantly, they can align security with the business pace. In today’s digital economy, APIs are the product.TakeawaysAPIs are your primary business attack surface, not back-end infrastructure.Most damaging API attacks use valid credentials and exploit weak authorisation.Visibility gaps and API drift quietly expand your exposure over time.Machine-to-machine identities often carry excessive, unmonitored privileges.Runtime, intent-aware detection is now essential to stopping business logic abuse.Chapters00:00 Introduction to API Security02:04 Understanding API Misconceptions04:49 Current API Threat Landscape06:43 Business Logic Abuse in APIs09:11 Challenges in API Security12:03 Runtime Protection and Intent Detection13:40 Key Takeaways for IT Decision MakersFor more information, please visit em360tech.com and radware.comFollow: @EM360Tech on YouTube, LinkedIn and XRadware YT: @radwareRadware LinkedIn: https://www.linkedin.com/company/radware/Radware X: @radware#APISecurity #BusinessLogicAbuse #AuthenticatedAttacks #RuntimeProtection #IntentAwareSecurity #Radware #Cybersecurity2026 #OWASP #BusinessLogic #ZeroTrust #TechPodcast #EnterpriseSecurity #IntentAwareProtection #TheSecurityStrategist #Cybersecurity

Episode metadata supplied by the publisher feed · Published Mar 11, 2026

Embed this episode

Ready to play

Unmasking the Invisible Threat: Defend Your APIs Before Attackers Do

0:00 13:04

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Security Strategist?

This episode is 13 minutes long.

When was this The Security Strategist episode published?

This episode was published on March 11, 2026.

Can I download this The Security Strategist episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!