31.01.2023 Views

Cyber Defense eMagazine February Edition for 2023

Cyber Defense eMagazine February Edition for 2023 #CDM #CYBERDEFENSEMAG @CyberDefenseMag by @Miliefsky a world-renowned cyber security expert and the Publisher of Cyber Defense Magazine as part of the Cyber Defense Media Group as well as Yan Ross, Editor-in-Chief and many more writers, partners and supporters who make this an awesome publication! Thank you all and to our readers! OSINT ROCKS! #CDM #CDMG #OSINT #CYBERSECURITY #INFOSEC #BEST #PRACTICES #TIPS #TECHNIQUES

Cyber Defense eMagazine February Edition for 2023 #CDM #CYBERDEFENSEMAG @CyberDefenseMag by @Miliefsky a world-renowned cyber security expert and the Publisher of Cyber Defense Magazine as part of the Cyber Defense Media Group as well as Yan Ross, Editor-in-Chief and many more writers, partners and supporters who make this an awesome publication! Thank you all and to our readers! OSINT ROCKS! #CDM #CDMG #OSINT #CYBERSECURITY #INFOSEC #BEST #PRACTICES #TIPS #TECHNIQUES

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

malicious communication pattern threatens your systems. The existing tools already help security,<br />

DevOps, and compliance teams in their work.<br />

Financial Services to Serve as a Key Operational Area <strong>for</strong> API Security Plat<strong>for</strong>ms<br />

Financial services are expected to represent the maximum applications of API security protocols and<br />

interfaces in <strong>2023</strong>. Studies have revealed that the financial sector has been lagging behind the most<br />

when it comes to incorporating API security, representing a mere 5% of all applications. Fortunately, an<br />

unseen benefit is expected this year, with some studies already establishing that penetration has already<br />

risen to the tune of 125% since 2020.<br />

The Federal Financial Institutions Examination Council (FFIEC) has already issued guidance governing<br />

securing authentication and access to financial institutions’ services and systems, including APIs. The<br />

guidelines aim to provide financial institutions with examples of effective risk management principles and<br />

practices <strong>for</strong> access and authentication. These principles and practices address business and consumer<br />

customers, employees, and third parties that access digital banking services and financial institution<br />

in<strong>for</strong>mation systems.<br />

This Guidance acknowledges significant risks associated with the cybersecurity threat landscape that<br />

rein<strong>for</strong>ce the need <strong>for</strong> financial institutions to effectively authenticate users and customers to protect<br />

in<strong>for</strong>mation systems, accounts, and data. It also recognizes that authentication considerations have<br />

extended beyond customers and include employees, third parties, and system-to-system<br />

communications.<br />

In <strong>2023</strong>, these regulators will increase their expectations around financial institutions’ API security. With<br />

their motherlode of rich customer data and transactions, banks, fintech companies, insurance companies,<br />

and other financial institutions represent a favorite attack target <strong>for</strong> hackers. In addition, the industry must<br />

develop a scalable approach to API security if it is to move <strong>for</strong>ward with open banking. Open banking,<br />

which provides third parties with access to financial transaction data, is completely powered by APIs.<br />

APIs to Offer a Shot at Innovation with Regard to Security Services<br />

API security is a Greenfield opportunity that leading chief in<strong>for</strong>mation security officers will exploit to<br />

choose and implement the best frameworks, processes, and tools <strong>for</strong> their organizations. Those that<br />

move ahead proactively to implement solutions, such as plat<strong>for</strong>ms that enable automated AI discovery,<br />

cataloguing, management, and real-time attack detection, will achieve significant improvements in<br />

security and risk mitigation.<br />

They will also integrate API security testing into pre-production processes, enabling developers to scan<br />

and remediate APIs be<strong>for</strong>e they are deployed. By doing so, they will enable teams to use DevSecOps<br />

processes to develop and deploy applications at pace, without increasing their organizations’ attack<br />

surface.<br />

<strong>Cyber</strong> <strong>Defense</strong> <strong>eMagazine</strong> – <strong>February</strong> <strong>2023</strong> <strong>Edition</strong> 77<br />

Copyright © <strong>2023</strong>, <strong>Cyber</strong> <strong>Defense</strong> Magazine. All rights reserved worldwide.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!