Londonchiropracter.com

This domain is available to be leased

Menu
Menu

Why cybersecurity needs an API-first mentality

Posted on January 28, 2021 by admin

While software is eating the world, it’s also siloing data along the way, stifling progress and innovation in the enterprise. Cybersecurity is woefully behind other industries in embracing an API-first mentality, and it’s finally reached a breaking point.

In the last year, research compiled in the Cloud Security Alliance’s on Cloud-based Intelligent Ecosystems and the Ponemon Cyber Resilience Study states:

  • Enterprises deploy, on average, 47 different cybersecurity solutions and technologies.
  • 69% report their security team currently spends more time managing security tools than effectively defending against threats
  • 53% say their security team has reached a tipping point where the excessive number of security tools in place adversely impacts security posture.

The enterprise demands from digital transformation combined with “unprecedented levels” of venture capital investment in cybersecurity over the last several years have created the perfect storm of tool proliferation for the modern enterprise cybersecurity leader.

Other major departments, like financial services, sales, and marketing technologies have certainly seen similar levels of supply and demand, so why is enterprise cybersecurity still so siloed?

[Read: How this company leveraged AI to become the Netflix of Finland]

One common explanation, particularly at this time of year, is to point to the skills gap in cybersecurity. Every year, a barrage of statistics comes out from the usual industry rags, and we collectively lament the lack of talent in the industry and the seemingly unstoppable growth in the number of open positions in cybersecurity. Late last year, ISC(2) put the number of open positions at over 4 million for an industry with about 2 million professionals.

We seem to be caught in a vicious cycle of buying more tools to cover the gap in people only to find we don’t have enough people to operate the tools. This is what Chase Cunningham and others would call a “self-licking ice cream cone of misery”.

After two decades of user interface demo duels on conference floors and asking derivatives of “how do I get alerted?” is it any wonder that we have too many user-dependent products creating too many alerts? Do we have a skills gap or is it a data integration gap?

Looking at other industries, is it possible that cybersecurity is just so unique? In other industries, there is a class of products that are the glue for the tools or applications. In cybersecurity, we are desperately lacking in these.

Phantom Cyber and its fast followers were the first forays into this in security. Like Zapier, these stand-alone cybersecurity ‘Orchestration’ platforms are useful, but they are what Dave McCombs in The Data-Centric Revolution: Restoring Sanity to the Enterprise would call “IFTTs” – they can mimic human behavior by sequencing automated actions on top of APIs. They are API-first, but they lack a data-awareness that is critical for success in integration and automation.

In other industries, we have seen a surge of successful API-first companies that are also data-centric, referring to an architecture where data is the primary and permanent asset, and applications (tools) may come and go. Unlike Zapier or Phantom which take data as an input and action as an output, at their core, these API-first data-centric platforms have data as an input and data as an output. And, by simply focusing on data transformation and normalization through a robust API, they bring integration, order, and automated outcomes to their industry.

Takeaways – How do I know if it’s the right API-first product?

  • Language – Is it about the data? Or is it about the tool? Is this product trying to be the “one-ring-to-rule-them-all” weaving in words like “single pane of glass”? Or is it a decoder ring to help stitch data across your various products claiming to be a “single pane of glass”?
  • Inputs & Outputs – Data-centric workflows where data is the input and data is the output. Will work off-the-shelf with your core detect and respond tools/apps and stand-alone orchestration tools.
  • Business Model – Not priced by the user, always a different lever, data processing units, or numbers of integrations.

And, if you still can’t tell, get a product demo, if the whole demo takes place in their UI, the product is not API first, will require human cycles to manage and while it may add new capability, it will not augment other investments you’ve made or create efficiencies in your stack.

This article was originally published by Patrick Coughlin on TechTalks, a publication that examines trends in technology, how they affect the way we live and do business, and the problems they solve. But we also discuss the evil side of technology, the darker implications of new tech and what we need to look out for. You can read the original article here.

Published January 28, 2021 — 14:00 UTC

Source

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Trump says Anthropic Pentagon deal is ‘possible’, weeks after blacklisting the company as a national security risk
  • Samsung and IKEA just made the $6 smart home real, and your TV is already the hub
  • OpenAI recruits Cognizant and CGI to take Codex into enterprise software shops worldwide
  • Lovable left thousands of projects exposed for 48 days, and the vibe coding security crisis is only getting worse
  • Humble emerges from stealth with $24M and a cableless autonomous electric truck built to go dock-to-dock

Recent Comments

    Archives

    • April 2026
    • March 2026
    • February 2026
    • January 2026
    • December 2025
    • September 2025
    • August 2025
    • July 2025
    • June 2025
    • May 2025
    • April 2025
    • March 2025
    • February 2025
    • January 2025
    • December 2024
    • November 2024
    • October 2024
    • September 2024
    • August 2024
    • July 2024
    • June 2024
    • May 2024
    • April 2024
    • March 2024
    • February 2024
    • January 2024
    • December 2023
    • November 2023
    • October 2023
    • September 2023
    • August 2023
    • July 2023
    • June 2023
    • May 2023
    • April 2023
    • March 2023
    • February 2023
    • January 2023
    • December 2022
    • November 2022
    • October 2022
    • September 2022
    • August 2022
    • July 2022
    • June 2022
    • May 2022
    • April 2022
    • March 2022
    • February 2022
    • January 2022
    • December 2021
    • November 2021
    • October 2021
    • September 2021
    • August 2021
    • July 2021
    • June 2021
    • May 2021
    • April 2021
    • March 2021
    • February 2021
    • January 2021
    • December 2020
    • November 2020
    • October 2020

    Categories

    • Uncategorized

    Meta

    • Log in
    • Entries feed
    • Comments feed
    • WordPress.org
    ©2026 Londonchiropracter.com | Design: Newspaperly WordPress Theme