Salt Security

170 STATS3 REPORTS

All Statistics

39% of organizations adhere to the NIST Cybersecurity Framework for API development and deployment.

Salt SecurityState of API Security Report ·Oct 8, 2025
APINIST

50% of security leaders have slowed a new application rollout due to API security concerns.

Salt SecurityState of API Security Report ·Oct 8, 2025
APIAPI security

14% of organizations oversee 1,001 or more APIs.

Salt SecurityState of API Security Report ·Oct 8, 2025
API

17% of organizations were 'not very confident' in the accuracy of their API inventories.

Salt SecurityState of API Security Report ·Oct 8, 2025
APIAPI inventory

30% of organizations are in the planning stage for their API security programs.

Salt SecurityState of API Security Report ·Oct 8, 2025
API

23% of organizations identify leveraging AI/ML capabilities for business insights or automation as a main driver behind the use of APIs.

Salt SecurityState of API Security Report ·Oct 8, 2025
APIAIML

52% of organizations identify development efficiencies and/or standardization as a main driver behind the use of APIs.

Salt SecurityState of API Security Report ·Oct 8, 2025
API

15% of organizations admitted they do not know which APIs expose PII.

Salt SecurityState of API Security Report ·Oct 8, 2025
APIPII

61% of all organizations reported modest increases (≤15%) in their API security budgets.

Salt SecurityState of API Security Report ·Oct 8, 2025
APIBudget

21% of organizations have basic API security programs focused on risk assessments or manual reviews.

Salt SecurityState of API Security Report ·Oct 8, 2025
API

10% of organizations raised their API security budgets by 0–5%.

Salt SecurityState of API Security Report ·Oct 8, 2025
APIBudget

42% of organizations reported managing 101–500 APIs.

Salt SecurityState of API Security Report ·Oct 8, 2025
API

11% of organizations adhere to NIS2 for API development and deployment.

Salt SecurityState of API Security Report ·Oct 8, 2025
APINIS2

36% of organizations say GenAI is somewhat concerning for API security.

Salt SecurityState of API Security Report ·Oct 8, 2025
APIGenAI

4% of organizations do not perform or have no formal assessment of their API security measures.

Salt SecurityState of API Security Report ·Oct 8, 2025
API

18% of organizations perform security audits to assess the effectiveness of their API security measures.

Salt SecurityState of API Security Report ·Oct 8, 2025
APISecurity audits

42% of organizations conduct code reviews and security testing.

Salt SecurityState of API Security Report ·Oct 8, 2025
APISecurity testingCode review

12% of respondents identified that their company's API program doesn’t invest enough in pre-production security.

Salt SecurityState of API Security Report ·Oct 8, 2025
API

13% of organizations experienced explosive API growth of 101–200%.

Salt SecurityState of API Security Report ·Oct 8, 2025
API

35% of organizations adhere to the OWASP API Security Top 10 for API development and deployment.

Salt SecurityState of API Security Report ·Oct 8, 2025
APIOWASP

43% of organizations are using specialized AI security tools.

Salt SecurityState of API Security Report ·Oct 8, 2025
APIAISecurity tool

18% of organizations said increased developer productivity is a metric for measuring API security ROI.

Salt SecurityState of API Security Report ·Oct 8, 2025
API

Only 7% of organizations reported increases in their API security budgets greater than 21%.

Salt SecurityState of API Security Report ·Oct 8, 2025
APIBudget

41% of organizations use vulnerability scanning to assess the effectiveness of their API security measures.

Salt SecurityState of API Security Report ·Oct 8, 2025
APIVulnerability scanning

29% of organizations identified account misuse or other fraud as the most common API security problem.

Salt SecurityState of API Security Report ·Oct 8, 2025
APIAccount misuseFraud

12% of organizations cited a lack of investment in pre-production security for their API programs.

Salt SecurityState of API Security Report ·Oct 8, 2025
API

26% of organizations are adopting governance frameworks to establish rules for AI use in development.

Salt SecurityState of API Security Report ·Oct 8, 2025
APIGovernanceAI

15% of organizations said their API programs do not adequately address runtime or production security.

Salt SecurityState of API Security Report ·Oct 8, 2025
APIRuntime securityProduction security

Only 3% of organizations indicated they do not know how many APIs they are responsible for.

Salt SecurityState of API Security Report ·Oct 8, 2025
API

45% of organizations identify digital transformation initiatives as a main driver behind the use of APIs.

Salt SecurityState of API Security Report ·Oct 8, 2025
APIDigital transformation

12% of organizations manage 501–1,000 APIs.

Salt SecurityState of API Security Report ·Oct 8, 2025
API

16% of respondents pointed to resource or staffing shortages as the primary barrier to implementing a strong API security program.

Salt SecurityState of API Security Report ·Oct 8, 2025
APIStaff

33% of security leaders have suffered an API incident in the past year.

Salt SecurityState of API Security Report ·Oct 8, 2025
APIAPI incident

35% of organizations identify cloud migration as a main driver behind the use of APIs.

Salt SecurityState of API Security Report ·Oct 8, 2025
APICloud migration

4% of organizations reported API increases of 201–300%.

Salt SecurityState of API Security Report ·Oct 8, 2025
API

25% of respondents pointed to budget limitations as the primary barrier to implementing a strong API security program.

Salt SecurityState of API Security Report ·Oct 8, 2025
APIBudget

7% of respondents pointed to time constraints as the primary barrier to implementing a strong API security program.

Salt SecurityState of API Security Report ·Oct 8, 2025
API

11% of respondents pointed to tooling/solutions gaps as the primary barrier to implementing a strong API security program.

Salt SecurityState of API Security Report ·Oct 8, 2025
APISecurity tools

10% of respondents identified that their company's API program doesn't focus enough on fleshing out requirements and documenting.

Salt SecurityState of API Security Report ·Oct 8, 2025
API

2% of organizations adhere to other specific security standards or frameworks for API development and deployment.

Salt SecurityState of API Security Report ·Oct 8, 2025
API

Only 19% of organizations were 'very confident' in the accuracy of their API inventories.

Salt SecurityState of API Security Report ·Oct 8, 2025
APIAPI inventory

55% of organizations were only 'somewhat confident' in the accuracy of their API inventories.

Salt SecurityState of API Security Report ·Oct 8, 2025
APIAPI inventory

8% of organizations were 'not at all confident' in the accuracy of their API inventories.

Salt SecurityState of API Security Report ·Oct 8, 2025
APIAPI inventory

11% of organizations said their API security budget did not increase.

Salt SecurityState of API Security Report ·Oct 8, 2025
APIBudget

21% of organizations rely on regular penetration testing to assess the effectiveness of their API security measures.

Salt SecurityState of API Security Report ·Oct 8, 2025
APIPen testing

4% of organizations do not know what specific security standards or frameworks they adhere to for API development and deployment.

Salt SecurityState of API Security Report ·Oct 8, 2025
API

57% of organizations train developers on secure coding practices for AI-generated code.

Salt SecurityState of API Security Report ·Oct 8, 2025
APIGenAI

18% of organizations said lower enterprise risk score is a metric for measuring API security ROI

Salt SecurityState of API Security Report ·Oct 8, 2025
API

51% of organizations are still in planning or basic stages of API security maturity.

Salt SecurityState of API Security Report ·Oct 8, 2025
APIAPI security maturity

28% of organizations manage between 1 and 100 APIs.

Salt SecurityState of API Security Report ·Oct 8, 2025
API