Report by Salt Security

State of API Security Report

138 FINDINGSPublished Oct 8, 2025
View Original Report →

Key Findings

25% of organizations said APIs are used to create new revenue streams.

Salt SecurityState of API Security Report·10mo ago
API

A small but notable 6% of organizations indicated their API volume more than tripled (301%+) in just 12 months.

Salt SecurityState of API Security Report·10mo ago
API

41% of organizations cited vulnerabilities as the most common API security problem.

Salt SecurityState of API Security Report·10mo ago
APIVulnerabilities

39% of organizations adhere to the NIST Cybersecurity Framework for API development and deployment.

Salt SecurityState of API Security Report·10mo ago
APINIST

56% of organizations perceive GenAI as a growing security concern for APIs.

Salt SecurityState of API Security Report·10mo ago
API

45% of organizations identify digital transformation initiatives as a main driver behind the use of APIs.

Salt SecurityState of API Security Report·10mo ago
APIDigital transformation

45% of organizations pointed to digital transformation initiatives as a primary driver for modernizing legacy systems and accelerating new services.

Salt SecurityState of API Security Report·10mo ago
API

50% of security leaders have slowed a new application rollout due to API security concerns.

Salt SecurityState of API Security Report·10mo ago
APIAPI security

14% of organizations oversee 1,001 or more APIs.

Salt SecurityState of API Security Report·10mo ago
API

41% of organizations reported API growth of 51–100% over the past year.

Salt SecurityState of API Security Report·10mo ago
API

33% of organizations flagged authentication problems as the most common API security problem.

Salt SecurityState of API Security Report·10mo ago
APIAuthentication

17% of organizations were 'not very confident' in the accuracy of their API inventories.

Salt SecurityState of API Security Report·10mo ago
APIAPI inventory

14% of respondents identified that their company's API program is out of control or hard to manage.

Salt SecurityState of API Security Report·10mo ago
API

30% of organizations are in the planning stage for their API security programs.

Salt SecurityState of API Security Report·10mo ago
API

7% of respondents pointed to time constraints as the primary barrier to implementing a strong API security program.

Salt SecurityState of API Security Report·10mo ago
API

23% of organizations identify leveraging AI/ML capabilities for business insights or automation as a main driver behind the use of APIs.

Salt SecurityState of API Security Report·10mo ago
APIAIML

52% of organizations identify development efficiencies and/or standardization as a main driver behind the use of APIs.

Salt SecurityState of API Security Report·10mo ago
API

15% of organizations admitted they do not know which APIs expose PII.

Salt SecurityState of API Security Report·10mo ago
APIPII

61% of all organizations reported modest increases (≤15%) in their API security budgets.

Salt SecurityState of API Security Report·10mo ago
APIBudget

21% of organizations have basic API security programs focused on risk assessments or manual reviews.

Salt SecurityState of API Security Report·10mo ago
API

10% of organizations raised their API security budgets by 0–5%.

Salt SecurityState of API Security Report·10mo ago
APIBudget

11% of organizations adhere to NIS2 for API development and deployment.

Salt SecurityState of API Security Report·10mo ago
APINIS2

25% of organizations said they were 'not very' or 'not at all confident' in the accuracy of their API inventories.

Salt SecurityState of API Security Report·10mo ago
APIAPI inventory

36% of organizations say GenAI is somewhat concerning for API security.

Salt SecurityState of API Security Report·10mo ago
APIGenAI

4% of organizations do not perform or have no formal assessment of their API security measures.

Salt SecurityState of API Security Report·10mo ago
API

18% of organizations perform security audits to assess the effectiveness of their API security measures.

Salt SecurityState of API Security Report·10mo ago
APISecurity audits

42% of organizations conduct code reviews and security testing.

Salt SecurityState of API Security Report·10mo ago
APISecurity testingCode review

13% of organizations experienced explosive API growth of 101–200%.

Salt SecurityState of API Security Report·10mo ago
API

35% of organizations adhere to the OWASP API Security Top 10 for API development and deployment.

Salt SecurityState of API Security Report·10mo ago
APIOWASP

43% of organizations are using specialized AI security tools.

Salt SecurityState of API Security Report·10mo ago
APIAISecurity tool

18% of organizations said increased developer productivity is a metric for measuring API security ROI.

Salt SecurityState of API Security Report·10mo ago
API

Only 7% of organizations reported increases in their API security budgets greater than 21%.

Salt SecurityState of API Security Report·10mo ago
APIBudget

41% of organizations use vulnerability scanning to assess the effectiveness of their API security measures.

Salt SecurityState of API Security Report·10mo ago
APIVulnerability scanning

51% of organizations are still in planning or basic stages of API security maturity.

Salt SecurityState of API Security Report·10mo ago
APIAPI security maturity

26% of organizations are adopting governance frameworks to establish rules for AI use in development.

Salt SecurityState of API Security Report·10mo ago
APIGovernanceAI

57% of organizations train developers on secure coding practices for AI-generated code.

Salt SecurityState of API Security Report·10mo ago
APIGenAI

12% of organizations cited a lack of investment in pre-production security for their API programs.

Salt SecurityState of API Security Report·10mo ago
API

Only 3% of organizations indicated they do not know how many APIs they are responsible for.

Salt SecurityState of API Security Report·10mo ago
API

33% of security leaders have suffered an API incident in the past year.

Salt SecurityState of API Security Report·10mo ago
APIAPI incident

35% of organizations identify cloud migration as a main driver behind the use of APIs.

Salt SecurityState of API Security Report·10mo ago
APICloud migration

4% of organizations reported API increases of 201–300%.

Salt SecurityState of API Security Report·10mo ago
API

25% of respondents pointed to budget limitations as the primary barrier to implementing a strong API security program.

Salt SecurityState of API Security Report·10mo ago
APIBudget

2% of organizations adhere to other specific security standards or frameworks for API development and deployment.

Salt SecurityState of API Security Report·10mo ago
API

Only 19% of organizations were 'very confident' in the accuracy of their API inventories.

Salt SecurityState of API Security Report·10mo ago
APIAPI inventory

11% of organizations said their API security budget did not increase.

Salt SecurityState of API Security Report·10mo ago
APIBudget

4% of organizations do not know what specific security standards or frameworks they adhere to for API development and deployment.

Salt SecurityState of API Security Report·10mo ago
API

28% of organizations manage between 1 and 100 APIs.

Salt SecurityState of API Security Report·10mo ago
API

14% of organizations reported their API programs are out of control or hard to manage.

Salt SecurityState of API Security Report·10mo ago
API

11% of respondents pointed to competing priorities as the primary barrier to implementing a strong API security program.

Salt SecurityState of API Security Report·10mo ago
API

18% of organizations said lower enterprise risk score is a metric for measuring API security ROI

Salt SecurityState of API Security Report·10mo ago
API

10% of organizations were not confident at all in their ability to detect and respond to attacks leveraging Generative AI.

Salt SecurityState of API Security Report·10mo ago
APIGenAI

9% of organizations rated the tools they use to detect and prevent API attacks as not very effective.

Salt SecurityState of API Security Report·10mo ago
APISecurity tool

23% of organizations indicated APIs are enabling advanced analytics, automation, and business insights powered by machine learning.

Salt SecurityState of API Security Report·10mo ago
API

20% of organizations monitor their APIs continuously in real-time.

Salt SecurityState of API Security Report·10mo ago
API

1% of organizations did not know how confident they were in the accuracy of their API inventories.

Salt SecurityState of API Security Report·10mo ago
APIAPI inventory

26% of organizations said a strong compliance posture is a metric for measuring API security ROI.

Salt SecurityState of API Security Report·10mo ago
API

18% of organizations said cost savings from breach prevention is a metric for measuring API security ROI.

Salt SecurityState of API Security Report·10mo ago
API

12% of respondents identified that their company's API program doesn’t invest enough in pre-production security.

Salt SecurityState of API Security Report·10mo ago
API

12% of organizations manage 501–1,000 APIs.

Salt SecurityState of API Security Report·10mo ago
API

11% of respondents pointed to tooling/solutions gaps as the primary barrier to implementing a strong API security program.

Salt SecurityState of API Security Report·10mo ago
APISecurity tools

10% of dominant attack vectors map to OWASP API1 Broken Object Level Authorization (BOLA).

Salt SecurityState of API Security Report·10mo ago
APIOWASP

15% of organizations said their API programs do not adequately address runtime or production security.

Salt SecurityState of API Security Report·10mo ago
APIRuntime securityProduction security

8% of organizations were 'not at all confident' in the accuracy of their API inventories.

Salt SecurityState of API Security Report·10mo ago
APIAPI inventory

21% of organizations rely on regular penetration testing to assess the effectiveness of their API security measures.

Salt SecurityState of API Security Report·10mo ago
APIPen testing

55% of organizations were only 'somewhat confident' in the accuracy of their API inventories.

Salt SecurityState of API Security Report·10mo ago
APIAPI inventory

16% of respondents pointed to resource or staffing shortages as the primary barrier to implementing a strong API security program.

Salt SecurityState of API Security Report·10mo ago
APIStaff

30% of organizations reported a 0–50% increase in API growth.

Salt SecurityState of API Security Report·10mo ago
API

10% of organizations monitor their APIs even less frequently than every few months.

Salt SecurityState of API Security Report·10mo ago
API

12% of organizations monitor their APIs only every few months.

Salt SecurityState of API Security Report·10mo ago
API

54% of organizations rely on developer documentation to identify which APIs expose sensitive data or PII.

Salt SecurityState of API Security Report·10mo ago
APIPII

22% of organizations raised their API security budgets by 6–10%.

Salt SecurityState of API Security Report·10mo ago
APIBudget

23% of organizations rely on weekly API checks.

Salt SecurityState of API Security Report·10mo ago
API

15% of respondents identified that their company's API program doesn’t adequately address runtime or production security.

Salt SecurityState of API Security Report·10mo ago
API

20% of organizations cited denial-of-service attempts as the most common API security problem.

Salt SecurityState of API Security Report·10mo ago
APIDDoS

More than half (59%) of organizations are leveraging GenAI within their own security operations to streamline threat detection and risk mitigation.

Salt SecurityState of API Security Report·10mo ago
APIGenAI

42% of organizations reported managing 101–500 APIs.

Salt SecurityState of API Security Report·10mo ago
API

29% of organizations identified account misuse or other fraud as the most common API security problem.

Salt SecurityState of API Security Report·10mo ago
APIAccount misuseFraud

28% of organizations reported breaches as the most common API security problem.

Salt SecurityState of API Security Report·10mo ago
APIBreaches

29% of organizations raised their API security budgets by 11–15%.

Salt SecurityState of API Security Report·10mo ago
APIBudget

51% of organizations use API management tools to identify which APIs expose sensitive data or PII.

Salt SecurityState of API Security Report·10mo ago
APIPII

9% of organizations said financial returns by the reduction in API security incidents is a metric for measuring API security ROI.

Salt SecurityState of API Security Report·10mo ago
API

10% of respondents identified that their company's API program doesn't focus enough on fleshing out requirements and documenting.

Salt SecurityState of API Security Report·10mo ago
API

2% of respondents identified 'Other' as their biggest concern about their company’s overall API program.

Salt SecurityState of API Security Report·10mo ago
API

20% of organizations rely on daily API checks.

Salt SecurityState of API Security Report·10mo ago
API

3% of organizations are taking other measures to mitigate the risks of using Generative AI to develop APIs.

Salt SecurityState of API Security Report·10mo ago
APIGenAI

3% of organizations do not know if Generative AI is perceived as a growing API security concern/risk within their organization.

Salt SecurityState of API Security Report·10mo ago
APIGenAI

11% of organizations raised their API security budgets by 16–20%.

Salt SecurityState of API Security Report·10mo ago
APIBudget

Only 19% of security leaders are 'very confident' in their API inventory accuracy.

Salt SecurityState of API Security Report·10mo ago
APIAPI inventory

10% of organizations rely on monthly API checks.

Salt SecurityState of API Security Report·10mo ago
API

16% of organizations cited APIs as critical for enabling autonomous systems such as AI agents, which rely on APIs for communication and orchestration.

Salt SecurityState of API Security Report·10mo ago
API

9% of organizations have no plans to use GenAI in API development.

Salt SecurityState of API Security Report·10mo ago
APIGenAI

35% of organizations are using APIs to support migration to modern cloud architectures.

Salt SecurityState of API Security Report·10mo ago
APICloud

6% of organizations conduct threat modeling to assess the effectiveness of their API security measures.

Salt SecurityState of API Security Report·10mo ago
APIThreat modeling

16% of respondents identified that their company's API program doesn't drive enough observability and control.

Salt SecurityState of API Security Report·10mo ago
API

10% of respondents identified that their company's API program is too difficult to staff/resource.

Salt SecurityState of API Security Report·10mo ago
API

8% of respondents identified that it’s difficult to know what to prioritize within their company's API program.

Salt SecurityState of API Security Report·10mo ago
API

30% of organizations reported intermediate maturity in their API security programs, with app sec testing and API gateways in place.

Salt SecurityState of API Security Report·10mo ago
APIMaturity

10% of organizations have advanced API security strategies that include dedicated API testing and protection.

Salt SecurityState of API Security Report·10mo ago
APIAPI testing

16% of organizations identify enabling AI agents or other autonomous systems as a main driver behind the use of APIs.

Salt SecurityState of API Security Report·10mo ago
APIAI agent

59% of organizations said the tools they use to detect and prevent API attacks are only somewhat effective.

Salt SecurityState of API Security Report·10mo ago
APISecurity tool

6% of respondents identified that their company's API program is too cumbersome and slows down delivery.

Salt SecurityState of API Security Report·10mo ago
API

Only 23% of organizations rated the tools they use to detect and prevent API attacks as very effective.

Salt SecurityState of API Security Report·10mo ago
APISecurity tool

3% of organizations rated the tools they use to detect and prevent API attacks as not effective at all.

Salt SecurityState of API Security Report·10mo ago
APISecurity tool

6% of organizations do not know how effective their existing security tools are in preventing API attacks.

Salt SecurityState of API Security Report·10mo ago
APISecurity tool

2% of attack attempts target internal-facing API endpoints.

Salt SecurityState of API Security Report·10mo ago
API

5% of organizations reported that GenAI is not a concern at all for API security.

Salt SecurityState of API Security Report·10mo ago
APIGenAI

13% of organizations reported using GenAI for all API development.

Salt SecurityState of API Security Report·10mo ago
APIGenAI

8% of organizations conduct incident response analysis to assess the effectiveness of their API security measures.

Salt SecurityState of API Security Report·10mo ago
APIIncident response analysis

49% of organizations are using GenAI for some API development.

Salt SecurityState of API Security Report·10mo ago
APIGenAI

23% of organizations plan to adopt GenAI within the next 6–12 months for API development.

Salt SecurityState of API Security Report·10mo ago
APIGenAI

45% of respondents cited the potential for new API vulnerabilities tied to AI-generated code.

Salt SecurityState of API Security Report·10mo ago
APIAI

56% of respondents cited a lack of control over AI model security used for code generation.

Salt SecurityState of API Security Report·10mo ago
APIAI

2% of respondents expressed other security concerns about using Generative AI to develop APIs.

Salt SecurityState of API Security Report·10mo ago
APIGenAI

35% of respondents cited difficulty ensuring quality and reliability of AI-generated code.

Salt SecurityState of API Security Report·10mo ago
APIAI

15% of organizations are very confident in detecting and responding to attacks leveraging Generative AI.

Salt SecurityState of API Security Report·10mo ago
APIGenAI

2% of organizations use other methods to assess the effectiveness of their API security measures.

Salt SecurityState of API Security Report·10mo ago
API

55% of organizations were somewhat confident in their ability to detect and respond to attacks leveraging Generative AI.

Salt SecurityState of API Security Report·10mo ago
APIGenAI

5% of organizations did not know about their ability to detect and respond to attacks leveraging Generative AI.

Salt SecurityState of API Security Report·10mo ago
APIGenAI

9% of organizations were unsure about their API security budget increase.

Salt SecurityState of API Security Report·10mo ago
APIBudget

15% of organizations were not very confident in their ability to detect and respond to attacks leveraging Generative AI.

Salt SecurityState of API Security Report·10mo ago
APIGenAI

80% of security leaders lack continuous, real-time API monitoring.

Salt SecurityState of API Security Report·10mo ago
APIAPI monitoring

98% of attack attempts target external-facing APIs.

Salt SecurityState of API Security Report·10mo ago
API

78% of dominant attack vectors map to OWASP API8 Security Misconfiguration.

Salt SecurityState of API Security Report·10mo ago
APIOWASP

28% of organizations identify partner enablement as a main driver behind the use of APIs.

Salt SecurityState of API Security Report·10mo ago
API

48% of organizations identify platform or system integrations as a main driver behind the use of APIs.

Salt SecurityState of API Security Report·10mo ago
API

25% of organizations identify monetization of functionality or data as a main driver behind the use of APIs.

Salt SecurityState of API Security Report·10mo ago
API

18% of organizations cited brute forcing or credential stuffing as the most common API security problem.

Salt SecurityState of API Security Report·10mo ago
APIBrute froceCredential stuffing

9% of organizations have no formal API security strategy in place.

Salt SecurityState of API Security Report·10mo ago
API

31% of organizations adhere to GDPR for API development and deployment.

Salt SecurityState of API Security Report·10mo ago
APIGDPR

6% of organizations do not know by how much the number of APIs has increased over the past 12 months.

Salt SecurityState of API Security Report·10mo ago
API

13% of organizations cited enumeration and scraping as the most common API security problem.

Salt SecurityState of API Security Report·10mo ago
APIEnumerationScraping

47% of respondents cited difficulty understanding and securing AI-generated code.

Salt SecurityState of API Security Report·10mo ago
APIAI

37% of organizations adhere to PCI DSS for API development and deployment.

Salt SecurityState of API Security Report·10mo ago
APIPCI DSS

39% of organizations adhere to HIPAA for API development and deployment.

Salt SecurityState of API Security Report·10mo ago
APIHIPAA

7% of respondents identified that it’s difficult to know if their company's API program is compliant with new policies/regulations.

Salt SecurityState of API Security Report·10mo ago
APICompliance

Nearly 80% of organizations increased their API security budgets in the past year.

Salt SecurityState of API Security Report·10mo ago
APIBudget

96% of attack attempts originate from authenticated entities (compromised users, insiders, or rogue agents).

Salt SecurityState of API Security Report·10mo ago
API

34% of organizations reported sensitive data exposure and privacy incidents as the most common API security problem.

Salt SecurityState of API Security Report·10mo ago
APIData exposure