APIs are at the heart of digital transformation. Whether organizations are launching new customer experiences, streamlining partner integrations, engaging with prospects, or improving internal workflows for employees, they’re doing it through APIs. From payroll systems to customer portals, APIs are the connective tissue enabling access to data and functionality at scale. As AI adoption accelerates, and particularly with the rise of agentic AI, API traffic is set

to go through the roof.

But while API usage is skyrocketing, is API security keeping pace? Many organizations are only beginning to grapple with the reality that traditional security controls, built for web applications not APIs, are falling short in protecting against today’s threats. APIs expose business logic, sensitive data, and core operations. That makes them both a prime target and a strategic vulnerability.

This report captures the voice of the global CISO. It’s a peer-driven snapshot of how security leaders are thinking about API risk today. From visibility gaps and auditing delays to overreliance on legacy tools and the slow adoption of purpose- built solutions, the findings paint a picture of an evolving challenge and a security discipline in transition.