Loading…
or to bookmark your favorites and sync them to your phone or calendar.
strong>API Security / Compliance (API World) [clear filter]
arrow_back View All Dates
Wednesday, November 6
 

10:00am PST

OPEN SESSION (API): Securing APIs Requires Cyber Survival Tactics
Wednesday November 6, 2024 10:00am - 10:25am PST
Steve Winterfeld, Akamai Technologies, Advisory CISO
Swetha Sridharan, IBM API Connect, Senior Product Manager 

APIs are the backbone of modern applications, enabling seamless communication and user experiences, but their widespread use makes them prime targets for cybercriminals. Business and IT leadership is quickly recognizing that cyber risk is business risk, and securing API driven transformation is critical to protecting revenue and brand. 
 
Fueled by the latest research from Akamai’s State of the Internet (SOTI) report as well as IBM’s 2024 Cost of a Data Breach report, you will learn about the latest threat trends including the most-targeted industries and attack surfaces so you can stay secure in an evolving threat landscape. Join us to understand how to leverage these tactics to strengthen your API security practices and posture. 
Takeaways
  • Understanding of threat trends 
  • Case studies by industry
  • Best practices, resources, and tools to mitigate the threat 
Speakers
avatar for Swetha Sridharan

Swetha Sridharan

Senior Product Manager, IBM API Connect
Swetha Sridharan is passionate about solving problems through technology and empathetic design thinking in API management and integration. She is currently a Senior Product Manager at IBM API Connect.
avatar for Steve Winterfeld

Steve Winterfeld

Advisory CISO, Akamai Technologies
Steve Winterfeld is Akamai’s Advisory CISO. He has a strong background in building operational security programs that are compliant with industry regulations. Before joining the team, he served as CISO for Nordstrom Bank, Managing Director of Incident Response and Threat Intelligence... Read More →
Wednesday November 6, 2024 10:00am - 10:25am PST
API World -- Expo Discovery Stage

11:00am PST

OPEN SESSION (API): Turn Fragmentation into Federation: A Guide to Effective API Management
Wednesday November 6, 2024 11:00am - 11:50am PST
Beerinder Rodey, Boomi, Director, API Product Management

The rapid proliferation and fragmentation of APIs create complexities and inefficiencies that hinder operational effectiveness for many organizations. If you’re an API developer, product owner, or architect facing these challenges, join this session.

We will discuss the current state of API management and outline strategies to move from fragmented APIs to a unified federated approach. Key topics will include dynamic API discovery, the issues caused by API sprawl, and how effective API management can enhance workflows, support API productization, and enable scalability in the context of AI integration.

Gain insights into improving API visibility, security, and governance while leveraging your existing API management investments like AWS, Azure, Apigee, and Kong. Witness federated API management in action and explore its potential to streamline your API ecosystem.

Join us to discover how to:
- Centralize API discovery and provisioning
- Strengthen API governance for better control
- Simplify API management practices
Speakers
avatar for Beerinder Rodey

Beerinder Rodey

Director, API Product Management, Boomi
As a product management leader with over 10 years of experience in the API Management space, Beerinder has a proven track record of managing globally distributed SaaS and Hybrid platform solutions at scale. Beerinder is passionate about customer engagement and finding innovative solutions... Read More →
Wednesday November 6, 2024 11:00am - 11:50am PST
API World -- OPEN Workshop Stage

11:30am PST

OPEN SESSION (API): Runtime API Governance: The Secret to Scaling Secure and Reliable APIs
Wednesday November 6, 2024 11:30am - 11:55am PST
Sudeep Goswani, Traefik Labs, CEO

As APIs become the lifeblood of modern software development, ensuring their security, reliability, and scalability is more crucial than ever. Runtime API governance is the unsung hero that enables this success, providing the necessary guardrails and constraints to produce the desired outcome. In this talk, we'll explore the critical components of runtime API governance, including security posture, conformance checks, and ongoing change management. We'll delve into the importance of these components and how they work together to create a checks and balances system that ensures APIs can handle the pace of business and don't fall prey to runtime issues. Join us to learn how to build a robust API governance strategy that will help you sleep better at night, knowing your APIs are secure, reliable, and scalable.
Speakers
avatar for Sudeep Goswami

Sudeep Goswami

CEO, Traefik Labs
With a 25-year career spanning multiple disciplines, including software programming, network desgin and engineering, technology consulting, product management, product marketing, corporate marketing, business development, and sales, Sudeep joined Traefik Labs as the Chief Revenue... Read More →
Wednesday November 6, 2024 11:30am - 11:55am PST
API World -- Expo Discovery Stage

2:30pm PST

PRO SESSION (API): Log for Success: Enhancing API Security and Operations Through Effective Audit Logging
Wednesday November 6, 2024 2:30pm - 2:55pm PST
John Tobin, Solsys, Principal Consultant

APIs are more vital - and more vulnerable - than ever before. The potential for exposing critical customer data or jeopardizing financial transactions puts organizations at significant risk of reputational and financial damage. Additionally, ensuring API performance and swiftly resolving client issues have become increasingly complex tasks. The solution to these challenges lies in effective API audit logging at key entry points. Understanding what to log and how to monitor this information for security threats is crucial. This session will provide essential practices for effective API audit logging, empowering you to safeguard your organization and enhance operational efficiency.
 
Speakers
avatar for John Tobin

John Tobin

Principal Consultant, Solsys
John has over 25 years of experience working in software and technology, with professional services consulting firms and product companies, ranging from large enterprises to small firms. John currently helps clients with their API governance, API management, and API security problems... Read More →
Wednesday November 6, 2024 2:30pm - 2:55pm PST
API World -- Workshop Stage B

3:00pm PST

OPEN SESSION (API): Unlock Shift-Left: Right Teams, Right Tools, Fixed Problems
Wednesday November 6, 2024 3:00pm - 3:25pm PST
Dan Hopkins, StackHawk, VP, Engineering

In today's fast-paced development environment, ensuring API security is more crucial than ever. Despite the strong desire to integrate security into software delivery cycles, many organizations struggle to achieve this effectively. This session will focus on the importance of proactive API security testing to match the pace of development and achieve business outcomes and goals. By understanding your organization's shift-left maturity, you can better position yourself to integrate security into your development processes seamlessly.

Using StackHawk's Shift-Left Maturity Model as a framework, we will explore how identifying your maturity stage is key to making meaningful progress. The session will delve into the three fundamental pillars of successful shift-left practices: people, process, and tooling. Join us to learn how to empower your team, optimize your processes, and leverage the right tools to shift left effectively and ensure robust API security.
Speakers
avatar for Dan Hopkins

Dan Hopkins

VP, Engineering, StackHawk
Dan Hopkins has been a software engineer for 20 years, working at high growth startups such as VictorOps and LivingSocial and at large high tech companies such as Splunk. For the last 10 years he has focused on building tools for progressive engineering teams adopting DevOps and DevSecOps... Read More →
Wednesday November 6, 2024 3:00pm - 3:25pm PST
API World -- Main Stage

4:00pm PST

KEYNOTE (API): Imperva -- API Security from Runtime to Security Testing: Avoid Common Data Protection Pitfalls
Wednesday November 6, 2024 4:00pm - 4:25pm PST
Madhusudhan Reddy, Imperva, Sr. Product Manager for Runtime Application Self Protection (RASP) and API Security

It is becoming more common for practitioners of API Security Testing to leverage runtime data to enhance their capability to discover business logic and API specific vulnerabilities. While runtime data are critical to overcome the limitation of static analysis, the data collection itself can raise real concerns over data privacy protection, especially when it can be seen as a breach of the compartmentalization between runtime and dev environments. In this talk you will learn best practices for the runtime API Security component to generate tests without jeopardizing data.
Speakers
avatar for Madhusudhan Reddy

Madhusudhan Reddy

Sr. Product Manager for Runtime Application Self Protection (RASP) and API Security, Imperva
Madhusudhan Reddy (Madhu) is the Sr. Product Manager for Runtime Application Self Protection (RASP) and API Security at Imperva, a Thales company. Madhu has over 15 years of experience in Cyber Security.  Prior to Imperva, Madhu worked at F5 where he managed threat intelligence products... Read More →
Wednesday November 6, 2024 4:00pm - 4:25pm PST
API World -- Main Stage
 

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date - 
  • Talk Type
  • OPEN Session
  • PRO Session
  • PRO Workshop
  • Track or Conference
  • AI & ML (CloudX)
  • API Case Studies & Success Stories (API World)
  • API Design / Architecture (API World)
  • API Leadership Summit (API World)
  • API Ops & Scalability & Usability (DX) & Testing (API World)
  • API Program Management (API World)
  • API Security / Compliance (API World)
  • API World
  • API World: API Innovation
  • API World: API Lifecycle
  • API World: API Strategy
  • API World: Microservices World
  • API-First Development (API World)
  • APIs (Dev Innovation)
  • Automated Testing & Monitoring & Reporting (CloudX)
  • CI/CD (CloudX)
  • CI/CD / Deployment (API World)
  • Cloud Development Technologies (CloudX)
  • Cloud Development Technologies (Dev Innovation)
  • Cloud Infrastructure (CloudX)
  • Cloud Innovation (AI & Edge & etc) (CloudX)
  • Cloud Security (CloudX)
  • Cloud Talent & Skills (CloudX)
  • CloudX
  • CloudX: Cloud Architecture & Infrastructure
  • CloudX: Cloud Strategy Conference
  • CloudX: Cloud-Native Development
  • CloudX: DevOps Summit
  • Containers & Kubernetes (CloudX)
  • Deployment Strategies (CloudX)
  • Dev Innovation (CloudX)
  • Dev Innovation Summit
  • Developer Tools (Dev Innovation)
  • DevSecOps (CloudX)
  • Digital Acceleration (CloudX)
  • Edge Computing (CloudX)
  • Emerging APIs: AI & IoT & Blockchain & Web3 & XR (API World)
  • Expo Challenge
  • Future of Cloud-Native Computing (CloudX)
  • Hybrid & Multi-Cloud (CloudX)
  • Hybrid APIs & Low Code APIs (API World)
  • Industries: Open Banking & Healthcare & Retail (API World)
  • Infrastructure-as-Code (CloudX)
  • Integration Management (API World)
  • Leadership Lounge
  • Microservices Design & Architecture (API World)
  • Microservices Design (CloudX)
  • Microservices Management (CloudX)
  • Observability (CloudX)
  • OPEN Session
  • Platform Engineering (API World)
  • Programming Languages (Dev Innovation)
  • Roundtables
  • Service Mesh & Containers & Kubernetes (API World)
  • Sponsor Spotlight
  • Virtual
  • In-Person/Virtual
  • In Person
  • Virtual
  • Virtual Exclusive