Richard Bird
speaker
50 appearances
1 recordings
1 series
first heard Oct 2024
last heard Oct 2024
Richard Bird’s voice in public audio — every appearance, attributed to the second.
Trend
recordings per month · last 12 monthsNo recordings in the last 12 months.Older appearances are listed below; set an alert to hear about the next one.
Appearances
I'm a longtime technologist, 30 years this year. I don't feel that old. I'm the chief security officer for Traceable, and I've been in the startup and solution side for about six years now. I spent more than 24 years in the corporate world where I was executive a number of different things.
All I like to say is it took me 25 years of work in the corporate world to become an overnight sensation in the startup world. So if you're willing to put the work in for a quarter of a century, you can be recognized for being good at almost anything. I met my now wife about eight years ago. We looked at each other and said we both love music.
I had been a young dad, so I hadn't been in the music scene for 25 years. In fact, I always like to tell people I saw Red Hot Chili Peppers in Columbus, Ohio in 1985 or 86. We looked at each other and said, who are we going to go see? And that's like asking your spouse, where are you going to go to dinner? And we looked at each other and said, have you ever been to a music festival? He said, no.
We're some 55 music festivals later now. So that for me is fun, number one. Fun number two is hopping in our van and going to any national park, going to any trailhead and hiking for as long as we're able to and hiking back out. I keep myself busy.
I think if you want to know what API sprawl is, and we're going to stay thematic with the creepy crawlers, watch The Last of Us, a virus, a thing propagating out of control and representing a threat to everybody. When we look at APIs, in the last dozen years, APIs have been used to create massive amounts of business value, but with very little to no security oversight.
The reason for that historically is that the goal was to find ways to get applications, particularly in the cloud, to communicate with each other without having to build all of these really heavy integration points that we used to do back in the old data center and application days. And so as soon as folks realized how they could use those APIs, they started doing it like crazy, right?
And they didn't have any security tools. They didn't have any guidance. An example of this is you can walk into any large company today and there'll be 30 organizations within that company that are developing APIs. And they're not using any standard protocols. They're using GraphQL. They're using SOAP. They're using REST. They're using all of these different language types.
And so now you think about, okay, what can that kind of sprawl create in terms of problems? Go back to the last of us, right? I don't know. What kind of problems can self-propagating technologies create once they're out in the wild besides making more of themselves? There are more and more APIs that are being built without these oversight components in place.
And I think it's always really important to point out, API sprawl is not a security problem. API sprawl is an operational problem. It only becomes a security problem when it is a security problem. And when somebody finds an exploitable API that's in this massive mess of APIs that have been created, now the bad guy can just simply take a pathway using that one exposed API.
And it wasn't sprawl necessarily that caused it. It was all of the lack of discipline and control that happens when you have a sprawl. I build it without authentication. I build it without the necessary safeguards. I build it and I put private information in it when I'm not supposed to.
These are all characteristics of behaviors that we see in the market today, and the scale of it is just staggering. We have a new API security report that's coming out. And 57% of the organizations that we've talked to have suffered an API breach in the last two years. And of those, 73% have had at least three. And 41% of them faced five or more API breaches just in the last two years.
And that is the consequence of what happens when API sprawl is allowed to continue uncontrolled and unchecked.
It goes back to the beginnings, which is security teams had no responsibilities or obligations to observe, manage, or secure APIs to begin with. When you look at organizations today, API creation definitely doesn't belong to security. It belongs to DevOps. When you look at remediation, say a vulnerable API that was found in testing, security people aren't developers anymore.
So you see a lot of tension in those organizations around mitigating or remediating the risk or the vulnerability that is associated. And so we really are living in a world where almost all of the traffic, like 75, 80 percent of the daily Internet traffic in the world is APIs. And we have security organizations that have been kept out of the equation for years and years.
And then we have an accelerating growth curve of APIs being developed. And we have a much slower curve of security organizations catching up. And it's always I always like to call that the time machine. When one curve is growing exponentially faster, API creation, then another curve, API security is growing. You literally would be better off not doing anything because you're so far behind.
Now, obviously, that's not the right security answer. But it's the mathematical part of this problem.
If API use and API componentry continues to grow at an exponential rate, and any study that you see will suggest API usage is growing anywhere from 3x to 7x a year, but API security is still a cognitive dissonance gap within an organization where people are arguing about whether I need API security because I have a web application firewall in
then you can see where the trend is going, which is even more sprawl, even less security and guideline guardrail control. And then probably more importantly, within the DevOps side of the equation, nobody's in charge of APIs, right? On the operational side, API ownership is fractioned across all the organizations that are developing it. So there's no head of API governance.
There's no head of API compliance and control. APIs haven't been looked at that way historically. And that will change. Inevitably, catastrophic consequences will change behaviors in that space. But it is the biggest gap I have ever seen. And I've said this now for more than two years. It is the biggest gap I've ever seen in a situation where people go, yes, I know I have an API security problem.
But no, I'm doing absolutely nothing about it. And that really is where the market is currently sitting for the most part. There are a lot of very mature and evolved API users in the corporate world that recognize the scale and size of this threat. They are definitely moving down the path, but that is a very small percentage of the overall Fortune 2000, Fortune 3000 landscape.
Showing 1–20 of 50 · page 1 of 3
Next →