SecurityInformed.com
  • Products
    Video Surveillance
    • Surveillance cameras
    • Video Surveillance software
    • IP cameras
    • Digital video recorders (DVRs)
    • Dome cameras
    • Network Video Recorders (NVRs)
    • IP Dome cameras
    • Security camera lenses
    Access Control
    • Access control readers
    • Access control software
    • Access control controllers
    • Access control systems & kits
    • Intercom Systems
    • Electronic lock systems
    • Access control cards/ tags/ fobs
    • Access control accessories
    Intruder Alarms
    • Intruder alarm system control panels & accessories
    • Intruder detectors
    • Intruder alarm warning devices
    • Intruder alarm communicators
    • Intruder alarm accessories
    • Intruder alarm lighting systems
    Technology's Role In Securing Banks And Financial Institutions
    Technology's Role In Securing Banks And Financial Institutions
    Dahua APOLLO 4G Solar Security System

    Dahua APOLLO 4G Solar Security System

    Morse Watchmans KeyWatcher Touch Key Control Modules

    Morse Watchmans KeyWatcher Touch Key Control Modules

    Hikvision AX PRO Wireless Alarm Keyfob

    Hikvision AX PRO Wireless Alarm Keyfob

    Delta Scientific Rapid Deployment Portable Barrier

    Delta Scientific Rapid Deployment Portable Barrier

  • Companies
    Companies
    • Manufacturers
    • Distributors
    • Resellers / Dealers / Reps
    • Installers
    • Consultants
    • Systems integrators
    • Events / Training / Services
    • Manned guarding
    Companies by Product area
    • CCTV
    • Access control
    • Intruder alarm
    • IP networking products
    • Biometrics
    • Software
    • Digital video recording
    • Intercom systems
    Technology's Role In Securing Banks And Financial Institutions
    Technology's Role In Securing Banks And Financial Institutions
  • News
    News
    • Product news
    • Corporate news
    • Case studies
    • Events news
    Latest
    • Steve Ingram Joins Cyble To Lead US Cybersecurity
    • RAD's SARA Assess Unveiled - Advanced Security Solution
    • TEPCO's Digital Transformation With Genetec Security
    • Blackline G8 Wearable At NSC Safety Congress 2026
    Technology's Role In Securing Banks And Financial Institutions
    Technology's Role In Securing Banks And Financial Institutions
  • Insights
    Insights
    • Expert commentary
    • Security beat
    • Round table discussions
    • Round Table Expert Panel
    • eMagazines
    • Year in Review 2023
    • Year in Review 2022
    Featured
    • Responsible AI Adoption Starts With Governance
    • How AI-Enabled Cameras Are Becoming Operational Sensors That Power Safety, Automation, And Business Intelligence
    • Solink's AI Agents Boost Efficiency Of Existing Infrastructure With Automation
    • Together, VIVOTEK And March Networks Will Boost Innovation And Engagement
    Technology's Role In Securing Banks And Financial Institutions
    Technology's Role In Securing Banks And Financial Institutions
  • Markets
    Markets
    • Airports & Ports
    • Banking & Finance
    • Education
    • Hotels, Leisure & Entertainment
    • Government & Public Services
    • Healthcare
    • Remote Monitoring
    • Retail
    • Transportation
    • Industrial & Commercial
    Technology's Role In Securing Banks And Financial Institutions
    Technology's Role In Securing Banks And Financial Institutions
    Enhance Hospitality Security With Key Control Systems

    Enhance Hospitality Security With Key Control Systems

    eCLIQ Enhances Security At Marin Hospital Of Hendaye

    eCLIQ Enhances Security At Marin Hospital Of Hendaye

    Alamo Colleges Boosts Safety With Alcatel-Lucent OmniSwitch Platform

    Alamo Colleges Boosts Safety With Alcatel-Lucent OmniSwitch Platform

    HID Mobile Access Enhances University Of Dundee Campus

    HID Mobile Access Enhances University Of Dundee Campus

  • Events
    Events
    • International security
    • Regional security
    • Vertical market
    • Technology areas
    • Conferences / seminars
    • Company sponsored
    Virtual events
    • Video Surveillance
    • Access Control
    • Video Analytics
    • Security Storage
    • Video Management Systems
    • Integrated Systems
    Technology's Role In Securing Banks And Financial Institutions
    Technology's Role In Securing Banks And Financial Institutions
    Securex Caspian 2026

    Securex Caspian 2026

    PACK EXPO Chicago 2026

    PACK EXPO Chicago 2026

    OFSEC - Oman Fire, Safety & Security Expo 2026

    OFSEC - Oman Fire, Safety & Security Expo 2026

    Milipol Qatar 2026

    Milipol Qatar 2026

  • White papers
    White papers
    • Video Surveillance
    • Access Control
    • Video Analytics
    • Video Compression
    • Security Storage
    White papers by company
    • HID
    • ASSA ABLOY Opening Solutions
    • Milestone Systems
    • Software House
    • Eagle Eye Networks
    Other Resources
    • eMagazines
    • Videos
    Technology's Role In Securing Banks And Financial Institutions

    Technology's Role In Securing Banks And Financial Institutions

    Integrated Systems Enable Critical And Compliant Security For Transportation

    Integrated Systems Enable Critical And Compliant Security For Transportation

    Modernizing Physical Access Control

    Modernizing Physical Access Control

    Access. Intrusion. One Estate.

    Access. Intrusion. One Estate.

About us Advertise
  • Securing Financial Institutions
  • AI special report
  • Cybersecurity special report
  • 6
Cyber security
  • Home
  • About
  • News
  • Expert commentary
  • Security beat
  • Case studies
  • Round table
  • Products
  • White papers
  • Videos

Four Emerging App Security Challenges Every CTO Needs To Know About

Four Emerging App Security Challenges Every CTO Needs To Know About
Jeff Curley
Jeff Curley
Contact company
Contact Radware
icon Add as a preferred source Download PDF version
Quick Read
⌵
Summary is AI-generated, newsdesk-reviewed
  • App security faces challenges from SaaS growth, requiring robust cloud security.
  • Identifying malicious bots crucial, as half of internet traffic is bot-generated.
  • API vulnerabilities expose sensitive data; integration increases security complexity.
Related Links
  • Unifying The Mobile Experience: Cloud, IoT And The AI Evolution Of Access Control
  • What Is The Role Of Ethical Hackers To Ensure Cybersecurity?

In the next three years, software as a service ‘SaaS’ is likely to grow by around 23%. That’s according to reports by Cognizance. It’s growth rests on the adoption of cloud public, private and hybrid.

Without the cloud applications can’t truly pervade an organization, nor can operational or customer benefits be derived. But there’s no point in adopting the cloud if it’s not secure - the proliferation of SaaS demands security, none more so in a GDPR world.

Large cloud environment

But modern applications are difficult to secure. SaaS based, web, mobile, or custom made all work on different platforms and frameworks. It’s a headache managing all the APIs needed to automate and sync tools. This introduces risk. The greater the number of apps the broader the attack surface and therefore the greater the chance there will be blind posts.

Keeping up to date with updates and new security policies is never easy

There are also added hazards. Applications are always changing. Keeping up to date with updates and new security policies is never easy, but especially hard in a large cloud environment. Failure to adopt changes puts the organization and customers at further risk. But the biggest obstacle is keeping applications and APIs out of harm’s way. It’s a near on impossible task when attack methods and sources are constantly changing.

More advanced threats

To be specific there are four emerging challenges when it comes to protecting apps. Firstly, managing the good and the bad bots and spotting which is which, secondly securing APIs as IoT adoption intensifies, thirdly the relationship between securing apps and DevOps and ensuring ownership of security, and finally denial of service attacks that use newer tactics such as brute force.

Basic security hygiene dictates that security teams refer to the OWASP Top 10. It’s considered the ‘ten commandments’ in security circles, providing a starting point for ensuring the most common threats and vulnerabilities are managed, detected and mitigated. Web Application Firewalls also come into the fray with guidance on testing for the ways hackers exploit vulnerabilities. However, though the basics are good to have in place, there are always more advanced threats to take care of. Bots being a big one.

Bot management

The more sophisticated bots will go as far as to mimic human behaviorAstonishingly about half of internet traffic is bot generated. Half of it is from bad bots. Discerning the good from the bad isn’t easy though and explains why around 80% of organizations can’t make a clear distinction between the two.

Bad bots can do a lot of damage like take over user accounts and payment information, scrape confidential data, or hold up inventory and skew marketing metrics. The more sophisticated bots will go as far as to mimic human behavior and bypass tools like CAPTCHA and even device fingerprinting based protection ineffective.

Securing APIs

Then there’s the complications derived from machine-to-machine and internet of things (IoT) communications. The more integrated ‘things’, the more data there is, the more events there are report on, and the more activity there is reliant on APIs to make the ‘things’ useful and agile.

That’s what makes them a target and the threats to API vulnerabilities include injections, protocol attacks, parameter manipulations, invalidated redirects and bot attacks. There’s the risk that business will grant access to sensitive data, without inspecting nor protecting APIs to detect cyberattacks.

 

Astonishingly about half of internet traffic is bot generated
There’s the risk that business will grant access to sensitive data, without inspecting nor protecting APIs to detect cyberattacks

Denial of service (DoS)

You might think there’s little to add to the swathes of denial of service warnings. Yet when businesses are still being targeted and feeling the ill effects it’s worth mentioning again that different forms of application-layer DoS attacks are still very effective at bringing application services down.

Even the greatest application protection is worthless if the service itself can be knocked down

This includes HTTP/S floods, low and slow attacks (famous examples being Slowloris, LOIC, Torshammer), dynamic IP attacks, buffer overflow, Brute Force attacks and more. The IoT botnets are the culprits and have made application-layer attacks so popular that they have become the preferred DDoS attack vector. Even the greatest application protection is worthless if the service itself can be knocked down.

Continuous security

It may seem easy to say but for modern DevOps, agility is valued at the expense of security. We see time and again examples of where development and roll-out methodologies, such as continuous delivery, mean applications are exposed to threats each time they are modified.

There’s no doubt it is extremely difficult to maintain a valid security policy and protect sensitive data in dynamic conditions without creating a high number of false positives. But we now find that this task has gone way beyond the capability of humans. Organizations now need machine-learning based solutions that map application resources, analyse possible threats, and create and optimise security policies in real time. Reaching this level in security planning should be a big wake-up call that security automation is an essential not a nice to have.

Running security plans

The board needs to know that investment is critical to protect their profits

It’s critical that the security solution your company adopts protects applications on all platforms, against all attacks, through all the channels and at all times. The board needs to know that investment is critical to protect their profits. As such there are six things they need to know:

  • Application security solutions must encompass web and mobile apps, as well as APIs.
  • Bot management solutions need to overcome the most sophisticated bot attacks.
  • DDoS mitigation must be an essential and integrated part of application security solutions.
  • A future-proof solution must protect containerized applications, severless functions, and integrate with automation, provisioning and orchestration tools.
  • To keep up with continuous application delivery, security protections must adapt in real time.
  • A fully managed service should be considered to remove complexity and minimise resources. No amount of human power will beat the bots.

That last point is the most critical. Skill is essential in designing and running security plans and policies that work. But the plans can’t be executed without automated tools. There are just too many decisions to make in a split second. Combining both is the path to an effective app protection strategy and a stronger brand to boot.

Download PDF version Download PDF version
Google logo Add as a preferred source on Google
  • Network / IP
  • Biometrics
  • Traffic surveillance
  • Application security
  • Security management
  • Security devices
  • Fingerprint recognition
  • Public security
  • Security software
  • IP security solutions
  • Security communication
  • Event security
  • Cyber security
  • Mobile communications
  • Internet of Things (IoT)
  • Data Security
  • Home automation
  • Cloud security
  • GDPR
  • Related links
  • Central Monitoring Option Access control software
  • Articles by Jeff Curley
  • Related categories
  • Access control software
Related white papers
Technology's Role In Securing Banks And Financial Institutions

Technology's Role In Securing Banks And Financial Institutions

Download
Security Technologies Promote Real-Time Awareness In K-12 Schools

Security Technologies Promote Real-Time Awareness In K-12 Schools

Download
An End User's Guide To Physical Security For Data Centers

An End User's Guide To Physical Security For Data Centers

Download
Related articles
How Physical Security Consultants Ensure Cybersecurity For End Users

How Physical Security Consultants Ensure Cybersecurity For End Users

How Managed Detection And Response Enhances Cybersecurity Management In Organizations

How Managed Detection And Response Enhances Cybersecurity Management In Organizations

Drawbacks Of PenTests And Ethical Hacking For The Security Industry

Drawbacks Of PenTests And Ethical Hacking For The Security Industry

Follow us

Sections Products Video Surveillance Access Control Intruder Alarms Companies News Insights Case studies Markets Events White papers Videos AI special report Cybersecurity special report RSS
Topics Artificial intelligence (AI) Mobile access Healthcare security Cyber security Counter terror Robotics Thermal imaging Intrusion detection Body worn video cameras
About us Advertise About us 10 guiding principles of editorial content FAQs eNewsletters Sitemap Terms & conditions Privacy policy and cookie policy Californian Residents (CCPA)
  1. Home
  2. Topics
  3. Cyber security
  4. News
  5. Expert commentary
About this page

Discover emerging app security challenges, CTO insights, and innovative solutions for a rapidly evolving cybersecurity landscape.

Subscribe to our Newsletter

Stay updated with the latest trends and technologies in the security industry
Sign Up

DMA

SecurityInformed.com - Making The World A Safer Place
Copyright © Notting Hill Media Inc. 2000 - 2026, all rights reserved

Our other sites:
SourceSecurity.com | TheBigRedGuide.com | HVACinformed.com | MaritimeInformed.com | ElectricalsInformed.com

Subscribe to our Newsletter


You might also like
Technology's Role In Securing Banks And Financial Institutions
Technology's Role In Securing Banks And Financial Institutions
Integrated Systems Enable Critical And Compliant Security For Transportation
Integrated Systems Enable Critical And Compliant Security For Transportation
Modernizing Physical Access Control
Modernizing Physical Access Control
Minimizing Storage, Maximizing Focus
Minimizing Storage, Maximizing Focus
Sign up now for full access to SecurityInformed.com content
Download Datasheet
Download PDF Version
Download SecurityInformed.com product tech spec