Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking and Finance Review

Global Banking & Finance Review

Company

    GBAF Logo
    • About Us
    • Profile
    • Privacy & Cookie Policy
    • Terms of Use
    • Contact Us
    • Advertising
    • Submit Post
    • Latest News
    • Research Reports
    • Press Release
    • Awards▾
      • About the Awards
      • Awards TimeTable
      • Submit Nominations
      • Testimonials
      • Media Room
      • Award Winners
      • FAQ
    • Magazines▾
      • Global Banking & Finance Review Magazine Issue 79
      • Global Banking & Finance Review Magazine Issue 78
      • Global Banking & Finance Review Magazine Issue 77
      • Global Banking & Finance Review Magazine Issue 76
      • Global Banking & Finance Review Magazine Issue 75
      • Global Banking & Finance Review Magazine Issue 73
      • Global Banking & Finance Review Magazine Issue 71
      • Global Banking & Finance Review Magazine Issue 70
      • Global Banking & Finance Review Magazine Issue 69
      • Global Banking & Finance Review Magazine Issue 66
    Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

    Global Banking & Finance Review® is a leading financial portal and online magazine offering News, Analysis, Opinion, Reviews, Interviews & Videos from the world of Banking, Finance, Business, Trading, Technology, Investing, Brokerage, Foreign Exchange, Tax & Legal, Islamic Finance, Asset & Wealth Management.
    Copyright © 2010-2025 GBAF Publications Ltd - All Rights Reserved.

    ;
    Editorial & Advertiser disclosure

    Global Banking and Finance Review is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    Home > Technology > The invisible battlefield of financial innovation
    Technology

    The invisible battlefield of financial innovation

    The invisible battlefield of financial innovation

    Published by Wanda Rich

    Posted on December 11, 2024

    Featured image for article about Technology

    By Chuck Herrin, Field Chief Information Security Officer for multi-cloud application services and security company, F5.

    sanity image

    APIs – or application programming interfaces – have become the lifeblood of digital transformation as they help power innovation, business-to-business integrations, and the management of vast quantities of sensitive data in financial services.

    That innovation has in turn revolutionised the financial sector in Australia through advances in digital banking, fostering greater accessibility and personalisation. A study showed that in 2023, Australian banks emerged as leaders in ICT investment among their APAC peers. The top six Australian banks collectively spent circa A$7.6 billion on ICT – a 6.1 per cent increase from 2022.

    This rapid rise has ushered in unprecedented agility and connectivity, but it has also created a massive security gap.

    What we see at F5 tells us that over 90 per cent of web-based attacks now target API endpoints, and Gartner predicts that API abuses will account for more than 50% of data breaches by 2025. This alarming trend highlights the urgency with which financial institutions must address security risks while navigating the quick-fire evolution of the industry.

    From Innovation to vulnerability

    Dating back to at least the 1960s as a method of communication between system components in early computing environments, APIs became more commonplace in the 1990s with the rise of web technologies. The open-source movement further accelerated their adoption, as developers shared frameworks and tools to standardise API design and implementation. Tech giants such as Salesforce and eBay then revolutionised the concept further by allowing third-party developers to integrate with their platforms in the early 2000s.

    APIs quickly became indispensable for modernising financial services, enabling seamless customer experiences and unlocking new revenue streams. However, security measures struggled to keep pace. It wasn’t until 2019 – nearly two decades later – that the OWASP API Top 10 spotlighted the unique vulnerabilities inherent to APIs.

    This lag in security preparedness has left financial institutions exposed to increasingly sophisticated attacks.

    Imagine a bank’s system that handles currency conversions, for example, turning Australian dollars into U.S. dollars. This system works via APIs – essentially a digital messenger that lets apps and websites talk to each other and request services, such as calculating exchange rates or completing transactions.

    In one real-world example, my former company’s research team showed a banking customer how to bypass their controls and manipulate transactions. This type of attack bypassed the security checks built into the bank’s app, allowing us to print free money completely undetected into one of our accounts.

    Even though the bank had otherwise sophisticated security measures in place, our team was able to exploit these gaps and make their actions look normal. As a result, the system couldn’t tell the difference between the hackers’ fake requests and legitimate ones, and the attack went unnoticed until we briefed the customer on what to look for and how to mitigate their API risks.

    High stakes balancing act

    Australian financial institutions are under immense pressure to innovate quickly while safeguarding customer trust. APIs are at the centre of this tension, offering the agility needed to launch new products and services rapidly. Yet, this speed often comes at the expense of security, leading to friction between development and security teams, as well as boards and executive management where speed-to-market and security are both top priorities.

    Bridging this divide requires clear governance standards that integrate security into the development lifecycle without stifling innovation.

    A proactive approach – embedding security considerations into product management decisions – is essential for reducing vulnerabilities from the outset, as is collaboration. Security solutions must align with development workflows to minimise disruption and encourage adoption. Simply put, you cannot secure that which you cannot see, or that which you don’t understand. Getting the visibility needed to ensure protection requires a proactive, simple, and effective approach.

    Regulatory frameworks add another layer of complexity to API security. Financial institutions must navigate strict compliance requirements while maintaining operational efficiency. Metrics like incident response times and results of API security assessments are vital for meeting regulatory expectations and improving overall resilience.

    Third-party risks and hidden threats

    As financial institutions increasingly rely on third-party APIs for core functions, their attack surfaces grow. These integrations are essential for enhancing services, but they also introduce risks due to limited visibility into third-party security practices.

    Compounding the challenge is the sheer number of APIs in use. Common industry estimates suggest that up to 50 per cent of API endpoints are unmanaged, and keeping an up-to-date inventory of APIs and endpoints is a daunting challenge. Dormant or outdated APIs – sometimes called ‘zombie or shadow APIs’ – are especially vulnerable, providing attackers with hidden entry points. Continuous monitoring and governance are critical to mitigating these threats and ensuring a secure API ecosystem.

    Lessons learned; actions required

    The rapid growth of APIs has reshaped financial services, but it has also created vulnerabilities that can no longer be ignored. These persistent challenges demand a proactive, forward-looking approach.

    By embedding security into the DNA of API management, fostering collaboration between teams, and learning from past mistakes, financial institutions can build robust defences against evolving threats. APIs are the backbone of tech and financial institutions are the backbone of funding future industry and economic growth – securing them is essential for innovation.

    Related Posts
    LakeFusion Secures Seed Funding to Advance AI-Native Master Data Management
    LakeFusion Secures Seed Funding to Advance AI-Native Master Data Management
    Clarity, Context, Confidence: Explainable AI and the New Era of Investor Trust
    Clarity, Context, Confidence: Explainable AI and the New Era of Investor Trust
    Data Intelligence Transforms the Future of Credit Risk Strategy
    Data Intelligence Transforms the Future of Credit Risk Strategy
    Architect of Integration Ushers in a New Era for AI in Regulated Industries
    Architect of Integration Ushers in a New Era for AI in Regulated Industries
    How One Technologist is Building Self-Healing AI Systems that Could Transform Financial Regulation
    How One Technologist is Building Self-Healing AI Systems that Could Transform Financial Regulation
    SBS is Doubling Down on SaaS to Power the Next Wave of Bank Modernization
    SBS is Doubling Down on SaaS to Power the Next Wave of Bank Modernization
    Trust Embedding: Integrating Governance into Next-Generation Data Platforms
    Trust Embedding: Integrating Governance into Next-Generation Data Platforms
    The Guardian of Connectivity: How Rohith Kumar Punithavel Is Redefining Trust in Private Networks
    The Guardian of Connectivity: How Rohith Kumar Punithavel Is Redefining Trust in Private Networks
    BNY Partners With HID and SwiftConnect to Provide Mobile Access to its Offices Around the Globe With Employee Badge in Apple Wallet
    BNY Partners With HID and SwiftConnect to Provide Mobile Access to its Offices Around the Globe With Employee Badge in Apple Wallet
    How Integral’s CTO Chidambaram Bhat is helping to solve  transfer pricing problems through cutting edge AI.
    How Integral’s CTO Chidambaram Bhat is helping to solve transfer pricing problems through cutting edge AI.
    Why Physical Infrastructure Still Matters in a Digital Economy
    Why Physical Infrastructure Still Matters in a Digital Economy
    Why Compliance Has Become an Engineering Problem
    Why Compliance Has Become an Engineering Problem

    Why waste money on news and opinions when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    More from Technology

    Explore more articles in the Technology category

    Can AI-Powered Security Prevent $4.2 Billion in Banking Fraud?

    Can AI-Powered Security Prevent $4.2 Billion in Banking Fraud?

    Reimagining Human-Technology Interaction: Sagar Kesarpu’s Mission to Humanize Automation

    Reimagining Human-Technology Interaction: Sagar Kesarpu’s Mission to Humanize Automation

    LeapXpert: How financial institutions can turn shadow messaging from a risk into an opportunity

    LeapXpert: How financial institutions can turn shadow messaging from a risk into an opportunity

    Intelligence in Motion: Building Predictive Systems for Global Operations

    Intelligence in Motion: Building Predictive Systems for Global Operations

    Predictive Analytics and Strategic Operations: Strengthening Supply Chain Resilience

    Predictive Analytics and Strategic Operations: Strengthening Supply Chain Resilience

    How Nclude.ai   turned broken portals into completed applications

    How Nclude.ai turned broken portals into completed applications

    The Silent Shift: Rethinking Services for a Digital World?

    The Silent Shift: Rethinking Services for a Digital World?

    Culture as Capital: How Woxa Corporation Is Redefining Fintech Sustainability

    Culture as Capital: How Woxa Corporation Is Redefining Fintech Sustainability

    Securing the Future: We're Fixing Cyber Resilience by Finally Making Compliance Cool

    Securing the Future: We're Fixing Cyber Resilience by Finally Making Compliance Cool

    Supply chain security risks now innumerable and unmanageable for majority of cybersecurity leaders, IO research reveals

    Supply chain security risks now innumerable and unmanageable for majority of cybersecurity leaders, IO research reveals

    Why AI's Promise of Efficiency May Break Tomorrow's Workforce

    Why AI's Promise of Efficiency May Break Tomorrow's Workforce

    Revolutionizing AppSec: The AI Security Crew Paradigm Shift

    Revolutionizing AppSec: The AI Security Crew Paradigm Shift

    View All Technology Posts
    Previous Technology PostThe benefits of implementing AI in the insurance industry
    Next Technology PostEyal Avramovich – A Journey from Electronics Engineering to Blockchain Innovation