
From BOLA to Bots: Building a Layered API Defense Against the Modern Top 10
About this episode
APIs are the "nervous system" of modern applications, making them the number one attack vector, with flaws like Broken Object Level Authorization (BOLA), Broken Object Property Level Authorization (BOPLA), and Broken Function Level Authorization (BFLA) accounting for a high percentage of breaches. This episode delves into the multi-layered "defense-in-depth" strategies required to mitigate these threats, focusing on input validation, rate limiting, and centralized enforcement via API Gateways We explore how integrating security testing into the CI/CD pipeline and maintaining a proper inventory helps organizations eliminate "shadow" or "zombie" APIs and build a true culture of digital resilience.
Sponsors: https://cloudassess.vibehack.dev https://vibehack.dev https://airiskassess.com https://compliance.airiskassess.com https://devsecops.vibehack.devGet every episode summarized
Each time CISO Insights: Voices in Cybersecurity publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from CISO Insights: Voices in Cybersecurity

Wear Your Firewall: Gadgets, Gear, and Hacker Culture
CISO Insights: Voices in Cybersecurity

Unlocking the Compliance Stack: AI Drafting, Premium Templates, and Do-It-Yourse...
CISO Insights: Voices in Cybersecurity

CISO DIY: Building the Sovereign AI Security Department
CISO Insights: Voices in Cybersecurity

Beyond the Checkbox: The $12 Billion Fight to Redesign the Teen Internet
CISO Insights: Voices in Cybersecurity