Course · Training · Workshop
API Security
Two-day course on developing and operating APIs securely: spot vulnerabilities from the OWASP API Security Top 10, ward off attacks, and apply security best practices.
APIs connect applications, systems, and services, making them indispensable for successful digitalization. However, their growing importance also increases the risk of security incidents. In our “API Security” course, you’ll gain the knowledge needed to protect your APIs from common attacks and maintain the integrity of your systems. Learn hands-on how to implement security measures and adhere to standards such as the OWASP API Security Top 10.
Trainers
What participants say






These customers booked courses in the same topic cluster.More customers →
Content
Day 1: API Security Fundamentals & Top 4 Risks
- Introduction to APIs
- Simplifying Cybersecurity: Core Principles
- Introduction to API Security
- OWASP API Security Top 10 (2023) Overview
- APISEC-1: Broken Object Level Authorization
- APISEC-2: Broken Authentication
- Authentication & Authorization
- APISEC-3: Broken Object Property Level Authorization
- APISEC-4: Unrestricted Resource Consumption
Day 2: Advanced API Security & Top 6 Risks
- APISEC-5: Broken Function Level Authorization
- User Management
- APISEC-6: Unrestricted Access to Sensitive Business Flows
- APISEC-7: Server Side Request Forgery
- APISEC-8: Security Misconfiguration
- APISEC-9: Improper Inventory Management
- APISEC-10: Unsafe Consumption of APIs
- Threat Modeling for APIs
- API Security Testing & Monitoring
We will focus on deepening and understanding a specific selection of topics.
The actual course content may differ from the above depending on the trainer, delivery, duration and the composition of participants.
Request this course in-house
Request a public date
No suitable public date? Register without obligation — once there is enough interest we schedule a new public date and let you know first.
More about API Security
APIs are the nervous system of modern digital infrastructures and at the same time a preferred attack target for cybercriminals. The OWASP API Security Top 10 provides a structured overview of the most critical vulnerabilities in APIs – from broken authentication and unrestricted resource consumption to server-side request forgery. A solid understanding of these risks is essential for developing and operating robust and secure API landscapes.Further resources:
History
APIs have existed since the early days of computing, but it was not until the rise of Web 2.0 and REST architectures in the 2000s that they moved to the center of modern application development. The OWASP Foundation published the API Security Top 10 for the first time in 2019 in response to the growing threat landscape for APIs – a milestone that raised industry awareness of API-specific security risks. A comprehensively revised edition followed in 2023, incorporating new attack patterns such as Unrestricted Resource Consumption and Server-Side Request Forgery.
High-profile API security incidents – including the Peloton data leak (2021) and the attack on Australian telecommunications provider Optus (2022) – demonstrated that missing or inadequate API security can lead to massive data breaches and reputational damage. Today, API security is one of the most important disciplines in DevSecOps processes, and tools for automated API security testing are an integral part of modern CI/CD pipelines.
