中文

Traceable AI Responds to FFIEC's Latest Compliance Guidelines, Strengthening API Security for Financial Institutions

On January 10, 2023, Traceable AI announced it will help FDIC-insured financial institutions meet the FFIEC's latest cybersecurity compliance requirements. The FFIEC updated its guidelines in October 2022, explicitly listing APIs as an independent attack surface and requiring financial institutions to inventory and conduct risk assessments of APIs. Traceable provides features such as API discovery, risk scoring, sensitive data flow monitoring, and automated consistency scanning, and supports on-premises, SaaS, or cloud deployment.

2026-09-0122views
Traceable AI Responds to FFIEC's Latest Compliance Guidelines, Strengthening API Security for Financial Institutions

San Francisco, January 10, 2023 — Traceable, the industry-leading API security and observability company, today announced it is providing the necessary API security measures to help FDIC-insured financial institutions meet the latest cybersecurity compliance requirements from the Federal Financial Institutions Examination Council (FFIEC).

On October 3, 2022, the FFIEC announced significant updates to cybersecurity requirements for financial institutions. For the first time, this update explicitly identifies APIs as a separate attack surface in regulatory guidance, marking a major shift in the compliance path and highlighting the growing threat of APIs. The FFIEC specifically developed these new guidelines to require financial institutions to include APIs in their overall information system inventory and risk assessments. For example, banks use APIs in digital banking services and information system access points, which makes data sharing more convenient and improves the customer banking experience. However, as a primary attack vector, APIs can be compromised within seconds if not carefully identified and protected, putting sensitive data of enterprises and their customers at significant risk.

"This will be the year of reckoning for financial institutions. With an average of three customer-facing API connections per bank, now is the time to understand your APIs and take immediate action to protect data and customers," said Richard Bird, Chief Security Officer at Traceable. "We have been working with large financial institutions to assess their APIs, helping them gain a comprehensive understanding of their threat landscape. Most organizations are shocked by the assessment results. This initial shock undoubtedly drives them to fully understand their API landscape—including existing and legacy, internal and external. With this understanding, they can take immediate action."

APIs have become the primary attack vector for data breaches, and Traceable is working closely with top financial institutions to help them take the first step in securing APIs—as required by the FFIEC. Through its data-rich catalog, Traceable discovers and identifies all APIs—including internal, external, third-party, and partner APIs—providing customers with comprehensive, real-time visibility into the API ecosystem and API sprawl. With Traceable's approach, financial institutions can immediately:

  • Continuously inventory APIs:Instantly identify and catalog all APIs in the environment, including internal, external, third-party, and partner APIs. API types include GraphQL, SOAP, HTTP, RESTful, XML-RPC, JSON-RPC, gRPC, and more.
  • Understand API risk posture:Traceable provides a security risk score for each API, enabling organizations to determine which APIs are most susceptible to abuse by collecting runtime data such as sensitive data flow, API call mapping, API usage behavior, user details, event details, threat activity levels, and more.
  • Identify sensitive data exposure:Because APIs may expose highly sensitive information and transmit this data from internal APIs to third-party applications, it is essential to understand sensitive data flows end-to-end to assess exposure levels.
  • Benefit from automated consistency scanning and analysis:An important part of API discovery and inventory is understanding whether development specifications match the APIs implemented in the production environment.

All of this is achievable through Traceable's flexible data collection and deployment options, including 100% on-premises deployment (air-gapped mode), SaaS deployment, or hosted in your own AWS, GCP, and Azure clouds. Financial institutions can immediately understand their situation through Traceable's free API Security Risk Assessment to better evaluate and understand the risks posed by APIs in their environment. Additionally, Traceable will host a webinar focused on FFIEC requirements. To attend, register here.

###

About Traceable

Traceable is the industry-leading API security platform that identifies APIs, assesses API risk posture, blocks API attacks, and provides deep analysis for threat hunting and forensic research. At its core, the technology is based on visualization of API paths, applying the power of distributed tracing and machine learning models throughout the development lifecycle for API security. Visualization provides insights into user and API behavior to understand anomalies and block API attacks, making organizations more secure and resilient. Learn more at traceable.ai.

{{press_release.company_name}} header image