Effective API protection demands more than perimeter controls but understanding which API protections to put where is a puzzle most organizations get wrong. Relying on a security team to provide all answers will slow down the delivery of services. Software engineering leaders are being asked to do more than ever before with less. To understand how to protect APIs, start with threats and attack vectors. This session will explore API security from the attacker’s point of view.