CISOs shift from perimeter security to API security

Bill Doerrfeld | March 30, 2026

My first-ever contribution to CSO Online looks at the shifting landscape, from perimeter-based security to API security, and how CISOs are responding.

API attacks are on the rise. But traditional security approaches like endpoint detection and response (EDR) can miss this vector entirely.


Excited to share my first-ever contribution to CSO Online today, which looks at the shifting landscape, from endpoint security to API security, and how CISOs are responding. You can read it here.


In a nutshell, malicious traffic may look like normal traffic, but legacy perimeter-based defenses miss business logic gaps and systemic authentication and authorization issues.


To respond, CISOs are using a combination of API governance frameworks, inventory management, API gateways, strong identity and authorization, and other techniques.


I'd love to write more for this publication, but it takes connecting with the right sources. If you're a CISO or work with one and have an interesting perspective to share, feel free to get in touch.

Read: APIs are the new perimeter: Here’s how CISOs are securing them

Other Blog Posts

By Bill Doerrfeld • September 15, 2026
Does your agent really need access to every tool call under the sun?
By Bill Doerrfeld • September 8, 2026
I'll be writing a weekly series for The New Stack this fall covering Kubernetes, cloud native, and everything happening on the road to KubeCon in November.
By Bill Doerrfeld • September 1, 2026
I'm teaming up with Dan Barahona and AI Security University to put together the MCP Security Conference, a free half-day virtual event dedicated to MCP security .
By Bill Doerrfeld • August 27, 2026
My latest DirectorPlus edition interviews Shopify's head of engineering, Farhan Thawar, on their unique internal engineering culture.
By Bill Doerrfeld • August 24, 2026
Neoclouds promise cheaper GPUs and AI-optimized infrastructure, but can they really challenge hyperscalers? My feature on InfoWorld explores their advantages, risks, and likely role in AI compute.
By Bill Doerrfeld • July 29, 2026
My latest for LeadDev interviews IBM's Neel Sundaresan on how to prevent a decades-old issue in software engineering.
By Bill Doerrfeld • July 13, 2026
The latest advancement in identity and access management (IAM) is something called zero standing privilege. It's a response to new agentic AI risks.
By Bill Doerrfeld • July 7, 2026
Big surprise: it's way easier to generate new code with AI than to reuse old code. But what are the long-term effects?
By Bill Doerrfeld • June 25, 2026
Agentic coding tools have become the default. "When we've taken that away accidentally from people, they scream."
By Bill Doerrfeld • June 17, 2026
My latest for LeadDev considers how engineering leaders should respond in the wake of uncertainty in the AI model market.