REGISTER NOW FOR THE KONG AGENTIC ERA WORLD TOUR GOVERN A2A TRAFFIC WITH KONG'S NEW AGENT GATEWAY WHY GARTNER’S “CONTEXT MESH” CHANGES EVERYTHING DON’T MISS API + AI SUMMIT 2026 SEPT 30 – OCT 1
  • [Why Kong](/company/why-kong)Why Kong
    • Explore the unified API Platform
        • BUILD APIs
        • [
          Kong Insomnia](/products/kong-insomnia)
          Kong Insomnia
        • [
          API Design](/products/kong-insomnia/api-design)
          API Design
        • [
          API Mocking](/products/kong-insomnia/api-mocking)
          API Mocking
        • [
          API Testing and Debugging](/products/kong-insomnia/api-testing-and-debugging)
          API Testing and Debugging
        • [
          MCP Client](/products/kong-insomnia/mcp-client)
          MCP Client
        • RUN APIs
        • [
          API Gateway](/products/kong-gateway)
          API Gateway
        • [
          Context Mesh](/products/kong-konnect/features/context-mesh)
          Context Mesh
        • [
          AI Gateway](/products/kong-ai-gateway)
          AI Gateway
        • [
          Event Gateway](/products/event-gateway)
          Event Gateway
        • [
          Kubernetes Operator](/products/kong-gateway-operator)
          Kubernetes Operator
        • [
          Service Mesh](/products/kong-mesh)
          Service Mesh
        • [
          Ingress Controller](/products/kong-ingress-controller)
          Ingress Controller
        • [
          Runtime Management](/products/kong-konnect/features/runtime-management)
          Runtime Management
        • DISCOVER APIs
        • [
          Developer Portal](/products/kong-konnect/features/developer-portal)
          Developer Portal
        • [
          Service Catalog](/products/kong-konnect/features/api-service-catalog)
          Service Catalog
        • [
          MCP Registry](/products/mcp-registry)
          MCP Registry
        • GOVERN APIs
        • [
          Metering and Billing](/products/kong-konnect/features/usage-based-metering-and-billing)
          Metering and Billing
        • [
          APIOps and Automation](/products/apiops-automation)
          APIOps and Automation
        • [
          API Observability](/products/kong-konnect/features/api-observability)
          API Observability
        • [Why Kong?](/company/why-kong)Why Kong?
      • CLOUD
      • [Cloud API Gateways](/products/kong-konnect/features/dedicated-cloud-gateways)Cloud API Gateways
      • [Need a self-hosted or hybrid option?](/products/kong-enterprise)Need a self-hosted or hybrid option?
      • COMPARE
      • [Considering AI Gateway alternatives? ](/performance-comparison/ai-gateway-alternatives)Considering AI Gateway alternatives?
      • [Kong vs. Postman](/performance-comparison/kong-vs-postman)Kong vs. Postman
      • [Kong vs. MuleSoft](/performance-comparison/kong-vs-mulesoft)Kong vs. MuleSoft
      • [Kong vs. Apigee](/performance-comparison/kong-vs-apigee)Kong vs. Apigee
      • [Kong vs. IBM](/performance-comparison/ibm-api-connect-vs-kong)Kong vs. IBM
      • GET STARTED
      • [Sign Up for Kong Konnect](/products/kong-konnect/register)Sign Up for Kong Konnect
      • [Documentation](https://developer.konghq.com/)Documentation
      • FOR PLATFORM TEAMS
      • [Developer Platform](/solutions/building-developer-platform)Developer Platform
      • [Kubernetes and Microservices](/solutions/build-on-kubernetes)Kubernetes and Microservices
      • [Observability](/solutions/observability)Observability
      • [Service Mesh Connectivity ](/solutions/service-mesh-connectivity)Service Mesh Connectivity
      • [Kafka Event Streaming](/solutions/kafka-stream-api-management)Kafka Event Streaming
      • FOR EXECUTIVES
      • [AI Connectivity](/ai-connectivity)AI Connectivity
      • [Open Banking](/solutions/open-banking)Open Banking
      • [Legacy Migration](/solutions/legacy-api-management-migration)Legacy Migration
      • [Platform Cost Reduction](/solutions/api-platform-consolidation)Platform Cost Reduction
      • [Kafka Cost Optimization](/solutions/reduce-kafka-cost)Kafka Cost Optimization
      • [API Monetization](/solutions/api-monetization)API Monetization
      • [AI Monetization](/solutions/ai-monetization)AI Monetization
      • [AI FinOps](/solutions/ai-cost-governance-finops)AI FinOps
      • FOR AI TEAMS
      • [Agent Gateway](/agent-gateway)Agent Gateway
      • [AI Governance](/solutions/ai-governance)AI Governance
      • [AI Security](/solutions/ai-security)AI Security
      • [AI Cost Control](/solutions/ai-cost-optimization-management)AI Cost Control
      • [Agentic Infrastructure](/solutions/agentic-ai-workflows)Agentic Infrastructure
      • [MCP Production](/solutions/mcp-production-and-consumption)MCP Production
      • [MCP Traffic Gateway](/solutions/mcp-governance)MCP Traffic Gateway
      • FOR DEVELOPERS
      • [Mobile App API Development](/solutions/mobile-application-api-development)Mobile App API Development
      • [GenAI App Development](/solutions/power-openai-applications)GenAI App Development
      • [API Gateway for Istio](/solutions/istio-gateway)API Gateway for Istio
      • [Decentralized Load Balancing](/solutions/decentralized-load-balancing)Decentralized Load Balancing
      • BY INDUSTRY
      • [Financial Services](/solutions/financial-services-industry)Financial Services
      • [Healthcare](/solutions/healthcare)Healthcare
      • [Higher Education](/solutions/api-platform-for-education-services)Higher Education
      • [Insurance](/solutions/insurance)Insurance
      • [Manufacturing](/solutions/manufacturing)Manufacturing
      • [Retail](/solutions/retail)Retail
      • [Software & Technology](/solutions/software-and-technology)Software & Technology
      • [Transportation](/solutions/transportation-and-logistics)Transportation
      • [See all Solutions](/solutions)See all Solutions
  • [Pricing](/pricing)Pricing
      • DOCUMENTATION
      • [Kong Konnect](https://developer.konghq.com/konnect/)Kong Konnect
      • [Kong Gateway](https://developer.konghq.com/gateway/)Kong Gateway
      • [Kong Mesh](https://developer.konghq.com/mesh/)Kong Mesh
      • [Kong AI Gateway](https://developer.konghq.com/ai-gateway/)Kong AI Gateway
      • [Kong Event Gateway](https://developer.konghq.com/event-gateway/)Kong Event Gateway
      • [Kong Insomnia](https://developer.konghq.com/insomnia/)Kong Insomnia
      • [Plugin Hub](https://developer.konghq.com/plugins/)Plugin Hub
      • EXPLORE
      • [Blog](/blog)Blog
      • [Learning Center](/blog/learning-center)Learning Center
      • [eBooks](/resources/e-book)eBooks
      • [Reports](/resources/reports)Reports
      • [Demos](/resources/demos)Demos
      • [Customer Stories](/customer-stories)Customer Stories
      • [Videos](/resources/videos)Videos
      • EVENTS
      • [API + AI Summit](/events/conferences/api-ai-summit)API + AI Summit
      • [Agentic Era World Tour](/agentic-era-world-tour)Agentic Era World Tour
      • [Webinars](/events/webinars)Webinars
      • [User Calls](/events/user-calls)User Calls
      • [Workshops](/events/workshops)Workshops
      • [Meetups](/events/meetups)Meetups
      • [See All Events](/events)See All Events
      • FOR DEVELOPERS
      • [Get Started](https://developer.konghq.com/)Get Started
      • [Community](/community)Community
      • [Certification](/academy/certification)Certification
      • [Training](https://education.konghq.com)Training
      • COMPANY
      • [About Us](/company/about-us)About Us
      • [We're Hiring!](/company/careers)We're Hiring!
      • [Press Room](/company/press-room)Press Room
      • [Contact Us](/company/contact-us)Contact Us
      • [Kong Partner Program](/partners)Kong Partner Program
      • [Enterprise Support Portal](https://support.konghq.com/s/)Enterprise Support Portal
      • [Documentation](https://developer.konghq.com/?_gl=1*tphanb*_gcl_au*MTcxNTQ5NjQ0MC4xNzY5Nzg4MDY0LjIwMTI3NzEwOTEuMTc3MzMxODI2MS4xNzczMzE4MjYw*_ga*NDIwMDU4MTU3LjE3Njk3ODgwNjQ.*_ga_4JK9146J1H*czE3NzQwMjg1MjkkbzE4OSRnMCR0MTc3NDAyODUyOSRqNjAkbDAkaDA)Documentation
  • [](/search)
  • [Login](https://cloud.konghq.com/login)Login
  • [Book Demo](/contact-sales)Book Demo
  • [Get Started](/products/kong-konnect/register)Get Started
[Blog](/blog)Blog
  • [AI Gateway](/blog/tag/ai-gateway)AI Gateway
  • [AI Security](/blog/tag/ai-security)AI Security
  • [AIOps](/blog/tag/aiops)AIOps
  • [API Security](/blog/tag/api-security)API Security
  • [API Gateway](/blog/tag/api-gateway)API Gateway
|
    • [API Management](/blog/tag/api-management)API Management
    • [API Development](/blog/tag/api-development)API Development
    • [API Design](/blog/tag/api-design)API Design
    • [Automation](/blog/tag/automation)Automation
    • [Service Mesh](/blog/tag/service-mesh)Service Mesh
    • [Insomnia](/blog/tag/insomnia)Insomnia
    • [Event Gateway](/blog/tag/event-gateway)Event Gateway
    • [View All Blogs](/blog/page/1)View All Blogs
We're Entering the Age of AI Connectivity [Read more](/blog/news/the-age-of-ai-connectivity)Read moreProducts & Agents:
    • [Kong AI Gateway](/products/kong-ai-gateway)Kong AI Gateway
    • [Kong API Gateway](/products/kong-gateway)Kong API Gateway
    • [Kong Event Gateway](/products/event-gateway)Kong Event Gateway
    • [Kong Metering & Billing](/products/usage-based-metering-and-billing)Kong Metering & Billing
    • [Kong Insomnia](/products/kong-insomnia)Kong Insomnia
    • [Kong Konnect](/products/kong-konnect)Kong Konnect
  • [Documentation](https://developer.konghq.com)Documentation
  • [Book Demo](/contact-sales)Book Demo
  1. Home
  2. Blog
  3. Enterprise
  4. API Infrastructure is Mission Critical — and Increasingly Under Attack
[Enterprise](/blog/enterprise)Enterprise
July 27, 2023
4 min read

# API Infrastructure is Mission Critical — and Increasingly Under Attack

Kong

### *Attacks estimated to surge 996% by 2030 — with the cost per breach rising to $14.5 million*

[APIs](https://konghq.com/blog/learning-center/what-is-api)APIs have revolutionized every industry. They fuel digital transformation and power the web, making up more than 83% of global internet traffic. And API adoption will only grow, with AI, [Web3](https://konghq.com/blog/engineering/web3-basics-for-frontend-developers)Web3, and [decentralization](https://konghq.com/blog/engineering/web3-basics-what-is-decentralization)decentralization only further driving API usage and integration.

But these sometimes-overlooked enablers of connectivity and communication present a serious security challenge: APIs are increasingly in the crosshairs of cyber-attackers.

In this post, we'll look at the rising number (and cost) of API-related security incidents, and why APIs should be considered mission-critical infrastructure.

## APIs are a leading attack vector

Gartner previously predicted that APIs were becoming the leading attack vector for web applications. And the headlines tell a similar story — with API-led cyberattacks leading to data breaches, customer data leaks, and lawsuits around the world.

  • - In Australia, the Optus breach impacted 40% of the country's populace and sparked government scrutiny of data security and management practices. Two weeks later, Telstra Health fell victim to an API-related hack.
  • - In the U.S., cyberattacks disrupted the critical infrastructure of one of the largest oil pipelines, leading the White House to release an executive order mandating zero-trust security for organizations with significant national security relevance.

## The rise of API attacks

In the Kong eBook [Leading Digital Transformation: Best Practices for Becoming a Secure API-First Company](https://konghq.com/resources/e-book/become-api-first-company)Leading Digital Transformation: Best Practices for Becoming a Secure API-First Company, we worked with Kong data analysts and outside economists to develop research to get a better look at the risk around poorly managed APIs in the coming years.

Some highlights of the research are below.

### **A surge of API attacks is predicted over the next decade**

Between 2021 and 2030, we project a surge of 996% in API attacks. This signifies an explosion in the frequency and severity of API-related cyber threats. An average annual increase of 31% in API attacks over this decade is projected.

[](https://kongwp.imgix.net/wp-content/uploads/2023/07/Growth-of-API-Attacks-Chart.png?auto=compress%2Cformat)

### **The cost of breaches to increase 95% by 2030 **

Not only will we see more API attacks, but we will see the cost of these attacks continue to grow as well. Today, the average cost for a security breach stands at $6.1 million, which accounts for remediation and lost value associated with damage to reputation.

Estimates in our study show that these costs are on an upward trend, and are predicted to increase 95% higher — to $14.5 million per breach — by 2030.

[](https://kongwp.imgix.net/wp-content/uploads/2023/07/Cost-of-Breaches-Chart.png?auto=compress%2Cformat)

### **U.S. attacks to cost $506 billion this decade **

In the United States alone, the economic cost of attacks is currently $10.6 billion per year. Our research projects the national cost to reach $198 billion within seven years, amounting to a cumulative cost of $506 billion this decade.

[](https://kongwp.imgix.net/wp-content/uploads/2023/07/Economic-Cost-of-Attacks-in-the-US-Chart.png?auto=compress%2Cformat)

## Are APIs really mission critical infrastructure?

So, are APIs really mission critical infrastructure?

Consider this: APIs are at the heart of everything an organization does and essential to every modern user experience — from user interfaces that delight customers to global partner networks that expand markets and drive revenue.

With this in mind, there's no doubt that APIs constitute mission critical infrastructure.

But even when APIs *are* recognized as mission critical, their infrastructure is often not accorded the same importance. This can lead to situations where attackers can identify and exploit discrepancies in API management and security, gaining system access and inflicting damage on enterprises and their customers.

*Technology leaders are expecting to build more APIs in the next five years, than all the APIs built until now. Are we prepared to manage this scale?*

This inconsistency often stems from a well-intentioned but problematic decision: distributing API infrastructure ownership across multiple teams.

This approach aims to promote speed and autonomy, but it unintentionally triggers a chain reaction of adverse issues affecting internal systems and controls.

In practice, we can enable teams to move fast and take ownership of operational policies applied to the underlying API infrastructure *without* disseminating core infrastructure ownership. The ideal objective? To have teams act as "users" of API infrastructure — not "builders."

This becomes even more crucial when the organization is a national security asset — such as financial institutions or telecommunication companies — when API infrastructure should comply with the same rigorous standards and regulatory mandates as other corporate and operating functions. Regrettably, this compliance often falls short when infrastructure ownership is spread across teams.

## How to build robust, reliable API infrastructure

Building a robust and reliable API infrastructure requires the establishment of an internal playbook that enables us to:

  • - **Adopt **[**consistent API controls**](https://konghq.com/blog/engineering/consistent-controls-api-security)**consistent API controls**** across teams**: Develop unified, robust, and secure API infrastructure that minimizes inconsistencies in API policy creation and enforcement.
  • - [**Enforce API security**](https://konghq.com/blog/engineering/layered-security-for-managing-apis])**Enforce API security**** by default:** Ensure security controls are in place across all teams and workflows, clarifying the organization-wide responsibility for API infrastructure.
  • - **Foster speed and self-service**: Encourage teams to innovate within an agile, self-service environment without compromising on consistency, security, or corporate responsibility.
  • - **Promote accountability and responsibility**: Cultivate a culture of API accountability, mirroring the responsibility inherent in other organizational areas. There must always be clear ownership of API infrastructure, with accountability upheld consistently.

The ultimate goal? To maintain continuous control over the API infrastructure that drives our organization’s present and future. This *can* be achieved responsibly, ensuring that teams remain productive and agile. But without the right practices in place, an organization’s ability to scale and expand its API portfolio is reduced — potentially exacerbating problems over time.

For a deep dive into each of these areas and a walkthrough of how to build a framework for establishing modern API practices within your organization, download the Kong eBook [Leading Digital Transformation: Best Practices for Becoming a Secure API-First Company](https://konghq.com/resources/e-book/become-api-first-company)Leading Digital Transformation: Best Practices for Becoming a Secure API-First Company.

### Conclusion

Most organizations today grasp the importance of APIs, but too few fully recognize that APIs *absolutely *constitute mission critical infrastructure that demands the appropriate management. As seen with recent API cyberattacks, insufficiently secured and managed APIs can result in severe damage to an organizations reputation and harm to customers.

## Developer agility meets compliance and security. Discover how Kong can help you become an API-first company.

[Get a Demo](/contact-sales)Get a Demo[Start for Free](/products/kong-konnect/register)Start for Free
- [API Security](/blog/tag/api-security)API Security- [API Management](/blog/tag/api-management)API Management- [Thought Leadership](/blog/tag/thought-leadership)Thought Leadership

## More on this topic

_Reports_

## Gartner® | How to Integrate AI Agents With Your Enterprise Applications

_eBooks_

## API Product Management Guide: Strategy, Lifecycle & Best Practices

## See Kong in action

Accelerate deployments, reduce vulnerabilities, and gain real-time visibility. 

[Get a Demo](/contact-sales)Get a Demo
**Topics**
- [API Security](/blog/tag/api-security)API Security- [API Management](/blog/tag/api-management)API Management- [Thought Leadership](/blog/tag/thought-leadership)Thought Leadership
Kong

Recommended posts

# The Enterprise API Strategy Cookbook: 8 Ingredients for Legacy Modernization

[Enterprise](/blog)EnterpriseFebruary 3, 2026

This is the pitch to the board and the C-suite. It must be brutally concise, focused entirely on your business outcomes, not the technology. If the first page doesn't articulate value, the strategy dies. Why? It immediately frames the initiative in

Steve Roberts
[](https://konghq.com/blog/enterprise/enterprise-api-strategy-legacy-modernization)

# Merge API Management & Identity to Unlock Your API Platform's Potential

[Enterprise](/blog)EnterpriseOctober 7, 2025

The challenge: A disconnected world Consider the typical enterprise architecture in a relatively mature organization, an API management layer defines and deploys services to an API gateway, an Identity Provider (IDP) manages human user identities, a

Dan Temkin
[](https://konghq.com/blog/enterprise/api-management-and-identity)

# Enable Enterprise-Wide Agentic Access to APIs

[Enterprise](/blog)EnterpriseOctober 3, 2025

Feed Agents (and humans, too) with *all* of your APIs While multi-gateway vendor deployments have been found to be lacking as a long-term strategy, the reality is that every large organization is — at some point — going to struggle with trying to wr

Alex Drag
[](https://konghq.com/blog/enterprise/enable-enterprise-wide-agentic-access-to-apis)

# You Might Be Doing API-First Wrong, New Analyst Research Suggests

[Enterprise](/blog)EnterpriseSeptember 3, 2025

Ever feel like you're fighting an uphill battle with your API strategy? You're building APIs faster than ever, but somehow everything feels harder. Wasn’t  API-first  supposed to make all this easier?  Well, you're not alone. And now industry analys

Heather Halenbeck
[](https://konghq.com/blog/enterprise/you-might-be-doing-api-first-wrong)

# Four Essential Best Practices for API Management in 2025

[Enterprise](/blog)EnterpriseNovember 1, 2024

The proper management of APIs is vital for organizations seeking to optimize their digital experiences and application performance. API management solutions facilitate the efficient administration of APIs by offering several features such as acces

Axandria Shepard
[](https://konghq.com/blog/enterprise/best-practices-for-api-management)

# The Critical Role of API Security in the Internet of Things (IoT)

[Enterprise](/blog)EnterpriseAugust 1, 2024

From smart homes to wearable devices to connected cars, the Internet of Things (IoT) is bringing about a new era of hyper-connectivity. Experts expect investments in the IoT ecosystem to rise above $1 trillion in 2026 — with no signs of slowing do

Kong
[](https://konghq.com/blog/enterprise/iot-api-security-guide)

# Building a Modern API Platform: Key Principles and Benefits

[Enterprise](/blog)EnterpriseNovember 9, 2023

APIs have become a crucial part of modern software architecture, allowing different applications and services to communicate with each other. As organizations adopt microservices and distribute their systems, they require a cohesive API platform to

Greg Peranich
[](https://konghq.com/blog/enterprise/modern-api-platform-principles)

## Ready to see Kong in action?

Get a personalized walkthrough of Kong's platform tailored to your architecture, use cases, and scale requirements.

[Get a Demo](/contact-sales)Get a Demo

## step-0

  • ## Company

    • [About Kong](/company/about-us)About Kong
    • [Customers](/customer-stories)Customers
    • [Careers](/company/careers)Careers
    • [Press](/company/press-room)Press
    • [Events](/events)Events
    • [Contact](/company/contact-us)Contact
    • [Pricing](/pricing)Pricing
      • Terms
      • Privacy
      • Trust and Compliance
  • ## Platform

    • [Kong AI Gateway](/products/kong-ai-gateway)Kong AI Gateway
    • [Kong Konnect](/products/kong-konnect)Kong Konnect
    • [Kong Gateway](/products/kong-gateway)Kong Gateway
    • [Kong Event Gateway](/products/event-gateway)Kong Event Gateway
    • [Kong Insomnia](/products/kong-insomnia)Kong Insomnia
    • [Documentation](https://developer.konghq.com)Documentation
    • [Book Demo](/contact-sales)Book Demo
  • ## Compare

    • [AI Gateway Alternatives](/performance-comparison/ai-gateway-alternatives)AI Gateway Alternatives
    • [Kong vs Apigee](/performance-comparison/kong-vs-apigee)Kong vs Apigee
    • [Kong vs IBM](/performance-comparison/ibm-api-connect-vs-kong)Kong vs IBM
    • [Kong vs Postman](/performance-comparison/kong-vs-postman)Kong vs Postman
    • [Kong vs Mulesoft](/performance-comparison/kong-vs-mulesoft)Kong vs Mulesoft
  • ## Explore More

    • [Open Banking API Solutions](/solutions/open-banking)Open Banking API Solutions
    • [API Governance Solutions](/solutions/api-governance)API Governance Solutions
    • [Istio API Gateway Integration](/solutions/istio-gateway)Istio API Gateway Integration
    • [Kubernetes API Management](/solutions/build-on-kubernetes)Kubernetes API Management
    • [API Gateway: Build vs Buy](/campaign/secure-api-scalability)API Gateway: Build vs Buy
    • [Kong vs Apigee](/performance-comparison/kong-vs-apigee)Kong vs Apigee
  • ## Open Source

    • [Kong Gateway](https://developer.konghq.com/gateway/install/)Kong Gateway
    • [Kuma](https://kuma.io/)Kuma
    • [Insomnia](https://insomnia.rest/)Insomnia
    • [Kong Community](/community)Kong Community

Kong enables the connectivity layer for the agentic era – securely connecting, governing, and monetizing APIs and AI tokens across any model or cloud.

  • English
  • Japanese
  • Frenchcoming soon
  • Spanishcoming soon
  • Germancoming soon
© Kong Inc. 2026
Interaction mode