Berkshire Bank Banks on Salt for API Protection

June 03, 2022

Berkshire Bank Banks on Salt for API Protection

It’s cool to win banks as customers – it’s even more cool when they go public with the news!

We’re proud to share this news, given how essential security is to financial institutions. The combination of working under extensive regulations and the criticality of protecting customers’ sensitive financial data sets the bar for security pretty high.

I especially enjoyed my conversation with Ryan Melle, SVP and CISO at Berkshire Bank. He’s a pragmatist, and he gets things done quickly. As with so many banks, Berkshire Bank is leveraging APIs to build a broader ecosystem with FinTechs and innovate fast. This skyrocketing use of APIs comes with a price.

“We’re seeing an increase in the number of API transactions, but we’re also seeing an increase in API attacks. We have to keep our data secure and our regulators happy, and we can’t get in the way of digital transformation – Salt fits right into that,” said Melle.

Because traditional solutions, such as web application firewalls (WAFs) and API gateways, lack the ability to correlate API activity over time, they can’t adequately protect this expanding attack surface. Bad actors have to probe APIs to understand the business logic and look for vulnerabilities. This reconnaissance means API attacks are  low and slow, and API security solutions must be able to spot this behavior as it occurs and before the bad actors achieve their targets.

Just as WAFs can’t correlate traffic over time, VM- or server-based API security solutions also fall short, lacking the scope of data and real-time analysis needed to build context to spot API attacks. Only cloud-scale big data, with sophisticated ML and AI doing real-time analysis yields the context needed to identify API attacks, which often unfold over days, weeks, and even months.

Berkshire Bank is tapping the Salt Security patented API Context Engine (ACE) architecture to get a full inventory of its APIs, perform API design analysis, ensure data protection by evaluating all traffic leaving the bank, and deliver runtime protection to stop API attacks.

According to Ryan,

“We considered other solutions, but they didn’t provide the range of capabilities we needed – we found the Salt architecture to be unique. The Salt system got stood up in a day, so it’s been simple operationally too.”

With Salt Security, Berkshire Bank can protect its APIs from account takeover (ATO) and ensure the safety of their services. Read more about how Berkshire Bank uses the Salt API security platform in this case study.

We love creating joint customer success stories like this one. How can we help you make your APIs attack proof and accelerate innovation? Feel free to contact us or request a customized demo.

‍https://salt.security/blog/berkshire-bank-banks-on-salt-for-api-protection



Also in News

MARKET UPDATE-24TH APRIL 2024
MARKET UPDATE-24TH APRIL 2024

April 24, 2024

In Australian economic and market news this week, new data show that unemployment is holding fairly steady. The latest figures reveal that unemployment rate rose by 0.1 percentage points to 3.8 per cent in March.
MARKET UPDATE-17TH APRIL 2024
MARKET UPDATE-17TH APRIL 2024

April 17, 2024

New data on inflation in the United States was stronger than expected for the third month in a row. Pressures on the cost of fuel and rents pushed overall consumer prices up by 0.4 per cent in March, and by 3.5 per cent over the year (up from 3.2 per cent in February). 
MARKET UPDATE-10TH APRIL 2024
MARKET UPDATE-10TH APRIL 2024

April 10, 2024

In recent weeks economic and market discussion has moved to a greater acceptance that monetary policy settings in the developed world, including Australia, may not loosen anytime soon.