LIVE · HOW WOULD YOU LIKE TO CONSUME THIS PAGE?
Close
Privacy settings
We use cookies and similar technologies that are necessary to run the website. Additional cookies are only used with your consent. You can consent to our use of cookies by clicking on Agree. For more information on which data is collected and how it is shared with our partners please read our privacy and cookie policy: Cookie policy, Privacy policy
We use cookies to access, analyse and store information such as the characteristics of your device as well as certain personal data (IP addresses, navigation usage, geolocation data or unique identifiers). The processing of your data serves various purposes: Analytics cookies allow us to analyse our performance to offer you a better online experience and evaluate the efficiency of our campaigns. Personalisation cookies give you access to a customised experience of our website with usage-based offers and support. Finally, Advertising cookies are placed by third-party companies processing your data to create audiences lists to deliver targeted ads on social media and the internet. You may freely give, refuse or withdraw your consent at any time using the link provided at the bottom of each page.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
WEBINAR

PT

PT

WAF vs. WAAP. API vs. AI. What Security Tools Do You Actually Need?

A straightforward framework for matching each layer of protection to the problem it actually solves.

‍

Trying to understand vendors in the modern application security space can feel a lot like trying to solve word scramble. Whether it’s remembering what the “A’s” in "WAAP” stand for, figuring out if “WAF” includes APIs, or assessing the actual function of a new AI security product, understanding what tools your team actually needs is getting harder all the time.   

‍

This session brings clarity to four terms that sometimes get used interchangeably: WAF, WAAP, API Security, and AI Security. We'll walk through the gaps that show up when a legacy WAF is asked to do API security's job, when a WAAP vendor's bot report gets mistaken for governance, and when "AI security" turns out to mean three different things depending on who you ask. 

Attendees will leave with a practical framework for auditing their own stack for functionality and a clear view of how to tie web app, API, and AI protection into one loop instead of three or more separate purchases.

‍

You'll learn:

  • Plain-language definitions of WAF, WAAP, API Security, and AI Security
  • The specific limitations of each tool
  • How to self-audit your own stack 
  • How Wallarm's Discover → Observe → Enforce → Govern loop can help you tie your application security together

Thanks for the download. 
Thank you for registering for our webinar, you will receive a confirmation email shortly. We look forward to seeing you soon!
Outlook
Google Calendar
Apple Ical
Outlook.com
Thanks for filling out the form!
The webinar link will open in the new tab. If its not, please follow
this link

Our Speakers

Tim Erlin
VP of Product at Wallarm
Désirée Wilson
Lead Information Security Architect/Consultant, Quantum Mergers
Sue Bergamo
Global CIO & CISO, BTE Partners

Tim Erlin: Okay, that's interesting. Because I think you talked about both, and I see, you know, for example, I, you know, I don't think the need to protect… if you have a, you know, a web application or an API that's, you know, that exists, that's exposed, I don't think the need to have a tool to protect that is going away. Like, you're going to continue to need to block attacks, right? But you may, in the near future, have an agent that manages and runs that tool for you. And that's… that's AI for cybersecurity. Now, at the same time, you are deploying and using AI in your environment, and that creates new interfaces and risks, although most of those end up being APIs one way or another.

now you also might need a tool to protect those models, or to protect, you know, for prompt injection, as an example. And that's cybersecurity for AI. But those are two different objectives, you know, to pursue. Like, you're not gonna get the… you're not gonna accomplish them with the same initiative.

Sue Bergamo: No, no. And again, it goes… for me, it goes back to, what is it that you're trying to do? And I'm gonna make a big leap, and I don't know if this is gonna work, but I'm gonna try it anyway. Way back when. when ERP and CRM, you know, took the world by storm, right? We had this concept of configuration versus customization, right? And everybody said, just configure, you know, all these big companies created you know, these vertical, you know, platforms, right? And then everybody got ahold of them, and they started to customize them. And it went wild, right? How many failures did we have in that… in both of those spaces? Tons of them, right? Because there was no plan.

And I'm seeing the same thing, and this is my leap in the AI space, is that there's no plan. It's not even a strategy. And strategy is the new, horrible term in the industry. You can't say strategy anymore, you have to say roadmap, but if you're not thinking about what you want to do with AI. why is the flag waving? Go. Because you're just wasting time and money. And there was a statistic, gonna get it wrong, but there… I think it was, like. 70% of AI implementations are failing. Sure they are, because you have no visibility, you have no control of your costs, and you don't have any strategy of what you're trying to do.

Tim Erlin: If you don't know what you're trying to accomplish, how can you fail?

Désirée Wilson: Or succeed. Or succeed.

Sue Bergamo: Desiree used to probably have something to say about that.

Tim Erlin: Yeah.

Désirée Wilson: Yeah, it's just… this isn't possible, you know? You're setting yourself up for failure.

Tim Erlin: Yeah, or you're setting yourself up for a negative result. Yeah, I mean, I think you're right. There is definitely a push to sort of, you know, for AI… for the sake of AI, as opposed to having a goal to accomplish. And I think… I feel… I mean, I don't know, tell me, Desiree, if you think this is right or not. If you… if you're deploying AI without a business objective, doesn't that make it incredibly difficult for any CISO or security professional to actually manage risk. Because the risk has to exist in the context of that business objective.

Désirée Wilson: Absolutely, yeah. I mean, you have to know the risk appetite. You have to know what you're trying to achieve, what is your end goal, and in order for you to identify your full attack surface, what are you trying to protect, and what is the ultimate actions being taken? How do you preserve that? What is the business outcome? There's lots of questions you need to be able to answer with any action you take. And, you know, with every action, there's a risk. But if you can't identify these, if you don't ask the question, have an answer for the question, then you cannot actually Secure the ultimate risk, or the many risks that are generated by that activity.

Tim Erlin: Yeah, yeah, yeah. One of the things I worry about… yeah, one of the things I worry about in that context is… Is giving up… well, let's just put it this way. Budget is finite, right? Cybersecurity budget is finite, you don't have an infinite amount, and when we… when we shift budget to AI security without a clear objective, we're now applying budget to risk that we can't actually measure, and taking it away from protecting things that have very clear risks. You know, go back to…

you know, the most common attacks that people see, you know, targeting, you know, targeting APIs, targeting web applications, you know, you could talk about things like SQL injection. SQL injection is not… while it's a solved problem in theory, it's still a very common, successful attack vector, or, what was the one I just saw? Centerpoint Energy, just, had, you know, I think it was… I can't remember the number, but some number of records were compromised through an unauthenticated API endpoint. Like, these are not complicated AI-based

problems, they are pretty straightforward attacks, but they have a material impact on the business. That's a risk that a CISO can actually quantify and protect against. But are we seeing budgets shift to AI security in a way that makes organizations less secure, or… or am I inventing that?

Sue Bergamo: I don't know if you're…

Désirée Wilson: organizations are so broad right now with their budgets. I see requests to bring in one person doing 10 different jobs because they're thinking, well, if you're using AI, you should be able to do them faster and more efficiently. And while in some cases that may be true, none of that support security by itself. Securing the AI, or securing the environment? None of that is… is supportive.

Tim Erlin: Yeah. Sue, you were about to say something there.

Sue Bergamo: Yeah, I will tell you, the CISOs that I'm talking to, I don't want to say it's a 50-50 split, but… A lot of them are saying budgets are flat going into 2027. This is budget planning time right now. So a lot of them are saying it's flat. Some of them are getting an increase specifically for AI. Those organizations may or may not have a strategy, but they have some semblance of a plan to go forward, and so they're getting… they… they know that they have to I want to be careful. I'm not going to say that it's tools or resources, but they're getting some additional funding to help figure all that out.

Tim Erlin: Yeah, yeah. Yeah, I'd say, I mean, it's definitely a challenge, I would agree, I would agree.

Sue Bergamo: I do want to add one other thing, too. the other thing that I hear, and… and I'm… I'm sorry, but this really… this one makes me… Angry? Because I know what's gonna happen in the background, but I hear a lot of CISOs saying that they're being mandated, or asked, you know, eliminate people, because AI can do it better and faster. And I'm sorry, at the end of the day, there needs to be a man in the middle figuring it all out. Or a woman.

Tim Erlin: Well, I mean, that sort of human in the loop, No, I'm thinking about it. Like, I have… I have… I have the same sense of… of… of… of anger you do, I think, about this idea that somehow, you know, you can just eliminate jobs with AI, but at the same time. you know, there… there is the ability… we could talk about automation, right? Automation can be done effectively, and can remove humans from the loop, depending on what the loop is. So I think there's a… Maybe there's a specific type of action that you're thinking about, or type of process where you need that human in the loop, or you think the human in the loop is not gonna go away, maybe, is the way to put it.

Sue Bergamo: Now, I guess the way that I think about it is, you know, every manager, every leader out there, or not even, right? Every individual who's creating some sort of agent. Should be looking at what are the routine things that you can automate, you know, the routine things in your job that can easily be automated with a prompt, right? Do it. Do it. But go on and do better things when you have more time. Because I haven't hit any company at this point in my career that is 100% ready to go, right? Like, we always need something new. So get rid of the mundane, and go off and do bigger, better things, go learn something new, go help your company grow in some other way.

be a hero. But… and that's what AI should be doing, is helping companies become productive and efficient, but not necessarily thinner in the resource aspect. Again, my opinion.

Tim Erlin: Yeah, well, I mean, I think we can apply… we can take that perspective and see how it applies to cybersecurity, right? You know, as we were talking about, having agents that manage your products for you. you know, where do you need a human in the loop for that process? If we talk about, you know, sort of the things that are on the… on the screen, you know, the WAF WAP API security. You know, you can have… you can… you can have agents certainly triage incidents. But probably not make decisions about blocking traffic. Maybe not. You know, traffic blocking can be done automatically already. You could have agents write policy based on what they see in the environment, I would think. That's a pretty reasonable thing to approach.

With, an Agentic piece.

Sue Bergamo: And what you just said calls to mind. So I went to the debrief, on Hugging Face.

Tim Erlin: Yeah.

Sue Bergamo: And at the end of the day, you know, The agent was told. you know, be badass, right? Go off and be the worst hacker ever, right? I mean, that was basically the instruction. And it was human error that made it go off and, you know, go beyond its environment. That wasn't… that wasn't… automation. And what ended up happening is it took a couple of days for that human in the loop to figure out that something was going on, because they went off. the humans went off, and they really weren't monitoring it. There was really no governance guardrails in place. And so, when it takes 2 days to go back and go, oh, oh, something's going on here. that's human error, right? So, in that case, if they really… well, again, my opinion,

that one got a lot of fanfare, right? A lot of misinformation in the industry. But if the engineers had just been looking at it from the moment the prompt went off, right, started, They would have figured out what was going on. Soon.

Tim Erlin: Well, and I think this gets us to this question about where the gaps show up, right? I think as… as human beings… let me ask it as a question. You know, Desiree, do you think that as human beings, we can actually conceptualize the scale Of the problem with… you know, API interactions, AI interactions, because saying something like, you know, if a human had seen that prompt, Is easy to say, but is it possible? Can you have a human in the loop examining prompts?

Désirée Wilson: Well, I think the bigger issue becomes, the massive amount of the data, you know? The data is so massive that that is what makes it hard for a human alone to be the one examining prompts. But you can still have that human oversight in the process. It… just because doing it one way doesn't mean that there's only one way to do it. So, you can create agents that help you examine the prompts. Like, you know, there are many ways of doing it, but as the human, you should… have enough knowledge of your inventory that you've created, or that you've allowed to operate and access the environment. You should know which identities are operating in the environment, and what credentials and permissions those identities have.

So there's… and so that way, when something acts outside of line, you know, when something is doing something it shouldn't, or there's a change in normal behavior. you should also have guardrails in place to identify those changes in behavior. So I think when, you know, we talk about the human in the loop, which I 100% agree, we still need that, that is a necessity, it has to be someone who's able to take that entire huge process and still identify the gaps when something isn't right, the anomalies. We still have to have that ability, and that's even if we're using other tools and technologies to do it.

But we still have to be able to identify that something went wrong, and it shouldn't take us 24, 48 hours later to do that. We need those alerts in place now, and we're the ones deciding what alerts those are. And that's where we are effective as the humans.

Tim Erlin: It's interesting. I find myself trying to draw a parallel, and I'll try and draw it out loud, and see if it goes anywhere. You know, we're talking about AI with prompts, and examining prompts, and, you know, are those prompts good or bad, I'll just say. You know, for… well, defining good or bad is tricky, but good or bad. We have the same challenge with API traffic. In that, you know, there's a large volume of API interactions, and transactions, they can be good or bad. But we don't say we need a human in the loop to examine API requests. We're okay with automating that. Why is it different for AI? Why aren't we pursuing the same end goal of automatic review and validation, you know, of prompts and responses?

Sue Bergamo: So…

Désirée Wilson: AI, where things really change, though, is because we're talking about things acting autonomously, but also starting to think for themselves and make decisions. And that changes things. I mean, with APIs. They're… they are acting autonomously, but it's… they're driven by… a certain level of parameters. And so… but with AI, as we've seen things get out of control, it's when things are acting outside of our expectation, outside of how we directed it to act, and now there's other actors getting involved, and maybe even other agents we didn't consider. And that's where it starts to grow arms and legs and run away from you, because this… you lack control. You completely lose control with AI, whereas I… in my…

in my experience, in my belief, we haven't necessarily lost that control with APIs. Not… it's not the same level as with AI.

Tim Erlin: Yeah, yeah. So, I saw you smile when I drew that parallel. What did you want to say there?

Sue Bergamo: I'm gonna disagree slightly.

Tim Erlin: Okay, with the parallel or with Desiree?

Sue Bergamo: No, with the parallel, so…

Tim Erlin: Okay, okay.

Sue Bergamo: and every engineer out there is going to hate me for my next statement, but I don't know too many engineers that actually try to segment their API traffic based on the data that's actually needed. It's just easier to open the pipe up and let.

Tim Erlin: Yeah. You're absolutely right.

Sue Bergamo: Absolutely right. So, you know, when you… if we go back to the data security, we go back to identity and access privileges, PAM, tokens, service accounts, the lack of rotation, tech debt, like, I could go on and on and on, I do think that API security while it's being monitored today, lost control a long, long, long time ago. So, sorry, engineers, but I do think that it's just a high-level area, or I should say a high-risk area, because it's a huge threat, you know, vector. And it is one of the biggest areas, you know, that we see, you know, being attacked. It's so easy. And then… We throw third-party supply chain management into the mix, and the lack of visibility into the supply chain and what's being shared externally, and it just gets…

even more complex. So, AI, in my opinion. isn't that much different here. And what I'm trying to say to the audience is get control of it before you lose control, because it's got more power. And the more power that it's given, the more data that could be exfiltrated unintentionally.

Tim Erlin: And I think, Desiree… so I agree with you, Sue. Desiree, you were making a point that I… I would rephrase as we… you know, AI is a… a… A non-deterministic system. And so, when you say that it behaves out… might behave outside our expectations, I mean, that's what it's designed to do, actually, is to… is to not behave within a set of specific expectations, whereas an API is built within a set of specific expectations. Now, to Sue's point. you may have a mismatch on the expectations from whoever is designing the product or has, you know, a policy about data sharing, about data, and the people who built the API itself and said, you know what?

I'm not going to include just those two fields from the database, because eventually they're going to ask me for the other five. I'll just give you the whole table and, you know, make the API only return, you know, hide the parameters so that it's not obvious in the documentation. So it's interesting because I think a lot of AI security, it seems like, is trying to take that non-deterministic system and apply external constraints to make it behave more deterministically, or limit the extent of its non-deterministic behavior, might be the way to put it.

Sue Bergamo: You're not wrong. Interesting. Yeah.

Tim Erlin: So, I know, I'm just keeping an eye on the time, and I always… I hate to have these sort of, conversations about problems and challenges and not get to a what you should do about it. Because ultimately, if you're attending this webinar, I'd like you to walk away with an idea of something you can do. And so, you know, we veered off the topics a little bit, but I think I can bring it back with, you know, the point, Sue, you made about understanding the objective. What's your objective?

And one of the things that you as an organization can do, or you as an individual can do, is look at your own technology stack and perform a kind of self-audit. And I know, Sue, that you have some particular advice and experience here. Do you want to jump in and talk about that sort of self-audit process a little bit?

Sue Bergamo: Yeah, I… I, I spend a lot of time in this space helping companies, understand overall, you know, what's in their tech stack. you know, how do you gain visibility into your environment? Where are the gaps? You know, and then how do you plug them up? So… If anyone has, questions in this area, there's a ton of tools out there. At the end of the day, you have to figure out what you can budget for, what tool are you trying to Find to solve what problem you have. You know, ping me on LinkedIn, I can help you through this. But honestly, it's really about understanding what is it that you're trying to do before you just buy something new. Don't just buy something new, think about it.

Tim Erlin: And Desiree, from your perspective, how do you see organizations approaching this challenge of addressing new problems, understanding what tools they have? Do you have advice for how they can audit their own existing tool stack?

Désirée Wilson: Yes, absolutely. Definitely, as Sue has said, know your intent, know what is running, know what you're trying to do. I believe that is our step one with anything we're going to do in this area. We have to know what our intent is from the beginning, and how to achieve it. And then once you have that, then you can actually put the policies and requirements in place so that you are directing your AI, rather than your

your AI directing you, which is, again, that lack of control, which is why that power shift that we've seen with AI, that even the creators can't control, is what makes this a scarier position to be in, and why everyone is kind of up in arms, and we're seeing so much regulation around it, because it is something that is very much out of control. And not that, you know, things we've created in the past haven't been able to be breached? Of course they have. Anything we create, there's… someone's going to figure out a way to overcome it. But that is where I see, in my approach with clients, I create, you know, a constant layer of, say, like, a MITRE atlas, where you're looking at those

attack vectors all the time, and you're looking at how this can be overcome, so that way you're putting those things in place from the beginning. You're considering OWASP and where your weaknesses lie. You're looking at all of these things, so it's not one thing. It's really a collaboration of many different layers of perspectives, but you have to start with where you want to go. what you're doing, why you're doing it, in order to identify how to control those behaviors, what risks are out there. So, it is definitely a layered approach. It's a lot of consideration, and it takes effort from the organization as a whole. This is… this is an enterprise effort. It's not one person or one department, as I mentioned.

It takes effort and commitment to understand and to act accordingly, and that is what I do with clients all the time in all areas of cybersecurity, but especially now that we're adding AI onto it. It's not one thing. If you have cybersecurity, you have AI security, so that's, Ludicrous, basically. No, you need both. You need them all.

Tim Erlin: Yeah, makes sense, makes sense. So, I'm gonna remind everybody that you can ask questions, so if you have questions, now is a good time to put them into the Q&A, and we'll see if we can take a few minutes to answer the ones we can. And while I give you an opportunity to do that, I'm just gonna talk a little bit about one slide of WallArm and what we do, in case you're not familiar.

So, WallArm, is a… provides a tool for API and AI security, WAP included. I know we didn't dive into those definitions too… too… in too much detail, but, we can break that down into sort of four key pillars, as we call them. So, the first is to understand what's running in your environment. We talked a little bit about that need to understand what's out there. That includes finding the APIs and AI systems. agents, models, and integrations, that are existing in your environment so that you know what's running out there. Giving you the ability to understand what they're doing, to see the activity, whether it's API sessions, or MCP sessions, or AI interactions that are occurring, is the second pillar. That's the observed pillar.

Giving you the ability to enforce and control behavior, so blocking attacks, blocking specific types of behavior, enforcing, behavior for agents in terms of what other tools they're allowed to interact with. is part of that enforce, enforce pillar. And then, you know, demonstrating that control with, governance or that govern pillar, that's reporting and evidence and the ability to show, show your work, so to speak, is all part of what, WallArm offers. So, with that, let's take a look at the questions that we have. In the Q&A. If I can open it… there it is.

Annette Reed: Yeah, Sue, you have a fan, that I will make sure you get their email address. They would love to connect with you afterwards to, have more conversations, so I will make sure that, is shared with you. And then Tim, I definitely… a lot of questions I'm seeing are around, you know, observability tools that are recommended for AI agents, so… Maybe you can go a little bit further into, I think, some of what Walmart does that can, provide solutions.

Tim Erlin: Sure. Well, I want to address one specific question in there, which is… because we talked a little bit about Agentic pen testing, and, I think the question here is… I mentioned Agentic pen testing and then the OWASP top 10 for agents. Is it actually possible, are there tools out there today that can actually test for, that full OWASP top 10, or are we really sort of at the beginning of that, you know, that industry, if you will? Is it developing?

Sue Bergamo: There are tools out there. There are. I don't want to name names, but if anyone's interested, ping me. I know of one very specifically that's in this space. Nice tool. And also, has a great mythos play in the back of it, because it's doing the same thing. Not just pen testing for pen testing, but, you know, looking at real vulnerabilities. So, yeah, they're out there. Yeah. And the market, again, is just getting broader and bigger as we speak.

Tim Erlin: No. I've got… thank you, Sue. I've got another question here that's specifically about WallArm, so I'm happy to answer that one. Does WallArm use client scanners or other retriever? So, WallArms, the product that we've had in market for a long time, for WAP and API security is primarily based around traffic analysis, so the, the… Standard sort of deployment is what we would call a filtering node. There are lots of different ways to deploy that, but its goal is to see traffic, and then do analysis on that traffic. The AI security tool that we've introduced called AI Hypervisor is built around an eBPF

model and a proprietary memory scanner, actually. That deployment is a little bit different, and it addresses sort of a different slice of the problem. It's targeted at production-deployed AI applications. So not desktop agent, but, you know, sort of if you're… if you're running an AI-based application in AWS, as an example, that would be what that does. So, that's the question there. And then I think there's one additional question, that we can probably answer, which is, It's fairly simple, I hope. Can you explain the difference between WAP and WAP? I'm happy to answer that, but Sue or Desiree, if you want to take a shot at it, feel free.

Sue Bergamo: I'll let Desiree answer that one. I've done a lot of talking today.

Désirée Wilson: I'll let you answer that.

Tim Erlin: Well, I'll answer it if you like.

Sue Bergamo: No, go ahead, I mean, I can, but go ahead, Tim.

Tim Erlin: Well, so, WAF stands for Web Application Firewall. That is sort of the traditional, web application tool that, that, sort of started the… the market, if you will. WAP is kind of the evolution of that to web application and API protection. So, as more and more developers were building APIs, WAP sort of evolved to also include some API protection, understanding API protocols. And some of the industry has shifted from WAP to WAP, or WAAP, although some of the industry is hanging on to WAF. So the distinction is actually, I said it was a simple question. It's actually not a simple answer, because some people say WAF and they mean they mean to include APIs, and some don't. But that's the intended distinction in any case.

So with that, I know we're at the end of our time. I want to thank Sue and Desiree for their participation. I thought it was an interesting conversation, super interesting, hopefully educational for the folks who attended. So, thank you so much for spending time with us, and hopefully we'll see you at the next webinar. Thank you, Sue. Thank you, Desiree.

Désirée Wilson: Thank you.

Sue Bergamo: Tim, I had fun.

Our Speakers

Tim Erlin
VP of Product at Wallarm
Désirée Wilson
Lead Information Security Architect/Consultant, Quantum Mergers
Sue Bergamo
Global CIO & CISO, BTE Partners
Trusted By

The world's most demanding teams run on Wallarm.