Wallarm announced the introduction of the industry’s first-ever API Revenue Protection capability, setting a new standard for aligning API security with business impact. Delivered as a set of integrated features in the Wallarm platform, this new capability empowers CISOs to become strategic business partners by quantifying how attacks impact revenue, disrupting attacker economics, and demonstrating financial ROI.
From AI-generated abuse to account takeovers and business logic exploits, API threats are evolving faster than signatures can keep up. At the same time, organizations rely on digital revenues enabled through APIs, such as payment processing and partner integrations. Downtime or compromise of these API endpoints can result in immediate, costly consequences.
Powered by agentic AI and transaction-aware telemetry to track revenue flows and shut down fraud in-session before attackers win, Wallarm’s new capability ensures continuous availability through protection of revenue-generating APIs, shielding them from the most sophisticated threats while providing visibility into the actual dollars at risk and protected.
Key features and benefits include:
- Automated Identification of Revenue-Critical APIs: Automatically detects which APIs contribute to revenue based on traffic patterns, monetization logic, and integration context.
- Transaction-Aware Revenue Attribution: Extracts revenue amounts directly from API transactions, such as order values, subscription events, or payment confirmations, to provide real-time financial insight using the actual revenue flowing through APIs.
- Advanced Threat Protection for High-Value Endpoints: Delivers effective, real-time mitigation of attacks, protecting revenue-generating APIs from OWASP Business Logic Abuse Top 10, account takeover (ATO) attacks, data scraping and credential stuffing, agentic AI-driven attacks, and business logic anomalies that can lead to fraud or service abuse.
- Business Context-Aware Detection and Response: Adapts in real time to evolving threat patterns while maintaining API availability and user experience by analyzing the full business logic and transaction flows behind each API.
- Purpose-Built Revenue Protection Dashboard: Quantifies protected revenue, highlights attack trends targeting monetized APIs, and helps security leaders communicate their value to executive stakeholders.
Security teams can now quantify how much revenue has been protected and shift the conversation from reactive risk mitigation to proactive value creation. For digital-first enterprises, they can now measure a new security metric: Revenue Secured Per Dollar Spent.
Wallarm’s Revenue Protection for APIs will be demonstrated at Black Hat USA 2025 in Las Vegas, is available for Early Access, and will be generally available in the second half of 2025.
For more information, visit https://www.wallarm.com/product/api-security-overview.
Xona announces the general availability of Xona Platform v5.4.2
Posted in Commentary with tags Xona on August 5, 2025 by itnerdXona today announced the general availability of Xona Platform v5.4.2, a major update that extends centralized control, unified policy enforcement, and scalable auditability across globally distributed operational environments.
Building on its proven foundation of secure, zero-trust access for OT, IT, and hybrid networks, Xona’s v5.4.2 release introduces new Xona Centralizer management features to extend existing enterprise-grade visibility and control across multiple Xona deployments. Combined with cross-gateway access groups, expanded identity provider support, and enhanced session governance, the release equips critical infrastructure organizations to scale secure access—without adding complexity or risk.
Platform Enhancements in v5.4.2
The Xona Platform v5.4.2 introduces key capabilities for managing secure access in complex, multi-site environments:
Scaling Secure Access for the Modern CI Enterprise
As critical infrastructure organizations expand operations across regions and third-party ecosystems, the need for secure, scalable access control is more urgent than ever. According to recent industry data, more than 88% of industrial organizations cite insecure remote access as a top cyber risk, while ransomware attacks on OT environments have surged over 80% year-over-year.
Xona’s v5.4.2 release directly addresses these trends, helping customers:
Trusted by Industry Leaders
Leading organizations across multiple industries trust Xona’s platform. Global giants such as GE, Baker Hughes, and Mitsubishi Corporation have adopted Xona’s secure access solutions to protect their critical infrastructure.
One of Xona’s long-standing customers in the power generation sector commented, “Xona has allowed our lean IT team to manage and troubleshoot issues remotely across all our sites. This has reduced the need for costly on-site visits and improved our overall operational efficiency.”
Why Xona Matters in Today’s Market
As critical infrastructure industries face increasing digital threats and navigate an evolving regulatory landscape, secure, simple access solutions like Xona’s are more critical than ever. The Xona Platform secures critical OT, IT, and cloud environments and supports compliance with leading standards including IEC 62443, the Cyber Resilience Act (CRA), and NERC-CIP by providing required access controls, auditability, and governance capabilities. Xona provides auditability and governance features that simplify the compliance process, all while reducing the operational burden on IT and OT teams.
Take a First Look or Another Look at Xona
For organizations seeking to improve their OT security, now is the time to consider Xona.
Visit the website at http://www.xonasystems.com to learn more about how the Xona Platform can transform your approach to secure access. Schedule a demo to see firsthand how Xona enables a zero-trust architecture that can reduce your attack surface, simplify operations, and protect your critical assets from today’s evolving threats.
Leave a comment »