API as the new perimeter: why NIS2 shifts the security focus
By 2026, digital infrastructure resilience has become not just an advantage, but a regulatory requirement. According to the ENISA Threat Landscape 2025 report, 4,875 incidents were analyzed between July 1, 2024, and June 30, 2025, with a significant portion of affected organizations falling under the "essential entities" category subject to the NIS2 directive. The report's key conclusion is that supply chain attacks have become the primary penetration vector. For architects, this means that traditional perimeter defense is no longer sufficient. Integration APIs, once considered internal "connectors," are now the most vulnerable attack surface.
The point-to-point trap: why simple connections become failure points
In many enterprise environments, integrations are still built as chaotic point-to-point connections. Architects often view APIs as simple "pipes," ignoring the fact that every integration point is a distinct trust boundary. Unauthorized access via legacy API endpoints, lack of schema validation, or service overload due to the absence of rate limiting are real threats confirmed by statistics: a significant portion of data breaches occur within digital infrastructure and services.
API-contract security: how to validate trust in supply chains
Moving away from point-to-point chaos requires a transition to a managed integration layer. The concept of API-contract security assumes that every interaction must be authenticated and validated. Using API gateways helps centralize authentication, rate limiting, and traffic observability. As noted by Hohpe and Woolf in Enterprise Integration Patterns, formalizing channels, routers, and transformers allows for the separation of business logic from transmission mechanisms. Using a Schema Registry ensures data integrity: messages that do not conform to the contract are rejected before entering the system, preventing injections and state corruption.
Architectural protection methods: from rate limiting to full audit trails
To comply with NIS2, a multi-layered defense must be implemented: centralized authentication (e.g., OAuth2/JWT), rate limiting, and maintaining an immutable audit trail for all transactions. For instance, events in Apache Kafka allow for replay capabilities to audit and reconstruct system state after incidents, which is critical for ensuring data integrity.
Built-in security: the UnityBase architectural approach
To ensure security in complex enterprise environments where integrations must be reliable, it is effective to use platforms where security is an integral part of the architecture. UnityBase is a joint development by the companies of Intecracy Group and provides a foundation where domain metadata unites data, APIs, and business logic. Solutions built on the UnityBase platform utilize built-in RBAC and RLS (Row-Level Security) mechanisms, allowing for security enforcement at the platform level. For high-load projects or those with heightened security requirements, the use of Enterprise (EE) or Defence (DE) editions is recommended, as they support additional options including OpenID Connect/OAuth2 and advanced audit tools. This architectural approach allows for the integration of external systems through a managed layer, minimizing risks to supply chains.
Checklist for integration interface readiness for NIS2 requirements
- Centralized authentication (OAuth2/JWT) for all API endpoints.
- Input data validation via Schema Registry.
- Implementation of rate limiting to protect against overloads.
- Maintenance of an immutable audit trail for all transactions.
- Access segregation at the data level (RLS) for integration services.
- Automated monitoring and alerting for traffic anomalies.
FAQ
How can legacy systems that do not support modern authentication protocols be protected?
Use an API gateway as a proxy layer that handles authentication (OAuth2/JWT) and forwards verified requests to the legacy system.
Is an API gateway sufficient for full NIS2 compliance?
An API gateway is a vital technical control, but NIS2 compliance requires a comprehensive approach, ranging from access policies and auditing to supply chain risk management.
How can data integrity be ensured when integrating with partners?
Use strict data contracts (Schema Registry) and transaction confirmation mechanisms (audit trail) that allow for tracking the origin of every record.