The primary approaches to well-architected solutions have neglected active defense as a core tenet of resilience. In this session, we will examine trends affecting the security of APIs, the concept and context of active defense as it relates to web applications, and considerations for incorporating active defense into our systems.