Wonga.com interview question

Extend the solution to the test How would you organize a web API application? How would you improve performance? What whould you do to prevent further damages in case it become compromised?