Join our Newsletter — 33% off our NHI Course

How should organisations build identity security skills when they cannot hire enough specialists?

Organisations should treat skills development as a control, not just a training benefit. Start by defining the identity capabilities needed for current operating models, then upskill existing staff through role-based learning, hands-on labs, and periodic recertification. This reduces dependence on scarce external hiring and helps keep administrators current as cloud identity, governance, and access patterns change.

Why This Matters for Security Teams

identity security skills shortages create a control gap, not just a staffing challenge. When only a few specialists understand secrets, service accounts, OAuth app governance, and privileged access, the organisation becomes dependent on fragile hero knowledge. That is risky because identity failures often persist in cloud, SaaS, and CI/CD environments long after platform teams think controls are in place. NHI Management Group has shown that only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, while many still lack full visibility into third-party OAuth connections in the report The State of Non-Human Identity Security.

Security leaders should treat capability building as part of operational resilience. Identity programs fail when access reviews, rotation, vault hygiene, and offboarding depend on one or two experts who can interpret every exception. Standards such as NIST SP 800-63 Digital Identity Guidelines and NIST SP 800-53 Rev 5 Security and Privacy Controls are useful, but they only help if staff can operationalise them in the real environment. In practice, many security teams discover their identity process debt only after a leaked token, a failed audit, or a cloud incident exposes how thin the bench really is.

How It Works in Practice

The practical answer is to build a repeatable skills model around the identity work the organisation already performs. Start by mapping core capabilities: human identity governance, NHI lifecycle management, secrets handling, privileged access, federation, and logging. Then assign those capabilities to role-based learning paths for IAM engineers, cloud engineers, SOC analysts, platform teams, and application owners. This makes development specific and measurable rather than generic training theatre.

Hands-on labs matter more than slide decks. Staff should practice tasks such as rotating API keys, detecting orphaned service accounts, reviewing OAuth consent, and validating vault configuration. That training should be paired with runbooks and peer review so that the process survives staff turnover. Guidance from the NIST framework family is strongest when mapped to concrete actions, and the same is true for NHIMG research such as Ultimate Guide to NHIs, which highlights how often secrets remain exposed outside approved managers and how rarely offboarding is fully automated.

A useful operating model is:

  • Define a minimum identity skill baseline for every role that touches credentials or access.
  • Use quarterly labs or tabletop exercises to test rotation, revocation, and monitoring workflows.
  • Require recertification for administrators who manage privileged, cloud, or NHI-heavy systems.
  • Cross-train so that at least two people can perform each critical identity operation.

Where possible, tie learning to actual control failures. A service account review that found excess privilege is a better lesson than a generic IAM workshop. These controls tend to break down when identity ownership is split across too many teams because no single group has enough context to train or enforce consistently.

Common Variations and Edge Cases

Tighter identity controls often increase operational overhead, requiring organisations to balance speed of delivery against the burden of more frequent reviews, labs, and recertification. That tradeoff is real, especially in smaller teams and fast-moving cloud environments. Best practice is evolving, but the current guidance suggests that skills uplift should be risk-based: the highest-frequency training belongs with roles that manage secrets, federation, privileged access, and third-party integrations.

Not every organisation needs a large formal academy. In some cases, a lightweight model works better: weekly clinics, embedded mentors, and short scenario drills tied to actual tickets. In others, especially where NHIs outnumber human identities by a wide margin, training must include developers and platform engineers because identity mistakes now happen in code, pipelines, and SaaS admin consoles. NHIMG’s Top 10 NHI Issues is useful here because it frames the recurring failure patterns teams should know how to spot.

The main exception is highly regulated or outsourced environments, where training alone cannot compensate for weak ownership or contractor churn. In those environments, organisations need explicit accountability for identity operations and clear segregation of duties, not just more learning content. When the environment is fragmented across multiple cloud tenants, SaaS platforms, and external providers, skills programs tend to lose effectiveness because the team cannot build consistent muscle memory across all the tools in scope.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63 and NIST AI RMF set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
OWASP Non-Human Identity Top 10 NHI-01 Skills gaps often cause weak NHI lifecycle and secrets handling.
NIST CSF 2.0 PR.AT-01 This question is fundamentally about security awareness and role-based capability building.
NIST SP 800-63 Digital identity guidance needs staff who can implement it correctly.
NIST AI RMF AI RMF supports governance of workforce capability and accountability.
CSA MAESTRO Agentic and cloud identity operations require cross-functional skills and repeatable controls.

Assign ownership for identity skills, measure gaps, and close them through governed learning paths.