Join our Newsletter — 33% off our NHI Course

Crown Jewel Analysis

Crown jewel analysis is the process of identifying the assets, data, identities, and systems that matter most to an organisation. In deception programs, it helps defenders place controls where an attacker is most likely to pursue impact, so the decoys and alerts align with realistic paths to high-value targets.

Expanded Definition

Crown jewel analysis is the discipline of ranking an organisation’s highest-value assets so defenders can focus controls, monitoring, and deception on the places an attacker is most likely to pursue impact. In NHI security, those assets are often not just databases or payment systems, but service accounts, API keys, automation pipelines, signing certificates, privileged tokens, and the systems those identities can reach.

Definitions vary across vendors on whether the analysis should include only technical assets or also business processes, legal exposure, and operational dependencies. NHI Management Group treats it as a practical prioritisation method that connects asset criticality to identity-driven attack paths, which is why it complements frameworks such as NIST SP 800-53 Rev 5 Security and Privacy Controls rather than replacing them. The goal is not to label everything important, but to identify where compromise would create the most severe confidentiality, integrity, or availability loss.

In mature programs, crown jewel analysis is updated as systems change, identities proliferate, and access paths evolve. It also informs where to place stronger segmentation, tighter privilege, and higher-fidelity detections. The most common misapplication is treating crown jewels as a static list of servers, which occurs when organisations ignore the identities and credentials that actually unlock those systems.

Examples and Use Cases

Implementing crown jewel analysis rigorously often introduces prioritisation tradeoffs, requiring organisations to weigh broad coverage against deeper protection for fewer, more consequential targets.

  • A payments company identifies its settlement ledger, transaction signing service, and the API key chain that can alter payment routing as crown jewels, then surrounds them with tighter access reviews and deception telemetry.
  • A cloud software provider uses the Ultimate Guide to NHIs to map service accounts, secrets, and automation roles that can reach production deployment systems, then builds decoys around those paths.
  • A healthcare organisation treats patient record export jobs and the machine identities that trigger them as high-value targets, because compromise would create both data exposure and regulatory impact.
  • A finance team aligns its crown jewel review with NIST SP 800-53 Rev 5 Security and Privacy Controls to decide which privileged paths deserve stronger logging, token rotation, and segmentation.
  • A security operations team places honey tokens near the systems most likely to be targeted after reconnaissance, so alerting is concentrated where attacker intent is most meaningful.

Why It Matters in NHI Security

Crown jewel analysis matters because attackers do not compromise every identity equally. They follow the shortest path to impact, which often means targeting the credentials, service accounts, and automation layers that sit closest to critical data or operational control. This is especially important in NHI environments, where identities outnumber humans by large margins and exposure is easy to underestimate.

NHI Management Group reports that Ultimate Guide to NHIs notes 80% of identity breaches involved compromised non-human identities such as service accounts and API keys. That statistic reinforces a basic governance lesson: if high-value systems are mapped without the identities that reach them, defenders will miss the attack surface that matters most. Crown jewel analysis also helps teams decide where to apply stronger identity controls, including the compensating measures described in NIST SP 800-53 Rev 5 Security and Privacy Controls.

Organisations typically encounter the real value of crown jewel analysis only after an intrusion reveals which forgotten identity, token, or automation path led to the most sensitive system, at which point the concept becomes operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
OWASP Non-Human Identity Top 10 NHI-01 Crown jewel analysis prioritizes the NHI assets most likely to enable high-impact compromise.
NIST CSF 2.0 ID.AM-01 Asset management underpins crown jewel identification and impact-based prioritization.
NIST Zero Trust (SP 800-207) SC-7 Critical-path analysis supports segmentation and path reduction in zero trust design.
NIST SP 800-63 IAL2 High-value identities need stronger assurance when they unlock crown jewel systems.
OWASP Agentic AI Top 10 A2 Agentic systems can become the path to crown jewels through tool and privilege misuse.

Maintain an accurate inventory of critical assets so protection efforts can focus on the highest-impact targets.