By NHI Mgmt Group Editorial TeamBased on JumpCloud: “Secure Database Access with Privileged Access Management” (September 11, 2025)

TL;DR: VPNs, shared credentials, and manual policies cannot keep pace with database access across cloud, on-premises, and containerised environments, according to JumpCloud, while citing a $4.9M average breach cost and multiple access-sprawl indicators. The governance problem is no longer theoretical: privileged access must be brokered, auditable, and lifecycle-aware or databases remain overexposed.


At a glance

What this is: This is JumpCloud’s analysis of why database access across cloud, on-premises and containerised environments now requires PAM rather than VPNs and manual policies.

Why it matters: It matters because database access is often the highest-value privilege path in hybrid IT, and IAM teams need brokered, auditable, least-privilege controls that can keep up with dynamic estates.


Context

Database access becomes an identity governance problem when broad network reach is treated as access control. In hybrid estates, cloud databases, on-premises systems and containerised workloads all need different privilege boundaries, but VPN-based trust and manually maintained policies flatten those differences into a single access path.

JumpCloud argues that this model no longer matches how modern databases are deployed or operated. The practical gap is not encryption in transit, but who can reach which database, under what conditions, for how long, and with what evidence after the session ends.


Key questions

Q: What breaks when database access is managed through VPNs alone?

A: VPN-only access breaks the link between network admission and database authorisation. Users may reach internal resources without any granular control over which database they can touch, which operations they can perform, or how long access should last. That creates broad privilege, weak auditability and high lateral movement risk across hybrid environments.

Q: Why do shared database credentials create so much risk in hybrid environments?

A: Shared credentials create risk because they outlive the task, the person, and often the environment that originally justified them. In hybrid estates, that means the same secret can be reused across cloud, on-premises, and third-party access paths, making attribution and revocation much harder. The result is a larger attack surface and a weaker audit trail.

Q: How do teams know whether MySQL access governance is actually working?

A: They should be able to show current grants, recent revocations, and clear account ownership for every database user. If access cannot be explained from identity source to database entitlement, governance is not working. The strongest signal is that privilege state and operational intent match without manual reconstruction.

Q: When should organisations prioritise PAM over manual database policies?

A: They should prioritise PAM when databases span cloud, on-premises and containerised environments, or when contractors and automation need access that must be tightly scoped. Manual policies fail once the pace of change outstrips human administration, especially where audit evidence and revocation discipline matter.


Technical breakdown

Why VPNs create implicit trust for database access

VPNs were built to establish network connectivity, not to govern database privilege. Once a user is inside the tunnel, the security model often becomes binary: on or off. That leaves the database itself exposed to broad reach, weak segmentation and inconsistent per-system rules. In modern hybrid environments, that design collides with Zero Trust architecture because network admission is not the same as authorisation to query, modify or export data. For contractors, third parties and remote teams, the result is excess reach that is hard to scope and even harder to audit.

Practical implication: treat VPN access as transport, not as a privilege decision, and move database authorisation to a dedicated control point.

How vaulting, JIT access and session recording change the control plane

PAM changes database access by separating authentication, credential handling and session execution. Credentials are vaulted instead of shared, access can be issued just-in-time rather than persistently, and every privileged session can be recorded for audit and forensics. That matters in environments where databases are accessed by DBAs, DevOps teams, pipelines and third parties because the control no longer depends on human memory or manual revocation. It also reduces the chance that hardcoded or reused credentials survive longer than the task they were meant to support.

Practical implication: require vaulted credentials, time-bound access and full session logging wherever database privileges are operationally sensitive.

Why hybrid and containerised databases make manual policy brittle

Manual database permissions break down when the environment changes faster than administrators can update access lists. Cloud services, Kubernetes workloads and legacy on-prem systems all move on different cadences, so static policy often lags behind actual use. That creates privilege sprawl, stale entitlements and inconsistent enforcement across environments. The article’s core point is that database governance now has to follow the pace of deployment, not the pace of ticket handling. Without that, access decisions drift away from current risk and current ownership.

Practical implication: align database access governance with workload and identity lifecycle changes, not with periodic manual review alone.


Threat narrative

Attacker objective: The attacker aims to reach high-value database data through overbroad access paths and weakly governed credentials.

  1. Entry occurs when users, contractors or applications obtain broad network reach through VPN tunnels or similarly implicit trust paths.
  2. Credential exposure follows when shared, hardcoded or manually distributed database credentials are reused across systems and users.
  3. Privilege abuse and lateral movement become easier because the database access model does not constrain which instance, query or session actions are permitted.
  4. Impact is broader data exposure, harder incident response and higher breach cost when access cannot be cleanly brokered or audited.
  • Azure Key Vault Contributor escalation 2024: Datadog found Azure Key Vault Contributor could add itself to access policies and read every secret, key and certificate in a vault.
  • BeyondTrust breach 2024: A stolen BeyondTrust Remote Support API key let a China state-sponsored actor reset accounts and reach US Treasury workstations in 2024.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Database access has become a privileged access management problem, not a networking problem. VPNs answer connectivity, but they do not answer who should hold database-level authority, for how long, or under what audit conditions. Once organisations conflate tunnel access with privileged access, they lose the ability to enforce least privilege at the point that matters. The implication is that database governance must move from perimeter logic to access brokering and session control.

Standing database privilege is the real governance debt in hybrid estates. Shared credentials, hardcoded secrets and manual policy updates create a long-lived access window that outlasts the task, the project and sometimes the person or vendor. That is the control failure the article surfaces: access persists because revocation depends on humans keeping pace with the environment. Practitioners should read this as a lifecycle problem, not just a hardening issue.

JIT database access is now a baseline expectation for hybrid operations. When workloads scale across cloud, on-premises and containers, the old model of broad standing rights no longer matches operational reality. Just-in-time access, when paired with vaulting and session recording, becomes the mechanism that preserves agility without surrendering accountability. The practical conclusion is that access duration, not just access scope, has become a primary governance variable.

Auditable database sessions are now a compliance control, not an optional control enhancer. The article correctly links privileged database access to standards such as ISO 27001 and PCI-DSS because regulators care about traceability as much as restriction. Session recording closes the gap between policy and proof by showing what happened after authentication. For teams running hybrid estates, evidence quality is now part of the access model itself.

Ephemeral database access debt: The article points to a category of risk where access rights are created for speed but never fully retired with equal discipline. That debt accumulates across contractors, pipelines and global teams, and it is visible only when organisations stop treating access as a static entitlement. The practitioner takeaway is that database privilege must be governed as a lifecycle, not a one-time grant.

From our research library:

What this signals

Hybrid database governance now depends on reducing privileged access density. When databases sit across cloud, on-premises and containerised environments, the main failure mode is not connectivity but excess entitlement. Teams should expect PAM to become the control layer that aligns database access with least privilege, revocation and evidence.

Privileged access review for databases should be tied to workload and contractor lifecycles. The hard part is no longer granting access, but proving that access ended when the task ended. That makes offboarding, session recording and JIT access part of the same governance motion, not separate operations.

Access brokered through PAM changes the operational baseline for hybrid estates. Security teams that still treat VPNs and manual policies as the primary control will keep carrying ephemeral access debt across environments, which makes exposure harder to see and harder to contain.


For practitioners

  • Broaden database access reviews Review who can reach cloud, on-premises and containerised databases and remove any standing access that is no longer tied to an active role or task.
  • Replace shared database credentials Move database authentication into a vaulted model so admins, contractors and automation do not reuse the same secrets across environments.
  • Broker third-party database sessions Route vendors and external operators through a controlled session broker instead of granting direct network paths or exposing login details.
  • Enforce just-in-time access windows Grant database privileges only for the duration of the approved task and revoke them automatically when the session ends or the job completes.
  • Record privileged database activity Capture session-level evidence for sensitive queries and administrative actions so audits and incident response can reconstruct what happened after login.

Key takeaways

  • VPN access alone does not govern database privilege in hybrid IT, because it grants network reach without fine-grained control over what users can do.
  • The article ties unmanaged database access to a $4.9M average breach cost and to access-sprawl indicators such as inappropriate access and retained access after departure.
  • PAM changes database governance by centralising credentials, issuing just-in-time access and capturing session evidence for audits and incident response.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThe article centres on excessive database privileges and standing access across hybrid environments.
NHI-07 — Long-Lived SecretsShared and reused database credentials are a central exposure path in the article.
Recommendation — Audit database access for overprivilege and remove standing rights that exceed task scope. Replace long-lived database secrets with vaulted, short-lived credentials and enforce rotation.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementThe article emphasises credential vaulting, rotation and revocation for database access.
Recommendation — Apply authenticator management controls to govern database credential lifecycle and reuse.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is fundamentally about scoping database permissions and entitlement review in hybrid IT.
Recommendation — Review database entitlements regularly and align permissions to least privilege.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementThe access model described directly affects credential abuse and lateral movement paths.
Recommendation — Map exposed database access paths to credential access and lateral movement detections.

Key terms

  • Privilege Access Management: Privilege Access Management is the discipline of controlling and monitoring elevated access to critical systems and data. It governs how privileged accounts, credentials, sessions, and commands are issued, used, recorded, and revoked, so administrative power is limited, traceable, and aligned to policy, risk, and operational need.
  • Just-in-Time Access Request: Just-in-Time Access Request is a pattern that grants access only when it is needed and only for the duration required. It reduces standing privilege by making access temporary, policy driven, and task scoped. This approach is especially useful for contractors, sensitive systems, and short-lived operational work.
  • Session Recording: Session recording is the capture of user activity during a privileged session, such as commands, queries, or administrative actions. It gives security and audit teams a verifiable record of what happened after authentication, which is essential when access itself is not enough to prove control.
  • Standing Privilege: Standing privilege is access that remains active even when no immediate task requires it. For NHI programmes, it is a common failure mode because long-lived credentials and persistent roles create unnecessary exposure. Reducing standing privilege usually means tighter expiry, on-demand access, and clearer review of who or what still needs access.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org