Join our Newsletter — 33% off our NHI Course

Credentialitis and secrets sprawl: what IAM teams are missing

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Passwords, API keys, tokens, and hardcoded blobs keep accumulating because vaults and scanning tools treat symptoms rather than the brittle credentialing model itself, according to Aembit. The underlying governance gap is now a workload identity problem, not a hygiene problem.

Editorial analysis by NHI Mgmt Group, based on content published by Aembit: “We’ve Identified a New IT Ailment. It’s Called Credentialitis – And It’s Spreading Fast”.

Key questions

Q: How should security teams reduce secrets sprawl without disrupting delivery?

A: Start by classifying secrets by business criticality, lifetime, and exposure path.

Q: Why do vaults and scanners fail to eliminate credential sprawl?

A: Because they act after the secret already exists.

Q: What are the signs that NHI credential governance is broken?

A: Common signs include secrets in repositories, repeated rotation work with no net reduction in exposure, unclear ownership across DevOps and security, and credentials that survive beyond the workload that was meant to use them.

Practitioner guidance

  • Define the workload credential inventory Catalogue where passwords, API keys, tokens, .env files, and hardcoded blobs are created, stored, copied, and retired across delivery pipelines and runtime systems.
  • Reduce persistent secret dependence Identify services and pipelines that can move from reusable credentials to workload identity, then prioritise those paths where secrets are currently baked into deployments.
  • Reclassify rotation as a compensating control Use rotation and scanning to limit exposure while you redesign the access model, rather than treating either one as the end-state governance answer.

Bottom line: Secret sprawl persists because teams keep layering vaults, rotation, and scanning over a credentialing model that still depends on reusable secrets.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 1 day ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 20967
 

Credentialitis is an NHI governance failure, not a hygiene problem. Secrets sprawl persists because organisations keep managing the symptom, which is leaked or misplaced credentials, instead of the underlying access model that depends on them. Vaults and scanners can reduce exposure, but they do not change the fact that workloads are still being built around brittle, reusable credentials. The practitioner conclusion is that the real control question is how machine access is issued, scoped, and retired.

A question worth separating out:

Q: When should organisations move from vault-based secrets to workload identity?

A: Organisations should make the move when workloads are growing faster than manual credential handling can safely support, or when the same secret is reused across services. If onboarding, rotation, and offboarding are already brittle, workload identity becomes a governance necessity rather than an optimisation.

👉 Read our full editorial: Credentialitis shows why secrets sprawl is still an NHI governance failure


This post was modified 1 day ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.