Join our Newsletter — 33% off our NHI Course

Database access without PAM: where VPNs and policies break down

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: VPNs, shared credentials, and manual policies cannot keep pace with database access across cloud, on-premises, and containerised environments, according to JumpCloud, while citing a $4.9M average breach cost and multiple access-sprawl indicators. The governance problem is no longer theoretical: privileged access must be brokered, auditable, and lifecycle-aware or databases remain overexposed.

Editorial analysis by NHI Mgmt Group, based on content published by JumpCloud: “Secure Database Access with Privileged Access Management”.

Key questions

Q: What breaks when database access is managed through VPNs alone?

A: VPN-only access breaks the link between network admission and database authorisation.

Q: Why do shared database credentials create so much risk in hybrid environments?

A: Shared credentials create risk because they outlive the task, the person, and often the environment that originally justified them.

Q: How do teams know whether MySQL access governance is actually working?

A: They should be able to show current grants, recent revocations, and clear account ownership for every database user.

Practitioner guidance

  • Broaden database access reviews Review who can reach cloud, on-premises and containerised databases and remove any standing access that is no longer tied to an active role or task.
  • Replace shared database credentials Move database authentication into a vaulted model so admins, contractors and automation do not reuse the same secrets across environments.
  • Broker third-party database sessions Route vendors and external operators through a controlled session broker instead of granting direct network paths or exposing login details.

Bottom line: VPN access alone does not govern database privilege in hybrid IT, because it grants network reach without fine-grained control over what users can do.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 4 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21545
 

Database access has become a privileged access management problem, not a networking problem. VPNs answer connectivity, but they do not answer who should hold database-level authority, for how long, or under what audit conditions. Once organisations conflate tunnel access with privileged access, they lose the ability to enforce least privilege at the point that matters. The implication is that database governance must move from perimeter logic to access brokering and session control.

A few things that frame the scale:

  • 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to the Ultimate Guide to NHIs.

A question worth separating out:

Q: When should organisations prioritise PAM over manual database policies?

A: They should prioritise PAM when databases span cloud, on-premises and containerised environments, or when contractors and automation need access that must be tightly scoped. Manual policies fail once the pace of change outstrips human administration, especially where audit evidence and revocation discipline matter.

👉 Read our full editorial: PAM is now baseline for securing database access in hybrid IT


This post was modified 4 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.