Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Hybrid cloud secrets sprawl: what IAM teams need to tighten now


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 8534
Topic starter  

TL;DR: Secrets security in hybrid cloud environments is difficult because passwords, API keys, certificates, and tokens spread across public, private, and mixed infrastructure faster than teams can govern them, according to Entro Security. The practical problem is not just exposure, but fragmented lifecycle control that leaves secrets harder to rotate, revoke, and audit consistently.

NHIMG editorial — based on content published by Entro Security: Secrets security in hybrid cloud environments

By the numbers:

Questions worth separating out

Q: How should security teams manage secrets across hybrid cloud environments?

A: Security teams should manage secrets across hybrid cloud environments by centralising ownership, standardising storage patterns, and automating rotation and revocation.

Q: Why do static credentials create more risk in hybrid cloud estates?

A: Static credentials create more risk because they remain valid across long periods of change, which gives attackers more time to reuse them after exposure.

Q: What breaks when secrets are spread across too many cloud platforms?

A: What breaks is consistency.

Practitioner guidance

What's in the full article

Entro Security's full blog covers the operational detail this post intentionally leaves for the source:

  • The article expands on hybrid and multi-cloud secrets patterns that create governance drift across environments.
  • It describes practical use of automation, orchestration, and infrastructure as code for secrets handling.
  • It outlines how centralized management, rotation, and access control are positioned together in the source discussion.
  • It includes the vendor's platform framing for detecting and managing active secrets across estates.

👉 Read Entro Security's analysis of secrets security in hybrid cloud environments →

Hybrid cloud secrets sprawl: what IAM teams need to tighten now?

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 2 months ago
Posts: 7990
 

Hybrid cloud secrets governance fails when the environment is treated as a collection of platforms instead of a single identity lifecycle. Secrets do not become safer because they sit in different clouds. They become harder to govern because creation, distribution, rotation, and revocation are split across teams and control planes. The implication is that secret lifecycle ownership must be unified before the estate becomes too fragmented to audit.

A few things that frame the scale:

  • 28% of secrets incidents now originate outside code repositories, in Slack, Jira, and Confluence, and are 13% more likely to be categorised as critical than code-based leaks, according to The State of Secrets Sprawl 2026.
  • 64% of valid secrets leaked in 2022 are still valid and exploitable today, proving that detection alone is not enough without automated revocation.

A question worth separating out:

Q: How do identity teams know whether secrets governance is actually working?

A: Identity teams know secrets governance is working when they can prove that every active secret has an owner, an approved scope, and a tested revocation path. If they cannot quickly identify where a secret is used or remove it without breaking the workload, governance is still incomplete.

👉 Read our full editorial: Secrets security in hybrid cloud environments needs tighter governance



   
ReplyQuote
Share: