Join our Newsletter — 33% off our NHI Course

OWASP NHI Top 10: what it means for IAM teams now

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Non-human identity risk is concentrated in familiar failures such as improper offboarding, secret leakage, overprivilege, weak authentication and environment reuse, with breach examples spanning public repositories, cloud workloads and third-party access, according to Aembit's analysis of OWASP's first NHI Top 10. The core issue is that NHI governance still treats machine credentials like managed user access, even though many persist, spread and operate outside human review windows.

Editorial analysis by NHI Mgmt Group, based on content published by Aembit: “OWASP’s Top Security Risks for Non-Human Identities and How to Address Them”.

By the numbers:

  • Non-human identities now outnumber human identities by 144 to 1 in the average enterprise, according to Entro Security research cited by Aembit.
  • Nearly 29 million new hardcoded secrets were exposed on public GitHub in 2025 alone, a 34% year-over-year increase, according to GitGuardian research cited by Aembit.
  • 64% of secrets exposed as far back as 2022 remained valid in early 2026, according to GitGuardian research cited by Aembit.

Key questions

Q: What breaks when NHI credentials are never offboarded?

A: When offboarding is missing, API keys, tokens and service accounts can remain valid after the workload or integration is gone.

Q: Why do leaked secrets remain such a persistent NHI risk?

A: Leaked secrets persist because they are often embedded in code, pipelines, or collaboration tools, then left valid long enough for reuse.

Q: When should teams prioritise least privilege over convenience for NHIs?

A: Always, but especially when an NHI can reach production data, cloud control planes or third-party systems.

Practitioner guidance

  • Map every NHI to an owner and an offboarding trigger Tie service accounts, API keys and workload identities to a named owner, a system of record and a revocation event when the workload or integration is retired.
  • Replace static secrets with expiring credentials Use short-lived tokens or federated workload identity so a leaked secret has a smaller replay window and a clear expiry path.
  • Right-size permissions by service boundary Review cloud roles, OAuth app scopes and service account grants against the actual function they support, then remove access outside that boundary.

Bottom line: OWASP's first NHI Top 10 shows that the hardest machine-identity problems are still lifecycle, scope and trust issues rather than purely technical misconfigurations.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 1 day ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 20967
 

OWASP's NHI Top 10 is really a lifecycle document, not just a threat list: the central problem is that many organisations still do not govern machine identities as identities. Offboarding, ownership, rotation and scoping are treated as implementation details instead of the core control plane. That is why the same failure patterns keep reappearing across cloud workloads, SaaS integrations and service accounts.

A few things that frame the scale:

  • NHIs outnumber human identities by 25x to 50x in modern enterprises, according to the Ultimate Guide to NHIs.

A question worth separating out:

Q: How do organisations govern third-party NHI access safely?

A: They should treat vendor-linked tokens, service accounts and integrations as governed dependencies with an owner, a scope and a removal date. The access should be monitored continuously and revoked when the business relationship, environment or integration purpose changes. Without that discipline, vendor access becomes persistent trust rather than controlled access.

👉 Read our full editorial: OWASP NHI Top 10 shows why NHI governance lags behind access risk


This post was modified 1 day ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.