Join our Newsletter — 33% off our NHI Course

Secrets management in 2026: are your controls keeping up?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: Secrets management is the practice of storing, rotating, and controlling access to passwords, API keys, certificates, and tokens across modern infrastructure, according to StrongDM. The real problem is not storage alone but the governance gap created when secrets are hardcoded, overexposed, or left without lifecycle control, because access paths outlive the assumptions behind them.

Editorial analysis by NHI Mgmt Group, based on content published by StrongDM: “What Is Secrets Management? Best Practices for 2026”.

Key questions

Q: What breaks when secrets are hardcoded into DevOps pipelines?

A: Hardcoded secrets break rotation, ownership, and offboarding at the same time.

Q: Why do temporary secrets reduce risk compared with long-standing credentials?

A: Temporary secrets reduce risk because they do not assume persistent access.

Q: What are the signs that secret governance is failing?

A: Common signs include secrets that never expire, weak rotation discipline, and inconsistent lifecycle management across vaults and applications.

Practitioner guidance

  • Standardise secret inventory and ownership Create a complete inventory of passwords, API keys, certificates, and tokens, then assign an owner, environment, and expiry for each credential.
  • Eliminate hardcoded credentials from code and pipelines Scan source repositories, build manifests, and configuration stores for embedded secrets, then move those credentials into a governed retrieval path.
  • Automate rotation based on credential lifetime Set rotation thresholds by secret type and runtime criticality, then enforce them through policy rather than manual ticketing.

Bottom line: Secrets management fails when credentials are hardcoded, duplicated, or left active beyond the systems they were meant to protect.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 4 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Secret sprawl is a governance failure before it is a storage problem. Once credentials are duplicated across vaults, pipelines, and configuration files, the organisation no longer has a single control surface. The real issue is not where the secret sits but whether its ownership, scope, and retirement are still knowable. For practitioners, that means secrets management must be treated as lifecycle governance across the full credential estate, not as a vault project.

A few things that frame the scale:

  • Companies are dedicating an average of 32.4% of their security budgets to secrets management and code security, with US organisations leading at 40.8%, according to the State of Secrets in AppSec.
  • 54% of organisations are dissatisfied with their current secrets management solution because not all secrets are secured, and 43% cite lack of central management, according to the 2024 State of Secrets Management Survey.

A question worth separating out:

Q: How should security teams govern machine credentials across cloud and CI/CD environments?

A: Security teams should treat machine credentials as production identities with owners, scopes, and lifecycles. That means inventorying service accounts, API keys, tokens, and certificates, mapping where they are used, and enforcing rotation and revocation through automated workflows rather than manual exception handling.

👉 Read our full editorial: Secrets management in 2026: the governance gap behind sprawl


This post was modified 4 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.