Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Application risk management and identity gaps: what teams need now


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Recent threat activity is being driven by VPN zero-days, identity and social engineering hybrids, and supply-chain vectors for ransomware and extortion, according to Veracode. The broader lesson is that application security now depends on visibility, prioritisation, and identity-aware control across the delivery chain, not isolated scanning.

NHIMG editorial — based on content published by Veracode: CISO Executive Briefing on mastering cyber threats with application risk management

By the numbers:

Questions worth separating out

Q: How should teams reduce identity risk in cloud supply chain attacks?

A: Start by inventorying every developer and automation identity that can reach repositories, build systems, and cloud roles.

Q: Why do exposed internet-facing assets increase the chance of identity abuse in application environments?

A: Because exposed assets often become the first place attackers test for weak trust, stale credentials, or overlooked administration paths.

Q: What do security teams get wrong about SCA and dependency governance?

A: They often treat SCA as a visibility tool rather than an enforcement mechanism.

Practitioner guidance

  • Inventory external assets continuously Run continuous discovery across domains, APIs, certificates, and edge services so that internet-facing exposure is measured against reality rather than stale asset records.
  • Shift dependency policy left of build time Enforce package acceptance rules before dependencies enter the development environment, and tie them to SBOM review and vulnerability suppression policies.
  • Correlate runtime validation with privileged access paths Prioritise DAST and targeted testing on applications that expose sensitive data, privileged workflows, or externally reachable administration surfaces.

What's in the full article

Veracode's full report covers the operational detail this post intentionally leaves for the source:

  • Specific workflow examples for EASM, SCA, SAST, DAST, Fix, and Risk Manager in one operating model
  • Implementation guidance for Package Firewall policy enforcement before dependencies reach development environments
  • Prioritisation and remediation mechanics for turning exploitability data into executive risk reporting
  • Step-by-step actions for operationalising the 30, 60, and ongoing day recommendations

👉 Read Veracode's CISO executive briefing on application risk management and cyber threats →

Application risk management and identity gaps: what teams need now?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 13221
 

Application risk management is now an identity governance problem as much as a code security problem. The article correctly links external exposure, supply-chain abuse, and runtime validation, but the deeper issue is who and what is trusted to reach privileged application paths. Secrets, service accounts, and third-party integrations are the identities that connect those layers. When they are not governed with the same discipline as human access, application risk becomes an identity problem by another name.

A few things that frame the scale:

  • From our research, companies are dedicating an average of 32.4% of their security budgets to secrets management and code security, with US organisations leading at 40.8%, according to The State of Secrets in AppSec.
  • The average estimated time to remediate a leaked secret is 27 days, despite 75% of organisations expressing strong confidence in their secrets management capabilities, according to The State of Secrets in AppSec.

A question worth separating out:

Q: Who is accountable when application risk leads to data theft or ransomware?

A: Accountability spans application security, identity governance, and platform ownership because the failure is usually cross-functional. If exposure came from unmanaged external assets, dependency intake, or privileged access paths, the programme owner must be able to show who owned discovery, who approved trust, and who controlled remediation before the incident became material.

👉 Read our full editorial: Application risk management is shifting toward identity-aware controls



   
ReplyQuote
Share: