TL;DR: Automotive identity security now sits at the centre of operational resilience because JLR, CDK Global, and Tata Motors show how trusted access can halt production, disrupt dealer ecosystems, and expose cloud-scale data. Unosecur’s analysis argues that the real control problem is identity blast radius across humans, suppliers, workloads, and AI agents.
NHIMG editorial — based on content published by Unosecur: Automotive identity security: What JLR, CDK Global, and Tata Motors teach us
By the numbers:
- When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes.
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them.
- NHIs outnumber human identities by 25x to 50x in modern enterprises.
Questions worth separating out
Q: What breaks when automotive teams do not govern machine identities properly?
A: Machine identities can retain broad, durable access to cloud storage, SaaS tools, and internal applications long after their original purpose has changed.
Q: Why do supplier identities create such a large risk in automotive ecosystems?
A: Because supplier access is often embedded in operational workflows, not isolated to a single system.
Q: What do security teams get wrong about secret management?
A: Teams often treat secret storage as if it were the same as access governance.
Practitioner guidance
- Build an effective-access map for automotive operations Inventory which human, supplier, service, and workload identities can reach production, dealer, finance, logistics, and cloud resources.
- Govern machine identities as owned principals Assign an owner, purpose, scope, and revocation path to every service account, API key, certificate, and workload credential.
- Replace durable secrets with short-lived or federated access where possible Remove hardcoded keys from code and portals, and use short-lived tokens or federated identity flows for applications and automation.
What's in the full article
Unosecur's full article covers the operational detail this post intentionally leaves for the source:
- The specific incident narratives behind JLR, CDK Global, and Tata Motors, including the business impact each one created.
- The vendor's discussion of automotive identity fabric, supplier identity control, and AI agent discovery in one platform model.
- The article's framing of how Identity Security Posture Management and Identity Threat Detection and Response fit together operationally.
- The broader product context around unified identity controls for automotive environments.
👉 Read Unosecur's analysis of automotive identity security and trusted access risk →
Automotive identity security: are your trusted access paths contained?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Identity blast radius is now the core automotive security metric. The sector no longer fails only at the factory perimeter or the corporate directory. It fails when a trusted identity can propagate into manufacturing, dealer operations, supplier workflows, or cloud storage faster than governance can contain it. That makes access scope, not just authentication, the decisive control variable.
A few things that frame the scale:
- NHIs outnumber human identities by 25x to 50x in modern enterprises, according to Ultimate Guide to NHIs.
- Only 5.7% of organisations have full visibility into their service accounts, which explains why hidden machine access keeps outpacing governance.
A question worth separating out:
Q: What should organisations do when agentic AI starts using enterprise tools?
A: Organisations should define what the system may access, what actions require approval, and who is accountable if behaviour changes during execution. The key is to govern runtime authority, not just initial provisioning. Without that boundary, the AI workflow can expand its own operational reach faster than conventional IGA can observe it.
👉 Read our full editorial: Automotive identity security and the blast radius of trusted access