The Ultimate Guide to Non-Human Identities Report
NHI Forum

Notifications
Clear all

How do I convince my management they need to address NHI risks?


 sam
(@sam)
New Member
Joined: 1 month ago
Posts: 1
Topic starter  

Whilst I am quite concerned about the huge risks that exist around Non-Human Identities, how should we make a business case to our management to start addressing NHI risks. There are so many other priorities for my management and so far we have not had any reported issues around NHIs, but I suspect it's only a matter of time before NHI accounts are used for some compromise.

Would love some advice please.


   
Abdelrahman and Mr NHI reacted
Quote
(@lalit)
Member Admin
Joined: 2 months ago
Posts: 25
 

Sam a great question - i would first suggesting reading The Ultimate Guide To Non-Human Identities where we explain in a lot of detail around the risks and challenges around NHIs, why now is the time to start tackling the exposure within your organisation. 

The key challenges of NHIs:

  • NHIs are typically unmanaged with very weak controls.
  • They have high privileges and access to critical data.
  • They are a key attack vector to compromise systems/data.
  • It is very challenging to remediate the risks.
  • NHIs outnumber Human Identities 25x – 50x.
  • There is a huge secrets sprawl problem with Cloud/SaaS integrations, microservices, containers, etc.
  • Significant use of NHIs by humans poses a huge internal threat that is often overlooked.
  • Monitoring controls are very challenging to implement and it is very hard to see “the wood from the trees.”
  • There have been significant breaches including third-party supply chain attacks.
  • GenAI is going to increase the use of NHIs significantly and create bigger risks.

Our group also published this week our 52 NHI Breaches report that highlights how attackers are now going after NHIs to compromise an organisations systems/data including their 3rd party supply chain providers, GenAI models ...

Our goal at the NHI Mgmt Group is to help organisations navigate the complexities of dealing with NHI exposure and providing a holistic approach to tackling NHI risks.


   
ReplyQuote
Share: