TL;DR: Cloud identity management now has to govern non-human identities, because APIs, service accounts, and CI/CD roles often carry long-lived access that expands blast radius; Apono cites a 57% API-related breach rate in the past two years and 73% of victims with three or more incidents. Static permissions, not cloud scale alone, are the real control failure.
Editorial analysis by NHI Mgmt Group, based on content published by Apono: “10 Essential Tips For Cloud Identity Management”.
By the numbers:
- 57% of organisations experienced an API-related data breach in the past two years.
- 73% of those victims suffered three or more incidents.
Key questions
Q: What breaks when cloud identities are not centrally governed?
A: Shadow accounts, orphaned credentials and inconsistent role definitions emerge because no single process can see the whole access picture.
Q: Why do over-privileged cloud entitlements increase breach impact?
A: They increase breach impact because a stolen credential or compromised integration can inherit far more access than the underlying task requires.
Q: How do security teams know if cloud identity controls are failing?
A: The clearest sign is when a stolen credential can be validated, reused, and operationalised from infrastructure that has no relationship to the original workload.
Practitioner guidance
- Inventory every non-human identity Build a single inventory that includes service accounts, API keys, workload roles, CI/CD identities, and the owners responsible for each one.
- Replace standing access with time-bound access Require expiry for elevated cloud permissions and use just-in-time access for tasks that do not need permanent entitlement.
- Tie permissions to lifecycle events Review and revoke access when pipelines change, services are decommissioned, or ownership shifts so stale entitlements do not survive the original use case.
Bottom line: Cloud identity management now fails most visibly where non-human identities are left with permissions that outlive the work they were created to do.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
NHI governance is no longer optional in cloud identity management. Cloud programmes that still centre human users are governing the wrong access model. The article shows that APIs, service accounts, workload roles, and CI/CD identities now carry much of the operational load, which means the primary risk surface has shifted from human sign-in to machine authorisation. Practitioners should treat cloud identity as a mixed estate of human and non-human control points, not a user-only problem.
A few things that frame the scale:
- Systems with least-privileged AI access had a 17% incident rate vs 76% for over-privileged systems. Organisations failing to scope AI access properly are 4.5x more likely to experience a security incident, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: Should organisations prioritise just-in-time access or standing permission cleanup first?
A: Standing permission cleanup comes first because just-in-time access cannot compensate for stale entitlements that already exist. If the environment is full of unused or unowned non-human identities, reducing persistent access has the biggest immediate effect on blast radius.
👉 Read our full editorial: Cloud identity management is failing without NHI governance