Join our Newsletter — 33% off our NHI Course

Understanding Identity and Access Governance: Key Insights & Risks

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: API-related breaches affected 57% of organisations over the past two years, and 73% of those reported three or more incidents, according to Apono. The pattern shows that governance built for human accounts is too slow and too static for cloud-native NHIs, where standing permissions and weak lifecycle control expand the attack surface.

Editorial analysis by NHI Mgmt Group, based on content published by Apono: “Identity and Access Governance (IGA): Definition & Differentiation Explained”.

By the numbers:

  • 57% of organisations experienced at least one API-related breach over the past two years, according to Apono.
  • 73% of those organisations saw three or more incidents, according to Apono.
  • Machine identities outnumber humans by over 80 to 1 in cloud-native environments, according to Apono.

Key questions

Q: What breaks when cloud-native access governance is built around human review cycles?

A: Periodic review breaks because many cloud-native identities are created and used faster than the governance cycle can certify them.

Q: Why do non-human identities make privileged access governance harder?

A: NHIs scale faster than human accounts and are often created for automation, integrations, and AI agents, which makes them easy to forget and hard to review.

Q: How do security teams know if cloud-native IGA is actually working?

A: Cloud-native IGA is working when every access grant has an owner, an expiry, a scope, and an audit trail that can be reconciled across clouds.

Practitioner guidance

  • Audit NHI standing permissions first Inventory service accounts, tokens, and automation identities with persistent access, then flag any credential that is not tied to a clear task window or ownership chain.
  • Shift reviews to issuance time Move approval and entitlement checks into the request and provisioning flow so ephemeral identities are assessed before they become active workloads.
  • Separate human and machine governance records Track non-human identities in a governed inventory that records owner, workload, scope, expiry, and revocation path instead of blending them into human access registers.

Bottom line: Cloud-native identity governance fails when review cycles are slower than the lifecycle of the identities being governed.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 1 day ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 20967
 

NHI governance is becoming the core test of cloud-native IGA maturity. Human-centric certification models can still work for stable employee accounts, but they do not fit identities that are created, used, and discarded by software. Once service accounts, tokens, and automation agents dominate access, governance must cover issuance, scope, expiry, and offboarding with the same seriousness once reserved for employees.

A few things that frame the scale:

A question worth separating out:

Q: What should organisations do about NHI access after a cloud breach pattern emerges?

A: Organisations should immediately map which service accounts, tokens, and automation identities could have been used to reach the affected systems, then revoke any standing access that has no clear operational need. The priority is containment through credential scope reduction, because delayed offboarding leaves machine access reusable after the incident is discovered.

👉 Read our full editorial: Identity and access governance is failing cloud-native NHI oversight



   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.