TL;DR: API-related breaches affected 57% of organisations over the past two years, and 73% of those reported three or more incidents, according to Apono. The pattern shows that governance built for human accounts is too slow and too static for cloud-native NHIs, where standing permissions and weak lifecycle control expand the attack surface.
Editorial analysis by NHI Mgmt Group, based on content published by Apono: “Identity and Access Governance (IGA): Definition & Differentiation Explained”.
By the numbers:
- 57% of organisations experienced at least one API-related breach over the past two years, according to Apono.
- 73% of those organisations saw three or more incidents, according to Apono.
- Machine identities outnumber humans by over 80 to 1 in cloud-native environments, according to Apono.
Key questions
Q: What breaks when cloud-native access governance is built around human review cycles?
A: Periodic review breaks because many cloud-native identities are created and used faster than the governance cycle can certify them.
Q: Why do non-human identities make privileged access governance harder?
A: NHIs scale faster than human accounts and are often created for automation, integrations, and AI agents, which makes them easy to forget and hard to review.
Q: How do security teams know if cloud-native IGA is actually working?
A: Cloud-native IGA is working when every access grant has an owner, an expiry, a scope, and an audit trail that can be reconciled across clouds.
Practitioner guidance
- Audit NHI standing permissions first Inventory service accounts, tokens, and automation identities with persistent access, then flag any credential that is not tied to a clear task window or ownership chain.
- Shift reviews to issuance time Move approval and entitlement checks into the request and provisioning flow so ephemeral identities are assessed before they become active workloads.
- Separate human and machine governance records Track non-human identities in a governed inventory that records owner, workload, scope, expiry, and revocation path instead of blending them into human access registers.
Bottom line: Cloud-native identity governance fails when review cycles are slower than the lifecycle of the identities being governed.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
NHI governance is becoming the core test of cloud-native IGA maturity. Human-centric certification models can still work for stable employee accounts, but they do not fit identities that are created, used, and discarded by software. Once service accounts, tokens, and automation agents dominate access, governance must cover issuance, scope, expiry, and offboarding with the same seriousness once reserved for employees.
A few things that frame the scale:
- NHIs outnumber human identities by 25x to 50x in modern enterprises, according to the Ultimate Guide to NHIs.
- 61% of organisations still define privileged users as humans only, overlooking the role of non-human identities in privileged access, according to KPMG.
A question worth separating out:
Q: What should organisations do about NHI access after a cloud breach pattern emerges?
A: Organisations should immediately map which service accounts, tokens, and automation identities could have been used to reach the affected systems, then revoke any standing access that has no clear operational need. The priority is containment through credential scope reduction, because delayed offboarding leaves machine access reusable after the incident is discovered.
👉 Read our full editorial: Identity and access governance is failing cloud-native NHI oversight