Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Identity-based attacks: are human and machine controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15984
Topic starter  

TL;DR: Identity-based attacks are now the leading breach path because attackers can target both people and machine identities, according to Akeyless. The operational gap is that secrets, certificates, and admin-level machine access often live longer than the access assumptions behind today’s IAM and PAM programmes.

NHIMG editorial — based on content published by Akeyless: Identity-based attacks are now the leading cause of cybersecurity breaches

By the numbers:

Questions worth separating out

Q: Why do long-lived machine credentials increase cloud security risk?

A: Long-lived credentials increase risk because compromise stays useful for longer and is harder to detect in time.

Q: Why do machine identities complicate traditional PAM programmes?

A: Machine identities complicate traditional PAM because they need access patterns that are automated, frequent, and often cross-cloud.

Q: What breaks when secrets are not rotated frequently enough?

A: The attacker’s dwell time expands.

Practitioner guidance

  • Inventory every machine identity class Map service accounts, API keys, certificates, CI/CD credentials, and workload identities to named owners, systems, and renewal dates.
  • Shorten credential validity windows Replace long-lived secrets with ephemeral credentials wherever workloads can support them, and set rotation intervals based on operational use rather than convenience.
  • Separate developer convenience from production trust Prevent secrets from being embedded in source code, shared across environments, or reused across unrelated automation jobs.

What's in the full article

Akeyless's full post covers the operational detail this post intentionally leaves for the source:

  • The fireside-chat context and full conversation flow between Akeyless and Ross Young
  • Specific examples of how secrets sprawl emerges across DevOps and cloud workflows
  • The vendor’s description of Distributed Fragments Cryptography and its operating model
  • The closing advice on developer education, SaaS adoption, and lifecycle management

👉 Read Akeyless’s discussion of identity-based attacks, machine identities, and secrets sprawl →

Identity-based attacks: are human and machine controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 15569
 

Identity security is no longer a human-only governance problem. The article is right to frame the shift from phishing users to stealing cloud resources, but the deeper point is that machine identities now sit on the same attack surface as people. That collapses older IAM assumptions about where trust begins and ends. Practitioners should read this as a call to govern identity by actor type, not by access channel.

A few things that frame the scale:

  • From our research: The average organisation believes more than 1 in 5 of their non-human identities are insufficiently secured, according to The 2024 ESG Report: Managing Non-Human Identities.
  • Two-thirds of enterprises have endured a successful cyberattack resulting from compromised non-human identities, with a quarter encountering multiple attacks.

A question worth separating out:

Q: Who should be accountable for machine identity offboarding?

A: Accountability should sit with the system or application owner, with identity operations enforcing the control. If no one owns retirement, service accounts and keys outlive the process that created them and continue to expand the attack surface long after their use case ends.

👉 Read our full editorial: Identity-based attacks are outpacing human and machine controls



   
ReplyQuote
Share: