Join our Newsletter — 33% off our NHI Course

Identity secret sprawl: what IAM teams need to fix first

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Shared secrets for machines outnumber human secrets by 20 to 45 times, and the article argues that secret sprawl persists because applications still authenticate with long-lived credentials stored in code, files, and CI/CD systems, according to Defakto Security. The governance shift is from rotating secrets more often to removing shared secrets from the operating model entirely.

Editorial analysis by NHI Mgmt Group, based on content published by Defakto Security: “Secret Sprawl: Understand It To Reduce Your Risk”.

Key questions

Q: What breaks when shared machine secrets are not removed from the operating model?

A: What breaks is not just storage discipline but the trust model itself.

Q: Why do shared NHI secrets create a bigger risk than simple credential sprawl?

A: Because each copy extends the number of places a credential can be used if it leaks.

Q: How do security teams know when secret sprawl is becoming unmanageable?

A: When they cannot confidently answer where each secret exists, which workloads depend on it, and how quickly it can be retired without breaking business services.

Practitioner guidance

  • Inventory every shared machine secret Map secrets across code repositories, developer workstations, CI/CD systems, and runtime environments so you know where credentials exist and who can reach them.
  • Replace reusable secrets with workload identity Prioritise applications that can use attested workload identity instead of usernames, passwords, or API keys, especially where automation already exists.
  • Shorten the exposure window for exposed secrets Build a rapid revocation path for any secret found in code, logs, chat, or deployed systems, then confirm every copy is removed from downstream environments.

Bottom line: Secret sprawl is a machine identity governance problem because shared credentials create duplicated trust across code, pipelines, and runtime systems.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 1 day ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 20967
 

Secret sprawl is an identity governance problem, not a vaulting problem. Secret managers reduce storage risk, but they do not remove the operational reality that shared credentials must be copied, distributed, and later revoked. That means the control surface remains fragmented across code, endpoints, pipelines, and runtime systems. Practitioners should treat secret sprawl as evidence that the workload identity model is still immature.

A question worth separating out:

Q: Should organisations move from managing secrets to managing machine identities?

A: Yes, where the platform allows it. Managing identities instead of shared secrets reduces duplication, narrows blast radius, and gives teams a cleaner lifecycle model for issuance, renewal, and revocation. The goal is not better secret storage, but fewer secrets in the first place.

👉 Read our full editorial: Identity secret sprawl is exposing NHI governance gaps


This post was modified 1 day ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.