TL;DR: 89% of organisations have suffered at least one security incident in the past three years, while 88% say credentials and secrets proliferation makes infrastructure access security harder, and 86% cite regulatory compliance as a major challenge, according to Teleport’s 2024 survey. The editorial case is that access governance now has to span security, engineering, and compliance together, not as separate problems.
NHIMG editorial — based on content published by Teleport: Why Secure Infrastructure Access Must Evolve: Insights from Teleport’s 2024 Survey
By the numbers:
- 89% of organisations suffered at least one security incident in the past three years.
- 88% of survey respondents said the increase in credentials and secrets creates a significant challenge for infrastructure access security.
- 86% of respondents included sustaining DevOps pipelines as a chief concern when securing infrastructure access.
Questions worth separating out
Q: How should security teams reduce standing privilege in cloud environments?
A: Start by identifying which cloud roles, service accounts, and automation identities have persistent access they do not need every minute of the day.
Q: Why do credentials and secrets create so much risk in modern infrastructure?
A: Because each credential or secret is both an access path and a lifecycle obligation.
A: The organisation loses a single source of truth for who can access what, when access expires, and how evidence is produced.
Practitioner guidance
- Map every privileged access path Build a register of human, machine, and service access paths across cloud, edge, and on-prem systems.
- Eliminate standing privilege where tasks are time-bound Replace persistent admin access with just-in-time access, short-lived credentials, and task-scoped approvals for operational work.
- Unify access policy across teams Bring security, engineering, and compliance into one policy model for infrastructure access so controls do not diverge across environments.
What's in the full report
Teleport’s full post covers the operational detail this post intentionally leaves for the source:
- Leader versus novice comparisons showing how mature access programmes reduce incident cost and frequency.
- The survey’s breakdown of where teams are most struggling across cloud, compliance, and DevOps environments.
- Teleport’s recommended access patterns for consolidating identities, policy, and privileged access workflows.
👉 Read Teleport’s 2024 survey on secure infrastructure access challenges and leader practices →
Infrastructure access security is lagging behind cloud complexity?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Infrastructure access is now an identity governance problem, not a tooling problem. The survey shows that cloud scale, secrets proliferation, and compliance pressure are converging into one control surface. That matters because the security outcome depends less on any single access product and more on whether ownership, revocation, and evidence are governed across humans and NHIs together.
A few things that frame the scale:
- Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security, according to The 2026 Infrastructure Identity Survey.
- 69% of security leaders agree identity management must fundamentally shift to address agentic AI systems, which shows that the governance model itself is under revision.
A question worth separating out:
Q: How do organisations know whether their infrastructure access programme is actually working?
A: Look for fewer standing credentials, faster revocation, and fewer exceptions handled outside the normal workflow. A working programme produces consistent audit evidence, reduces access sprawl over time, and lets teams make changes without reintroducing unmanaged paths or slowing delivery.
👉 Read our full editorial: Infrastructure access security is lagging behind cloud complexity