TL;DR: Legacy secrets management is struggling to keep pace with the growth of non-human identities, with Akeyless noting that every human identity now maps to more than forty-five non-human identities under the surface. The real failure is that access review, rotation, and vault-centric controls were designed for static environments, not dynamic application ecosystems where secrets proliferate faster than governance can track them.
NHIMG editorial — based on content published by Akeyless: Secrets at Risk: Why Legacy Secrets Management Is Failing Your Security Strategy
Questions worth separating out
Q: How should security teams reduce secrets sprawl without disrupting delivery?
A: Start by classifying secrets by business criticality, lifetime, and exposure path.
Q: Why do legacy secrets management approaches struggle in cloud and multi-cloud estates?
A: Because they were designed for slower-changing environments where secrets and access relationships were easier to track.
Q: What breaks when organisations rely on long-lived credentials for modern applications?
A: The main failure is blast-radius expansion.
Practitioner guidance
- Build a complete secrets inventory across environments Identify every place credentials, tokens, API keys, and certificates are created, stored, or copied.
- Replace long-lived secrets with short-lived access patterns Prioritise ephemeral credentials, federated identity, and secretless workflows for high-churn applications and pipeline access.
- Reduce vault fragmentation and duplicated control planes Consolidate overlapping secrets manager instances where possible and standardise on a single governance model for issuance, rotation, and revocation.
What's in the full article
Akeyless's full article covers the operational detail this post intentionally leaves for the source:
- The webinar framing around legacy secrets failure modes and the shift from static vaults to modern secrets patterns.
- The “Secrets Management Maturity Model” introduced in the session and how it is used to assess programme progress.
- The operational trade-offs between unified secrets control, developer friction, and secretless or ephemeral approaches.
- The practical narrative used in the webinar to connect manual rotation, overhead, and application development impact.
👉 Read Akeyless's webinar analysis of legacy secrets management and NHI risk →
Secret sprawl and legacy vaults: are your controls keeping up?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Legacy secrets governance is a lifecycle problem, not a storage problem. The article shows that the real issue is not whether a vault exists, but whether the organisation can classify, rotate, revoke, and retire secrets across a fast-moving application estate. When secrets are duplicated across pipelines, environments, and teams, control ownership breaks down. The practitioner conclusion is that secrets must be governed as identities with lifecycles, not as static objects.
A few things that frame the scale:
- The average estimated time to remediate a leaked secret is 27 days, despite 75% of organisations expressing strong confidence in their secrets management capabilities, according to The State of Secrets in AppSec.
- Only 44% of organisations are currently using a dedicated secrets management system, according to The 2024 State of Secrets Management Survey.
A question worth separating out:
Q: What is the difference between ephemeral credentials and secretless access for NHI governance?
A: Ephemeral credentials still issue a short-lived secret for a task or session, while secretless access removes reusable secrets from the workflow where possible. Both reduce standing exposure, but secretless patterns push governance further by eliminating the durable secret altogether.
👉 Read our full editorial: Legacy secrets management is failing modern NHI governance