Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

WISeKey joins Hedera Council: what it means for machine identity


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20360
Topic starter  

TL;DR: The move into Hedera Council highlights a broader push toward trusted machine-to-machine identity, secure authentication, and decentralized transaction models for IoT and AI systems, according to WISeKey. For practitioners, the question is no longer whether non-human identities will transact at scale, but how governance, trust, and accountability will hold when they do.

NHIMG editorial — based on content published by WISeKey: WISeKey joins the Hedera Council network of strategic and community partners

Questions worth separating out

Q: How should security teams govern machine identities in industrial environments?

A: Security teams should govern machine identities the same way they govern privileged access: assign an owner, define a specific purpose, limit scope, and review it continuously.

Q: Why do autonomous machine transactions create extra identity risk?

A: Because the identity is no longer only requesting access, it is executing value-moving or workflow-triggering actions at runtime.

Q: When should organisations prioritise post-quantum planning for machine identities?

A: They should start as soon as they can inventory certificates, signing keys, and long-lived tokens that would be hard to replace.

Practitioner guidance

  • Inventory machine trust anchors across decentralised environments Map certificates, keys, device roots of trust, and service identities used in IoT, blockchain, and partner integrations so ownership and revocation paths are explicit.
  • Define lifecycle ownership for non-human transaction identities Assign accountable owners for issuance, renewal, suspension, and retirement of machine identities, including service identities used for autonomous exchange.
  • Plan crypto-agility for embedded and long-lived devices Identify hardware and firmware constraints that will delay post-quantum migration, then sequence remediation for the highest-risk device classes first.

What's in the full analysis

WISeKey's full article covers the operational detail this post intentionally leaves for the source:

  • The partnership structure and named ecosystem participants involved in Hedera Council's partner network
  • The specific SEALCOIN and QAIT references behind the machine-trust and quantum-risk narrative
  • The company background on WISeKey's IoT, PKI, and post-quantum product portfolio
  • The forward-looking language the vendor uses to describe autonomous device commerce and trusted infrastructure

👉 Read WISeKey’s announcement on joining Hedera Council and machine identity →

WISeKey joins Hedera Council: what it means for machine identity?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19951
 

Machine identity is becoming the trust substrate for decentralised infrastructure. The WISeKey and Hedera partnership reflects a wider shift away from treating identity as a human login problem. In IoT, blockchain, and autonomous exchange models, the machine identity is the thing that must be issued, trusted, rotated, and ultimately revoked. Practitioners should read this as a signal that identity governance is now part of infrastructure design, not just IAM administration.

A few things that frame the scale:

  • 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to Ultimate Guide to NHIs.
  • Only 5.7% of organisations have full visibility into their service accounts, which shows how much of the machine identity estate still sits outside effective governance.

A question worth separating out:

Q: How do teams know if machine identity governance is actually working?

A: Look for evidence that each service account has a current owner, a narrow purpose, a short credential lifetime, and a clear retirement path. If any of those are missing, the programme may appear controlled on paper while still leaving durable access paths in production.

👉 Read our full editorial: WISeKey and Hedera signal a shift toward machine identity



   
ReplyQuote
Share: