The main mistake is assuming the highest-risk users are the only ones that matter. In practice, attackers often target overlooked accounts, shared credentials, and machine identities because those paths are less visible and less consistently governed. If protection stops at a subset, the organisation keeps the weakest links outside policy, monitoring, and response processes.
Why Security Teams Misjudge the Real Blast Radius
Protecting only a subset of users and accounts creates a false sense of coverage. Security teams often concentrate on executives, admins, and a few named service accounts, while attackers move toward the paths that remain lightly governed: shared credentials, stale accounts, machine identities, and third-party connections. NHI risk is usually a systems problem, not a badge problem, which is why coverage gaps become exploit paths.
This is where identity programs lose alignment with operational reality. The NIST Cybersecurity Framework 2.0 emphasizes governance and continuous risk management, but many organisations still apply identity controls selectively instead of consistently. NHIMG research shows the scale of the issue: in the Ultimate Guide to NHIs, only 5.7% of organisations report full visibility into their service accounts, and 97% of NHIs carry excessive privileges. In practice, many security teams discover the missing protections only after an attacker has already used the least watched account to gain persistence or move laterally.
How Selective Protection Fails in Practice
Selective protection usually starts with a narrow risk definition: high-value users get MFA, PAM, monitoring, and faster review cycles, while “ordinary” users, shared accounts, API keys, and automation identities receive weaker controls. That approach breaks because attackers do not follow the same hierarchy. They look for whichever identity has the easiest route to privileged systems, data pipelines, or cloud control planes.
Effective coverage means treating identity risk as a full population issue. The NIST SP 800-53 Rev 5 Security and Privacy Controls supports consistent access control, account management, and audit logging across the environment, not only for the most visible accounts. For NHI programs, that means inventorying every identity class, then applying lifecycle controls uniformly: discovery, ownership, rotation, least privilege, logging, and revocation. The State of Non-Human Identity Security reports that lack of credential rotation is the top cause of NHI-related attacks for 45% of organisations, with inadequate monitoring and over-privileged accounts each cited by 37%.
- Inventory human, machine, and third-party identities together, not in separate governance silos.
- Apply policy to the long tail of accounts, including shared and dormant identities.
- Prioritise rotation, logging, and ownership for every secret, token, and key.
- Review access based on actual usage and exposure, not on assumptions about importance.
Teams also need to connect identity governance to incident response. If an overlooked account can authenticate to cloud services, source control, or SaaS integrations, it is part of the attack surface whether or not it appears in the privileged-user report. These controls tend to break down in environments with fragmented ownership and hundreds of unmanaged service accounts because no single team can see the full identity graph.
Where the Model Breaks Down and What to Watch Next
Tighter protection for everyone often increases operational overhead, requiring organisations to balance stronger coverage against the reality of limited staff, legacy systems, and business-critical automation. That tradeoff is real, but selective protection usually creates hidden cost later through incident response, recovery, and repeated exceptions.
Best practice is evolving toward risk-based coverage with no identity class left outside governance, even if the depth of controls varies by exposure. Some low-risk accounts may not need the same approval workflow as domain admins, but they still need ownership, logging, and revocation paths. Guidance also differs for third-party access: current practice suggests treating vendor-linked OAuth apps and API tokens as first-class identities because they often bypass normal user controls. NHIMG’s Schneider Electric credentials breach illustrates how credential exposure can spread through paths that were not originally scoped as “high-risk” by the organisation.
The practical test is simple: if an identity can authenticate, automate, or reach sensitive systems, it belongs in policy. Anything outside that boundary becomes the attacker’s preferred path.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Selective coverage leaves NHI inventory gaps and unmanaged identities. |
| NIST CSF 2.0 | PR.AC-4 | Consistent access control is the antidote to protecting only a subset of accounts. |
| NIST SP 800-63 | Identity assurance weakens when some accounts are excluded from standard controls. | |
| NIST AI RMF | GOVERN | Governance must cover the full identity surface, including machine and service accounts. |
| CSA MAESTRO | I2 | Agentic and automated workloads need coverage beyond a privileged subset. |
Use identity assurance and lifecycle controls for every identity class with the same governance model.
Related resources from NHI Mgmt Group
- What do security teams get wrong about protecting service accounts from interception?
- What do security teams get wrong about cyber resilience in identity-heavy environments?
- What do security teams get wrong about event based identity coordination?
- What do security teams get wrong about identity transformation programmes?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org