Join our Newsletter — 33% off our NHI Course
Home FAQ Threats, Abuse & Incident Response Why do dormant service accounts and unused APIs…
Threats, Abuse & Incident Response

Why do dormant service accounts and unused APIs create outsized risk in aviation environments?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 28, 2026 Domain: Threats, Abuse & Incident Response

Dormant identities often keep access long after the business need has ended, which makes them easy targets for misuse. In aviation, those accounts may still connect to maintenance, scheduling, or control systems, creating a low-visibility path into critical operations. Unused access also weakens accountability, because no one may realise the identity is still active until an incident occurs.

Why This Matters for Security Teams

Dormant service accounts and unused APIs are dangerous because they look low-priority while still holding real authority. In aviation, that authority often reaches maintenance scheduling, flight operations, baggage, identity, or support systems, where a forgotten credential can become a durable entry point. Current guidance from NIST Cybersecurity Framework 2.0 and NHIMG research both point to the same problem: visibility and lifecycle control are what prevent old access from becoming operational risk.

What makes aviation different is the blast radius. A dormant API may not be used daily, but if it still authenticates to a scheduling feed, maintenance platform, or integration hub, an attacker can exploit it without triggering the scrutiny reserved for interactive logins. NHIMG’s Ultimate Guide to NHIs — Key Challenges and Risks notes that 97% of NHIs carry excessive privileges, which is exactly why stale access is so valuable to an intruder.

In practice, many security teams encounter dormant NHI exposure only after an incident review shows an identity was still active months after the business owner had stopped using it, rather than through intentional lifecycle governance.

How It Works in Practice

The core issue is not just that a service account exists, but that it often keeps the same permissions, secrets, and network reach long after the original system dependency has changed. In aviation environments, these identities can connect to ticketing, maintenance, flight data exchange, cargo handling, or vendor integrations. If an account is unused but not revoked, it becomes an attractive foothold because it blends into routine machine traffic and may never appear in human access review lists. NHIMG’s Top 10 NHI Issues and Ultimate Guide to NHIs — What are Non-Human Identities both emphasise that machine identities need the same lifecycle discipline as human users, but with tighter automation.

Effective control usually combines inventory, usage analysis, and revocation:

  • Discover every service account, API key, certificate, and integration token across flight, maintenance, and operations tooling.
  • Measure last use, owner, system dependency, and privilege level, then classify dormant identities by business criticality.
  • Rotate or revoke secrets that have no verified current dependency, and replace static credentials with short-lived alternatives where possible.
  • Bind each identity to a clear owner and an explicit decommission path so “unused” does not mean “unknown.”
  • Use policy and logging to flag machine-to-machine activity that persists after the application or vendor contract has ended.

For controls, NIST SP 800-53 Rev. 5 Security and Privacy Controls supports least privilege, account management, and auditing practices that map well to NHI hygiene. These controls tend to break down when aviation organisations have fragmented ownership across airlines, airports, and third-party maintenance providers because no single team can confirm whether an identity is truly obsolete.

Common Variations and Edge Cases

Tighter revocation often increases operational overhead, requiring organisations to balance safety against the risk of breaking legacy integrations or safety-critical workflows. That tradeoff is real in aviation, where older systems may depend on long-lived credentials, vendor-managed endpoints, or interface contracts that were never designed for modern identity controls. Current guidance suggests phasing out those dependencies rather than accepting permanent exceptions, but there is no universal standard for this yet.

One common edge case is the “inactive but still required” account, such as a failover integration, disaster recovery connector, or maintenance vendor token that is rarely used but still necessary under defined conditions. Another is the API that appears unused because it has low volume, when in fact it supports seasonal or irregular operations. In both cases, the question is not whether traffic is visible today, but whether the identity is still intentionally trusted.

This is where governance matters as much as tooling. Aviation teams should review dormant access alongside contract renewals, system retirement, and privilege recertification, not as a one-time cleanup exercise. NHIMG’s 2024 ESG Report: Managing Non-Human Identities highlights that 72% of organisations have experienced or suspect an NHI breach, which reinforces the need to treat forgotten machine access as a standing risk, not a theoretical one.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST AI RMF, NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-03Dormant identities need lifecycle cleanup and secret rotation.
CSA MAESTROIAM-02Agent and workload identities must be governed through their full lifecycle.
NIST AI RMFGovernance and lifecycle accountability reduce unmanaged autonomous access risk.
NIST CSF 2.0PR.AC-1Access management must ensure only approved identities retain access.
NIST Zero Trust (SP 800-207)SC-7Zero trust limits blast radius when dormant identities are abused.

Inventory dormant NHIs, revoke unused access, and rotate any surviving secrets on a fixed schedule.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org