Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk Why do passwords and OTPs create persistent risk…
Governance, Ownership & Risk

Why do passwords and OTPs create persistent risk in enterprise identity programmes?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 24, 2026 Domain: Governance, Ownership & Risk

Passwords and OTPs are vulnerable because they can be shared, reused, stolen through phishing, or bypassed through social engineering and approval fatigue. They also do not prove device trust. In cloud and hybrid environments, those weaknesses scale quickly, so organisations need stronger cryptographic authentication that reduces account takeover and limits reliance on user memory or repeated prompts.

Why This Matters for Security Teams

Passwords and OTPs look familiar, but familiarity is not resilience. In enterprise identity programmes, they create a durable attack surface because they depend on human memory, user behaviour, and repeated challenge prompts that attackers can manipulate. Once credentials are phished, reused, or socially engineered, the security model often degrades into who can be tricked fastest rather than who should be trusted. NIST’s Cybersecurity Framework 2.0 treats identity as a core control plane, yet many organisations still anchor access decisions to factors that are easy to intercept, relay, or fatigue into approval.

That risk becomes especially visible when secret sprawl and weak governance intersect. NHIMG’s Ultimate Guide to NHIs shows how common it is for organisations to store credentials outside managed systems, which is a useful reminder that authentication weaknesses rarely stay isolated to one login flow. For identity teams, the practical problem is not just one compromised password, but the way the same weak pattern propagates across cloud apps, admin portals, scripts, and service access paths. In practice, many security teams discover the breadth of password and OTP exposure only after a phishing chain or MFA-bypass incident has already turned into account takeover.

How It Works in Practice

The operational issue is that passwords and OTPs authenticate a moment, not a trustworthy device, workload, or session. A password proves only that someone knows a shared secret. An OTP proves that a code was received or generated, but not that the endpoint presenting it is trustworthy, uncompromised, or resistant to relay attacks. This is why current guidance increasingly favours phishing-resistant authentication, device-bound credentials, and stronger session controls rather than repeated prompts that simply add friction.

In mature programmes, teams reduce persistent risk by layering controls around the login event:

  • Replace reusable secrets with phishing-resistant methods where possible, such as cryptographic authenticators that bind the session to a device.
  • Limit OTP use to lower-risk or transitional scenarios, then phase toward stronger methods for privileged and remote access.
  • Shorten session lifetimes and re-evaluate trust when risk changes, rather than assuming the original login remains valid indefinitely.
  • Monitor for impossible travel, prompt fatigue, token replay, and suspicious approval patterns that indicate identity abuse.

This is also where NHIMG research matters operationally. The patterns documented in the 52 NHI Breaches Analysis and the JetBrains GitHub plugin token exposure reinforce a broader lesson: once a secret is portable, it becomes shareable, replayable, and hard to contain. Passwords and OTPs extend that portability to human identity flows, which is why the security outcome often depends more on detection and recovery than on the authentication method alone. These controls tend to break down in hybrid environments with legacy apps, shared admin accounts, and help-desk reset workflows because those conditions preserve fallback paths that attackers can abuse.

Common Variations and Edge Cases

Tighter authentication often increases user friction and support load, requiring organisations to balance stronger assurance against operational continuity. That tradeoff is real, especially in environments with contractors, frontline staff, or legacy systems that cannot yet support modern authenticators. There is no universal standard for every application path, so best practice is evolving toward risk-based segmentation rather than a single rule for all users.

One common exception is recovery. Even strong authentication can be undermined if password reset, OTP fallback, or service desk verification remains weak. Another edge case is third-party access, where partner portals and shared support channels often lag behind internal identity standards. In those contexts, identity teams should treat fallback workflows as production attack paths, not administrative conveniences. The Top 10 NHI Issues illustrates the same governance gap from a non-human perspective: security controls fail when ownership, lifecycle, and revocation are unclear. For human identity programmes, the equivalent fix is to remove static secrets, reduce recovery exceptions, and make stronger authentication the default for high-value access. Organisations that still rely on password resets plus OTPs as the main safety net usually find that the safety net is exactly where attackers land.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-01Identity proofing and auth strength are central to password and OTP risk.
NIST SP 800-63AAL2OTP weaknesses are addressed by assurance level guidance and phishing resistance.
NIST Zero Trust (SP 800-207)4.1Zero Trust requires continuous verification beyond a one-time password check.
OWASP Non-Human Identity Top 10NHI-01Password and OTP sprawl mirrors weak secret handling across identity assets.
NIST AI RMFGOVERNIdentity risk must be governed as a lifecycle issue, not just a login issue.

Map high-risk access to stronger authentication and reduce reliance on shared secrets.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org