Join our Newsletter — 33% off our NHI Course
Home Glossary Cyber Security Break and Inspect
Cyber Security

Break and Inspect

← Back to Glossary
By NHI Mgmt Group Updated September 1, 2026 Domain: Cyber Security

Break and inspect is a network security technique that intercepts traffic so it can be decrypted, examined, and re-encrypted. It is often used to monitor web activity, but it creates cost, complexity, and user friction. Because it works outside the session, it cannot fully govern how data is handled inside the browser.

Expanded Definition

Break and inspect is a traffic interception method that decrypts, examines, and then re-encrypts network data so security controls can apply policy inspection to sessions that would otherwise be opaque. In enterprise environments, it is most often deployed at secure web gateways, proxies, or inline firewalls to spot malware, credential theft, policy violations, and data exfiltration. For NHI governance, the concept matters because encrypted traffic often carries API calls, service-to-service requests, and automation tokens that influence how non-human identities behave across systems.

Definitions vary across vendors on how much session visibility this technique should provide and how aggressively privacy exceptions should be handled. No single standard governs this yet, so implementation usually reflects a local risk decision rather than a universally settled model. The control is distinct from endpoint telemetry or browser-level policy enforcement, which can observe or restrict activity inside the client rather than outside the session. The most common misapplication is treating break and inspect as a complete control for data use, which occurs when teams assume decrypted traffic visibility also governs what an agent, browser, or script does after the request is allowed.

Examples and Use Cases

Implementing break and inspect rigorously often introduces latency, certificate management overhead, and user trust concerns, requiring organisations to weigh inspection depth against operational friction.

  • Inspecting outbound web traffic from managed endpoints to detect credential harvesting pages before users submit secrets or tokens.
  • Monitoring API calls from automation platforms when service accounts reach external endpoints that may carry sensitive payloads.
  • Applying policy to cloud access traffic while allowing approved business sites to pass through with reduced inspection exceptions.
  • Detecting exfiltration attempts hidden inside encrypted sessions to file-sharing, messaging, or paste services.
  • Using session decryption alongside identity controls to reveal whether an NHI is making unusual requests that deserve investigation.

For broader NHI context, the Ultimate Guide to NHIs explains why visibility into service account behavior is often weak, while the NIST Cybersecurity Framework 2.0 provides a practical structure for aligning monitoring with governance and risk response.

Why It Matters in NHI Security

Break and inspect is relevant in NHI security because encrypted traffic frequently contains the very signals defenders need to understand whether a service account, API key, or agent is behaving normally. When teams cannot see inside sessions, they may miss exfiltration, misuse of privileged credentials, or abnormal automation paths that blend into routine traffic. That visibility gap becomes more serious when NHIs are overprivileged or poorly inventoried. NHIMG reports that only 5.7% of organisations have full visibility into their service accounts, which shows how often the problem is not just transport encryption but identity blind spots that sit behind it.

The security value is real, but so is the governance burden: certificate distribution, device trust exceptions, privacy review, and false positives all increase operational complexity. The technique is therefore most useful when paired with identity-centric controls, logging, and policy enforcement rather than treated as a standalone safeguard. Organisations typically encounter the consequences only after an alert, leak, or incident review reveals that encrypted traffic was concealing NHI abuse, at which point break and inspect becomes operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0DE.CM-1Break and inspect supports continuous monitoring of network traffic and anomalous activity.
NIST Zero Trust (SP 800-207)Zero Trust relies on traffic inspection plus policy enforcement, but never on encryption visibility alone.
OWASP Non-Human Identity Top 10NHI-05NHI visibility controls address how service account activity is monitored and investigated.
NIST AI RMFAI risk management covers monitoring, transparency, and operational controls for automated systems.
CSA MAESTROMAESTRO emphasizes runtime oversight for agentic systems that may act through encrypted channels.

Inspect encrypted sessions where needed, then correlate findings with identity telemetry and incident response.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 1, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org