Join our Newsletter — 33% off our NHI Course
Home Glossary Cyber Security Composite Attack
Cyber Security

Composite Attack

← Back to Glossary
By NHI Mgmt Group Updated August 27, 2026 Domain: Cyber Security

A composite attack is an intrusion pattern that links multiple smaller weaknesses into one working path to compromise an environment. Attackers use trust relationships, identity gaps, and cross-domain flaws together, which is why isolated control reviews often miss the full risk picture.

Expanded Definition

Composite attack describes a multi-step intrusion pattern in which individually modest weaknesses are chained into a single compromise path. In NHI and Agentic AI environments, that chain often crosses identity, secrets, orchestration, and trust boundaries, so the attack is not defined by one flaw but by how those flaws compose. That is why NHI Management Group treats the term as operational, not merely descriptive: the real risk emerges when a valid token, an overbroad role, an exposed API key, and an implicitly trusted workflow align. This is closely related to the logic behind the MITRE ATT&CK Enterprise Matrix, but composite attacks in NHI settings often rely more on identity persistence than on malware alone. Guidance in the industry is still evolving on where one “attack” ends and a chain of coordinated abuses begins, especially in agentic systems with delegated tool access. The most common misapplication is treating each control failure as separate and low severity, which occurs when teams review secrets, permissions, and trust relationships in isolation.

Examples and Use Cases

Implementing controls against composite attacks rigorously often introduces friction, because tighter identity boundaries can slow automation and require more governance over service-to-service access. The tradeoff is between fast integration and the ability to see how multiple low-grade weaknesses can combine into a high-impact breach.

  • A leaked API key is discovered in a CI/CD variable, then used to call internal tools through a service account that was granted broad permissions and never rotated.
  • An AI agent is allowed to invoke external tools, and a weak prompt filter becomes dangerous only after the agent also inherits an overprivileged NHI and access to sensitive secrets.
  • A third-party integration is trusted by default, but an exposed credential plus permissive network reach lets an attacker move from a vendor workflow into production data.
  • An attacker combines a public cloud secret leak with predictable token lifetimes, using the valid credential quickly enough to evade manual response windows, a pattern highlighted in LLMjacking: How Attackers Hijack AI Using Compromised NHIs.
  • Patterns in The 52 NHI Breaches Report show that identity abuse often becomes visible only after several smaller exposures have already been linked.

Composite attack analysis is strengthened when teams compare local findings with external threat models such as NIST SP 800-53 Rev 5 Security and Privacy Controls, which helps translate the chain into concrete control gaps.

Why It Matters in NHI Security

Composite attacks matter because NHI estates tend to be dense, interconnected, and over-permissioned. NHIMG research shows that 97% of NHIs carry excessive privileges and 80% of identity breaches involved compromised non-human identities such as service accounts and API keys. That combination makes “small” issues dangerous when they line up. The operational lesson from Ultimate Guide to NHIs — Why NHI Security Matters Now and Ultimate Guide to NHIs — Key Challenges and Risks is that visibility, rotation, offboarding, and least privilege cannot be governed as separate hygiene tasks if attackers are already chaining them. This is why composite attack thinking also aligns with the CISA cyber threat advisories approach to layered threat analysis and the MITRE ATLAS adversarial AI threat matrix when AI agents participate in the path.

Organisations typically encounter the full impact only after a routine alert reveals lateral movement, at which point composite attack analysis becomes operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-02Composite attacks often start with exposed or mismanaged secrets and credentials.
OWASP Agentic AI Top 10A2Agentic systems can chain tool access, trust, and prompt weaknesses into one intrusion path.
NIST CSF 2.0ID.RA-1Risk assessment must consider how separate weaknesses combine across identity boundaries.
NIST Zero Trust (SP 800-207)SC-7Zero Trust addresses composite attack paths by eliminating implicit trust between components.
NIST SP 800-63Identity assurance concepts help explain when credentials and authenticators are strong enough for risk.

Assess chained identity and access failures together, not as isolated findings, before prioritising remediation.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org