Join our Newsletter — 33% off our NHI Course
Home Glossary Cyber Security High-Performance Computing
Cyber Security

High-Performance Computing

← Back to Glossary
By NHI Mgmt Group Updated August 27, 2026 Domain: Cyber Security

A computing model designed to run demanding workloads that need fast processing, specialised graphics, or large-scale parallel execution. In cloud environments, HPC often depends on powerful virtual machines, strict performance tuning, and careful access control so users can run heavy tasks without creating unnecessary security or cost risk.

Expanded Definition

High-performance computing, or HPC, is a computing model built to execute workloads that exceed the practical limits of standard systems by using parallel processing, specialised accelerators, high-throughput storage, and tightly tuned infrastructure. In NHI and cloud operations, HPC is not just about speed; it also creates a distinct identity and access pattern because jobs, schedulers, storage services, and automation often need credentials that can act at machine scale.

Definitions vary across vendors when HPC is discussed alongside cloud bursting, batch orchestration, or AI training clusters, so the term should be used precisely. NHI Management Group treats HPC as an execution environment where performance engineering and access governance must be designed together, especially when secrets, service accounts, and workload identities are used to submit jobs or reach shared datasets. For a standards-based security lens, the NIST Cybersecurity Framework 2.0 remains relevant because HPC programs still need asset visibility, protective controls, and recovery discipline even when the workload is highly specialised.

The most common misapplication is treating HPC credentials like ordinary user access, which occurs when automated jobs inherit broad, long-lived permissions that were never scoped for parallel execution.

Examples and Use Cases

Implementing HPC rigorously often introduces scheduling, network, and data-governance constraints, requiring organisations to weigh faster scientific or engineering output against tighter operational control.

  • Research clusters running genomic analysis use queued jobs that require workload identities to read large datasets without exposing reusable human credentials.
  • AI training environments on GPU nodes may need ephemeral access to object storage, which makes secret rotation and short-lived tokens operationally important.
  • Engineering simulations often depend on shared file systems and orchestrators, where a single mis-scoped service account can spread access across many nodes.
  • Hybrid cloud burst scenarios can move compute into temporary infrastructure, making identity federation and job-level authorization more important than static host trust.
  • Large batch pipelines may start through automation rather than a person, so offboarding a project requires revoking the workload paths described in the Ultimate Guide to NHIs and aligning them with the trust model in the NIST Cybersecurity Framework 2.0.

HPC is therefore not only a performance architecture but also an identity-heavy operating model, especially when schedulers and automation agents need to move data between secure zones.

Why It Matters in NHI Security

HPC matters in NHI security because its scale magnifies small identity mistakes into broad exposure. A single overprivileged service account can grant many jobs access to datasets, internal APIs, or build systems, and shared compute fabric often makes those permissions harder to detect. NHI Management Group reports that 97% of NHIs carry excessive privileges, which is especially consequential in HPC environments where parallel tasks can fan out those privileges quickly. The same body of research also shows that only 5.7% of organisations have full visibility into their service accounts, a visibility gap that becomes more dangerous when thousands of compute jobs are launched automatically.

Practitioners should treat HPC as a Zero Trust problem as much as a compute problem, with strong job authentication, short-lived credentials, and clear separation between orchestration, storage, and execution roles. The most common failure mode is not a lack of compute capacity but an identity control that was assumed to be harmless because it only belonged to machines. Organisations typically encounter the true security cost only after a cluster compromise, at which point HPC identity governance becomes operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST Zero Trust (SP 800-207), NIST CSF 2.0, NIST SP 800-63 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-02HPC relies on service accounts and secrets whose sprawl is covered by NHI controls.
NIST Zero Trust (SP 800-207)SA-3HPC clusters need per-request trust and segmentation instead of implicit network trust.
NIST CSF 2.0PR.AC-4HPC access control maps to managing permissions for machines, jobs, and data pathways.
NIST SP 800-63AAL2HPC operator access and federated workflows often depend on assurance for credential handling.
NIST AI RMFHPC frequently underpins AI systems that need governance for high-risk compute and data access.

Apply zero trust to jobs, storage, and orchestration with explicit verification at every access point.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org