Non-Human Identities Explained: The Security Problem You Didn't Know You Had
In modern cloud-native organisations, non-human identities outnumber human identities by 100 to 1. That's not a typo. Here's what they are, why they're a problem, and why most companies don't even know they have them.
Non-Human Identities Explained: The Security Problem You Didn't Know You Had
Published: 2026-06-24 | Category: Cybersecurity & AI | Reading time: ~6 min | Sources cited below
There's a number that should keep every CISO awake at night 🌙: in modern cloud-native organisations, non-human identities outnumber human identities by 100 to 1. That's not a typo. 📈
For every employee with a login, there are roughly one hundred service accounts 🤖, API keys 🔑, workload identities ⚙️, OAuth apps 🔗, certificates 📜, and machine-to-machine credentials doing things on their behalf — most of them without anyone keeping track of who created them, what they're allowed to touch, or whether they're still even needed. 🫥
If you've never heard the term "non-human identity" before, that's the problem. 🧩 Because the attackers certainly have. 🎯
So what is an NHI, really? 🤔
A non-human identity is any digital identity that isn't tied to a human being. 🙅♂️ Think of it as the credential a thing uses instead of a person.
Common examples you've almost certainly got in your environment right now ⏰:
- A service account running a scheduled job that pulls reports from your CRM 📊
- An API key your billing system uses to talk to Stripe 💳
- An OAuth token letting Slack read files from your Google Drive 📁
- A workload identity your Kubernetes cluster uses to access your database 🗄️
- A certificate authenticating a microservice to another microservice 🔐
- An AI agent with persistent permissions to read your inbox and update your calendar 📅
These things log in. They make API calls. They move money. 💸 They read sensitive data. 📂 They write to production systems. 🔧 They do it 24/7, 365 days a year, without ever taking a holiday or forgetting their password. 🏖️
And until very recently, almost nobody was governing them properly. ❌
Why this matters right now 🆕
Microsoft's 2026 Secure Access Report found that 97% of organisations experienced an identity-related incident in the past year, with 70% of those incidents originating from AI-related activity. 🤖📉
That's a staggeringly high number. 📊 And the uncomfortable part is that most security teams still think about identity the way they did in 2010 — humans, usernames, passwords, MFA, done. ✅🔒
That model never really fit machines. 🧍♂️↔️🤖 And now that AI agents are acting on those machine credentials at scale 📈, the gap between what we can govern and what we actually have running in production is widening fast. 🌪️
GitGuardian's 2026 State of Secrets Sprawl report found 28.65 million hardcoded secrets were added to public GitHub in 2025 — that's a 34% year-on-year increase. 📈 Every one of those secrets is an NHI that nobody is watching. 👁️🗨️
How NHIs differ from human identities 🧍♂️ vs 🤖
It helps to make the difference explicit. 📋 Because a lot of the confusion around NHIs comes from trying to govern them with human-centric thinking. 🧠❌
Lifespan ⏳ — A human identity lives for the duration of employment. 📅 A non-human identity might live for the lifetime of the application, which could be 15 years. 📆 Or it might live for the duration of a single API call. ⚡ Both are normal.
Volume 📈 — An organisation might have 5,000 employees. 👥 It might have 500,000 NHIs. 📊 Different scale entirely.
Activity pattern 📡 — Humans log in during business hours. ☀️ NHIs run 24/7. 🌙 They don't take vacations. 🏖️ They don't sleep. 😴 They don't get suspicious login alerts because they always log in from the same place. 🏠
Visibility 👀 — A human leaving the company triggers an offboarding workflow. 🚪 An NHI being orphaned triggers nothing. 🫥 There's no HR system watching the service account. 👁️🗨️
Blast radius 💥 — When a human account is compromised, the attacker can do what that human could do. 👤 When an NHI is compromised, the attacker can do what the application could do — which is often far more than any individual human could. 🏢
This is why "just treat them like users" doesn't work as a strategy. ❌ They're not users. 👤❌ They're workloads. 🤖 And they need their own governance model. ✅
The breaches are already happening 💥
These aren't theoretical risks. Real incidents are landing in the news right now. 📰
- The U.S. Department of the Treasury breach started with a leaked machine identity. 🏛️
- Toyota was hit through an exposed service account credential. 🚗
- The New York Times had source code and infrastructure accessed via a mismanaged API key. 📰
In every case, the attacker didn't need to phish an employee 🎣 or break a firewall 🔥. They found a credential that was created years ago by someone who left the company 🚪, given far more access than it needed ⚖️, and then forgotten. 🫥
Sound familiar? 👀 That's because almost every organisation has the same problem. 🏢
The five flavours of NHI you should know 🍦
When security people talk about NHIs, they usually mean one of these categories. Knowing which one you're looking at matters because each one is governed differently. 🔍
1. Service accounts 🛠️ — long-lived identities for applications and automation 2. API keys and tokens 🔑 — the most common, and the most leaked 3. Workload identities ⚙️ — short-lived credentials for cloud-native workloads (Kubernetes, Lambda, containers) 4. OAuth apps and integrations 🔗 — third-party tools that act on your behalf in SaaS platforms 5. AI agents 🤖 — the new category, where an LLM takes autonomous actions using the credentials above
The first four have been around for years. 📅 The fifth is what's making NHI governance a board-level conversation in 2026. 🎤
What "good" looks like (at a high level) ✅
You don't need to boil the ocean. 🌊 The basics, in order of impact: 📋
- Inventory 📋 — know what NHIs exist in your environment. You can't govern what you can't see. 👀
- Ownership 👤 — every NHI should have a human responsible for it. No orphan credentials. 🚫
- Least privilege 🎯 — give each NHI only the access it actually needs. Read-only when possible. 👁️
- Rotation 🔄 — credentials should be short-lived and rotated regularly. Long-lived static secrets are the problem. ⏳
- Revocation 🛑 — when the workload or application is decommissioned, the identity dies with it. ⚰️
If you're doing those five things consistently, you're ahead of most organisations. 🏆
The regulatory clock is ticking ⏰
If commercial pressure isn't enough, regulatory pressure is arriving. 📜
- The EU's Digital Operational Resilience Act (DORA) — in force for financial entities since January 2025 — explicitly requires ICT third-party risk management that extends to machine identities used by service providers. 🏦
- The SEC's new cybersecurity disclosure rules require public companies to disclose material incidents within four business days. 📅 When a leaked service account is the entry point, "we didn't know about it" is no longer a defensible position. ❌
- ISO 27001:2022 added controls specifically for secrets management and privileged access rights — including for non-human accounts. 📋
- The NIST Cybersecurity Framework 2.0 (released 2024) added a "Govern" function that explicitly covers identity and access management for all identity types — human and machine. 🏛️
The frameworks are catching up to a problem the industry already had. 🏃 What's new is that auditors are now checking. 👀 The "we'll fix it next quarter" answer is becoming harder to give when DORA, the SEC, and ISO auditors are asking pointed questions. 🎤
If you're an MSP serving regulated clients 🖥️, this is also your problem now. ⚠️ Your client's NHI posture affects their compliance posture. 🪪 And by extension, yours. 📋
What's coming next 🔮
This is the beginner piece. 📘 Over the next two articles I'll walk through what's actually breaking in production 🛠️ (intermediate), and the platform landscape emerging to fix it 🏗️ (advanced).
The short version? 📌 Non-human identity governance is now a recognised security category. 📂 In 2024 there was essentially $0 of venture funding for dedicated NHI platforms. 💰 By 2026 there are over ten. 🚀 The market is telling you something. 📣
The attackers already treat your service accounts as identities. 🎯 It's time the defenders did too. 🛡️
A quick self-assessment for your organisation ✅
Before you close this tab, here are five questions worth answering honestly. 🤔💯
1. Can you list every API key currently active in production right now? 🔑 If you can't, you're in the majority. 📊 2. Do you know which NHIs have access to your most sensitive data? 🗄️ Not "should have" — actually do. ⚠️ 3. When was the last time you rotated a long-lived service account credential? 🔄 If the answer is "I don't know," that's a finding. 📋 4. If a developer leaves tomorrow, do you know which machine credentials they created? 👋 If not, you have an orphaning problem. 🫥 5. Do you have a documented NHI lifecycle policy? 📝 Onboarding, rotation, decommissioning — the same way you have one for humans. 🧍♂️
If you answered "no" or "I don't know" to two or more of those, you're exactly the audience for the intermediate piece. 📖
The good news: 🟢 none of this requires ripping out your infrastructure. 🛠️ It requires inventory first 📋, then policy 📝, then tooling. 🛠️ In that order. 🔢
The bad news: 🔴 every week you delay, the surface grows. 📈 Because AI agents keep being deployed. 🚀 And every agent has credentials. 🪪
Sources: GitGuardian State of Secrets Sprawl 2026; GitGuardian IAM Strategy for Non-Human Identities 2026; Microsoft Secure Access Report 2026; CSO Online RSAC 2026 coverage; Cremit RSAC 2026 NHI Field Report; The Hacker News NHI coverage
Does your organisation have an inventory of its non-human identities? 🤔 If the honest answer is "probably not" 😅 — you're in good company. But you're also exposed. ⚠️ That's where the next article picks up.