Non-human identities now form the core of modern digital ecosystems, driving automation, microservices, and cloud-native operations. Yet most organizations lack cohesive strategies to manage these short-lived, highly privileged entities. This webinar explores the scale, complexity, and security risks posed by unmanaged machine identities and outlines a strategic governance approach that integrates lifecycle automation, policy enforcement, and real-time detection to strengthen enterprise security and operational agility.
Nitish Deshpande, Research Analyst at KuppingerCole Analysts will share the realities of today’s NHI landscape, covering the limitations of legacy IAM/PAM tools and the critical need for purpose-built NHI governance. He will highlight the top 5 steps necessary for securing NHIs. Nitish will also discuss the results from the latest KuppingerCole Leadership Compass on Non-Human Identity Management. This webinar is designed for IT leaders and IAM specialists seeking insights into the current NHI landscape.
Hello everyone, welcome to today's KuppingerCole webinar on securing the rise of non-human identities. My name is Nitish Deshpande, I'm a research analyst or KuppingerCole analyst and in today's webinar we will take a look at what are some of the challenges when it comes to NHIs, what are the measures that can be taken to address these challenges and also we will give you a short glimpse into the results of our 2025 Leadership Compass on Non-Human Identities.
So I will be presenting some results from that report towards the end of this webinar so stay tuned towards the end and I think we'll have some interesting results. Before we begin here's some quick housekeeping rules for everyone. So you all are muted centrally, you don't need to mute or unmute yourself, we are controlling these features.
As always we try to keep these webinars very interactive so we will be running a few polls during this webinar and I would like to encourage all our attendees to participate in these polls, provide your opinions and we will discuss the results of these polls towards the end of the webinar which is the Q&A session. So also if you have any questions during the webinar you can enter those questions at any time using the Livestorm control panel and we will try to answer as many questions as possible in the given time.
And finally we are recording this webinar so the presentation and the recording will be made available for download in the coming days. So here's a quick look at the agenda. So first I want to start by addressing what are NHIs, what are the challenges, how to govern these NHIs and also what is the future of AI in terms of NHIs and what we also see as some of the requirements in the market regarding NHI management. Second we will take a look at how we go through the Leadership Compass process and also I will share the results of the 2025 NHI Leadership Compass and finally the Q&A session.
But first before we begin I would like to start with the first poll of today's webinar. What is the current ratio of NHIs versus human identities in your organization? Is it first? Don't know. Is it second? NHIs are 0 to 20 times more than human identities. Is it third? Is it 20 to 50 times NHIs that is more than human identities? Or is it fourth where NHIs are exceeding human identities by more than 50 times? You can select the option of your choice using the control panel and I look forward to seeing the results towards the end. So why do NHIs represent such a big challenge?
Well first many are invisible to the traditional IM tools. They are often unmanaged with static credentials. They have overprivileged access and also they have a very weak governance. And what this leads to is consequences such as breaches, compliance failures and ultimately you can say loss of trust with customers and stakeholders. So the core problem is that how do we securely authenticate, authorize and govern NHIs at scale? When they behave very differently from humans.
So before we go into that we need to first ask ourselves some questions such as are the NHIs already outnumbering human identities in your environment? Is the AI adoption accelerating this imbalance? And without zero trust for NHIs would they become the weakest link? So once you have answered these questions you can then go towards the next step which is addressing some of the risks of NHIs and the possibilities of governing them and managing them. Over here I have outlined some of the key risks which have been outlined in OWASP.
So they vary from various domains such as improper onboarding where NHIs are left active when the owner of the NHI is no longer in use which kind of impedes the attack surface. Secrets leakage is another risk where sensitive credentials leak via source code. Vulnerable third-party NHIs as well. You have third-party tools that are not integrated into workflows and external NHIs may have elevated permissions. Elevated permissions is again another huge risk when it comes to NHIs. Your core permissions could give attackers excessive access.
Excess entitlements can also make it difficult for auditing. Long live secrets is another one. Your secrets with distant expiration which gives attackers prolonged access if compromised. You have NHI reuse where multiple applications are reusing the NHIs which increases the blast radius and human use of NHIs as well as using NHIs for manual tasks and make actions indistinguishable from automated. And overall these several risks can lead to several failures as discussed earlier. So how do we go and address some of these risks? We start that by first securing NHIs in the step by step process.
It's a five step process to govern the NHIs where we answer some questions around what to do and how to close this gap. The first is discovery and classification. This is one of the most crucial aspects of NHM lifecycle management you can say. You have to map all the accounts across various environments. You have to categorize them by function and risk and assign ownership. This journey from discovery, inventory, classification to ownership is a very crucial aspect and which is where most of the organizations were in 2025.
Once you have identified the owner, next is then enforcing least privilege. Grant only the required rights for each NHIs purpose. Just-in-time and time-bound access can also go a long way in ensuring proper governance of these NHIs. Regular access reviews and revoking excess entitlements is again another way of monitoring these NHIs. And finally it's about involving humans for approvals where there are some critical applications and critical operations. So especially for AI agent operations where the AI agents are kind of like a hybrid identity.
They are an NHI but they sometimes act on behalf of human identities so there's a blur between their operations. So we need to have some sort of human in the loop for approvals when it comes to that. Then you have the secrets management part as well. Hard-coded tokens are static, exposed, and hard to rotate and they are risky. So you need to use secure vaults for rotation, revocation, and auditable protection. You need to automate key renewal and revocation of secrets for this minimum exposure. Then the fourth step is about monitoring and auditing.
You need to have a continuous logging of all NHI activity especially for NHIs which are growing and multiplying at a rapid rate. You need to have a continuous monitoring system for detecting anomalies and using behavior analytics as well. Integration of NHI logs into SIEM and SOAR platforms is also recommended for a more centralized monitoring and escalating critical actions for human authorization when anomalies or high risk requests from NHIs are requested. And this again comes back to then monitoring the behavior analytics.
And finally it's about identifying unused or abandoned NHIs and tracking and decommission active NHIs owned by orphaned human accounts. Once we have done this five-step process of governing the NHIs, then that can lead to good results. But even after you are performing, when you are performing these functions, there could be some challenges coming in this process. And some of the key challenges if we take into account in this process, let's say for discovery for example, many NHIs are undocumented that remain hidden.
So you need a strong discovery process as well and that leads to the classification ownership. If you do not have clear accountability of who creates this NHI, who owns these NHIs, you cannot enforce the right types of rules, governance and management on these NHIs. Posture management where all privileged or static permissions granted in active accounts remain dominant. Secrets and credentials in this space, secret rotations and hard-coded tokens and API pose challenges.
While during the monitoring and the governance phase, anomaly detection and limited or also linked to NHI activity can increase your attack surface. And finally, having orphaned accounts still active in terms of the NHIs which they own can create security risks. So decommissioning, in the decommissioning phase, it is important to address some of these challenges.
But if you take a look at what is the NHI market right now and what the customers are looking for, so if you take the priorities and these priorities come from various reasons such as the traditional tools not being able to address some of these concerns and the first one being unified discovery and automated remediation. So organizations can no longer afford fragmented visibility across cloud platforms, workloads and tools. So you need a single consistent way to identify every NHI, understand what it can access and automatically remediate risks without relying on manual interventions.
Second big shift is towards AI and machine learning driven detection and governance. With the scale and speed at which the NHIs are growing, as humans we simply cannot keep up with governing and monitoring every NHI individually. So we are seeing this rapid adoption of adaptive authentication, anomaly detection and even autonomous governance actions that can respond in real time to unusual behavior or misconfigurations. Another priority which we see in the market from the customers is reducing the risk introduced by static credentials.
That's where these just-in-time and ephemeral identities are coming in. So instead of long-lived secrets that sit exposed for months, identities are spun up when needed and disappear when the task is complete. This kind of drastically reduces the window of attack. We're also seeing organizations invest in broader integrations across the CI-CD pipelines, DevSecOps, multi-cloud environments and their enterprise SaaS ecosystems. So because NHIs don't operate in isolation, they move through the complex automation chain and governance needs to follow them across this entire life cycle.
And finally, there's a growing emphasis on advanced governance for NHIs and these AI agents. That means clearly assigning the ownership, enforcing consistent policies and automating as much as possible about the governance process as possible. And as AI agents become more and more dynamic in terms of decision-capable identities, which creates the need for having more stronger guardrails. So overall, the market is prioritizing automation, unified discovery, visibility, intelligence, and flexibility. So this is where then the Zero Trust becomes essential.
You need to apply Zero Trust principles to NHIs. We need a Zero Trust framework tailored for NHI, which means continuous authentication and authorization for every access request. Human approvals for sensitive operations, you need human in the loop. Fine-grained policies are needed so NHIs can do exactly what they need and no more or no less. And logging and monitoring for full traceability is also important. So just like the humans, trust has to be earned and re-verified at every step.
So to wrap up the message, I would say NHIs are here, they're growing, and they're growing at a faster rate than we think. So managing them isn't optional anymore. It's critical from security, compliance, and operational and trust point of view. And by applying lifecycle governance, enforcing least privilege, adopting these Zero Trust principles, we can get ahead of the curve and secure the future of identities in this age of AI. And as this AI adoption grows, the number of NHIs will grow. Every new AI-driven process spawns APIs, microservices, and bots.
These identities are often short-lived ephemeral, making them harder to track with traditional IAM tools. Actually, the complex web of dependencies in the AI ecosystems and governance becomes extremely difficult. So without adaptive automated governance, the attack surface expands dramatically. So it's not just about the scale, it's about the speed as well. So AI-driven systems move faster than traditional controls can keep up, and this will proportionately have an effect on how we manage NHIs.
I would like to then again introduce another poll in this webinar, and this is about the risks associated with the NHIs. So what risk concerns you most about an unmanaged NHIs? Is it vast privileged escalation? Is it second, orphaned or abandoned NHIs? Is it third, long-lived secrets? Or is it fourth, where multiple applications are using NHIs? You can again provide your votes in the control panel of the live stream, and we will take a look at the results of all the polls that we have done so far towards the end of the session.
We're coming towards the leadership compost process and the results from the 2025 NHI management leadership compost. Before we go towards the results, I would like to give a brief introduction on our methodology and the standard categories that we read in this leadership compost process.
The leadership compost process is a very comprehensive and detailed process where the first step is about research, where we identify the vendors relevant to that market, we conduct briefings and demonstrations with those vendors, and we also then receive a technical questionnaire which is very comprehensive to understand all the capabilities that are relevant about that vendor. Usually in most of the leadership composts, the number of vendors varies from 15, 20, it can sometimes go to 30 as well.
So we take all this information from all the vendors, go into the second phase which is the analysis phase, where we evaluate the information, create the draft of the report, and then we send an after regress interval checks, internal reviews, we send it for fact check to the vendors for review. And in this fact check process, the vendors can provide us with updates. So for example, the timeline from the research to fact check can be anywhere from two to three months, which is enough for vendors to provide maybe, add maybe new capabilities to the product.
So we also have this fact check process where we can take that into consideration. And once this has been agreed with all the vendors, the fact check, we then move on to publishing the report on www.trippinacole.com slash research. But when it comes to now this particular 2025 leadership compost report on NHI management, there are a few key findings which we encountered. And first is that this market has evolved and is rapidly maturing.
The NHIs we found after, after several conversations with several vendors, we found that the number which which was about NHIs in comparison to humanities were around 25 to 50 times. And these NHIs include various types of entities such as workloads, your Sunweak accounts, applications, containers, API keys, bots, scripts, secrets, devices as well. Poor governance of these NHIs such as unmanaged secrets, hard-coded credentials, and lack of ownership created a significant attack surface.
Vendors that are moving towards a more integrated lifecycle management, which includes the entire process from the discovery to decommissioning, were considered for this report. Integration with DevSec DevOps pipelines, CICD workflows, and infrastructure code has now become required core capability when it comes to evaluating vendors to provide NHI management capabilities. Other advanced features such as behavioral analytics, context-aware access, having a more dynamic risk scoring were proven to be quite differentiators between different NHI vendors.
So this market has, you can say, slightly trending towards a convergence between CIEM, secrets management, forming a more, you can say, a unified policy-driven identity security layer for NHIs, and maybe in the future we'll see a bit more convergence in these three domains. Let's take a look at some of the vendors which participated in the query to define a leadership composite and non-human identities. So on the left side, you have these rated vendors which participated, where they went through the process of briefings, questionnaires, analysis, fact check, and finally publishing.
So you can see it's a large list of vendors. On the right side, we have these vendors to want section. So these vendors we consider as important for this domain of NHI management, but they could not participate in this leadership composite due to various reasons such as timing or other commitments. But we have still considered them and they are mentioned in the report towards the end of the report. Here's the final picture after we've done the analysis of all the vendors. This is the final picture that we get about the NHI management solution providers.
On the right side, in the red section, you have the overall leaders. In the middle, you have the challengers, and on the right side, you have the followers. So overall leaders are basically the vendors which have strong product capabilities, they have strong innovative capabilities, and they also have a very good market presence. While in the challenger segment, you have vendors which have strong product capabilities and also maybe innovative capabilities, but they are maybe lacking some sort of market presence or maybe some sort of maybe basic or more advanced product capabilities.
In the follower segment, in this particular report, we don't have any vendor in the follower segment. So I think the vendors that you see in the challenger segment, we see them as advancing very rapidly and investing very heavily in their own product. And maybe in the next iteration, when we do this report, these vendors could possibly move towards the leader section as well. So I think if you take a quick look at the leader section, it includes NHI specialists, large vendors like Microsoft. While in the challenger segment, you have especially more NHI specialists involved in that segment.
There's another aspect where we go ahead and do much more deep dive into each product, each vendor, and we try to evaluate the product on several different capabilities. For example, if you take this vendor, for example, from the rated vendors, this vendor was rated on their NHI lifecycle management capabilities, on the architecture and deployment capabilities of the overall solution. You also have the secrets management capabilities that were taken into consideration.
Audit, reporting, compliance, monitoring, that was another part which was very relevant and very important for this leadership compose. So we were very much evaluated on their capabilities. Automation and intelligence, very important as we saw as the number of NHIs are growing so rapidly. There is a need from the market perspective to have more automation to manage these NHIs, their governance as well. DevOps and CI-CD integration, as mentioned, is again a very crucial capability that was found when we did our research.
Discovery and classification, it says discovery and classification, but I think the screenshot has slightly not the correct cropping, but discovery classification is overall a very important point we realized in the entire NHI lifecycle management because in the last year, mainly most of the vendors and the customers that we spoke to, they were in the phase of from the discovery to classification to ownership phase. So we had a very specific requirement to evaluate just the vendors on this capability to have more visibility into that.
And also access governance of all the NHI vendors on the capability of the product as well was taken into consideration on how these NHIs are governed and what principles they are governed. So we have this, we go much more deeper into each product, each vendor, and we have a very detailed report on each vendor in the entire report, which you can find in our website. It is live along with other documents, such as the BIOS confers on it as well. And I think that brings us now to Q&A session, but before we move to the Q&A session, I would like to quickly check the poll results if it's possible.
Let's check the first poll result. The first question was, what is the current ratio of NHIs versus human identities in your organization? And we have received really good, large number of votes. Thank you so much for that. And the most, you can say, common answer is 43 percent don't know, which is not surprising as during our conversations with vendors and customers, I think that was our common theme as well, is that organizations are still not aware how many NHIs they have in their system.
And that is why, again, the discovery and classification phase is very important from our point of view, is to first identify how many NHIs are there in your system, and then move towards the governance and management of these NHIs. The second common answer at 30 percent is 0 to 20 times NHIs more than humans, which is in line, again, with all we saw. And also 17 percent is for 20 to 50 times NHIs more than humans. So these are the fairly, I would say, common answers that align with our theme and our findings as well.
Second question we asked around was the risks, is what risk concerns you most about these unmanaged NHIs? And top answer that we have with almost 50 percent votes is privilege escalation, which I completely agree with that one, is that NHIs can very rapidly accumulate lots of privilege, they can get overprivileged, and so there is definitely a significant risk coming out of that. And that needs to be definitely addressed, and it can be done through the zero-trust principles that we mentioned earlier. Applying those principles, you can, to an extent, address this risk.
The second most common risk was, at 22 percent votes, is long-lived secrets, while multiple applications using NHIs and orphaned abandoned NHIs came out respectively, third and fourth. So thank you, thank you everyone, especially for participating in these polls and for providing your answers. I think now we can maybe quickly go through some of the questions as well.
So, okay, we have a question here already from chat here, is that should NHIs ever be allowed to request or escalate their own access? If so, how do we control the level of anonymity they have? And I think that's a very, very good question, is that should NHIs be allowed to?
Okay, so maybe, I think it depends on different use cases as well. So there are scenarios where NHIs need dynamic access, so, and if we allow NHIs to request access, the request must stay within those well-defined boundaries within those card rails. And it should be also defined by, let's say, pre-approved roles, time-limited evaluation, you need to have time-bound access, and also you need to have policy-based triggers as well. So the control layer needs to be extremely tight. You need card rails, like mandatory approvals for anything outside the baseline access.
But you also need automated, I think, policy checks and continuous monitoring, definitely. That is another crucial, important point for governing these NHIs. So the autonomy should be limited to what's maybe predictable, auditable, reversible, and if anything that is beyond that, if NHI performs any activity beyond that, then that becomes a risk, and that needs to be then very well-defined using the card rails and the boundaries as well. Let me go ahead and check if we have any other questions here.
Second question is, how can you ensure a human in the loop when you have multiple NHIs talking to NHIs talking to other multiple NHIs at scale and speed? That is, again, a very, very important question, a very good question as well is, the speed at which NHIs are growing and moving, having a human in the loop is definitely a very ideal scenario, but applying that practically at that scale where, as you mentioned, where multiple NHIs are constantly moving across environments, talking to other multiple NHIs at scale and multiplying as well, that will be definitely a challenge.
So I think it again goes back to first identifying your NHIs and then moving towards adding the necessary guardrails around those NHIs, which can then help you in ensuring which NHIs need human intervention, which NHIs can operate on their own. I think that's just two questions. We have a couple of minutes left. We have one more question for you is, how would you rate the content of this webinar? So please let us know how you feel about this webinar before I move towards the next slide, which is about sharing about our related research. We have a couple of minutes left.
I would like to use this couple of minutes to highlight our work in the NHI space. We have been very active in our research on NHIs. We have released several papers on NHIs, several advisory notes as well, and a blog post. So you can find all this content on our website and we will definitely be making this slide deck available for download later. So you can click on these links and access those documents.
But if you want to still go ahead before we share the deck, you can go ahead on the website and just type in the search bar about NHIs and you will have a wide variety of different kinds of content that addresses different kinds of needs and customers available on our website. Some promotional material here as well is we have several events coming up in this year, such as this NHI Impact Day, which will be focusing purely on discussing topics on NHIs. It takes place in Munich, Germany on October 7th. So you can secure a spot today using this QR code.
Also, these are on our different services that we provide around research events and advisory as well. I think we have just reached the end of the time perfectly. So if you have any questions, if I missed taking any questions, I saw there were some questions in the chat, but I'll be happy to take them offline. You can reach out to me on my email address or you can reach out to me via LinkedIn as well. So I look forward to continuing this conversation this year as well. And thank you everyone for your patience and your attendance and I will see you next time. Thank you.
See All Locations
See All Locations