Secrets—from API tokens to X.509 keys, SSH keys, or passwords—and related objects such as X.509 certificates and SSH certificates are a primary target for attackers. Secrets are used by humans, workloads, and things. The rise of Non-Human Identity (NHI) Management, or what some call “machine identity management,” highlights the need for better management of secrets of all types. New types of secrets, such as FIDO2 tokens and passkeys, add to the challenge.
While there are many specialized solutions available—from password management to NHI management to Certificate Lifecycle Management (CLM) solutions—organizations are increasingly seeking approaches that provide insight into the state of security and governance across all secrets, and that deliver consistency and integration throughout the entire secrets lifecycle.
The LC Enterprise Secrets Management, which has been published recently, analyzes the solutions in this market. Martin Kuppinger, Principal Analyst at KuppingerCole Analysts, will present his perspective on the state of this market segment.