The focus of Identity and Access Management (IAM) is shifting beyond human identities. Non-human identities are proliferating and taking on new importance for identity and security managers in modern computing environments. From IoT devices and cloud workloads to bots and containerized services, the complexity and volume of these identities pose significant management challenges.
This session will explore the complexities of managing non-human identities and highlight the need for advanced tools, best practices, and a zero-trust approach to secure these critical identities without disrupting automation, governance, and compliance.
Join Matthias Reinwarth, IAM Practice Director at KuppingerCole; Dr. Heiko Klarl, an expert in Identity and Access Management (IAM); Lalit Choda, Founder of the Non-Human Identity Management Group; and Selen Memik Yılmaz, Head of Identity and Access Technologies at Garanti BBVA Teknoloji, for an insightful discussion on the challenges and innovations in managing non-human identities.
Moderated by Alejandro Leal, Research Analyst at KuppingerCole.
Hello. Welcome to today's webinar, Beyond Humans — Securing the Digital Frontier with Non-Human Identity Management. My name is Alejandro Leal. I'm a Senior Analyst at KuppingerCole, and this is one of the webinars to prepare the Road to EIC, where we will be having more conversations around this topic in May.
Today, I have a great lineup joining me. I'm going to let them introduce themselves.
So, first, we can start with Selen. How are you, Selen?
Thank you, Alejandro. I'm very fine. It's great to be here. Thank you for inviting me into this insightful topic and hard topic. I can introduce myself. My name is Selen Yılmaz. I'm the Head of Identity and Access Management Team in GarantiBBVA. GarantiBBVA is a private bank in Turkey, and it has 15 million customers and over 23,000 employees.
And also, GarantiBBVA is a part of BBVA Global. You know, maybe it's a global bank. And I hope we'll have fun with this topic. Thank you.
I hope so, too. Thank you, Selen. Happy to have you here with us.
Maybe, Lalit, you can tell us a little bit about yourself. Hi, everyone. I'm Lalit Chodha. I'm the founder of the Non-Human Identity Management Group. 30-plus years in the industry, mainly in investment banking, working on large global IM, PAM, and NHI programs. Recently finished a huge program at a huge bank, looking at NHIs, hundreds of thousands of them.
Last year, I formed the Non-Human Identity Management Group initially on LinkedIn, nearly 2,000 active members, and created probably the biggest knowledge center around NHIs in the industry, now known by the name Mr. NHI. Awesome. Thank you so much. Dr. Heiko? Yeah.
So, hi, everyone. I'm Heiko. I'm the CEO of Nexus, a leading software vendor for enterprise authorization governance. More than 20 years in the identity and access management space. Most of the time, not on the software vendor side, but in the consultancy and professional services side in various roles. And I did a lot of research and focus on non-human identities, NHI, during the last couple of months or the whole last year. Thank you. And last but not least, Matthias?
Yeah, thank you for having me, Alejandro. I'm Matthias. I'm the IAM practice director here at Copenhagen Coal. I'm with Copenhagen Coal for 10 years, but I'm in the industry since the mid of the 1990s, so then the term identity and access management did not exist, so it was directory services and all this kind of stuff. But I always did identity and access, and as an analyst and advisor, NHI, of course, is a topic that we as Copenhagen Coal have to have an eye on, and that's maybe the reason why I'm here.
So it's really something that is gaining traction, and as you said, Alejandro, we will have a track on this at EIC in Berlin in May, and I hope we have a great discussion with Mr. NHI and all the other experts here around. Awesome.
Well, thank you so much, everyone. Now to set the stage, maybe we can start with you, Matthias. First question, in your opinion, what has driven the rise of non-human identities, and why is their management now a critical priority in identity and access management?
Okay, maybe a starting point. I know there are lots of these arguments to say, okay, cloud and cloud native and all this orchestration part is the most important part, but I think the point where I want to start with is most or many of those are not yet new, and we just did not take proper care of those identities. So what we now think of non-human identities, I think they are around for quite a while. We put them into PAM and we put them into IGA and abusing, misusing IGA for that.
Finally, we understand that they are important and need to be taken care of, and that could be technical accounts and communication between two autonomous systems. But of course, the overall movement is towards more of those and much more of those through orchestration, but I think it's an issue that we just happily ignored for quite a while, but now it's really coming back to us and it's coming massive, and there are lots of other good reasons for that.
Absolutely, and as I was talking to you guys earlier, I'm currently doing some research on access management, and I did a report on that topic two years ago, and one of the trends that I see is that lots of vendors are talking about it now. It seems like it's a hot topic. They're trying to address it, but I'd like to know more about your thoughts on this, Lalit. Maybe you can tell us your opinion.
Yeah, look, I think, as Mattia said, this problem's been there ever since I started my career. My first dealings with NHIs were actually 25 years ago, right, when meeting SOCs, regulations around cycling passwords, and we struggled to do that in those days.
We didn't have vault solutions and had big issues, look, I think, definitely in the last five to 10 years with kind of cloud, SaaS, obviously all the on-prem, legacy, estate, containerization, microservices, and obviously API-based kind of interfaces, and obviously now with Gen AI that's coming is going to kind of take the NHI landscape to a much, much more concerning level. You know, we quote regularly, you know, NHIs outnumber humans 25 to 50x, and look, we're now seeing lots of breaches.
We reported 40 breaches late last year around NHIs over the last couple of years, and even yesterday, you know, there was a publication around nearly 24 million secrets found in public GitHub repos. So these NHIs now are easy to discover. It used to be more of an internal issue. It's now more of an external issue as well.
You know, hackers are discovering them, you know, and it's compromising not only clients but their third-party supply chain vendors as well. So, look, that's, I think, to the question of why this has risen and why now it's a challenge that we need to tackle. What's your take on that, Selen? When we come to this point, the systems have changed. We have lots of different systems, mainframe distributed systems, cloud systems like on-premise cloud, public cloud, and the application architecture has changed a lot.
And also, we have different kinds of devices in our environment. Eventually, we have to connect these devices, applications, and like automated secrets, robot users, and the ecosystem, I think, has expanded a lot.
So today, that's why we are dealing with non-human identities. Back then, it was like the users. Only there were users.
But today, there are lots of systems that have to connect to each other and talk to each other. And eventually, they have to authenticate to communicate with each other.
So today, we have lots of non-human identities in our environment. And I think, like we have in our finance, in our company, in finance systems, we always focused on the human identity, human users.
But today, we finally are aware of the non-human identity is more crucial than user identities. We have to govern them and make processes to govern and govern the lifecycle of them.
Because, like Dalit said, the numbers are huge, and we don't treat them like normal users. We first create the user, non-human user, and we don't think about it after the creation. They stay there. The secrets are everywhere, in files, in databases, anywhere. So the risk is huge, and the attack surface is very expanded. So it is critical to govern the lifecycle of non-human identities, like the human identities, at least like human identities. And I think the onboarding and offboarding processes are crucial. And another thing is the credential and secret management of non-human identities.
That's another critical point to manage. Like I said, the secrets and credentials are everywhere. So we have to manage them. We have to keep track on them and change them and put necessary policies and processes to govern them. Yes. What do you think, Heiko? Do you see some of the things that were already mentioned with the work that you do at Nexus? So basically, that was a great summary from the colleagues addressing different aspects. And basically, I think the development in IT and architecture across the last 10 or 15 years changed tremendously.
So we had, what Matthias said, systems in the past were used as a kind of app used, using an IGA for non-human identities or managing secrets in a PAM installation. We had a tremendous shift in how we do software applications or how we build software architectures. We went away from monolith architectures. We have a service-oriented architecture. We have so many services interacting together. We have the cloud ecosystem, and it's not just about shifting from a non-PAM data center into the cloud. It's also the design principle, how we build an architecture.
An architecture of application has changed tremendously. We have completely new possibilities. And with that new possibilities, so many things have outnumbered when we have system-to-system interaction.
And now, when we think about the trend in gen-AI, another layer is coming on top. What has not been mentioned yet is the thing from compliance and regulatory requirements that you have now in parts liability at the top management level if you have not taken care about securing your IT environments. We have a change in the geopolitical landscape. Cyber attacks have been rising. And so many different factors have influenced the need for addressing this very important topic that has been solved somehow, probably okay-ish working 10 to 15 years ago.
But now, with the modern ecosystem, it's basically not manageable with the tools from yesterday. Thank you for that. I think all of you provided great input, but maybe we can get a little bit more specific. And perhaps we can start with you, Heiko. What would you say are the biggest security risks associated with non-human identities? And where do you think organizations struggle the most? That's a good question.
So, first of all, it's probably discovery. So, figuring out, Lalit mentioned the GitHub scan, that 24 million, I think, tokens have been found.
So, basically, most organizations, frankly speaking, don't have a clue on where they really use non-human identities or whether they have secrets, certificates stored, built in code, probably provided to public code repositories as well. After you have discovered, I think, then you have to do the work, kind of ensuring vaulting, rotation, kind of that stuff.
So, ensuring a proper management with tools that are already there or on the market. But then the next step comes when we think about that non-human identities have outnumbered their identities, their human identities. And when you have a classical identity and access management background and you still have customers having challenges with managing human identities.
So, employees, partners, or customers, and you have, there are different numbers out in the market from outnumbering from 20 to a factor of 40 or even more. So, that's a tremendous amount.
So, basically, you have to think about processes in place on how you ensure a proper assignment of ownership, on how to ensure a proper delegation from the human's authorization to delegate some rights. And, for example, AWS VPC to a machine or human identity to make a deployment in a broader environment.
So, there are so many aspects to think of. And I think that's probably the most and the long lasting challenge to really change the processes on how things have been done into a more managed phase or managed approach for non-human identities in the future.
Maybe, Lalit, you can tell us about an example or a real use case that you encounter with an organization that surprised you when it comes to maybe misconceptions or people not understanding the security risks of non-human identities. Sure. And I think there's a question on this as well around understanding this a bit better.
Look, I would echo everything Heiko said. You know, look, in a nutshell, though, NHIs typically are unmanaged, right, and have very weak controls. They have high privileges.
You know, humans use them today. You know, we have lots of hard-coded passwords.
You know, we have lots of stale accounts that are out there that increase the surface area of risk. You know, excessive privileges, lack of cycling.
You know, we even see sharing of credentials. So, look, I'll give you a great example that occurred a number of years ago. I won't divulge where it was, but I get called by my CISO to say, look, we've got a major issue where there was a production incident that caused huge business impact. And we believe it's as a result of an NHI.
So, as me and some of our team investigated the issue, it turned out there was a human that knew the password for a non-human identity, like a technical account on a database. And they were trying to bypass kind of human PAM controls to use this account to do some activities. They were trying to do the work in UAT, but accidentally connected to production.
So, the first two issues were humans using non-human identities, which is against policies, to the same identity, logically was in production and non-production with the same password. Our CIO says, I want this password cycled immediately within the next 24 hours. It took us three weeks to cycle one password in production. Why? As we started speaking to the application team, they said, well, look, to cycle the password, we need to find out where are we using this password. We probably got many scripts, right? And we don't even know all the places where we've referenced this password.
If we cycle the password, some of our scripts might fail to operate. And we believe, by the way, a few years ago, we shared the password with other business applications.
So, even if we fix all of our hard-coded passwords and we cycle, we think other major business applications will also be impacted and break once the password cycled. So, we then had to put in monitoring controls on databases, look at who was logging in, from which IP addresses, which hosts. And we found potentially like around eight to 10 other applications that were all sharing the same NHI credentials. They all had to then move to their own unique credentials, fix all their code. And all this took three weeks just to cycle one password.
So, if you multiply that by the tens of thousands of passwords that are out there, hard-coded, this is a massive, massive problem for the industry and for any organization to solve. I hope that was a great example. It was. It was. Thank you. I'm aware that the audience is already asking some questions.
So, we're going to save those for perhaps the last 20 minutes because I have one more question for you guys. But before, I'd like to ask Mathias or Selene if you would like to add anything to what already has been said.
Actually, all the scenarios Lalit talked and explained to us, we get through them. We live them. And it was like I was living the situations when he was talking about the situations. I want to add one more thing to this. There's also a compliance issue with these for the regulations with our local banking regulations. It is strictly forbidden that any non-human identity without accountable.
So, it is very important for us to build an accountable ecosystem and to govern this accountable ecosystem. And it has to be always available. What do you mean with available? You have to manage the lifecycle of the accountable as well, like the identities. It's another part for us with the regulations. I can add this scenario for this topic. And maybe if I can add to that as well.
So, we are using the term NHI and this is just an umbrella term. There are lots of different types of non-human identities actually hiding under that umbrella. And I think if we look at some of those from IoT devices to OT devices, we've talked a lot about technical accounts with these hard-coded credentials somewhere in config files or in the code. They have different attack vectors that need to be taken care of containers, cloud instances. And with this move that we have in all of this that I just mentioned, more or less comes to machine-machine communication or system-system communication.
That's API communication. We are looking at REST. We are looking at API keys. And all of these different types of identities that are hiding under this NHI umbrella have their specific attack vectors and their security posture. And we need to make sure that we understand them individually as good as we think we should manage also the human identity. And I really, as an IAM, IGA guy, I really want to make sure that I reiterate on what Selen just said.
So, ownership, proper lifecycle management for people, having a successor in a role, making sure that there's not an abandoned NHI, whatever it may be. That is of utmost importance to make sure that there is a consecutive flow of responsible people for individual NHIs or for clusters of NHIs when we talk about orchestration and huge numbers of NHIs.
Thank you, Matias. Before we jump into the questions from the audience, I have one more question for you guys.
So far, we already introduced the concept of non-human identities. We briefly talked a little bit about the security risks.
So now, are there any solutions? What are the, let's say, how should organizations rethink traditional IAM approaches to govern and secure these identities? What would be the number one advice you would give to organizations? Maybe we can start with Lalit first.
Yeah, look, I think a lot's been mentioned about lifecycle processes. Look, I would say this is probably going to be the hardest challenge you're going to face in your IT career to solve. It's much more complex than dealing with human identity management. And because there are so many weak controls and lack of processes around how you provision, decommission, how you discover inventory, how you classify the ownership, the permissions, you're going to have a lot of hygiene issues with inactive accounts and shared accounts.
And then you've got to go on to securing, protecting the credentials, the hard-coded passwords, rotation. You need monitoring controls to understand is anyone inappropriately using your accounts, whether it's an external threat actor or someone internally, right? And then you've got to think longer term about prevent controls. How do you stop people checking in hard-coded secrets? How do you move to sort of just-in-time dynamic secrets and real-time threat protection?
You know, a lot of the issues we have today are because we have lots of static secrets, right? So longer term, moving to more of a zero-trust footing and ephemeral secrets is where we need to get to. But in terms of to your question around tooling, look, I've had experience, you know, at some major banks where we were able to use some existing tool sets and then supplement them with, you know, scanning tools and vaulting solutions to sort of, and our own in-house inventory solutions, cycling solutions, monitoring solutions.
But this is a really, really heavy uplift to try and do it yourself, build these solutions yourself. Look, there have been tooling that's kind of come through a lot of vendors in the last 18 to 24 months that are providing pure NHI solutions. There are some vendors that are now providing human, non-human solutions, and some PAM providers that are now pushing kind of NHIs as another angle to their offering. I would say some of the existing PAM IGA tool sets are not really designed, right, to meet all the low-cycle requirements of NHIs.
And that's why a number of products have emerged over the last few years. But we're going to see a lot of interesting kind of maturity in this space as all the existing vendors and new vendors all come together, converge. So my number one advice would be is, first, look at this as your overall strategy, your risk-based approach, focus on policies, governance. Don't think about a solution. That should be the last thing you do. You first need to think about how you're going to tackle this elephant in the room, taking a risk-based approach.
So come up with a structured strategy, understand your current maturity, and then think about how you start tackling this. You know, you can't do this in a year. It's a multi-year journey. So you need to plan for it properly. Understood. What do you think, Selene? Anything that you would like to tell an organization that has all these questions? I think the approach must be in a more holistic way.
The processes, the policies, the procedures we put in place for human identities should be in place for, at least these processes should be in place for non-human identities, like the least privilege controls or the zero-trust approach. And the whole lifecycle management and secret management, for the legacy approach, we only think about the human users. But we have to change our point of view and we have to include non-human identities as well in the whole process.
Like, I can give an example. We have lots of regulations, you know, and PCI DSS is one of the regulations for card management. So with this new regulation, PCI DSS version 4, a new regulation has come and it says that we have to make access reviews for also non-human identities. It's a new thing for us as a financial organization. We do access reviews for all users, but we didn't do access reviews for non-human identities before today. So we have to make the approach in a holistic way. What we do in place, what we put, the policies, the procedures should be put also for non-human identities.
What do you think, Heiko? Anything to add?
Yeah, so basically, let me just pick up a couple of things Lalit said. So with my consulting background, sort of clear advice, start with the strategy first. And as the topic is so large, you have to drive somehow a risk-based approach. You can't say, I buy now a tool and everything is solved. That would be wishful thinking and it would be great, but it won't solve your challenge immediately. So basically you start with a risk-based approach and identifying the highest risk areas for your business or for your IT and try to work on that and get rid of the risks on the one hand.
And on the other side, probably as a parallel stream, one is cleaning up the past. And this takes time, like cleaning up a dirty kitchen. The other thing is being or doing the right things in the future. And this thing should be driven in parallel. So you can work on cleaning up and de-risking your existing infrastructure, your existing IT architecture, your existing non-human identities. But at the same time, you can, in an HR way, step-by-step decrease the security posture of everything that you build new.
And you build a massive stack every year, new in your IT organization, in the sense of thinking about how to manage secrets in the right way, how to define ownership, how to define probably lightweight IMO, IGA and authorization processes on NHRIs. And then you can mature step-by-step, step-by-step. But I think that's probably the most important approach an organization can drive in the future.
Matthias, any last thoughts before we jump into the audience questions? Yeah, right. I think everything that was said is perfectly right. And I think what I want to add is actually the aspect of perception within an organization, that organizations actually get the message that they understand that there is this risk out there. And I hope that webinar and the EIC and everybody else and Mr.
NHI, who was talking about it, really raises attention to make sure that these non-human identities are understood as high-risk assets. And they need to be treated properly. And that is something where we really need to make sure that this is properly done. And then we come to automated lifecycle management for all these individual types of NHRIs that I mentioned earlier. And there are so many more. And everything that you just mentioned.
But first of all, if we currently talk to organizations and ask them how many of you are already executing a program, an effort to secure your non-human identities, I think the results will be far too low. And I think perception of this risk is maybe one of the most important advice that I can give to make sure that it's really taken care of, because there are more. We are taking care of human identities. We do phishing simulations. We train people. We have least privilege in our identity and access management in the IGA. We do recertification. Why don't we do it for our non-human identities?
And I think that is the advice I would like to give. Treat non-human identities at least as well as you do it for human identities. One thing I'd like to add that people should walk away. I did allude to it in the example I gave. A lot of people think of the NHRI problem as an external threat issue. And there's also been lots of big breaches.
But look, what I would say is, look, the use of NHRIs by your staff is happening right under your noses for BAU activities. And as we went on a big program to turn on PAM controls for our human users in production, we thought the job was done, right? We got our PAM controls. No one can get into production without a ticket. What did we see as we turned on monitoring controls of NHRIs? We saw a huge spike in people using NHRIs. They knew the passwords. They didn't like to use PAM controls, so they started to use NHRIs more and more, right?
So if you think you've solved the human problem, you've actually created a bigger NHRI problem. And actually, a lot of the issues, the reasons why programs kick off in a number of organizations is due to the internal issues of humans using NHRIs and all the implications, lack of repudiation, impacting books and records. People should remember this is a problem happening at the moment internally with your staff as well.
Thank you, Lalit. We have a lot of questions from the audience, and some of those questions have been voted two or three times, so I'm going to start with those. And I'm going to ask a question, and you can raise your hand if you would like to answer it. If no one does, then I will just choose somebody. Okay. The first question is, how do you see regulations like the EU's NIS2 and DORA shaping the future of non-human identity management?
All right, you both can take it. Maybe you can go first. I think Lalit was first. Let's go first.
Yeah, look. Obviously, Celene mentioned PCI DSS, which is now very real. And I mentioned SOX 25 years ago. Both of us being in the sort of financial industry, we've had to deal with regulators, the Fed, CBEST, the UK regulators, the MAS, Singapore Authority, and many other regulators. And I can tell you very clearly, having run a huge regulatory program for over three and a half years, the regulators came in, and they were asking very loaded questions. Do you have hard-coded passwords in your source code repos? Do you cycle your non-human identities? Do you have monitoring controls?
And many of these regulators, right, they perform testing, right, you know, red team testing. And the first thing they find, it's so easy, is hard-coded passwords in source code, right? Forget the public repos. There's actually eight times more chance of finding secrets in your internal private repos, right?
So, look, you know, as regulation comes and auditors and regulators, you're going to realize you've got a massive problem in front of you. And our advice would be, get in front of it before the regulators and auditors hit you, because when they do, you'll end up having to stop all your activities just to focus on this one problem.
So, that would be just some of my initial opening thoughts on regulatory implications. I'll hand it over to you. Thank you. Adding on what Lalit has said, so often IT folks see regulatory requirements or standards as a kind of burden.
Oh, we have to implement this. This is yet another requirement on my bucket list I have to fulfill in my release. You can see it from a different point of view as well or frame it for yourself. From my point of view, it's not a burden, but it helps you as an organization to clean up the room, to do the right things.
So, the maturity of the contents of a regulation is really helpful for you as an organization to get things sorted, to follow state-of-the-art requirements or state-of-the-art approaches, implementation procedures, and so on. So, this can be really helpful to follow the standards. And when you are working in an IT department or a business department, the good thing is when you have been probably an evangelist or an advocate for doing things right in the past, you probably never had the support to get your things prioritized.
So, there is always timing constraints, budget constraints, constraints of the delivery team. And so often, organizations tend to go features first, features for the customers, features for my product, features for my processes, and the rest, like security, can probably wait a little bit until there is time, but there won't be never time for implementing it. But when you have now the support from an official side outside the company, from a law, from a regulatory requirement, you can involve your whole management chain.
You can involve the CISO, you can involve your CFO to de-risk the company in the sense of, okay, when we are compliant to standard, we reduce our risk for the enterprise. And the risk can be numbered in financial figures. We de-risk our risk exposure by a couple of million euros by year. And then you have a good argument in the sense of supporting your initiatives. And I think that might be very helpful for so many in operational roles to use this play and seeing regulatory requirements as friends and as a support for getting the right things implemented in your IT organization.
Thank you for answering that question. We have another question that received three votes.
So, what would be the authentication mechanism for non-humans in the future? Okay, I'm going to choose Matthias.
Yeah, I was just raising my hand. So, all good. I think we need to understand, again, which types of identities there are. If we are looking, for example, at machine-to-machine communication, then we need to make sure that we secure the bearer tokens that we are looking at. And these are API keys.
So, I think API keys won't go away. The question is, where do we store them? Maybe their secrets management is the right place to use that. And we need to have a proper protection of the communication channel.
So, that would be one example of securing authentication and parts of authorization as well properly for one type of NHI. And I think others might be much more difficult, but this would be one example.
So, really having proper secrets management for API keys and securing communication in transit, that would be a good starting point. Thank you, Matthias. The next question says, what is your stance on we just block interactive login for our technical accounts and be done with, especially as we see API keys and tokens being leaked on large scale almost weekly? Dalit?
Yeah, look, I've got a lot of experience dealing with this term interactive login. I guess folks that are maybe used to the Unix, Linux environments and some of the technical accounts there, you know, you have the ability to have interactive login. And this is part of like your PAM processes, right? You can SU, sudo to a technical account and impersonate. The same can be done for Windows admin accounts. And this is the standard mechanism. Historically, on some of our legacy on-prem environments, right, where you would potentially be able to do support. There's an issue with your application.
It's running out of memory, right? So, you would sudo to that technical account using interactive login.
So, definitely one of the best principles, controls, guidelines you have is to turn off interactive login for your service accounts, for your technical accounts, right? Generally, that shouldn't be required.
And, you know, we did that at one of our previous organizations. But that's just tip of the iceberg because you've got databases, right, that have local accounts, right, that you can't turn off. There's no concept of enabling or disabling interactive login.
You know, all the API keys and tokens, they're just strings, right? You don't need, they don't really have concepts of interactive login. You just know it's like a password, right? If you know the API key, you can interact with an API or a service, right?
So, interactive logins on their own is just one small part of the problem. It's not going to fix this issue. And usually, PAM controls the ones that handle interactive logins. Our problems are much, much bigger for the broader scope of NHI, as Matthias mentioned earlier. Thank you. The next question, I believe we talked about a use case earlier. But this user is asking, as I am new to the topic and to better understand the peculiarities of the problem, is it possible to give an example of a user scenario? How was it handled before and what would be the path forward to avoid the problem?
I think we did cover in that example before, but look, I think the biggest issue today is with the static secrets, right? They're hard coded. There's no ownership. They're not cycled. They're shared. The same credential is used in production, non-production. They have excessive privileges, right?
So, these are all the fundamental issues around NHIs. So, the biggest problems we have are the fact these are static and then we have to do a lot of work to fix those issues. Put the credentials, the secrets into a secret vault, cycling where you break something unless you know all the dependencies.
So, really, that's kind of the old way. And as some folks have touched on, what you need to move to is a zero-trust model using dynamic secrets, ephemeral, just-in-time secrets. And that way, you know, if someone has your key, you know, it's out of date immediately, right? Because you're dynamically creating and authenticating and authorizing, you know, a service-to-service interaction. And that's the way we need to go.
And I think, especially as we now move on to kind of gen AI, agentic AI, to Aiko's point, whilst fixing all the static credentials is going to be a problem that you need to get and manage in a risk-based approach, at least for your more new stuff, the shiny new AI stuff, you should be using the best of breed in terms of zero-trust models. So, at least, you know, the AI solutions that even have more privileges and are going to create more AI and more NHIs are better protected.
And we've already seen our group reported three major breaches, right, on AI LLM agents where people use the AI API keys that they discovered, took over and made the AI LLM models do things like dark role-playing, right? So, definitely for AI, NHI controls needs to be using zero-trust techniques. Matthias?
Yeah, and maybe to add to that, and Lalit mentioned that already, there are lots of these hard-coded secrets around. And the question was how, what would be the path forward to avoid the problem? First of all, avoiding would be making things better or having better practices, better processes around. But Heiko mentioned cleaning up the kitchen, or I think of cleaning up the basement because everything is hidden down there. And we need, first of all, to find these issues that are around and that pose these threats.
And just, you can only manage what you understand. This is a truism, I know that. But first of all, you have to find these dangers that are already around. And there are tools for that. There are discovery tools. They're not perfect, but they can support you. And once you know what you have, then you can apply this risk-based approach that Heiko mentioned. First of all, you need to have some kind of inventory of what to clean up and what the risk level is. And then you can continue from there.
Of course, you need to have better processes for new NHIs. That is obviously clear with proper lifecycle management, with clear joiners and levers for each individual type of NHI. But cleaning up, doing the homework first, and this is a boring and tedious work, I get that. That would be a starting point, because having old threats lying around in the basement doesn't help. It's a problem when you still are better in the new processes. So cleaning up, I think, is important. And the older an organization is, the bigger the development team is, the larger the basement is.
Just to quickly add on that, we had hundreds of thousands of NHIs at a previous financial organization. Just to tackle the ownership problem that Celene mentioned earlier took us three years. There were like thousands of thousands of NHIs that no one knew who created them. Are they still in use? So back to the housekeeping, the hygiene, very important. Clean up and reduce the surface area risk as much as you can before you start remediating.
Adding on that, when you just think about the complexity of assigning ownership, which is a complexity on its own, if you just go one step further and think about assigning authorizations, so what is the NHI really allowed to do, then the complexity increases or basically explodes. We think, also in the audience, that there are area managers, department managers out, who have already a problem doing a proper recertification for the team members. What are they allowed to do in certain IT systems? And then we are talking about 30, 50, probably 100 people and colleagues, human beings.
They work day by day together, where you basically expect, oh, the manager knows what his team should be doing. And it's a very complex and complicated task. If you transform this into an NHI world, where you have a token, which is allowed to do some actions in a cloud environment, where you basically have no clue that this action even exists, then the problem gets so many facets that are really hard to manage.
Heiko, you mentioned a good thing, because we are currently dealing with this. We are trying to make access certifications for service users that are used in PCI DSS regulated platforms. And no one wants to decide whether the privilege is okay or not. We are dealing with all the service users one by one and trying to understand what are the users for and are the privileges enough or the users are overprivileged for these tasks. The accountables also have the tendency to say, okay, this is the deeded privilege, don't touch them. If you touch them, the systems will fail.
We don't want to be accountable for this. And it's a huge work and it's very hard. Just to add quickly on that, 20 years ago, meeting SOCKS requirements around password cycling, we were failing as an organization to do it. No one wanted to cycle, things would break, all the hard-coded passwords. We didn't have vaults. So what did we do? We actually started monitoring on databases, the usage patterns. And we found nearly 90% of our SOCKS accounts, SOCKS cares about rights, updating data, books and records. And we found 90% of the NHIs that had right privileges were only doing reads.
So we reclassified those accounts from write to read and we reduced our surface area risk by 90%, reduced our cycling requirements by 90%. So overprivileging, making things from write to read, again, help you de-risk massively in your organization. So these are the kind of techniques you should focus on to take that risk-based approach. Yes. And for also lifecycle management and the privilege part, we have to make automated processes and auto-discoveries, like you mentioned. If you don't do these automated or discovery processes, we cannot go through with the accountables or the system owners.
Thank you, everyone, for all this information. There was a question on discovery, actually.
So maybe, Selene, if you have something to add. The question is, are there specific tools or methodologies for the discovery part? I can say we are using a CyberArk DNA tool for discovery to discover the accounts that are used in operating systems and if they have the privileges or the proper privileges, and if they are open to some attacks or hash-to-pass attacks. I have an experience in that. But maybe there are furthermore discovery tools my colleagues can add.
Yeah, look, I wrote a huge white paper on this topic, including discovery. Look, there's kind of discovery of the NHIs themselves, right, which can be very challenging. I guess in cloud environments, it's much easier to kind of discover things. But in the sort of legacy on-prem environments, you need to have endpoint connectivity. You may have local accounts on servers, databases. So the discovery challenge is really, really difficult there.
I think the other discovery side is how do you find out about the hard-coded passwords, right, that are scattered all over your repos and your confluence and your Slack channels. And to that, there are tools, for example, that are dedicated scanning tools. You have Git leaks that you get out of the box. But there are other vendors that do quite good scanning, but you do end up having a lot of false positives as well. And some of the new kind of NHI vendors try and make discovery easy, at least for the environments that are easy to connect to and discover from.
But anyone that's got lots of large legacy on-prem kind of estates, local accounts, lots of directory services, identity providers, discovery is a non-trivial exercise. And, you know, one of our orgs, we spent many years building endpoint connectors to get full visibility. And even once you get the visibility, the next step is what's the privilege, as Heiko said. When was the account last used? Is it stale? Does it have write permissions, read permissions? So discovery and the privileges that those accounts have is a massive, massive problem.
And as Matthias said, it's probably one of the biggest things you should focus on, discover and then understand the size of the problem and the risk that you have. Thank you. Since we're running out of time, we have eight minutes left. So maybe just one more question and I will let each of you answer it. This question got four votes, so I believe it's relevant for many people in the audience. For organizations just beginning to address non-human identity security, what are the first three actions they should take? Maybe we can start first with Selene.
I think the first action is to know and discover what you have in place. Like Matthias said, if you have legacy systems in place and you are running the systems for a long time, the basement is full and first you have to see what you have. You have to discover and learn if they are still used, orphaned or stale accounts. First to know your system. And then the second thing to make is to manage the secrets.
I think first discover and learn whether it is used in the system or orphaned or stale and then manage the secrets with a tool and make sure that the secrets are not in files or in codes in some places that people can see and use. And I think the last part is, the third part is to make well-defined and governed processes to make the new coming non-human identities be well-governed and well-processed.
Thank you, Selene. Heiko, any takes on that? So a bit overlapping what Selene has said. So start with a strategy. Make a clear plan towards the future. That's number one. Then when you look to the past, try to de-risk as much as possible. Identify quick wins. Identify things you can easily achieve. Probably balance it out between time and effort and the business value reach so that you get the most out of it in cleaning up the foundation or cleaning up the kitchen. And for the future, do the right things and start as of tomorrow. So don't try to do what often enterprise organizations try to do.
They're starting a project and producing paperwork for too long. But you can decide, okay, from tomorrow on, we stop doing this. And from tomorrow on, we start doing this. Probably build a flagship team within the organization. And the earlier you start, the better it is. And then you can kind of inherit this new behavior, these new procedures when they have proven step-by-step to other teams so that you avoid building up the kind of ballast still in the future. Then it's just about cleaning the past and doing the right things in the future. Thank you.
Before I give the floor to Matias and Lalit to conclude the webinar, I would like to remind everyone on our EIC conference taking place in May where we will have the topic of non-human identity as well as way, way more topics. So make sure to check our website for more information on that. And Matias, what do you think about this last question?
Yeah, I won't come up with three items because those that have been mentioned are really great already. I want to just add one thing that has been mentioned also before. These NHIs, they don't just pop up. They don't just show up and nobody is responsible for that. The exact opposite is the case.
Ownership, responsibility, liability, and proper lifecycle management for those who have to own these NHIs is key. And doing this wrong might lead to two years' paperwork and trying to identify ownership concepts. That is not the way to move forward. But really to understand that people who are responsible for NHIs, who own API keys, who own systems, who own development processes, CICDs, chains, they need to understand that they are also responsible for the associated NHIs. And this ownership needs to be established, understood, and really put into practice and lived every day.
And that needs to also be applied very soon because you will need these owners for cleaning up as well. Lalit?
Yeah, look, following on from what Matthias said, it's all about the first thing I would say to organizations in addition to what Heiko said that we discussed earlier around the strategy, the risk-based approach. You've got to focus on policies, standards, and controls. This is super important. And education of your staff around the risks and what is acceptable, checking in hard-coded credentials, not acceptable, whether you have tooling or not in place to prevent that.
At a previous organization, we made it very clear to all staff members that if you're found checking in new credentials, hard-coded credentials, it's a disciplinary offense and could lead to termination. You've got to set the bar top-down for management and have senior management totally bought into this around what's acceptable. And then you can start putting in place some of the controls. It's all about people, process, technology. So define the policies, the standards, and live and breathe that, as Matthias said, and then start seeing what you can do.
You can start putting in prevent controls. There are solutions that can stop you checking in credentials. So you need to make some big infrastructure decisions and plays on how you're going to tackle this monster elephant-in-the-room problem. So involving strategy and architecture organizations into this, your CICD organizations, and making sure you move to a shift-left DevSecOps strategy. It's critical. It's a huge problem that touches all of our lifecycle processes and IT teams.
So you all need to come together as an organization and work out the overarching strategy and architecture will be my closing thoughts. Thank you so much. We have one more minute. So maybe just very, very briefly, any final thoughts? Maybe we can start with Heiko.
Oh, in just a couple of seconds. Start with a strategy, as I said before, and start acting on solving your NHI problem, and start acting today. Matthias?
Yeah, just if you feel that this webinar rang a bell for you, yeah, do it. Just what Heiko said. So if you came across in the back of your mind, yeah, I could clean this up, do it. Selene? I think that it's a hard topic for non-human identities to manage non-human identities. So start from today, I can say that. And Nalit?
Look, finally, this might be a cheeky plug, but I would say go to nhimg.org. We've got the best independent knowledge repository on NHIs, and you can learn everything about what we discussed. But the first step is educate your management, get their buy-in, and then work from there. All right. On that positive note, we'll conclude the webinar. Thank you very much to all of you for attending, for the questions. And if you have any further questions, make sure to reach out to any of the attendees today, and they'll be happy to help you. Once again, thank you very much, and have a nice day.
Thank you. Thank you.
Thanks, Alejandro. See you at EIC. Thank you.
See All Locations
See All Locations