Download Publication
Who it's for:
- All cybersecurity professionals
The State of Non-Human Identity Security
Release Date: 09/11/2024
- Perceptions around NHIs and their security risks
- Current security efforts, policies, and management of NHIs
- Challenges with connecting to third-party vendors
- Current management and policies for API keys
- Only 15% of organizations feel highly confident in preventing NHI attacks, while 69% express concerns about them. This indicates awareness of the risks but a lack of confidence in current security measures.
- Major pain points include managing service accounts, auditing and monitoring, access and privilege management, discovering NHIs, and policy enforcement.
- Only 20% of organizations have formal processes for offboarding and revoking API keys. Even fewer have procedures for rotating them.
- Many organizations rely on a mix of security tools not specifically designed for NHIs. This results in a lack of cohesion and effectiveness.
- A promising trend shows increased investment in NHI security capabilities. 24% of organizations plan to invest within the next six months and 36% within the next 12 months.
Download this Resource
Related Certificates & Training
Learn the core concepts, best practices and recommendation for securing an organization on the cloud regardless of the provider or platform. Covering all 14 domains from the CSA Security Guidance v4, recommendations from ENISA, and the Cloud Controls Matrix, you will come away understanding how to leverage information from CSA's vendor-neutral research to keep data secure on the cloud.
Learn moreFor those who want to learn from the industry's first benchmark for measuring Zero Trust skill sets, the CCZT includes foundational Zero Trust components released by CISA and NIST, innovative work in the Software-Defined Perimeter by CSA Research, and guidance from renowned Zero Trust experts such as John Kindervag, Founder of the Zero Trust philosophy.
Learn more