Non-human identities (NHIs) — bots, service accounts, API keys, OAuth tokens, machine certificates — now outnumber human identities in most large organizations by 10:1, yet remain largely ungoverned. Drawing on breaches like SolarWinds, Uber 2022, and Okta 2023, the piece argues that unmonitored NHIs are a critical attack vector. A more immediate threat in 2026 is mass certificate expiration: infrastructure built rapidly during 2020–2022 used 3–5 year certificates that are now lapsing simultaneously, risking cascading outages. The recommended approach prioritizes governance over tooling — starting with a discovery sprint to inventory NHIs, pulling certificate expiration data immediately, and auditing privilege on high-sensitivity service accounts. Existing identity frameworks (RBAC, PAM) were built for humans and don't fit NHIs well, and standards bodies are moving too slowly relative to the expiration timeline.

7m read timeFrom csoonline.com
Post cover image
87 Impressions