Organizations have spent years securing human identities, but a new and rapidly expanding attack surface is emerging: non-human identities (NHIs).
Service accounts, APIs, workloads, bots, machine identities, cloud credentials, and AI agents now outnumber human users in many enterprises by factors of 20 to 50 times. Yet these identities often operate with excessive privileges, limited governance, and little visibility. In this session, we'll examine the most common types of NHIs and why they have become a preferred target for attackers. Through real-world breach examples, and an understanding of the NHI breach kill chain, we'll explore how compromised credentials, excessive privileges, and unmanaged secrets enable attackers to move laterally, escalate access and compromise critical systems.
Speaker:
- Larry Chinski, VP, Enterprise Strategy | One Identity