4 MIN READ
Here is the number worth sitting with for a moment. The typical company runs roughly 45 machine identities for every human employee, according to the 2025 CyberArk identity security threat landscape report. Service accounts, API keys, OAuth tokens, machine certificates, workload identities in Kubernetes, the long lived credentials in legacy applications. Most of those identities are unmanaged. They have credentials that never rotate. They have access rights set at deployment and never reviewed. The non human identity surface in 2026 sits as the dominant credential attack surface, and almost nobody has mapped it.
What the surface actually looks like
Five categories make up the bulk of the surface, in roughly descending order of volume.
Service accounts come first. The Windows service account, the Linux daemon account, the database application account, the SAP dialog account, all of them accumulating since the 1990s. Passwords that nobody rotates because rotation requires downtime. Local administrator rights because that was the path of least resistance when the application was deployed. They run critical workloads today, and most have not been touched in over a decade.
API keys sit close behind. The AWS access key, the GitHub personal access token, the Stripe API key, the Google Maps API key, embedded in code, in CI pipelines, in cron jobs, in infrastructure as code. Lifetimes measured in years. Frequently checked into git repositories, where they sit until a scanner catches them or a breach leaks them.
OAuth tokens and refresh tokens have a different shape but the same problem. Lifetimes measured in months, with refresh tokens that can extend the lifetime indefinitely. A token, once stolen, is good until it expires, and the expiry can be a long way out.
Machine certificates are the fourth category. TLS server certificates, client certificates, S/MIME certificates, code signing certificates. They rotate on a schedule harder to manage than human credentials, and the rotation is often automated in a way that loses track of which certificate belongs to which system. When the certificate management plane fails, the failure can take weeks to find.
Workload identities in the cloud have become the fastest growing slice. AWS IAM roles, Azure managed identities, GCP service accounts, Kubernetes service account tokens. Tied to the workload rather than the human, inheriting whatever access rights the application needs, which is often far more than it should have. Least privilege on a workload identity is harder to reason about than least privilege on a human user, and most of the cloud platform tooling has only just started to support it.
Why this matters in 2026
Two reasons this matters more in 2026 than it did in 2020.
The first sits in the credential attack surface. A stolen service account password gives the same access as the account itself, which is often local administrator on a domain joined machine. A stolen AWS access key with iam:full access amounts to the keys to the kingdom. A stolen Kubernetes service account token lets an operator pivot to every pod in the namespace. The non human identity, once compromised, gives persistence and privilege that a stolen human identity rarely matches.
The second sits in the regulatory and insurance exposure. The SEC disclosure rules in 2024, the DORA regulation in the EU in 2025, and the cyber insurance underwriting questionnaires in 2026 all ask about non human identity management. The organisation that cannot answer has a disclosure problem and an insurance problem on top of the security one.
What to actually do
Three moves, in priority order.
Start with inventory. Run a discovery tool like Venafi, CyberArk, or one of the open source alternatives (HashiCorp Boundary, the cloud native identity discovery tools from the major cloud providers) across the environment. The first pass produces a list longer than the IAM lead expected, often ten times the human headcount or more.
Move to credential rotation. Any non human identity with credentials older than twelve months is the first priority. Static API keys in particular, replace them with short lived tokens where the cloud provider supports the pattern. AWS IAM roles, Azure managed identities, GCP workload identity federation, all of them remove the long lived secret from the equation.
Finish with access review. The workload identity with access it does not need sits as the highest risk identity in the environment. The least privilege work the platform security team has been deferring on human identities is more urgent here, because the blast radius of a compromised workload identity is usually larger than a compromised human account.

The bottom line
Inventory, rotation, access review. The non human identity surface is the largest credential attack surface in 2026, and almost nobody has mapped it. The first pass produces a list longer than the IAM team expected. The work is not glamorous. The work is necessary.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.



