The secrets rotation in 2026 counts as the discipline of treating the credential as the security control the credential is, rather than as the configuration value the credential has been treated as for the last twenty years. The credential counts as the thing the attacker is going to target, the credential stands as the thing the attacker is going to use, and the credential serves as the thing the attacker is going to monetise. The credential sits as the most privileged thing in the production environment, and the credential runs as the most under protected thing in the production environment. This serves as the playbook to fix that.
The secret rotation counts as the right answer. The secret rotation has to be automated, the secret rotation has to be tested, and the secret rotation has to be measured.
What to rotate and what to retire
The three categories of credentials that should be rotated are the human credentials, the machine credentials, and the third party credentials.
Human credentials. The passwords, the API keys, the tokens, and the certificates the humans use to access the production environment. The human credentials should be rotated when the human leaves the organisation, and the human credentials should be rotated on a regular cadence. The human credentials are the credentials the security team is going to be auditing, and the human credentials are the credentials the security team is going to be defending.
Machine credentials. The API keys, the tokens, the certificates, and the SSH keys the machines use to access the production environment. The machine credentials should be rotated on a short lived cadence (hours, not months), and the machine credentials should be rotated when the machine is decommissioned. The short lived machine credentials are the answer to the long lived credential problem, the short lived machine credentials are the answer to the credential leakage problem, and the short lived machine credentials are the answer to the credential reuse problem.
Third party credentials. The API keys, the tokens, the certificates, and the shared secrets the third party vendors use to access the production environment. The third party credentials should be rotated on a regular cadence, the third party credentials should be scoped to the minimum permissions, and the third party credentials should be revoked when the third party relationship ends. The third party credentials are the credentials the security team is going to be auditing, and the third party credentials are the credentials the security team is going to be defending.
How to do the rotation
The rotation has to be automated. The rotation that is done by hand counts as the rotation that does not happen, and the rotation that does not happen sits as the rotation the attacker is going to exploit. The automation is what the platform team has to do, the automation is what the platform team has to budget for, and the automation is what the platform team is going to be integrating with the secrets manager.
The rotation has to be tested. The rotation that is not tested stands as the rotation that breaks the production at 3 AM, and the rotation that breaks the production at 3 AM runs as the rotation the engineering team is going to be paged for. The testing is what the platform team has to do, the testing is what the platform team has to automate, and the testing is what the platform team is going to be doing in the staging environment first.
The rotation has to be measured. The rotation that is not measured runs as the rotation that the security team cannot prove is happening, and the rotation that the security team cannot prove is happening amounts to the rotation the security team is going to be defending in the audit. The measurement is what the platform team has to do, the measurement is what the platform team has to report, and the measurement is what the platform team is going to be doing in the quarterly review.
What to retire
The credentials that should be retired are the credentials that have been around for more than a year, the credentials that nobody knows the purpose of, the credentials that nobody can find the owner of, the credentials that are stored in the wrong place, and the credentials that have access to things they should not have access to. The credentials that are retired are the credentials the security team is going to be removing from the secrets manager, the credentials the security team is going to be removing from the production environment, and the credentials the security team is going to be removing from the audit log.
The retirement is what the security team has been avoiding, the retirement is what the security team has to do, and the retirement is what the security team is going to be doing this quarter. The retirement is what the security team is going to be doing to make the secrets rotation defensible.
What to do this quarter
Audit the top 20 machine credentials. The audit is what the platform team has been wanting to do, the audit is what the platform team has to budget for, and the audit is what the platform team is going to ship this quarter. The audit is what the platform team is going to do to find the credentials that need to be rotated, the credentials that need to be retired, and the credentials that need to be scoped down.
Set up the automated rotation for the top 5 services. The top 5 services are the services with the most credentials, the services with the longest lived credentials, the services with the most privileged credentials. The automated rotation is what the platform team is going to ship, the automated rotation is what the platform team is going to test, and the automated rotation is what the platform team is going to maintain.
Build the secrets rotation dashboard. The dashboard is what the platform team has been wanting to build, the dashboard is what the platform team has to build, and the dashboard is what the platform team is going to ship this quarter. The dashboard sits as the artefact the security team is going to defend in the audit, and the dashboard amounts to the artefact the security team is going to be glad the security team has.
The bottom line
The patterns the post covers have been showing up in production for long enough that the patterns have names, the failures, the mitigations, the gaps. The work the security team and the engineering team and the operations team are quietly doing today sits as the work that decides whether the practice the post names sits as a tool the team uses or a liability the team is paying for.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.


