5 MIN READ
Treat the credential as the security control it actually is, not as the configuration value the industry has been treating it as for the last twenty years. Most of the major incidents of the last three years trace back to a credential that was leaked, reused, or never rotated. The threat actor goes for the credential first because the credential is the shortest path to the data. This is the playbook for fixing that.
Three things matter. Automate the rotation. Test the rotation. Measure the rotation. The order is the order of how much each one costs when it is missing.
What to rotate and what to retire
Three categories of credentials cover almost every incident. Human credentials, machine credentials, and third party credentials. Each one has a different rotation profile, and each one has a different retirement profile.
Human credentials. Passwords, API keys, tokens, certificates. Rotate on the day a person leaves the organisation, and rotate on a regular cadence for everyone else. AppSec owns the audit trail. They own the incident response when one of these lands in the wrong place.
Machine credentials. API keys, tokens, certificates, SSH keys. Short lived is the answer, hours rather than months. Short lived handles the long lived credential problem, the credential leakage problem, and the credential reuse problem in one move. Rotate on the day the machine is decommissioned, and rotate any time the workload changes hands.
Third party credentials. API keys, tokens, certificates, shared secrets. Vendor relationships that touch production get rotated on a cadence, scoped to the minimum permissions, and revoked the day the relationship ends. A vendor offboarding checklist is the cheapest insurance the procurement lead will ever buy.
How to do the rotation
Automated or it does not happen. Hand-rolled rotation is the rotation that breaks at 3 AM and the rotation the threat actor exploits. Platform engineering has to build the automation, budget for it, and wire it into the secrets manager the rest of the stack already trusts.
Tested or it breaks production. Untested rotation is the rotation that pages the on-call at 3 AM. Every rotation should run in staging first, every rotation should have a rollback, and every rotation should produce a runbook the on-call can execute without paging anyone else.
Measured or it cannot be defended in the audit. If the security org cannot prove the rotation happened, the rotation did not happen from the auditor’s point of view. A dashboard that shows credential age, last rotation date, and owner is the artefact they walk into the audit with.
What to retire
Any credential over a year old, any credential with no known owner, any credential stored in the wrong place (Slack, Confluence, a developer laptop), and any credential with permissions broader than the workload actually needs. Retirement is the part everyone has been avoiding. It is also the part that closes the audit finding.
Schedule it. Walk the secrets manager, the production environment, the audit log, and the deployment configs. Tag every credential with an owner. Anything without an owner is retired this quarter, no exceptions.
What to do this quarter
Three actions, in this order. Audit the top 20 machine credentials, set up automated rotation for the top 5 services, and ship a rotation dashboard the security org can point at in the next audit review.
Audit. Pull the top 20 machine credentials by privilege, by age, and by blast radius if leaked. The audit finds what to rotate, what to retire, and what to scope down. It also surfaces the credentials the platform org has been wanting to retire for two years but has not had a list to start from.
Automate the top 5. Pick the five services with the most credentials, the longest lived credentials, and the most privileged credentials. Stand up automated rotation for those five this quarter. The rest follows next quarter.
Ship the dashboard. Credential age, last rotation, owner, and a count of credentials past their cadence. The dashboard is the artefact the security org defends in the audit, and the artefact the platform org uses to prove the rotation work is actually landing.

The bottom line
Rotate the credential before the threat actor does. Short lived machine credentials, scoped third party credentials, and a dashboard that proves the rotation is happening. The organisation that still treats secrets as configuration is the one that will explain the next breach in public.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.



