TL;DR
- CSA publishes an annual "State of Non-Human Identity Security" survey with enterprise-scale data on inventory, incident rates, and maturity.
- Consistent findings: NHI-to-human ratios of 20:1 to 50:1+, incident prevalence around two-thirds of organisations, inventory completeness well below 50% for most.
- Programme recommendations converge on: inventory, ownership, rotation, lifecycle automation, OAuth governance.
- Most useful as a benchmarking artefact, where does my programme sit relative to the surveyed population?
What CSA publishes
The Cloud Security Alliance (CSA) is a nonprofit industry body that publishes research, guidance, and assurance frameworks (notably the Cloud Controls Matrix and STAR program). In 2024, CSA began publishing a dedicated "State of Non-Human Identity Security" survey and associated programme guidance, responding to member interest in the rapidly-growing NHI category.
The research typically combines:
- Quantitative survey data from hundreds of enterprise respondents (security leaders, IAM practitioners, DevSecOps engineers)
- Qualitative commentary on what's working and what isn't
- Programme-maturity recommendations aligned with the survey findings
- Tooling-category observations (discovery, rotation, secrets management, workload identity)
Recurring findings (across 2024 to 2025 editions)
Specific numbers shift year to year, but the directional findings have been remarkably stable:
- NHI population. NHIs outnumber human users by 20:1 to 50:1 or more, depending on industry and cloud maturity. The ratio is increasing year on year.
- Incident prevalence. A substantial majority of respondents, around two-thirds in recent editions, report at least one identified incident involving NHI compromise or misuse in the prior year.
- Inventory completeness. A minority of respondents believe their NHI inventory is complete. Self-reported "I know what I have" consistently runs below 50%.
- Ownership gaps. Respondents consistently identify "no clear owner" as the most common NHI governance gap.
- Credential age. Long-lived credentials (over a year) are the norm, not the exception, in most surveyed environments.
- Tool fragmentation. Most organisations use 5+ tools across the NHI control surface, with meaningful gaps in consolidation.
Programme recommendations
CSA's programme guidance converges, broadly, with the capability structure we use on this site (see NHI management). The recurring emphases:
- Start with inventory. You cannot govern what you cannot see. Automated, continuous discovery across all source systems.
- Enforce ownership at creation. No NHI should exist without a named owner.
- Rotate credentials on a schedule. Automated rotation, shorter TTLs where possible.
- Adopt workload identity where available. Replace static credentials with cryptographic attestation.
- Monitor behaviourally. Baselines plus anomaly alerting.
- Govern third-party integrations. OAuth apps reviewed on install, re-reviewed on change, revoked on deprecation.
- Automate lifecycle. Tie offboarding to identifiable upstream events.
How we suggest using the CSA research
Three practical uses for a CISO or IAM leader:
- Benchmarking. Use CSA survey data to position your programme against peers. "Our inventory is 70% complete; CSA's survey shows a median below 50%, we're ahead on this dimension but behind on rotation."
- Business case support. Reference CSA findings in executive-level narratives about NHI investment priorities. Third-party research carries weight.
- Baseline programme shape. Use CSA's programme recommendations as the default structure for a new NHI programme, combined with the OWASP NHI Top 10 for risk coverage and the SPIFFE/SPIRE frame for workload-identity architecture.
Primary source
Research is available at cloudsecurityalliance.org/artifacts/state-of-non-human-identity-security-survey-report (current edition). CSA's NHI-focused working group pages and events are the live-updated entry point; check the CSA research catalogue for the latest edition.
A note on statistics
Survey research has methodological limits. Self-reported maturity skews optimistic; incident prevalence can be under-reported by respondents nervous about disclosing; sampling varies across editions. We treat CSA data as directional and triangulate against vendor product data and breach case studies where possible.