A readiness score
How many of six documented incidents your current controls would have stopped, contained, or missed entirely.
The specific control
For each scenario, the control that would have changed the outcome, and roughly what it costs to put in place.
Your weakest vector
Which attack path you are least prepared for, which is rarely the one teams expect.
Before you start
6 real incidents, about 5 minutes. Everything runs in your browser. Nothing is transmitted, nothing is stored, and no email is requested at any point. Answer honestly rather than aspirationally, because the output is only as useful as the input and nobody else sees it.
Why these seven scenarios
Each one is an incident where the primary failure vector was non-human identity, not phishing, not unpatched software, not ransomware-as-a-service. The attackers in each case found an NHI that was long-lived, overprivileged, leaked, or miscontextualised, and used it to do damage. Together they span the most common NHI attack patterns: SaaS OAuth compromise (Salesloft/Drift), stolen credentials for unfederated service accounts (Snowflake), supply-chain worm through developer environments (Shai-Hulud), signing-key misuse (Storm-0558), session-token leakage (Okta), CI/CD credential theft (Codecov), and instrumented-tool exfiltration (Codecov).
About the scoring
Yes = 100%, Partial = 50%, No = 0%, averaged across the seven scenarios. The bands are informal: 80% and above is "resilient to the core patterns," 50 to 79% is "partial coverage with material uncovered surface," 25 to 49% is "material exposure on recent public attack patterns," and below 25% is "systemic exposure, this is where budget should go." These are not compliance categories. They are diagnostic framings for a conversation.
What the score does and doesn't tell you
It tells you whether you'd stand up to the kinds of NHI attacks that have actually happened, publicly, in the last four years. It does not tell you whether you'd stand up to the next novel attack, or to targeted advanced-persistent-threat activity specific to your sector. For that you need threat modelling tied to your environment, not a checklist. Use this to surface the obvious and force the conversation, not to conclude you're safe.
The underlying teardowns
Each scenario in this tool is a compressed version of a full breach write-up in our breach library. The full analyses, indicators, timelines, attribution where confirmed, control-level takeaways, live here:
- Salesloft / Drift OAuth compromise (August 2025)
- Snowflake UNC5537 (May to June 2024)
- Shai-Hulud npm worm (November 2025)
- Microsoft Storm-0558 (2023)
- Okta support case system (October 2023)
- Codecov Bash Uploader (April 2021)
Related
For programme-level positioning, use the NHI maturity assessment. For control-specific coverage, use the OWASP NHI Top 10 self-audit.
Scored lower than you expected?
The score tells you where you are. A 20-minute call with HumanAudit will tell you which gap to close first and what it costs.
What to do with your result
A score is only useful if it changes what you do next. These are the routes we would suggest depending on where you land.
| If your result shows | Do this next |
|---|---|
| Third-party OAuth | The Salesloft/Drift pattern. Start with a grant register. |
| Supply chain | The Shai-Hulud pattern. CI/CD credential scope is the lever. |
| Standing credentials | Most of the rest. Shorten lifetimes before you buy anything. |
Want a second read on your result?
Twenty minutes with HumanAudit, free and with no obligation. Bring the score and we will tell you which gaps actually matter for your estate and which are noise. If we are not the right answer we will say so on the call.