By HumanAudit Inc. editorial teamLast reviewed 5 August 2026
VerifiedLast reviewed 5 August 2026 by the HumanAudit Inc. editorial team.Corrections logEditorial policy
On this page
  1. Why these seven scenarios
  2. About the scoring
  3. What the score does and doesn't tell you
  4. The underlying teardowns
  5. Related
  6. What to do with your result
You get

A readiness score

How many of six documented incidents your current controls would have stopped, contained, or missed entirely.

You get

The specific control

For each scenario, the control that would have changed the outcome, and roughly what it costs to put in place.

You get

Your weakest vector

Which attack path you are least prepared for, which is rarely the one teams expect.

Before you start

6 real incidents, about 5 minutes. Everything runs in your browser. Nothing is transmitted, nothing is stored, and no email is requested at any point. Answer honestly rather than aspirationally, because the output is only as useful as the input and nobody else sees it.

Why these seven scenarios

Each one is an incident where the primary failure vector was non-human identity, not phishing, not unpatched software, not ransomware-as-a-service. The attackers in each case found an NHI that was long-lived, overprivileged, leaked, or miscontextualised, and used it to do damage. Together they span the most common NHI attack patterns: SaaS OAuth compromise (Salesloft/Drift), stolen credentials for unfederated service accounts (Snowflake), supply-chain worm through developer environments (Shai-Hulud), signing-key misuse (Storm-0558), session-token leakage (Okta), CI/CD credential theft (Codecov), and instrumented-tool exfiltration (Codecov).

About the scoring

Yes = 100%, Partial = 50%, No = 0%, averaged across the seven scenarios. The bands are informal: 80% and above is "resilient to the core patterns," 50 to 79% is "partial coverage with material uncovered surface," 25 to 49% is "material exposure on recent public attack patterns," and below 25% is "systemic exposure, this is where budget should go." These are not compliance categories. They are diagnostic framings for a conversation.

What the score does and doesn't tell you

It tells you whether you'd stand up to the kinds of NHI attacks that have actually happened, publicly, in the last four years. It does not tell you whether you'd stand up to the next novel attack, or to targeted advanced-persistent-threat activity specific to your sector. For that you need threat modelling tied to your environment, not a checklist. Use this to surface the obvious and force the conversation, not to conclude you're safe.

The underlying teardowns

Each scenario in this tool is a compressed version of a full breach write-up in our breach library. The full analyses, indicators, timelines, attribution where confirmed, control-level takeaways, live here:

For programme-level positioning, use the NHI maturity assessment. For control-specific coverage, use the OWASP NHI Top 10 self-audit.

Scored lower than you expected?

The score tells you where you are. A 20-minute call with HumanAudit will tell you which gap to close first and what it costs.

What to do with your result

A score is only useful if it changes what you do next. These are the routes we would suggest depending on where you land.

If your result showsDo this next
Third-party OAuthThe Salesloft/Drift pattern. Start with a grant register.
Supply chainThe Shai-Hulud pattern. CI/CD credential scope is the lever.
Standing credentialsMost of the rest. Shorten lifetimes before you buy anything.

Want a second read on your result?

Twenty minutes with HumanAudit, free and with no obligation. Bring the score and we will tell you which gaps actually matter for your estate and which are noise. If we are not the right answer we will say so on the call.