Pass, partial or fail
Against each of the ten OWASP NHI risks, with coverage expressed as a single percentage.
The gap explained
Every result you do not clear links to the guidance that explains what the control actually requires.
A prioritised order
Which risks to close first, ranked by how often each one appears as the root cause in real incidents.
Before you start
10 risks, about 8 minutes. Everything runs in your browser. Nothing is transmitted, nothing is stored, and no email is requested at any point. Answer honestly rather than aspirationally, because the output is only as useful as the input and nobody else sees it.
How the scoring works
Pass counts as 100% of that risk. Partial counts as 50%. Fail counts as 0%. Coverage is the average across all ten risks. This is deliberately simple, it is not a weighted risk model. For that, you need an actual risk assessment done by someone who knows your environment. What this score does do is identify where the most obvious gaps are and give you an honest internal baseline.
About the OWASP NHI Top 10
The OWASP Non-Human Identities Top 10 was published in 2025 as a community-driven consensus on the most impactful NHI-specific risks. It is not a standard. It is a starting point, shaped by real incidents and practitioner input. The ten risks are: NHI1 Improper Offboarding, NHI2 Secret Leakage, NHI3 Vulnerable Third-Party NHI, NHI4 Insecure Authentication, NHI5 Overprivileged NHI, NHI6 Insecure Cloud Deployment Configurations, NHI7 Long-Lived Secrets, NHI8 Environment Isolation, NHI9 NHI Reuse, NHI10 Human Use of NHI.
For the full write-up of each risk with examples and recommended controls, see the OWASP project page and our annotated reference.
What this tool is and isn't
It is a practical self-assessment you can run in ten minutes to get a defensible snapshot of your controls. It isn't an audit artefact, a compliance deliverable, or a substitute for internal work. Use it to start a conversation, not end one.
Related
For programme-level positioning, use the NHI maturity assessment. For scenario-specific exposure testing against real breaches, try the breach readiness score.
Want a second read on your score?
The tools give you a number. A 20-minute call with HumanAudit will tell you which gap to close first, roughly what it costs, and what you can defer with a documented rationale.
What to do with your result
A score is only useful if it changes what you do next. These are the routes we would suggest depending on where you land.
| If your result shows | Do this next |
|---|---|
| NHI1, improper offboarding | The most common finding anywhere. See access reviews. |
| NHI2, secret leakage | Start with the enumeration sources, particularly CI/CD and archived repositories. |
| NHI5, over-privilege | The authority ratio in metrics turns this into a number you can track. |
Want a second read on your result?
Twenty minutes with HumanAudit, free and with no obligation. Bring the score and we will tell you which gaps actually matter for your estate and which are noise. If we are not the right answer we will say so on the call.