By HumanAudit Inc. editorial teamLast reviewed 5 August 2026
VerifiedLast reviewed 5 August 2026 by the HumanAudit Inc. editorial team.Corrections logEditorial policy
On this page
  1. How the scoring works
  2. About the OWASP NHI Top 10
  3. What this tool is and isn't
  4. Related
  5. What to do with your result
You get

Pass, partial or fail

Against each of the ten OWASP NHI risks, with coverage expressed as a single percentage.

You get

The gap explained

Every result you do not clear links to the guidance that explains what the control actually requires.

You get

A prioritised order

Which risks to close first, ranked by how often each one appears as the root cause in real incidents.

Before you start

10 risks, about 8 minutes. Everything runs in your browser. Nothing is transmitted, nothing is stored, and no email is requested at any point. Answer honestly rather than aspirationally, because the output is only as useful as the input and nobody else sees it.

How the scoring works

Pass counts as 100% of that risk. Partial counts as 50%. Fail counts as 0%. Coverage is the average across all ten risks. This is deliberately simple, it is not a weighted risk model. For that, you need an actual risk assessment done by someone who knows your environment. What this score does do is identify where the most obvious gaps are and give you an honest internal baseline.

About the OWASP NHI Top 10

The OWASP Non-Human Identities Top 10 was published in 2025 as a community-driven consensus on the most impactful NHI-specific risks. It is not a standard. It is a starting point, shaped by real incidents and practitioner input. The ten risks are: NHI1 Improper Offboarding, NHI2 Secret Leakage, NHI3 Vulnerable Third-Party NHI, NHI4 Insecure Authentication, NHI5 Overprivileged NHI, NHI6 Insecure Cloud Deployment Configurations, NHI7 Long-Lived Secrets, NHI8 Environment Isolation, NHI9 NHI Reuse, NHI10 Human Use of NHI.

For the full write-up of each risk with examples and recommended controls, see the OWASP project page and our annotated reference.

What this tool is and isn't

It is a practical self-assessment you can run in ten minutes to get a defensible snapshot of your controls. It isn't an audit artefact, a compliance deliverable, or a substitute for internal work. Use it to start a conversation, not end one.

For programme-level positioning, use the NHI maturity assessment. For scenario-specific exposure testing against real breaches, try the breach readiness score.

Want a second read on your score?

The tools give you a number. A 20-minute call with HumanAudit will tell you which gap to close first, roughly what it costs, and what you can defer with a documented rationale.

What to do with your result

A score is only useful if it changes what you do next. These are the routes we would suggest depending on where you land.

If your result showsDo this next
NHI1, improper offboardingThe most common finding anywhere. See access reviews.
NHI2, secret leakageStart with the enumeration sources, particularly CI/CD and archived repositories.
NHI5, over-privilegeThe authority ratio in metrics turns this into a number you can track.

Want a second read on your result?

Twenty minutes with HumanAudit, free and with no obligation. Bring the score and we will tell you which gaps actually matter for your estate and which are noise. If we are not the right answer we will say so on the call.