Skip to content

Advisory

The NHI Assessment: What We Would Look for in Your First 30 Days

A practical executive blueprint for moving from NHI uncertainty to a prioritized exposure picture and 90-day action plan.

By Anish Karkare8 min read

A CISO asks a simple question:

How exposed are we because of non-human identities?

The wrong response is a six-month transformation program.

The other wrong response is a dashboard containing 25,000 findings.

The first objective should be to create an executive-quality picture of exposure, ownership and control gaps quickly enough to drive decisions.

Here is how AVIKORE would approach the first 30 days.

The Outcome

At the end of the assessment, leadership should understand:

  • what the major NHI populations are;
  • where the highest-risk identities live;
  • where ownership is missing;
  • where privilege is excessive;
  • where static credentials create avoidable exposure;
  • which identities support critical business services;
  • where lifecycle governance is weak;
  • how existing IAM/PAM/PKI/secrets/cloud controls fit;
  • what needs immediate remediation;
  • what should happen over the next 90 days.

The deliverable is not an inventory.

It is a decision model.

Week 1 — Define the Estate

Do not begin by scanning everything.

Begin by defining what matters.

Establish the NHI taxonomy

Agree on the populations in scope.

Service accounts.

Applications.

Workloads.

Service principals.

Cloud roles.

Certificates.

API credentials.

Automation.

Integrations.

Agents.

The taxonomy becomes the language used across security, IAM, cloud and engineering.

Identify the control ecosystem

Map the existing environment:

  • IdP;
  • IGA;
  • PAM;
  • secrets management;
  • PKI;
  • cloud IAM;
  • Kubernetes;
  • CI/CD;
  • source control;
  • CMDB;
  • SIEM;
  • CNAPP;
  • application inventory.

This prevents the assessment from assuming that NHI begins and ends with a new platform.

Identify critical business services

The technical estate must be connected to business consequence.

Which applications cannot fail?

Which processes move money?

Which systems contain regulated data?

Which workloads support manufacturing or operations?

Which integrations connect critical platforms?

Risk becomes more useful when identity exposure is tied to business dependency.

Week 2 — Discover and Connect

Now build the inventory.

But resist the temptation to celebrate the number.

“We discovered 31,412 NHIs” is not an executive outcome.

The objective is to connect the identities to context.

For each high-value population, determine:

What is it?

Where is it?

Who owns it?

How does it authenticate?

What can it access?

What depends on it?

Is it active?

How is it governed?

Week 3 — Find Exposure

AVIKORE would look for patterns rather than isolated findings.

Unknown ownership

Critical identities without accountable owners.

Excessive privilege

NHIs whose effective access exceeds their expected function.

Static credentials

Long-lived secrets, keys or tokens where stronger patterns may be available.

Orphaned identities

Identities whose creator, application or original purpose no longer exists.

Dormant access

Inactive identities or credentials that remain enabled.

Unmanaged lifecycle

Identities created outside governed processes or without review and retirement controls.

Dangerous dependencies

Credentials that cannot be rotated because nobody knows what will break.

Control fragmentation

The identity is visible in one system, credential in another, privilege in a third and activity somewhere else—with no consolidated accountability.

Agentic exposure

Agents, agent credentials or agent-to-tool access that does not fit the existing identity model.

Week 4 — Prioritize

Do not deliver a giant vulnerability spreadsheet.

Create an executive exposure model.

AVIKORE NHI Exposure Matrix

Prioritize using four questions:

Business Impact

What happens if this identity is compromised or disrupted?

Access Power

How much privilege or sensitive access does it possess?

Governance Confidence

Do we know its owner, purpose and lifecycle?

Credential / Behavioral Risk

How strongly is it authenticated and how well is its activity understood?

This creates a more meaningful conversation than severity labels alone.

The 30-Day Deliverable

Leadership should receive:

1. Executive Exposure Brief

The ten issues leadership should understand.

2. NHI Landscape

Major identity populations and control coverage.

3. Critical Exposure Register

Prioritized exposures—not every discovered object.

4. Ownership Gaps

Critical identities without accountable owners.

5. Architecture Map

IGA / PAM / PKI / secrets / cloud / NHI / monitoring relationships.

6. Quick Wins

Actions that can materially reduce risk in 30–60 days.

7. Strategic Gaps

Capabilities requiring architecture, process or technology decisions.

8. 90-Day Roadmap

Sequenced remediation and program-development plan.

What We Would Not Do

We would not begin by recommending a vendor.

We would not treat every secret as an identity.

We would not assume every NHI is a machine identity.

We would not assign the same risk to every discovered object.

We would not automatically rotate or disable identities without dependency context.

We would not create a parallel governance program if existing IAM controls can be extended.

And we would not leave leadership with thousands of findings and no decision path.

AVIKORE Executive Takeaway

A good NHI assessment answers three questions:

What matters?

Why does it matter?

What should we do next?

Everything else is supporting evidence.

Leadership Discussion Questions

  • Could we identify our ten highest-risk NHIs today?
  • Which critical identities have unknown ownership?
  • Which NHI controls are already available but inconsistently adopted?
  • Where would remediation create production risk?
  • Are AI agents already creating a new unmanaged identity population?

Research sources

Market and vendor material reviewed as evidence during research — cited for context, not as endorsement.

Related insights