CIOs must rethink identity now people are being outnumbered by nonhuman entities
Identity is the fundamental currency in any technology transaction so we need to treat nonhuman assets with the same care as we apply to people.
We’re outnumbered! Nonhuman identities (NHIs) outnumber human identities in the enterprise by a ratio of up to 50:1.
This Non-Human Identity Management Group statistic from 2025 is likely already outdated, and in a year from now the ratio will be exponentially higher as rapid growth trends like AI/Machine Learning, the Internet of Things, digital assistants and the burgeoning API Economy continue to accelerate automation .
What are NHIs? Machines, processes, service principals and accounts, virtualized and other workloads, and applications that are granted digital credentials.
Think, for an everyday example, of a helpdesk chatbot on your favorite website.
Managing NHIs is a challenge that CIOs, identity experts, and CISOs must accept.
This in some ways is a re-run of what happened 40 years ago when identity access management was widely deployed.
It’s just that now we are not only dealing with human beings.
And I don’t know a single organization that has its collective head around the concept of who is, or should be, ‘the HR chief’ for NHIs.
Leaders today need to consider nonhuman identity in the way they consider human identity.
When we hire, we onboard people by harnessing and securing the details we need to pay them and manage them, but we also work to imbue them with our organizational culture, systems, risks, security processes and so on.
We set and tweak permissions based on who needs access to what and when, depending on their roles, seniority, specific tasks they perform at a given time and so on.
We need to have similar controls and contextual understanding of our nonhuman assets.
An urgent case where context is king Without making that change CIOs and other leaders will have no foundational basis of understanding where risks are coming from or what measures they need to take.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.techradar.com — the content belongs to TechRadar.