GitGuardian unveils strategy to protect non-human identities
GitGuardian has introduced a new Non-Human Identity (NHI) Security strategy aimed at managing the growing number of NHIs and the secrets they depend upon.
At the centre of this new strategy is GitGuardian NHI Governance, which promises comprehensive visibility and control over the lifecycle of NHIs and their associated secrets. This marks a significant advancement as it includes integrations across prominent secrets management platforms, namely HashiCorp Vault, CyberArk Conjur, AWS Secrets Manager, Google Cloud Secrets Manager, and Azure Key Vault.
The current ratio of NHIs to human identities is reportedly 50 to 1, creating challenges for enterprises in managing the security of NHIs. These NHIs use secrets such as API keys, credentials, and access tokens, which can be dispersed across various codebases and tools, leading to security vulnerabilities and inefficiencies.
Eric Fourrier, CEO of GitGuardian, highlighted the issue, stating, "Secrets and non-human Identities are now the backbone of modern digital infrastructures, but securing them has become a nightmare for enterprises. Through our NHI Security strategy, we're urging enterprises to step up and regain control of their secrets. We're giving them a clear, actionable path forward: a way to discover and secure their NHIs at scale while reducing risk and complexity."
GitGuardian NHI Governance offers organisations a framework that incorporates complete visibility with centralised tracking, proactive posture management for detecting compromised secrets, and lifecycle automation for consistent policy enforcement.
Eric Fourrier further explained the vision, "Our commitment is to empower security and development teams with actionable insights, robust governance, and scalable solutions. This new NHI Governance module is a natural extension of our deep expertise in secrets security. It not only helps organizations remediate leaked secrets but also strengthens overall NHI management and hygiene."
One of the challenges identified is 'vault sprawl', which occurs when multiple secrets managers are used across organisations, leading to fragmented management and potential blind spots.
The integration with leading vaults aims to address these issues by providing unified secrets visibility, mitigating vault sprawl, enabling cross-vault incident resolution, auditing the secrets lifecycle, and ensuring efficient vault migrations.
Eric Fourrier remarked, "While vaults play a key role in secrets management, they aren't sufficient to address the full spectrum of secrets security challenges. Our integrations take those platforms to the next level, ensuring enterprises can centralize their secrets management, reduce risks, and save on operational costs."
GitGuardian is committed to ongoing enhancement of its NHI security offerings to keep enterprises protected against emerging threats, with plans for future developments in automation, NHI hygiene analytics, and incident response tools.