What Is OWASP NHI Top 10?
The OWASP NHI Top 10 is a community-driven framework published by the OWASP Foundation that catalogs the ten most critical security risks associated with non-human identities (NHIs) — service accounts, API keys, OAuth tokens, machine credentials, and increasingly AI agents. Modeled on the well-known OWASP Top 10 for web application security, it gives security teams, auditors, and developers a shared vocabulary for classifying and prioritizing NHI-related risks, such as improper secret management, overprivileged access, insecure authentication methods, and inadequate lifecycle governance. First published in 2025, it draws on incident data and practitioner input to reflect how NHIs are actually being exploited in production environments, and is increasingly referenced in security assessments, vendor evaluations, and internal governance frameworks.
Why It Matters
The OWASP NHI Top 10 matters because it puts a name and a ranking on a category of risk that has outgrown ad hoc handling. According to OWASP's own 2025 research, 80% of identity breaches involve a non-human identity, yet most organizations still lack a systematic way to reason about the risk. NHIs now routinely outnumber human employees 45 to 1, with a typical 100-person company running 2,000+ of them — each one a credential that can be leaked, over-provisioned, or forgotten. Without a shared framework, security teams struggle to communicate NHI risk to leadership, benchmark their posture, or prioritize remediation. The Top 10 also underpins emerging regulatory expectations: NIS2 enforcement beginning October 1, 2026 explicitly covers service accounts and machine credentials under ANSSI ReCyF Objective 13, making OWASP's categorization a practical reference point for compliance mapping.
How Cydenti Helps
Cydenti maps discovered non-human identities directly against the OWASP NHI Top 10 categories, turning an abstract risk framework into a concrete, prioritized inventory of exposures across your environment. Instead of manually cross-referencing service accounts, API keys, and OAuth grants against each risk category, teams get continuous visibility into which identities fall into which OWASP risk bucket — and how that maps to audit and compliance requirements. This makes it easier to demonstrate a structured, industry-aligned approach to NHI risk management. See how this connects to broader compliance reporting.
Explore →Frequently Asked Questions
Is the OWASP NHI Top 10 a compliance requirement?
No, it is not a legal or regulatory requirement — it is a community-authored best-practice framework from the OWASP Foundation. However, it is increasingly referenced by auditors and used to structure NHI risk assessments that feed into regulatory frameworks like NIS2 and ISO 27001.
How is the OWASP NHI Top 10 different from the OWASP Top 10?
The original OWASP Top 10 focuses on web application vulnerabilities like injection and broken access control. The NHI Top 10 is a separate list specifically addressing risks tied to machine and service identities — secrets, tokens, and automated credentials rather than application code flaws.
Discover the machine identities you didn't know you had
— in 27 minutes, for free.
NIS2 enforcement begins October 1, 2026. The Audit Flash delivers your complete NHI exposure snapshot — service accounts, orphaned credentials, OAuth grants, AI agents — with a first report in 3 hours. No commitment.
No commitment • No credit card • Data hosted in Europe • Response within 24h