Clutch has launched the Non-Human Identities (NHI) Index to enable IT teams to secure and manage NHIs across their environments. Clutch claims that NHIs now outnumber human identities inside IT environments by 45:1.
Ofir Har-Chen, Co-founder and CEO of Clutch said, “We identified a critical gap in the understanding and management of NHIs. The NHI Index is our response to the growing challenges of securing NHIs in today’s fragmented enterprise environments. It not only equips security professionals with practical tools and insights but also highlights just how prevalent and integral NHIs are across cloud and SaaS technologies.

“In many cases, their use is mandatory, embedded within the very services enterprises rely on. By providing this resource, we aim to shed light on the scale of NHI usage and the urgent need for effective management and security. We encourage the community to engage with the NHI Index, share insights, and stay informed on the latest developments in NHI security.”
What is an NHI?
Simply put, it is any authorised account inside your IT environment that does not map directly to a human. Typical examples are printers, computers, applications, APIs and IoT devices. They also include building management systems, UPS and door controls.
These accounts are often created and then forgotten about, meaning that their security is questionable. They have passwords and privileges that give them access to data and systems. Those passwords are rarely reviewed or unique, and worse, many are factory-set. This makes them ideal targets for malicious actors who take over those accounts to spread malware through IT environments.
Clutch says the ratio of NHI to human identities is 45:1. It means that over 95% of the accounts in an Active Directory (AD) are NHIs. As organisations map their AD environment to the cloud it is an opportunity to address security policies around NHIs.
The company continues to say many cloud-based NHIs use less than 5% of their assigned permissions. Additionally, it claims that over 80% remain inactive. To validate that point it says “These risks are not theoretical; recent SEC 8-K filings, including a high-profile case involving Dropbox, have directly linked NHI vulnerabilities to serious security breaches.”
What is the Clutch NHI Index?
The company describes the NHI Index as, “The Index is the industry’s only centralized resource featuring detailed mapping of hundreds of Non-Human Identities across diverse environments, equipping security and IT teams with the knowledge to navigate the complex landscape of NHI security.”
The goal of the NHI Index is to enable IT and security teams to identify NHI is in their environments. This is especially important where that environment is a cloud or hybrid environment. That is because many of the NHI will have been created by SaaS applications that are not always deployed by IT.
It has provided a list of over 350 different types of NHI used by over 480 cloud services, code repositories, CI/CD solutions, and SaaS applications. Using this, Clutch says the NHI Index allows it to provide guidance and actionable steps on how to manage NHI.
The company says that the key features of the NHI Index Include:
- Detailed NHI Catalog: An exhaustive list of NHIs used across major cloud providers, code repositories, CI/CD solutions, and SaaS applications. Each entry includes critical details such as service names, environments, types of NHIs, and key security features like audit logs, IP allowlists/denylists, and set expiry options.
- Essential Resources for Reducing NHI Attack Surface: Practical guides on establishing OpenID Connect (OIDC) between cloud service providers (CSPs) and version control systems, as well as enabling inter-cloud connectivity using ephemeral keys. These resources, including Terraform files and step-by-step tutorials, help organizations transition from static, long-lived NHIs to ephemeral ones—drastically reducing their attack surface and enhancing their security posture.
Cloud providers are a major source of NHI
According to Clutch, cloud providers are becoming the most prominent users of NHI. That should come as no surprise as they are highly automated environments. NHIs account for 65% of AWS and 67% of CGP entries in their Identity Access Management (IAM) services.
Surprisingly, not all of these are audited. While Google claims to be able to audit almost all of these NHIs, AWS only audits around 80% through its CloudTrail service. In Microsoft Azure, Clutch says that Entra ID accounts for 33% of the NHIs mapped to Azure services and only 86% are audited in Azure Activity Logs.
This lack of auditing increases the attack surface of organisations and it is important that they address that. Of concern to CISOs will be that these NHIs are outside of their control, yet abuse of them directly impacts their security.
Enterprise Times: What does this mean?
The rise of NHIs has accelerated over the last two decades. Driving this has been the use of cloud-based applications and IoT. The explosion in identities has overwhelmed many organisations that still struggle to manage just human identities. As a result, NHIs are often ignored, which makes them a significant security issue.
What Clutch is trying to address with the NHI Index is the lack of visibility that organisations have around NHIs. When you look at the NHI Index it shows just how many NHIs popular applications use. This will be an eye-opener to many IT teams and will allow them to start to address the issue.
For many organisations, however, there is an urgent need to audit their identity repository, be that AD or something else. They need to develop routines to identify when NHIs security credentials were last changed. They also need to verify what permissions and rights they have. Without that, organisations will struggle to control the risk from NHIs.

















