Inside the OWASP Top 10 for Non-Humani Identities

For the March edition of our Ask Me Anything series, we sat down with Tal Skverer, Head of Research at Astrix Security, to explore the newly launched OWASP Top 10 for Non-Human Identities. Tal contributed his research and expertise to the project and shared how the risks were ranked, why the initiative matters, and what practitioners can do today to start closing gaps in their NHI posture.

Whether you’re new to OWASP or already wrestling with AI agent access, this session breaks down the real risks—and why NHI security can’t be an afterthought in modern development pipelines.

“Once a Top 10 project comes out, a lot of tools start integrating those risks into their frameworks. It’s one of the best ways OWASP has helped drive standardization—and now we’re finally doing that for Non-Human Identities.”

Key highlights:

What makes NHI security unique—and overdue: Despite NHIs being at the heart of many recent breaches, there wasn’t a dedicated framework to address their risks. The new Top 10 changes that.

How the risks were ranked: Tal walks through the OWASP risk methodology and explains how exploitability, prevalence, detectability, and technical impact shaped the list.

Why AI agents amplify NHI exposure: The rush to deploy agentic AI has led to widespread use of insecure, overly permissive NHIs—often indistinguishable from human users in audit logs.

What you can do today: From tackling ownership of legacy NHIs to defining better offboarding workflows, Tal shares immediate steps for teams—whether or not they use Astrix.