Inside the OWASP Top 10 for Non-Humani Identities
For the March edition of our Ask Me Anything series, we sat down with Tal Skverer, Head of Research at Astrix Security, to explore the newly launched OWASP Top 10 for Non-Human Identities. Tal contributed his research and expertise to the project and shared how the risks were ranked, why the initiative matters, and what practitioners can do today to start closing gaps in their NHI posture.
Whether youβre new to OWASP or already wrestling with AI agent access, this session breaks down the real risksβand why NHI security canβt be an afterthought in modern development pipelines.
βOnce a Top 10 project comes out, a lot of tools start integrating those risks into their frameworks. Itβs one of the best ways OWASP has helped drive standardizationβand now weβre finally doing that for Non-Human Identities.β
Key highlights:
What makes NHI security uniqueβand overdue: Despite NHIs being at the heart of many recent breaches, there wasnβt a dedicated framework to address their risks. The new Top 10 changes that.
How the risks were ranked: Tal walks through the OWASP risk methodology and explains how exploitability, prevalence, detectability, and technical impact shaped the list.
Why AI agents amplify NHI exposure: The rush to deploy agentic AI has led to widespread use of insecure, overly permissive NHIsβoften indistinguishable from human users in audit logs.
What you can do today: From tackling ownership of legacy NHIs to defining better offboarding workflows, Tal shares immediate steps for teamsβwhether or not they use Astrix.