Please ensure Javascript is enabled for purposes of website accessibility

Identity Stored in Plaintext

Risk Category

Storage

Risk Description

Storing NHIs in plaintext offers no encryption to guard credentials, significantly raising the risk of attack. Learn best practices to reduce this danger now.

Why It’s a Risk

Storing credentials in plaintext makes it easy for attackers to access sensitive information, leading to unauthorized access, data breaches, or service disruptions. Plaintext storage leaves no encryption layer to protect credentials, increasing the risk of exploitation.

Likelihood of Occurrence

moderate

Medium, particularly in older systems or environments without strict encryption policies.

Impact Level

high

High to critical, as plaintext identities are easily compromised, leading to data breaches or unauthorized access.

Mitigation Strategy

Detect and encrypt all identities stored in plaintext, ensuring that all credentials are moved to secure storage solutions. Implement strict access controls and enforce Zero Trust validation of every consumer to prevent unauthorized use of exposed identities.

Playbooks in Clutch

110

Applies for:

Cloud Service Provider

AWS
Azure
Google Cloud Platform

Vault

AWS Secrets Manager
GCP Secret Manager
Hashicorp Vault

Source Manager

Bitbucket
GitHub
GitLab

CI/CD

CircleCI
GitHub Actions
Jenkins
TeamCity

Password Manager

1Password
LastPass

EDR

Crowdstrike
SentinelOne
Microsoft Defender

Data

AWS Redshift
MongoDB Atlas
MySQL
PostgreSQL
Snowflake

Network

Akamai
Cloudflare

PaaS

Azure Kubernetes Service
Amazon Elastic Kubernetes Service
Google Kubernetes Engine
Kubernetes

Collaboration

Atlassian Confluence
Notion

Project Management

Atlassian Jira

Log Analytics

Datadog
Elastic
Splunk

IDP

Google Workspace
JumpCloud
Microsoft Entra ID
Okta

CRM

Hubspot
Salesforce

MDM

Microsoft Intune
Jamf

IM

Microsoft Teams
Snowflake

Ticketing

ServiceNow
Zendesk

Automation

Tines
Torq

HRIS

BambooHR
HiBob

SIEM

Exabeam (Logrhythm)
Sumo Logic

Stay Secure Without the Hassle of Rotations: Clutch’s Zero Trust & Ephemeral Identity Approach.