Skip to main content

Cybersecurity statistics / Non-Human Identities

One-third of organizations regularly rotate or audit service accounts and non-human identities, while just 11% do so continuously.

PublisherSophos
ReportThe State of Identity Security 2026
Published12 May 2026
TopicsNon-Human Identities, Access Management, Identity Attack

Published by Sophos in The State of Identity Security 2026, 12 May 2026. The figure is taken from the report as published; the full methodology is in the source.

View the original report

Related statistics

Non-human identities outnumber human users in 83% of organizations.
JumpCloud Inc., 18/07/2026
Only 21% of organizations have implemented controls for non-human identities (NHIs).
JumpCloud Inc., 18/07/2026
Only 19% of organizations fully govern non-human identities.
Netwrix, 15/06/2026
76% of organizations do not fully govern or monitor non-human identities.
Netwrix, 15/06/2026
Organizations with weak NHI management are 22% more likely to experience financial theft.
Sophos, 27/05/2026
Weak non-human identity (NHI) management was cited in 41% of identity incidents.
Sophos, 27/05/2026

Get the newsletter

Weekly cybersecurity statistics by email.