The ratio is the headline and the least useful part of the finding. Published figures for the same measure range from 45 to 1 up to 144 to 1 depending on who is counting, which tells you the industry has not agreed what a machine identity is, not that some enterprises have three times more of them than others.
The number worth acting on is the pair underneath it. Eighty-eight percent of respondents apply the word privileged only to humans. Forty-two percent of machine identities hold privileged or sensitive access. Those two facts together describe an organization whose governance vocabulary does not reach almost half of its own privileged surface.
That is a governance failure before it is a tooling failure, and it explains why buying a machine identity product first usually disappoints. The product will enumerate thousands of identities and hand back a list nobody owns. Assigning ownership is the prerequisite, and it is unglamorous policy work that no vendor can do for you.
Common questions
- How many machine identities does an organization have per employee?
- CyberArk puts the ratio at roughly 82 to 1, and other published figures for the same measure range from 45 to 1 up to 144 to 1. The spread reflects disagreement over what counts as one identity, since a short-lived container token, a TLS certificate, and a long-lived service account are each counted differently across reports.
- Why is non-human identity a governance problem before a tooling problem?
- Because the vocabulary does not reach it. CyberArk found 88% of respondents apply the term privileged user only to humans, while 42% of machine identities hold privileged or sensitive access. Buying a discovery tool before assigning ownership produces a list of thousands of identities that nobody is accountable for.
- Does a higher machine identity count mean worse security?
- No, and often the reverse. A platform issuing a short-lived credential per workload generates a far higher count than one using a few long-lived shared accounts, and the second architecture is more dangerous. The ratio measures architectural style rather than risk, so treating a rising count as deterioration misdirects a program.