
Kevin Bocek at Venafi talks to teiss about how the rise of machine identities is exposing companies to risks that have left millions of customers unable to access data services.
What are machine identities and what are they used for?
Machine identities manage the privacy, authentication and integrity of communications between different machines. Every machine must have a unique identity to help it authenticate and verify other machines it encounters, including applications, websites, devices, microservices or even algorithms.
Just like with human identities – where we may have passwords, biometrics, pass keys and so on to authenticate our identity – there are many different types of machine identities. Some common ones include TLS certificates, SSH keys and code signing certificates. These provide the rails that our online world runs on.
For example, a software update will be signed with a code signing machine identity to prove the software has been checked and validated and that is hasn’t been tampered with – ultimately, this tells other machines that it is safe to run. In other instances, if you are entering payment details or other personal information on a website, a TLS machine identity certifies that information is encrypted and cannot be read by anyone who does not have the key.
How can machine identities cause outages?
Some machine identities – such as SSL/TLS certificates – are issued for a finite time. When they expire, then they no longer work. This means the communication between those machines is no longer encrypted and secure. This can either result in a warning that the connection is no longer trusted, or the service will not work at all.
Machine identity-related failures and outages have probably impacted all of us at some point. Have you ever clicked on a website just to be met with a “cannot be trusted” warning? Or just discovered you couldn’t connect to a different site? In these instances, it’s more than likely that a machine identity has expired, which means that connection is no longer encrypted and protected.
This can cause huge disruption – particularly in our complex modern IT infrastructures, where diagnosing the root cause of a problem is not always obvious. There have been many high-profile outages we’ve witnessed in recent years that were caused by expired SSL certificates and inevitably had costly impacts for all involved. These include incidents impacting O2 that left millions of customers unable to access data services, and Spotify, preventing listeners from accessing podcasts.
Moreover, since every business uses machine identities by the thousands or even millions, failures are only becoming more common.
How is digital transformation impacting this issue?
Across the board, we’ve seen more companies shift to cloud-native development as part of a digital transformation strategy with cloud-native technologies like Kubernetes now commonly used throughout development environments, and the huge growth in the use of cloud providers such as AWS, Azure and Google. Alongside this companies are increasing the speed of development brought about by adopting DevOps processes.
This has resulted in a significant increase in the number of machine identities that companies need to manage. In fact, Venafi research found that digital transformation and the shift to cloud environments have driven an average of 42% annual growth in the number of machine identities. Each of which presents a potential risk of either being misused by an attacker or causing an outage due to human error.
The speed of development is also playing a pivotal role in making machine identities more difficult to manage. With everything now moving at machine speed, the lifespan of machines and their corresponding identities are shortening as well – there are containers that are spun up for seconds then disappear. These factors combined have made it significantly more difficult to track and manage the security of machine identities.
What are the consequences of this? How are cyber criminals taking advantage of this influx of machine identities?
Compromised machine identities pose a significant security threat to organizations. Malicious actors can use machine identities to establish concealed encrypted communication tunnels on enterprise networks, enabling privileged access to otherwise restricted data and resources. Fake or stolen machine identities can also mask an attacker’s machine, helping them masquerade as legitimate and enabling access to sensitive data.
We have also seen several instances of code signing machine identities being used to sign malware so that it runs trusted on machines and evades detection. Such as in the Kaseya, Stuxnet and Solar Winds attacks. In these attacks, stolen or forged machine identities gave cyber criminals legitimacy and trust, acting as a cloak of invisibility allowing them to move around networks without being spotted.
Machine identities can also be used to impersonate or spoof websites, creating a false impression that they are genuine and secure, and fooling unwitting victims. Attackers can also use them to sign malware, meaning that hazardous software can appear to come from legit sources such as Microsoft or Apple. This can vastly increase the distribution rate of malware as if it appears to come from a trusted source, it’s significantly more likely to be accepted by machines globally.
What can people do about this?
Companies need to take proactive steps to manage their machine identities to prevent costly outages and reduce the risk of machine identity misuse. Given the speed of the machine world and the volume at which identities are being created, automation is critical.
Organisations need a control plane to manage their machine identities, to ensure they are renewed – therefore preventing outages – and that they are secure and protected to avoid misuse.
Kevin Bocek is Vice President, Security Strategy and Threat Intelligence, at Venafi
Main image courtesy of iStockPhoto.com
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543