CyberArk Expands Machine Identity Security Portfolio with Advanced Discovery, Context Capabilities
Because Machine Identities Outnumber Human Identities, 82-to-1

CyberArk, the global leader in identity security, has announced new discovery and context capabilities across its Machine Identity Security portfolio. The enhancements enable security teams to automatically find, understand and secure machine identities—spanning certificates, keys, secrets, workloads and more—reducing risk and simplifying compliance at scale.
Machine identities outnumber human identities by an estimated 82 to 1, driven by increased Artificial Intelligene (AI) adoption and cloud native growth. As a result, machine identity-related security incidents are on the rise, with 72% of security leaders reporting certificate-related outages and 50% experiencing security incidents or breaches from compromised machine identities, according to CyberArk research. Manual processes can no longer keep up, and organisations need an automated discovery and context-driven approach to stay ahead.
“Implementing machine identity security programs has become increasingly complex as organisations grapple with shrinking certificate lifespans, the rise of AI agents, vault sprawl, and vulnerable software supply chains. With these new discovery, context and remediation capabilities, customers gain the visibility and control they need to tame sprawl, enforce policy and secure their environments more efficiently,” said Kurt Sand, GM of Machine Identity Security at CyberArk. “This milestone, just one year after our acquisition of Venafi, marks a significant step forward in our commitment to delivering the industry’s most comprehensive, end-to-end machine identity security solution.”
What CyberArk Upgrades Mean
CyberArk’s expanded Machine Identity Security portfolio delivers centralised visibility, automated policy enforcement and context-driven insights to help organizations monitor and secure every machine identity, anywhere, across the enterprise. Key enhancements include:
-
Discovery and Context for HashiCorp Vault: Helps address critical vault sprawl challenges by providing visibility into dispersed HashiCorp Vault instances and ensuring enterprise-wide policy compliance without disrupting developer workflows.
-
Risk Management and Remediation Dashboard: Centralises observability across market-leading secrets vaults and integrates third-party scanner data to identify high-risk areas, enabling organisations to prioritise remediation and track compliance progress.
-
CA/B Forum TLS Certificate (47-day) Dashboard: Provides real-time visibility into certificate expiration timelines, renewal projections and certificate authority usage to help organisations prepare for reduced TLS certificate lifespans (from 398 days today to 200 days in 2026, 100 days in 2027 and 47 days by 2029), allowing them to easily manage renewals and prevent outages.
-
Code Sign Management, Policy Enforcement, and Deep DevOps Integrations: Provide automated, policy-enforced code signing and governance alongside certificate lifecycle management to reduce infrastructure overhead, accelerate adoption and help ensure only trusted, compliant software is released.
-
New Authorisation and Policy Controls: Grant real-time authorisation tracking and discovery for centralsed visibility, risk reduction and audit compliance to help better manage SSH key sprawl and unmitigated access.
-
Watch the keynote at CyberArk IMPACT World Tour 2025 in Long Beach for demos of the new features (available live and on-demand).
-
Join Securing the New Frontier of Agentic AI virtual event on 4 November 2025 for new updates on the CyberArk Secure AI Agents Solution (available live and on-demand).
-
Join Workload Identity Day Zero on 10 November 2025 in Atlanta for new updates on the CyberArk Secure Workload Access Solution (available on-demand).



