Cyber Security
How IT can reduce credential risk across every department
Published
1 month agoon
By
Jon Tru
Credential sprawl is becoming a growing cybersecurity challenge as organizations rely on more cloud services, third-party platforms, AI tools, APIs, social media accounts, and remote workers. While single sign-on (SSO) can centralize access to many enterprise applications, it cannot eliminate every password, API key, token, or secret used across a modern organization.
The rapid adoption of artificial intelligence is adding another layer to the problem. AI assistants and agents increasingly require access to sensitive credentials and business systems, creating new questions about how organizations can provide the necessary access without exposing secrets.
A recent 1Password webinar examined how credential risks appear across departments such as product, marketing, finance, sales, and external contractors, while highlighting approaches organizations can use to improve visibility and access control.
AI Is Expanding the Credential Security Challenge
Credential management is no longer limited to passwords used by IT teams and developers. Organizations now rely on API keys, authentication tokens, connection strings, service accounts, and other secrets to power applications and AI-driven workflows.
Product managers and other nontechnical employees may also use AI tools to accelerate tasks such as drafting documentation, developing product requirements, or designing workflows. If sensitive information is accidentally included in an AI prompt, credentials and other secrets could potentially be exposed.
This means organizations need security controls that protect credentials even when employees and AI-powered tools interact with sensitive systems.
Product Teams Face Growing Secrets Exposure
Developers traditionally manage large numbers of credentials and application secrets. However, the expansion of AI tools means those secrets can increasingly be accessed or handled outside traditional engineering workflows.
API keys, staging credentials, connection strings, and other sensitive information may be included in development activities involving AI assistants. This creates a broader security perimeter that IT and security teams must monitor.
One approach demonstrated by 1Password involves acting as an access layer between AI development tools and sensitive credentials. Instead of placing secrets directly inside an AI model’s working context, credentials can remain protected and be authorized only when they are required.
This model can help organizations provide AI agents with necessary access while limiting direct exposure of sensitive secrets.
Marketing Accounts Are Often Overlooked
Corporate social media accounts can represent another significant credential-management challenge.
Platforms such as Instagram, Facebook, and LinkedIn may not provide the same centralized identity controls available in many enterprise applications. As a result, marketing teams sometimes share account credentials among employees, agencies, or contractors.
Without centralized visibility, organizations may not know exactly who can access a particular account or whether former employees and vendors still have access.
A compromised business social media account can have consequences beyond unauthorized access. Attackers may use it to distribute malicious links, impersonate the organization, manipulate advertising accounts, or damage a company’s reputation.
Finance and Sales Handle High-Value Credentials
Finance and sales departments frequently use applications that contain sensitive financial, customer, and business information.
Finance teams may rely on banking, payment, billing, or accounting portals protected by passwords that are shared or reused. Sales employees may also use specialized services that are not integrated with their organization’s SSO environment.
These credentials can become difficult for IT teams to monitor because they exist outside centralized identity systems.
A centralized password-management strategy can give administrators greater control over who can access sensitive credentials. Access can be assigned according to job responsibilities and revoked when an employee changes roles or leaves the organization.
Third-Party Access Creates Additional Risk
Contractors, agencies, suppliers, and other external partners often require access to company systems. The challenge is determining exactly what access they need and ensuring that it does not remain active after their work is complete.
Third-party-related security incidents have become an important concern. Verizon’s 2026 Data Breach Investigations Report reported a substantial year-over-year increase in breaches involving third parties and identified authentication weaknesses and inadequate least-privilege controls among recurring issues.
Manual access removal can make the situation worse. If an organization does not maintain an accurate record of shared credentials, administrators may struggle to determine which passwords were provided to which external users.
Time-limited credential sharing can help reduce this risk. Organizations can provide access to specific credentials for a defined period and restrict access to designated recipients, reducing the likelihood of long-term unauthorized access.
Why SSO Alone Cannot Solve Credential Sprawl
Single sign-on remains an important security control, but many applications and services still operate outside an organization’s SSO environment.
According to data cited by 1Password, a significant portion of business applications are not protected by SSO, while employees can also introduce shadow IT services without formal approval from IT or security teams.
This creates visibility gaps. Security teams may know which applications are officially approved but have limited information about credentials employees are actually using.
Password and secrets management tools can help fill these gaps by providing visibility into credentials that exist beyond centralized identity infrastructure.
Monitoring Password Health and Credential Usage
Security teams can strengthen credential governance by regularly examining password health and access activity.
Capabilities such as credential monitoring and audit logging can help organizations identify:
- Weak or reused passwords
- Credentials exposed in known breaches
- Accounts that lack stronger authentication controls
- Users with unnecessary access
- Credential-sharing activity
- Passwords that may require rotation
Detailed audit records can also provide organizations with evidence of who created, accessed, or shared credentials and when those activities occurred. Such records can support security investigations and compliance requirements.
Building a Stronger Credential Security Strategy
Organizations can reduce credential-related risk by treating passwords, API keys, tokens, and other secrets as critical security assets rather than isolated pieces of information.
A stronger strategy should include centralized visibility, least-privilege access, multifactor authentication, regular credential reviews, timely access removal, and controlled sharing with external partners.
AI introduces additional considerations because automated agents may need access to sensitive systems. Organizations should therefore establish clear controls around which credentials AI tools can access and ensure secrets are not unnecessarily exposed within AI prompts or model contexts.
The Road Ahead
Credential sprawl is no longer solely an IT problem. Product, marketing, finance, sales, contractors, and AI-powered workflows can all create new access paths that traditional identity tools may not fully cover.
Organizations that combine SSO with comprehensive credential management, strong access policies, monitoring, and human oversight can gain better visibility into these hidden access points.
As businesses continue adopting AI and expanding their digital ecosystems, controlling credentials across every department will become increasingly important for reducing security exposure and maintaining compliance.
You may like
US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries
Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data
BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory
Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners

