Security Insights

Secrets Management

Thinking on cybersecurity, compliance, and managed defence - from the CyberCheck team.

Secrets Sprawl: Why Your Codebase Has More Credentials Than You Think

API Discovery: Why You Probably Have More APIs Than You Think

Every codebase accumulates more credentials than anyone tracking access controls believes it has, and the gap between “credentials we know about” and “credentials that actually exist and work” is what security teams call secrets sprawl — a problem that grows quietly with every API integration, every CI pipeline, and every developer who hardcodes a token … Read more

Kubernetes Secrets Management: Why the Default Approach Is Not Enough

Kubernetes Secrets Management: Why the Default Approach Is Not Enough

Kubernetes native secrets provide a convenient built-in mechanism for managing sensitive configuration data, but security-conscious organizations increasingly recognize that the default Kubernetes secrets approach carries real limitations that make it insufficient for security-sensitive production use without additional, deliberate hardening. What Kubernetes Native Secrets Provide Kubernetes secrets offer a built-in mechanism for storing and injecting sensitive … Read more

Secrets Sprawl: Finding Hardcoded Credentials Before Attackers Do

Security Awareness Training That Employees Do Not Tune Out

Hardcoded credentials – API keys, passwords, and tokens embedded directly in source code rather than properly managed through a dedicated secrets management system – remain a persistent, common security finding despite being a well-understood risk for years. Understanding why this keeps happening, and how to address it systematically, matters for any organization with a real, … Read more