---
title: Security Pros Don’t Protect Keys and Certificates as Effectively as Usernames and Passwords
description: While almost all organizations have a policy that governs password length for human identities, only half have a written policy on length and randomness of keys for machine identities
image: https://businessinsights.bitdefender.com/hubfs/lock%20security.jpg
---

[![](https://businessinsights.bitdefender.com/hubfs/2021/09/logo-white.svg)](https://businessinsights.bitdefender.com/?hsLang=en-us)

[![CONTACT AN EXPERT](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd)

- [For Home](https://www.bitdefender.com/solutions/)
- [For Business](https://www.bitdefender.com/business/)
- [Resources](https://www.bitdefender.com/business/resource-library.html)
- [Webinars](https://www.bitdefender.com/business/webinars.html)

# [BUSINESS INSIGHTS](https://businessinsights.bitdefender.com/?hsLang=en-us)

 By [**Filip Truta**](https://businessinsights.bitdefender.com/author/filip-truta) / Dec 27, 2019

# Security Pros Don’t Protect Keys and Certificates as Effectively as Usernames and Passwords

Share this [![Share on email](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/email-color.png)](mailto:?subject=Check%20out%20https://businessinsights.bitdefender.com/security-pros-dont-protect-keys-and-certificates-as-effectively-as-usernames-and-passwords&utm_medium=social&utm_source=email%20&body=Check%20out%20https://businessinsights.bitdefender.com/security-pros-dont-protect-keys-and-certificates-as-effectively-as-usernames-and-passwords&utm_medium=social&utm_source=email) [![Share on twitter](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/twitter-color.png)](https://twitter.com/intent/tweet?original_referer=https://businessinsights.bitdefender.com/security-pros-dont-protect-keys-and-certificates-as-effectively-as-usernames-and-passwords&utm_medium=social&utm_source=twitter&url=https://businessinsights.bitdefender.com/security-pros-dont-protect-keys-and-certificates-as-effectively-as-usernames-and-passwords&utm_medium=social&utm_source=twitter&source=tweetbutton&text=) [![Share on linkedin](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/linkedin-color.png)](http://www.linkedin.com/shareArticle?mini=true&url=https://businessinsights.bitdefender.com/security-pros-dont-protect-keys-and-certificates-as-effectively-as-usernames-and-passwords&utm_medium=social&utm_source=linkedin) [![Share on facebook](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/facebook-color.png)](http://www.facebook.com/share.php?u=https://businessinsights.bitdefender.com/security-pros-dont-protect-keys-and-certificates-as-effectively-as-usernames-and-passwords&utm_medium=social&utm_source=facebook)

A study comparing security controls for human and machine identities reveals a worrying trend. While almost all organizations have a policy that governs password length for human identities, only half have a written policy on length and randomness of keys for machine identities - this, despite the rapid spread of machines that need to authenticate themselves to each other so they can communicate securely.

When authenticating themselves to machines, people rely on usernames and passwords to gain access to data and services. Similarly, machines need to authenticate themselves to each other to communicate in a secure manner. Virtual machines (VMs), applications, algorithms, APIs and containers, and even IoT devices, rely on cryptographic keys and digital certificates, which serve as machine identities that lets them know it’s safe to share data.

A [survey](https://www.businesswire.com/news/home/20191219005004/en/) by Venafi, a firm specialized in securing cryptographic keys and digital certificates, found that 85% of organizations have a policy that governs password length for human identities. The survey of 1,500 IT security professionals from the U.S., the U.K., France, Germany and Australia showed that only 54% have a written policy on length and randomness for keys for machine identities.

Venfai found organizations will spend upwards of $10 billion this year solely to protect human identities. Machine identity protection spending remains “relatively flat,” the researchers said (no exact number provided), despite an exponential increase in the number of machines that need identities, including virtual machines, applications, algorithms, APIs and containers.

“Because cybercriminals understand the power of machine identities and their lack of protection, they target them for exploitation,” the survey takers said.

Additional findings include:

- 49% of organizations audit the length and randomness of their keys, while 70% do so for passwords.
- Only 55% have a written policy stating how often certificates and private keys should be changed, while 79% have an equivalent policy for passwords.
- Only 42% of organizations automatically enforce the rotation of TLS certificates, while 79% automatically enforce the rotation of passwords.
- Only 53% audit how often certificates and private keys should be changed, compared with 73% for passwords.

Researchers say that, while attacks using machine identities are relatively new, they’re very effective. Furthermore, the gap between the security controls applied to human identities and those applied to machine identities is exposing organizations to immense risks, especially for digital businesses that rely heavily on machines for mission critical, day-to-day operations. 

### Explore More Topics

- [Enterprise Security (743)](https://businessinsights.bitdefender.com/topic/enterprise-security)
- [Threat Research (201)](https://businessinsights.bitdefender.com/topic/threat-research)
- [Cloud Security (174)](https://businessinsights.bitdefender.com/topic/cloud-security)
- [SMB Security (170)](https://businessinsights.bitdefender.com/topic/smb-security)
- [Ransomware (166)](https://businessinsights.bitdefender.com/topic/ransomware)
- [Privacy and Data Protection (137)](https://businessinsights.bitdefender.com/topic/privacy-and-data-protection)
- [Cybersecurity Awareness (134)](https://businessinsights.bitdefender.com/topic/cybersecurity-awareness)
- [Endpoint Protection & Management (126)](https://businessinsights.bitdefender.com/topic/endpoint-protection-management)
- [Endpoint Detection and Response (124)](https://businessinsights.bitdefender.com/topic/endpoint-detection-and-response)
- [Managed Detection and Response (119)](https://businessinsights.bitdefender.com/topic/managed-detection-and-response)
- [Virtualization & Data Center Security (82)](https://businessinsights.bitdefender.com/topic/virtualization-data-center-security)
- [Threat Intelligence (76)](https://businessinsights.bitdefender.com/topic/threat-intelligence)
- [IT Compliance & Regulations (71)](https://businessinsights.bitdefender.com/topic/it-compliance-regulations)
- [Bitdefender Threat Debrief (55)](https://businessinsights.bitdefender.com/topic/bitdefender-threat-debrief)
- [Managed Service Providers (53)](https://businessinsights.bitdefender.com/topic/managed-service-providers)
- [#Featured (52)](https://businessinsights.bitdefender.com/topic/featured)
- [Advanced Persistent Threats (46)](https://businessinsights.bitdefender.com/topic/advanced-persistent-threats)
- [Events (38)](https://businessinsights.bitdefender.com/topic/events)
- [Independent Testing (18)](https://businessinsights.bitdefender.com/topic/independent-testing)
- [Cybersecurity Advisory Services (9)](https://businessinsights.bitdefender.com/topic/cybersecurity-advisory-services)
- [Podcast (3)](https://businessinsights.bitdefender.com/topic/podcast)
- [top (2)](https://businessinsights.bitdefender.com/topic/top)

See all topics

### Subscribe to Blog Updates

## Read more about this topic

<https://businessinsights.bitdefender.com/leoni-fraud-email-impersonation-scam?hsLang=en-us>

### [German wire supplier Leoni loses €40m in email impersonation scam](https://businessinsights.bitdefender.com/leoni-fraud-email-impersonation-scam?hsLang=en-us)

<https://businessinsights.bitdefender.com/many-cios-believe-expired-tls-certificates-could-affect-their-business?hsLang=en-us>

### [Many CIOs Believe Expired TLS Certificates Could Affect Their Business](https://businessinsights.bitdefender.com/many-cios-believe-expired-tls-certificates-could-affect-their-business?hsLang=en-us)

<https://businessinsights.bitdefender.com/fbi-businesses-email-impersonation-scams?hsLang=en-us>

### [FBI: Businesses lost $3.1 billion in email ‘impersonation’ scams](https://businessinsights.bitdefender.com/fbi-businesses-email-impersonation-scams?hsLang=en-us)

![bitdefender](https://businessinsights.bitdefender.com/hs-fs/file-2685110570-png/Bitdefender-Mar2015-Theme/Images/avatar_img_footer.png)

![bitdefender](https://businessinsights.bitdefender.com/hs-fs/file-2676149282-png/Bitdefender-Mar2015-Theme/Images/logo_white_footer.png)

- [![https://twitter.com/Bitdefender_Ent](https://businessinsights.bitdefender.com/hs-fs/file-2658233851-png/Bitdefender-Mar2015-Theme/Images/ft_soc_tw.png?width=33&name=ft_soc_tw.png)](https://twitter.com/Bitdefender_Ent)
- [![Linkedin-icon-300x300](https://businessinsights.bitdefender.com/hs-fs/hubfs/Bitdefender-Mar2015-Theme/Images/Linkedin-icon-300x300.png?width=33&name=Linkedin-icon-300x300.png)](https://www.linkedin.com/company/bitdefender-gravityzone-enterprise-security)
- [![](https://businessinsights.bitdefender.com/hs-fs/file-2676149307-png/Bitdefender-Mar2015-Theme/Images/ft_soc_yt.png)](https://www.youtube.com/user/BitdefenderSecurity)

- [Legal Terms](https://www.bitdefender.com/legal/)
- [Privacy Policy](https://www.bitdefender.com/site/view/legal-privacy-policy-for-bitdefender-websites.html)
- [EULA](https://www.bitdefender.com/site/view/legal-eula.html)
- [Contact Us](https://www.bitdefender.com/business/contact.html)

Copyright © 1997-2023 Bitdefender All rights reserved.

![](https://px.spiceworks.com/px/5rec)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Filip Truta",
    "url" : "https://businessinsights.bitdefender.com/author/filip-truta"
  },
  "dateModified" : "2019-12-27T11:02:25.309Z",
  "datePublished" : "2019-12-27T11:02:25.000Z",
  "headline" : "Security Pros Don’t Protect Keys and Certificates as Effectively as Usernames and Passwords",
  "image" : [ "https://businessinsights.bitdefender.com/hubfs/lock%20security.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://businessinsights.bitdefender.com/security-pros-dont-protect-keys-and-certificates-as-effectively-as-usernames-and-passwords",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://businessinsights.bitdefender.com/hubfs/Bitdefender_Logo_Transparent-2.png"
    },
    "name" : "Bitdefender"
  }
}
```