
Published on: February 28, 2025 Updated 2 times since publishing
85% of identity breaches stem from compromised machine identities, yet most companies still rely on legacy solutions that create costly security gaps, operational inefficiencies, and scaling nightmares instead of reducing risk.
In this SafetyDetectives interview, Refael Angel, Co-Founder & CTO at Akeyless, explains why secrets and machine identities are now the #1 attack vector, and how Akeyless is eliminating single points of failure with its cloud-native, vaultless approach.
In 2-3 sentences, why does Akeyless exist? What’s the pain point it was designed to solve and how does it solve it?
Traditional secrets management solutions—especially vault-based approaches—are costly, complex to maintain, and difficult to scale, leading to security gaps and operational inefficiencies.
Akeyless eliminates these issues with a cloud-native SaaS platform powered by Distributed Fragments Cryptography (DFC™), which ensures that no single entity (not even Akeyless) ever holds full access to an encryption key.
Going more into details, what makes this pain point so severe in your industry that you set out to create your own solution to solve it?
Secrets and machine identities now outnumber human identities by a factor of 45:1, making them the most commonly exploited attack vector.
85% of identity-related breaches are caused by compromised machine identities, and stolen credentials are involved in 49% of all breaches.
Despite this, most organizations struggle with siloed, outdated, and manually intensive security tools, which create blind spots, compliance risks, and unnecessary complexity.

Most existing solutions are point solutions that only manage one part of the lifecycle of managing secrets and machine identities. Many organizations attempt to address this by using multiple tools—secrets managers, certificate managers, password vaults, and access control solutions—but this fragmentation increases cost and complexity rather than solving the underlying problem.
We saw the need for a unified, cloud-native approach that provides complete security across the lifecycle of secrets & non-human identities, without the burden of managing infrastructure.
What kind of people or organizations are most affected by this issue, and why are they stuck with it?
Organizations of all sizes can be heavily impacted but especially financial institutions, technology companies, and global enterprises with complex, multi-cloud environments (such as Akeyless customers Dropbox, Cimpress, and Wix). These kinds of companies face unique challenges due to the sheer number of machine identities they need to protect.
- Many are stuck using outdated, on-premise vaults that were never designed for today’s dynamic, automated environments.
- Others attempt to stitch together multiple security solutions, leading to fragmentation, increased costs, and operational inefficiencies.
- The problem is further compounded by the shortage of cybersecurity talent, leaving security teams overburdened and unable to keep up with evolving threats.
What’s everyone else doing to solve this problem, and why do you think these solutions are flawed?
Most organizations rely on a mix of legacy vaults, open-source solutions, and cloud-native key management services, none of which fully address the challenge:
- Traditional Vaults (such as self-deployed secrets management tools) are complex to deploy, expensive to scale, and require ongoing maintenance, creating a massive operational burden.
- Open-Source Tools (such as open source secrets management solutions) can provide flexibility to tailor tools in-house but require significant expertise and engineering resources to manage effectively.
- Cloud Provider Solutions (e.g., AWS Secrets Manager, Azure Key Vault) lock organizations into specific ecosystems, limiting multi-cloud interoperability and flexibility.
These fragmented solutions lead to vault sprawl, operational bottlenecks, and increased attack surfaces, making it easier for attackers to exploit hardcoded credentials, mismanaged machine identities, and unrotated secrets.
How exactly do you solve this problem in a better way?
Akeyless delivers the world’s first Unified Secrets & Machine Identity Platform—a cloud-native, SaaS solution that integrates Secrets Management, Certificate Lifecycle Management, Next-Gen Privileged Access Management (PAM), and Encryption Key Management into a single platform.
What sets Akeyless apart:
- Zero-Knowledge Security: Our patented Distributed Fragments Cryptography (DFC™) ensures that no single entity, not even Akeyless, has full access to encryption keys, eliminating single points of failure.
- Cloud-Native & Vaultless: Unlike traditional vault-based solutions, Akeyless requires no infrastructure maintenance, reducing operational overhead by up to 70%.
- Automated & Secretless Access: Eliminates the risk of static credentials through Just-in-Time (JIT) access and ephemeral secrets.
- Seamless Multi-Cloud Integration: Works across AWS, Azure, GCP, on-premise, and hybrid environments—providing full visibility and control from a single platform.
With Akeyless, organizations reduce security risks, streamline operations, and eliminate the need for costly, fragmented security tools.
How do you think this issue will evolve in the near future, and what should people do to get ready?
The threat landscape is evolving rapidly, and machine identities are now the primary attack surface. Security teams need to rethink their approach to protecting non-human identities before breaches become even more catastrophic.
What’s next:
- Secrets Sprawl will get worse: The average organization manages over 6-10 secrets management instances, leading to inconsistent security controls.
- Credential-based attacks will continue to rise: 83% of hacking-related breaches involve stolen credentials, making secretless authentication models critical.
- AI and automation will increase the attack surface: With AI-driven development and automation expanding, security teams must move beyond human-centric security models to protect non-human identities.
- Regulatory and compliance pressures will increase: Financial institutions and enterprises will face stricter compliance mandates for protecting machine identities and enforcing least privilege access.
How to prepare:
- Adopt a unified platform: Eliminate security silos by consolidating secrets management, certificate lifecycle automation, and machine identity security.
- Embrace a secretless model: Move away from long-lived credentials and implement Just-in-Time (JIT) access as well as frameworks such as SPIFEE.
- Automate certificate & key management: Ensure continuous security by automating rotation, renewal, and revocation of credentials and certificates.
- Prioritize Zero-Knowledge security: Choose solutions that provide complete control of your secrets by restricting even the SaaS vendor from full access to encryption keys.
How can our readers connect with you?
LinkedIn: https://www.linkedin.com/in/refael-angel-571a1050/
Learn more about Akeyless and request a demo HERE:
https://www.akeyless.io/