# Cisco Acquires Astrix and WideField for NHI

> Cisco adds Non-Human Identity capabilities to its security stack through acquiring Astrix Security and WideField AI, targeting machine credential governance.

**URL:** https://www.ciptadusa.com/blog/cisco-acquires-astrix-widefield-nhi-20260629  
**Type:** blog  
**Author:** PT Cipta Dua Saudara  
**Category:** Application Security  
**Published:** 2026-06-29  
**Cover:** https://cdn-uagents.enitip.com/uploads/blog/2026-06/daily-appsec-20260629-014641.jpg  

## Article

Cisco just acquired two companies simultaneously — Astrix Security and WideField AI — to close a critical gap in non-human identity security. This move confirms that service accounts, API keys, and machine credentials are now attack vectors as serious as human credentials.

## Summary

Cisco adds Non-Human Identity (NHI) capabilities to its security stack through the acquisition of Astrix Security and WideField AI, targeting visibility and governance over millions of machine credentials in enterprise environments.

## Background

In modern infrastructure, non-human identities — service accounts, API tokens, OAuth clients, bot credentials, and machine-to-machine certificates — outnumber human identities by a **45:1 ratio** in the average enterprise. Every microservice, CI/CD pipeline, and SaaS integration requires its own credential.

Dark Reading reports that Cisco acquired **Astrix Security** (specializing in NHI discovery and lifecycle management) and **WideField AI** (AI-driven identity governance) to integrate these capabilities into Cisco Security Cloud. This dual acquisition marks an industry pivot: IAM is no longer sufficient when it only secures human logins.

The fundamental problem is simple yet dangerous: **machine credentials often have excessive privileges, are never rotated, and go unmonitored**. A single API key leaked from a public repository can provide lateral access across an entire environment — without triggering alerts in traditional SIEMs designed to detect human behavioral anomalies.

## Implications

This acquisition has three practical implications:

**1. NHI Discovery Becomes Table Stakes**

Organizations without a complete inventory of their machine credentials are now in a more vulnerable position. If Cisco — the largest networking vendor — considers NHI critical enough for two simultaneous acquisitions, auditors and regulators will follow.

**2. Posture Management for Non-Humans**

Astrix brings the ability to detect service accounts with excessive privileges, tokens that are never rotated, and overly broad OAuth grants. This is posture management — a concept already established for cloud resources (CSPM) — applied to machine identities.

**3. AI-Driven Governance**

WideField AI adds an intelligence layer: predicting which credentials are high-risk based on access patterns, blast radius if compromised, and historical behavior. This moves beyond rule-based policy to adaptive risk scoring.

For security teams, the practical first step is a simple audit: how many active service accounts exist in your environment, when were their credentials last rotated, and does each have the minimum required scope?

## References

- [Cisco Adds NHI to Security Stack With Astrix, WideField Acquisitions — Dark Reading](https://www.darkreading.com/identity-access-management-security/cisco-adds-nhi-security-stack-with-astrix-widefield)
- [The Rise of Non-Human Identities — Astrix Security](https://astrix.security/research/)
- [OWASP Non-Human Identity Top 10](https://owasp.org/www-project-non-human-identity-top-10/)

---

*Markdown version of https://www.ciptadusa.com/blog/cisco-acquires-astrix-widefield-nhi-20260629 — generated for AI agents and LLM crawlers.*
