Secrets Management: Why Vault Is a Governance Decision

Every system a firm runs holds secrets — passwords, API keys, tokens, certificates, database credentials — and in most organisations those secrets are scattered: hard-coded in applications, sitting in configuration files, embedded in scripts, shared informally, and rarely rotated. A secrets-management platform like HashiCorp Vault centralises and governs them, and adopting one is often framed as a technical infrastructure decision. It is better understood as a governance decision, because secrets are the credentials that protect everything, and how they are stored, accessed, rotated and audited is a control that regulators, auditors and attackers all care about. The scattered status quo is a serious exposure hiding in plain sight.

Why scattered secrets are a governance problem

Secrets scattered across the estate are ungoverned by definition. Hard-coded credentials in code end up in source control and are almost never rotated. Keys in configuration files spread wherever the configuration goes. Shared secrets have no individual accountability. And nobody has a complete picture of where the firm’s secrets are, who can access them, or when they last changed. This is exactly the profile an attacker exploits — a leaked or discovered credential that is broad, static and long-lived — and exactly what an auditor flags. The governance failure is not that secrets exist but that they are unmanaged: no central control, no rotation, no access governance, no audit trail. A secrets-management platform addresses this, but only if adopted as the governance capability it is rather than a technical store bolted on.

What good secrets governance requires

  • Centralisation and inventory. Secrets held in a governed central store rather than scattered, so the firm knows what secrets exist and where — the foundation everything else rests on.
  • Access control and least privilege. Who and what can access each secret, governed and least-privilege, so a secret is reachable only by what genuinely needs it.
  • Rotation. Secrets rotated regularly and automatically, so a leaked credential has a limited life and static long-lived secrets stop being the norm.
  • Audit trail. A record of who accessed what secret and when, so access can be reviewed and an incident investigated — the evidence a supervisor and an investigation both need.

Adopting it as governance

  • Treat it as a control, not just infrastructure. A secrets-management platform is a security and compliance control; adopt it with the governance outcomes — centralisation, access control, rotation, audit — as the goal, not just the deployment.
  • Start by finding the secrets. You cannot govern secrets you have not found; discovering the scattered credentials across the estate is the necessary and often revealing first step.
  • Get applications off hard-coded secrets. The highest-value move is usually eliminating hard-coded credentials in code and configuration, replacing them with governed retrieval from the platform.
  • Enforce rotation and least privilege. The point of centralising is to enable rotation and access governance; a central store that still holds broad, static secrets has moved the problem rather than solved it.

Secrets management is one of those capabilities that looks like infrastructure and is really governance, because the secrets in question are the credentials that protect the firm’s systems and data. The scattered, hard-coded, unrotated status quo is a serious and common exposure, and a platform like Vault addresses it — but only if adopted as the governance capability it is, with centralisation, access control, rotation and audit as the actual goals. The firms that get this right turn their secrets from an ungoverned liability that attackers and auditors both find into a governed control the firm can account for; the ones that deploy the platform without the governance just relocate the scattered secrets into a central place and leave them nearly as exposed.

Free · 4 minutes

Would you survive contact with a determined attacker — or an auditor?

Fourteen questions on access, patching, detection, and recovery — the basics that prevent most real incidents, and the ones most often assumed rather than verified. Banded finding on screen, full sheet by email.

Who this is for

This reading is for:

  • CISOs and platform leads whose secrets are scattered and ungoverned
  • CTOs considering a secrets-management platform like HashiCorp Vault
  • Compliance leads who cannot answer where the firm’s credentials live
  • Boards accountable for the keys that protect everything

Sixteen Pillars helps firms adopt secrets management as the control it is – centralisation, access control, rotation and audit – rather than a store that just relocates the scattered secrets. Pricing is published at /pricing/. If this is live for your organisation and you would like an independent reading, the place to start is a conversation.

Sixteen Pillars is a technology governance consultancy based in Cyprus. Engagements run remote across the EU, UK, and Middle East, with on-site time where the engagement requires it.

Free interactive tool

Website compliance checklist

What your site has to do, based on what it actually does

Answer as much or as little as you like — the list builds as you go. Nothing is stored against your name and no email is required.

Free interactive tool

Interactive deadline calculator

Check which regulations apply to you and when

Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.

Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.

Most technology problems are not technology problems. They are control problems.

The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.

Full Governance by Sixteen Pillars

Govern your business. Prove your compliance.

A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.

See what's coming