Fragmentation and Finding a Home for Vault
Vault arrived at Nationwide four or five years ago for a single use case. It bounced between teams, never gaining traction beyond that one deployment, until Lee March’s encryption team took ownership about a year and a half before this talk. That team already ran certificates, PKI, and privilege access management. A natural home. Riverpoint’s Gabe Maentz assessed the environment and found the technology was solid. The problem was fragmentation: no anchor, no owner, no path to scale.
Making the Business Case at the Executive Level
Lee March took the case directly to a CTO cabinet meeting. The CTO turned to one of his VPs and asked whether the VP’s team had suffered outages from expired secrets. The VP confirmed they had. March offered to take the entire rotation burden off that team: Vault would manage it, no human would ever need to know the secret, and rotation cadence could drop from once a year to every 10 hours. Industry data backed the security argument too. Between 60 and 75% of cyber events over the past few years involved identity compromise.
Culture and Organizational Change Management
Gabe Maentz’s core argument: stop focusing on the technology and start mapping the cultural terrain. Most enterprises build Vault, then nobody shows up. Nationwide is approaching 100 years old, and legacy processes run deep. To cut friction, the encryption team built end-to-end automated migration so consuming teams received a notification that their secrets had moved and nothing more. For new capabilities, planning started in March for the following year, giving business teams time to budget. An executive sponsor with authority to push back on competing priorities was the other non-negotiable.
Compliance, Non-Human Identities, and What Comes Next
Vault gives Nationwide a single control set for SOC 2, SOC 1, and PCI audits. Auditors come to one system instead of chasing practices across 50 teams. Vault Radar extends that posture by scanning for secrets still in the wild.
It is the wild west. — Gabe Maentz
A proof-of-value run in production found enough that Lee March called it “scary to see what it finds.” Certificate lifetimes are dropping to 47 days externally, and Nationwide wants the same internally. With tens of thousands of certificates and agentic AI workloads incoming, full automation is non-negotiable. Post-quantum cryptography is also on the three-year list.
Notable Quotes
have to do change management. Gabe Maentz · ▶ 24:19
almost game over. Lee March · ▶ 18:22
It is the wild west. Gabe Maentz · ▶ 21:32
Key Takeaways
- Vault adoption stalled at one or two use cases until Nationwide unified secrets, PKI, and PAM under a single encryption team.
- Executive roadshows and per-minute financial impact data from P0 outages converted resistant teams faster than technical arguments.
- Certificate lifetimes dropping to 47 days and agentic AI workloads make secrets automation non-optional at enterprise scale.