The Default Security Posture Most Startups Actually Ship With
Most teams ship with secrets in Kubernetes environment variables, no dedicated secret store, and a “TTLS” posture: total trust, everyone has access to everything. Security teams rarely talk to the engineers building the product. Munjal ran that exact setup at his previous startup. A service account key sat exposed, an attacker found it, spun up maxed-out GCP machines over a weekend, and ran a crypto-mining operation that cost roughly a million dollars.
That outcome is not unusual. It is what happens when there is no enforced boundary between what a service can reach and what it should.
Unmeasured Security Is Just Theater
Buying a Sentinel One subscription or a Wiz license is not a security posture. As Munjal put it: “measure uh security it’s just theater.” GitHub saw 23.77 million new secrets leaked in 2024 alone. Of detected secrets that year, 58% were generic, a 9% jump over prior years. Of exposed GitLab API keys, 58% had full access. MongoDB credentials topped the cloud key exposure list, and Neo4j connections grew 188% year over year.
GitHub’s push protection helps but does not catch everything. Secrets are easy to push and very hard to track down afterward.
Five Metrics That Turn Security Into a Business Signal
Munjal proposed five KPIs to turn HashiCorp telemetry into business numbers. Risk Footprint Index (RFI) scores what fraction of production sits behind mTLS, dynamic secrets, or a PAM system. Time to Remediate (TTR) captures how fast an incident closes. Mean Access Grant Time (MAGT) times how long a Boundary session request takes to approve. Toil tracks automatable work that is not yet automated. Break-glass counts manual control bypasses.
None of these come out of the box. They require composing raw Vault, Consul, and Boundary metrics into one signal, then surfacing it in Prometheus and Grafana.
Demo Results: Two Clusters, Measurable Proof
Munjal built two Kubernetes clusters side by side: “daily life,” with secrets as bare environment variables and no dedicated tooling, and “HashiCorp 2025,” running Vault for dynamic secrets, Consul for mTLS sidecars, and Boundary for session requests. He ran scenarios across both for 3 hours 40 minutes and scraped results into Grafana. See the two-cluster Vault + Consul + Boundary demo (23:55) for the full walkthrough.
RFI rose sharply on the HashiCorp cluster. TTR and MAGT both dropped. Standardizing to that stack, he argued, already delivers 80% of security coverage without reaching the scaling tier of HashiCorp’s three-stage SLM model.
Notable Quotes
measure uh security it’s just theater Prerit Munjal · ▶ 7:20
23.77 Prerit Munjal · ▶ 15:44
blameless learning evidence over fear Prerit Munjal · ▶ 22:51
Key Takeaways
- 58% of detected secrets in 2024 were generic, and 23.77 million new secrets leaked on GitHub that year alone.
- Combine Vault, Consul, and Boundary telemetry into five KPIs — RFI, TTR, MAGT, toil, break-glass — to make security legible to business.
- A 3h40m controlled test showed RFI up, TTR down, and MAGT down when the HashiCorp stack replaced bare Kubernetes secrets.