Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Managing resilience»Technology»There is a clear trend for shorter TLS certificate lifespans, but automation is a must for resilience (Page 16)
Technology

There is a clear trend for shorter TLS certificate lifespans, but automation is a must for resilience

December 31, 20244 Mins Read
TLS certificates and security concept.

Transport Layer Security (TLS) certificates, often known as SSL certificates, secure Internet connections by encrypting data to protect it against modification or theft. The technology is essential but is also the root cause of outages when certificates expire without being renewed.

When TLS certificates were initially introduced renewal was a manual process with certificates often having yearly expiration periods. Now the certificate industry has recognised that shorter lifespans make it harder for attackers to compromise certificates, but with shorter lifespans the risk with manual certificate renewals increases.

Looking ahead, Let’s Encrypt, one of the key players in the certificate market, has announced that in 2025 it plans to make certificates with a lifetime of six days available. “This is a big upgrade for the security of the TLS ecosystem because it minimizes exposure time during a key compromise event,” says Let’s Encrypt Executive Director, Josh Aas.

How should organizations response to this resilience opportunity and challenge? The answer is to scrap manual renewals completely and embrace automation, says Kevin Bocek, Chief Innovation Officer, at Venafi, a CyberArk company.

Here, Kevin explains more about the Let’s Encrypt announcement and its implications:

“Let’s Encrypt announcing that it will be offering 6 day certificates from next year is a clear signal to where the market is moving. There has been growing momentum around shorter certificate lifecycles – with Google having stated its intention to shorten the lifespan of public TLS certificates used with Chrome from 398 days to 90 days, and Apple directing a vote among Certification Authority Browser Forum (CA/B Forum) members, to cut certificate lifespans to 47 days by 2028. And with good reason. Certificate lifespans are currently far too long, which increases the likelihood that they will be compromised – over half (57%) of organizations have experienced security incidents involving compromised TLS certificates in the past year. Shortening certificate lifespans will help businesses reduce that risk.

“Let’s Encrypt has boomed in popularity with developers over the last few years, as it gives developers a quick, free and easy way to issue TLS machine identities for all manner of critical web services – from websites to customer applications. In offering this new service, Let’s Encrypt is throwing down the gauntlet to other Certificate Authorities (CAs) to follow suit. Yet to take advantage of this new service and others like it, businesses will need the right processes and tools in place. Automation is essential if you want to rotate certificates every six days. However, recent research shows that many aren’t. When asked recently about their views on Google’s proposal to reduce certificate lifespans to 90 days, 81% of security leaders believe it will amplify existing challenges they have around managing certificates, with nearly three-quarters (73%) saying it could cause ‘chaos’ and a further 75% saying it could even make them less secure. Worryingly, 77% think more outages are ‘inevitable’.

“One of the reasons that so many companies are feeling alarmed is that they do not have the right tools and resources in place to manage their machine identities at scale. Just 8% of organizations fully automate all aspects of TLS certificate management across the entire enterprise – with almost a third (29%) still relying on their own software and spreadsheets to manage the problem. As a result, organizations take 2-3 working days (21 and ¾ hours) to manually deploy a certificate. While shortening certificate lifecycles helps reduce some risks and is a step in the right direction, it also brings added complexity for security teams. We’re not just dealing with minor red flags here – we’re seeing problems everywhere, from the cloud to virtual machines and Kubernetes clusters. It’s not just one vendor’s issue; it’s the entire Internet at stake. The good news is this is a solvable problem. Security teams can get certificate lifecycle management (CLM), PKI-as-a-service and workload identity issuers all on one control plane now.”

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleFrom crisis to control: building a cyber incident response plan
Next Article Machine identities are the next big target for cyberattacks according to large survey

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
Digital Europe map with stars, symbolizing EU cybersecurity and technology.

ENISA releases guidance to help organizations develop successful cyber security exercises

February 19, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?