Skip to main content
NEW: RSAC 2026 NHI Field Report. How Non-Human Identity became cybersecurity's central axis
All Customers/enterprise
ENlighten

28,800 power plants, and the keys to them

An energy platform preparing for ISMS certification extended credential visibility across its Google Cloud environment.

enterprise150+ employees
28,800+
Solar plants on the platform
GCP
Where the keys lived
ISMS-P
Audit the scan fed
Read the Story
The Challenge

ENlighten operates a platform that manages more than 28,800 solar power plants across Korea. Generation forecasting, asset monitoring and energy trading all run on Google Cloud, which makes a service account key less of a minor secret and more of a door into the systems that read and act on national generation data. The company was preparing for ISMS certification while winning enterprise customers who bring their own security requirements. Several years of fast development had left GCP service keys sitting in repositories, internal documents and collaboration tools, and the certification work needed an accounting of where they were.

The Solution

Cremit scanned the development and collaboration environments together and returned the GCP service keys that had ended up outside the places meant to hold them. The team rotated them. Each key came back with the repository or document it was found in, which is the form the audit question takes as well: not whether the company manages cloud credentials, but how it knows where they are.

As we prepared for ISMS certification, Cremit helped us identify Google Cloud service keys we didn't even know were exposed. Securing these credentials not only reduced our risk but gave us the documented evidence we needed for the audit.

ENlighten
Jinseok Yeo
Security Engineer
The Results

The scan turned up a substantial number of Google Cloud service keys that had built up across the stack over several years. All of them were rotated. The scan record then went into the ISMS submission. Credential management is one of the controls an audit asks a company to demonstrate rather than assert, and a dated scan across every repository and document is that demonstration.

Ready to achieve similar results?

Join ENlighten and other leading companies securing their infrastructure with Cremit

Trusted by industry leaders

Next SecuritiesRapportlabs8PercentSBSiOrdercheckSpoonlabs