TrustRadius: an HG Insights company

CyberArk Privileged Access Management vs. IBM Vault

Save this comparison

Save this comparison

Add Product

Recommended Comparisons

    Overview
    ProductRatingMost Used ByProduct SummaryStarting Price

    CyberArk Privileged Access Management

    Score8.5 out of 10
    N/ACyberArk is a privileged account and access security suite issued by the company of the same name in Massachusetts . The Core Privileged Access Security Solution unifies Enterprise Password Vault, Privileged Session Manager and Privileged Threat Analytics to protect an organization’s most critical assets.N/A

    IBM Vault

    Score8.6 out of 10
    N/AIBM Vault (formerly Hashicorp Vault) is an encryption tool for managing secrets including credentials, passwords and other secrets, providing access control, audit trail, and support for multiple authentication methods. It is available open source, or under an enterprise license.

    $0.03

    Pricing
    CyberArk Privileged Access ManagementIBM Vault
    Editions & Modules
    No answers on this topic
    Cloud - HCP Vault
    $0.03/hr
    Open Source
    Free
    Enterprise
    Contact sales team
    Offerings
    Pricing Offerings
    CyberArk Privileged Access ManagementIBM Vault
    Free Trial
    YesNo
    Free/Freemium Version
    NoYes
    Premium Consulting/Integration Services
    NoNo
    Entry-level Setup FeeNo setup feeNo setup fee
    Additional DetailsCyberArk offers a variety of Identity Security packages for different user types within an organization.—
    More Pricing Information
    Community Pulse
    CyberArk Privileged Access ManagementIBM Vault
    Considered Both Products
    Cyberark
    No answer on this topic
    IBM
    Chose IBM Vault
    We evaluated Symantec as an existing partner within our enterprise. We found that the API provided by Vault is superior and that was a critical use case in our organization. We also found that Vault has more engine types which allow different types of data to be stored. This …
    Incentivized
    Key User Insights
    Would buy again
    100%
    Would buy again
    7 Answers
    No answers on this topic
    Delivers good value for the price
    83%
    Delivers good value for the price
    5 Answers
    No answers on this topic
    Happy with the feature set
    86%
    Happy with the feature set
    6 Answers
    No answers on this topic
    Lived up to sales and marketing promises
    No answers on this topic
    No answers on this topic
    Implementation went as expected
    100%
    Implementation went as expected
    5 Answers
    No answers on this topic
    Best Alternatives
    CyberArk Privileged Access ManagementIBM Vault
    Small Businesses
    No answers on this topic
    Keeper
    Score8.3 out of 10
    Medium-sized Companies
    Delinea Secret Server
    Score7.2 out of 10
    Keeper
    Score8.3 out of 10
    Enterprises
    BeyondTrust Endpoint Privilege Management
    Score10 out of 10
    No answers on this topic
    All AlternativesView all alternativesView all alternatives
    User Ratings
    CyberArk Privileged Access ManagementIBM Vault
    Likelihood to Recommend
    9.0
    (10 ratings)
    8.0
    (7 ratings)
    Likelihood to Renew
    -
    (0 ratings)
    10.0
    (1 ratings)
    Usability
    9.0
    (1 ratings)
    9.0
    (3 ratings)
    Support Rating
    7.2
    (4 ratings)
    6.3
    (3 ratings)
    User Testimonials
    CyberArk Privileged Access ManagementIBM Vault
    Likelihood to Recommend
    Cyberark
    The system is great for enterprise or larger IT departments or teams where temporary or full access may be given using privileged IDs. Requirements for needing local admin access is also eliminated which can help with specific Windows workstation related tasks. It can be very useful when working with remote teams or contractors who may need temporary access to a system when required.
    Incentivized
    Read full review
    IBM
    HashiCorp Vault, in my opinion, is a defacto standard for any cloud or automation implementation. They're the best of the best as far as products for secrets management and the ability to use it against relatively any service you have is unheard of for other products. HashiCorp has really taken out all the stops when it comes to creating a nice, extensible tool that people can use to suit their needs.
    Incentivized
    Read full review
    Pros
    Cyberark
    • Automatically discover new servers on the network and take control of the local admin password by vaulting it and ensuring nobody knows the password. A different password on every server.
    • Automatically roll the password in a configurable manner - after each use, after a certain period of time, etc.
    • Track and govern sensitive account usage by ensuring only properly authorized users can access the vault and obtain the credentials and then monitor usage.
    Incentivized
    Read full review
    IBM
    • The HTTP API you use to write and read secrets is open and can be used by any application.
    • It keeps our sensitive data/credentials out of our GitLab repositories.
    • Sealing and unsealing the Vault on demand adds an additional layer of security.
    Incentivized
    Read full review
    Cons
    Cyberark
    • GUI - right now everything is on one page/dashboard. Some level of folder/Safe type view would be great
    • More options when storing passwords - especially for network based passwords
    • Better integrations with vendors like Cisco so that admins dont need to really get the password from the vault (think Last Pass type add on)
    Incentivized
    Read full review
    IBM
    • Session Management is terrible to manage
    • Monitoring is hard and not enough information
    • User management
    • Configuration is too complex
    • More user friendly UI
    Read full review
    Likelihood to Renew
    Cyberark
    No answers on this topic
    IBM
    HashiCorp Vault is the best there is out there, and it has become critical to our secret management use cases. It would be difficult to find anything that would suit our needs better and that would be beneficial for us to switch over to.
    Incentivized
    Read full review
    Usability
    Cyberark
    It’s very usable once the complexity of deployment has completed. It is a useful tool that is easy to learn and the user interface is laid out well. It works with SSO for our organization which makes secure login very fast as well. It works well across our need of on premises systems and cloud very quickly.
    Incentivized
    Read full review
    IBM
    We spent a little more time than we imagined to conceptually understand how HashiCorp Vault operates, as well as how it is configured. This is not trivial, and keep in mind that you will need to take some time to get a thorough understanding of the tool. The documentation could be more helpful in this regard.
    Incentivized
    Read full review
    Support Rating
    Cyberark
    I've been an engineer and architect in the Identity space for many years and CyberArk is the #1 tool I've found to help me secure accounts and credentials. I've architected CyberArk and built the implementation from the ground up twice in previous roles and found it here upon my arrival at my current job. I wouldn't want to have to live without it as it helps me sleep at night
    Incentivized
    Read full review
    IBM
    Hashicorp has been very responsive to our questions and inquiries up to this point. We are currently working on them to develop a more granular permissions model within Vault. We are very close to achieving our objectives with the help of their support team. We do not seem to be in the same time zone which makes it hard for escalated issues.
    Incentivized
    Read full review
    Alternatives Considered
    Cyberark
    These other vendors have most of the safe features, but there were some things that I think CyberArk performed better while evaluating the other solutions. AWS secret manager was not available in one of the products and this was definitely needed in my environment. Also, bulk loading of accounts had a lot more flexibility in CyberArk than the other solutions. They offer both API and GUI options where the other vendors may not offer both.
    Incentivized
    Read full review
    IBM
    HashiCorp Vault is way better than Azure Key Vault; it has more features and it goes beyond a key-value secret store.
    Incentivized
    Read full review
    Return on Investment
    Cyberark
    • Decreased the probability of an external cyber attack to privileged accounts..
    • Management can control privileged account life cycle management more effectively
    • Recording privileged sessions allows our organization to play back exactly the point of a breach or malicious behavior
    • Automated system to manage and verify passwords, as privileged accounts are constantly created and deleted
    • Automatic PWD change functionality will substantially decrease probability of PWD theft or misuse.
    Incentivized
    Read full review
    IBM
    • Helped us reach our security compliance goals.
    • Helped us strengthen our security position in our infrastructure by improving on poor secret management practices.
    Incentivized
    Read full review
    ScreenShots

    CyberArk Privileged Access Management Screenshots

    Screenshot of ISPSSScreenshot of Privilege CloudScreenshot of Identity Security IntelligenceScreenshot of Identity Security Intelligence

    IBM Vault Screenshots

    Screenshot of an example of writing a secret to Vault. Secrets are always encrypted and written to backend storage.Screenshot of the secrets menu to manage integrated secrets engines. Secrets Engines are components which store, generate, or encrypt data and are enabled at a path in Vault.Screenshot of where vault identity has support for groups. A group can contain multiple entities as its members. A group can also have subgroups.Screenshot of HCP Vault, which provides all of the power and security of Vault, without the complexity and overhead of managing it yourself.Screenshot of where to view entity client and non-entity client counts.Screenshot of MFA is built on top of the Identity system of Vault.