TrustRadius: an HG Insights company

CyberArk Privileged Access Management

Score9.3 out of 10

70 Reviews and Ratings

What is CyberArk Privileged Access Management?

CyberArk is a privileged account and access security suite issued by the company of the same name in Massachusetts . The Core Privileged Access Security Solution unifies Enterprise Password Vault, Privileged Session Manager and Privileged Threat Analytics to protect an organization’s most critical assets.

Categories & Use Cases

Media

Screenshot of ISPSS
Screenshot of Privilege Cloud
Screenshot of Identity Security Intelligence
Screenshot of Identity Security Intelligence

1 / 4

Screenshot of ISPSS

CyberArk a Trusted Partner in PAM

Use Cases and Deployment Scope

It is SaaS that provides our business vault accounts with rotating credentials that help secure our infrastructure access. It also provides logs, session recordings, and monitoring that keeps our compliance with regulatory requirements. We use this for keeping our administrative accounts secure and free of credential theft, and with the sessions recorded we can also effectively prevent account abuse of privileged accounts. We make our information technology department more efficient by not having to manage and oversee maintaining the security of the accounts we use within this software.

Pros

  • Auditing
  • Account management
  • Endpoint security

Cons

  • Deployment complexity
  • Cost
  • Simplified set of features

Return on Investment

  • We’re more efficient by at least 25%
  • We have had 0 cases of account credentials being used fraudulently
  • We’ve maintained 100% compliance with regulations necessary

Usability

Alternatives Considered

BeyondTrust Endpoint Privilege Management

Other Software Used

1Password, Wrike, Calendly, Microsoft Power BI

CyberArk is a great corporate solution for managing access.

Use Cases and Deployment Scope

I have used CyberArk Privileged Access Management to manage all Windows local administrator accounts and all UNIX root accounts for servers. We were an organization that used to have the same password for all servers, and it was not very secure. We also use this solution to manage database, ILOs, websites, etc...

Pros

  • Managing local administrator accounts for Windows Servers
  • Managing local root accounts for Unix Servers
  • Managing service accounts for Windows Servers
  • Managing IIS Application pool passwords for Windows web servers.

Cons

  • The management of Safes could be a little more simplistic.
  • Creating custom connection components are sometimes tricky.
  • Setting up remote vendors can be a little cumbersome.

Return on Investment

  • It has made local servers much more secure and helps with prevent horizontal attacks.
  • Cyberark is easy to scale up once the software is in place and setup.
  • The high initial investment and complex setup is a negative impact.

Usability

Alternatives Considered

Delinea Account Lifecycle Manager and BeyondTrust Password Safe

Other Software Used

SolarWinds Network Performance Monitor (NPM), ManageEngine ADManager Plus, ManageEngine ServiceDesk Plus

A comfortable way to manage privileged and service accounts

Pros

  • Managing Service Accounts. We like using CyberArk for using it when we need to remote into certain systems and the password is stored on CyberArk.
  • Managing Privileged Accounts. It allows our IT personal to use their privileged accounts without having to remember their passwords. It also keeps our staff compliant with complexities with passwords.
  • Using CyberArk as a jump host has saved us on licensing issues. It's also easy to use when needing to remote in and automatically signing you in.

Cons

  • I'm not sure what could be done differently. There are some things that were once an issue that are no longer an issue. For instance, creating a short cut on the desktop for RDP through CyberArk. Since the upgrade and updates, we are now able to save shortcuts to our desktop.

Return on Investment

  • A positive impact is passing SOX audits when it comes to privileged account management. Making sure we are compliant with password expiration policies and complexities.

Other Software Used

Netwrix Auditor, FireEye Network Security, FireMon

A reliable solution to store credentials

Use Cases and Deployment Scope

CyberArk Privileged Account Security provides robust and resilient for enterprise level deployments and it is one of the nice PAM solutions out there. It works well with both Windows and Linux systems.

Pros

  • Product capabilities
  • Integration & deployment
  • Services and support

Cons

  • Upgrades are not easy
  • Deployment wouldn't be easy for complex environment

Most Important Features

  • Customer focus
  • Services expertise
  • Compliance & risk management

Return on Investment

  • Improved compliance & risk management

Alternatives Considered

The Okta Identity Cloud, Broadcom Unified Infrastructure Management and formerly from CA

Other Software Used

The Okta Identity Cloud, Snowflake, Talend Cloud Integration, Cloudera Data Platform

Make your privileged data safe using CyberArk

Pros

  • Identify and reduce the number of privileged accounts
  • Eliminate shared/service accounts having non-expiring passwords
  • Automatically changing privileged account passwords
  • Automate password verification and reconciliation
  • Frequently identify, change and verify hardcoded passwords
  • Connect Target Systems directly without displaying passwords to users

Cons

  • The initial product cost is a little on the higher side, which might turn off small & medium enterprises.
  • As it talks about security, it has a lot of hardware/software requirements for the initial setup, which might make the rollout timeline a little lengthy.
  • Product should be easy to customize based on different industry's needs.

Return on Investment

  • Decreased the probability of an external cyber attack to privileged accounts..
  • Management can control privileged account life cycle management more effectively
  • Recording privileged sessions allows our organization to play back exactly the point of a breach or malicious behavior
  • Automated system to manage and verify passwords, as privileged accounts are constantly created and deleted
  • Automatic PWD change functionality will substantially decrease probability of PWD theft or misuse.

Alternatives Considered

Centrify Endpoint Services

Other Software Used

Imprivata OneSign, Oracle Service Cloud