Focusing on Identity Security, CyberArk is a specialist in privileged access management. It develops secure solutions for diverse identities - human or machine to cater to numerous business applications. The company ensures protection across varied work environments like distributed workforces, hybrid cloud workloads, and throughout the DevOps lifecycle. CyberArk's primary objective is to avert cyberattacks that abuse insider privileges and pose a threat to crucial enterprise assets. In addition to this focus, the company offers security solutions aimed at preventing the progression of cyber threats, thus protecting businesses from substantial damage. CyberArk's security solutions align with rigorous compliance and audit requirements to service businesses' need to guard their most valued possessions. The company has a global presence with offices spread across countries like the U.S., Israel, U.K., Singapore, Australia, France, Germany, Italy, Japan, Netherlands, and Turkey.
Do You Manage Peer Insights at Palo Alto Networks (CyberArk)?
Access Vendor Portal to update and manage your profile.
CyberArk PAM On-Premise offers good control and customizability in the latest version release along with an ever-growing number of integrations available on the CyberArk Marketplace. Customer service is generally very responsive to support tickets when issues arise. The On-Premise version releases include LTS versions, where the end-of-life and support for those particular versions last several years instead of several months. The PSM (privileged session manager) records every session with user action and screen capture capabilities. This has been invaluable for internal audit and compliance purposes.
Security First Architecture for the end user is what I do like, but unfortunately the journey has been very long in the implementation phase which is what lets this product down. Remote access, when it works, is smooth, there's not much latency. Future updates look good with AI driven analytics and TDR.
Session Isolation and Monitoring (PSM). The ability to record every single action an administrator takes on a critical serverand to do so without the admin ever knowing the actual passwordis a game-changer. It provides a definitive audit trail and prevents lateral movement by attackers. Additionally, its Vault architecture is incredibly secure, providing a physical-like security layer for digital secrets.
Specific to the on-premise offering and NOT the SaaS version, upgrades and maintenance of every single component of PAM takes a long time depending on how many instances of each and how large the environment is. The learning curve for administration, deep troubleshooting, and maintenance is steep, especially for teams without prior PAM experience. The licensing and cost complexity model can lead to cost expansion if more capabilities are added, such as Conjur, CCP, and CP. CyberArk is a premium product, and it can be difficult to justify the pricing for smaller organizations and teams. With the introduction of the SaaS version of PAM, newer features, UX/UI improvements, and integrations come much slower for the on-premise offering. This can lead to extended timelines for onboarding and integration of newer platforms or products as plugins and extensions may not be immediately updated.
Configurations can vary (on premise, cloud, LDAP etc). CA didn't initially offer best practices or tell us some of those don't work with password rotations etc. Check ins are a major pain with the teams due to needing an admin user to manually check them out. 365 logins don't work for us. It just takes us to our tenant due to browser addons being blocked on our company.
Complexity and Administrative Overhead. The platform is notoriously difficult to set up and maintain. The user interface (UI) can feel dated and clunky compared to newer, cloud-native competitors. It requires a dedicated team of certified experts to manage it effectively; if you don't have the right staff, the system can quickly become a bottleneck for your IT operations.