TechValidate Research on CyberArk Products


CyberArk Case Study

Case Study: Fortune 500 Financial Services Company

Introduction

This case study of Voya Financial is based on an April 2018 survey of CyberArk customers by TechValidate, a 3rd-party research service.

“The use of CyberArk has made our security organization analyze how privileged accounts are utilized and can be compromised. More importantly, through the management of the privileged access lifecycle, we are continually taking steps to keep our secrets secure utilizing CyberArk. "

Challenges

The business challenges that led the profiled company to evaluate and ultimately select CyberArk:

  • Resolved the following challenges after using CyberArk:
    • Securing credentials used by applications
    • IT admins having more privileges than they truly need
    • Unmanaged or unaudited third-party / remote vendor access
    • Auditing the use of privileged access in production systems
    • Too many endpoints with local administrator privileges
  • Adopted CyberArk’s privileged access security because of the following compelling business drivers:
    • Failed an audit
    • Initiated a proactive security project
  • Selected a solution for privileged access security to:
    • Limit the exposure of privileged credentials
    • Enforce strong passwords, store them in an encrypted vault, and rotate them
    • Simplify audit and compliance requirements
    • Secure privileges on endpoints

Use Case

The key features and functionalities of CyberArk that the surveyed company uses:

  • Uses CyberArk for the following:
    • Securing privileged credentials in a vault
    • Rotating credentials based on policies
    • Securing and rotating shared service accounts
    • Monitoring and recording privileged sessions
  • Managing the following types of privileged accounts, credentials, and secrets with CyberArk in the next 12 to 18 months:
    • Domain admin accounts
    • NIX admin accounts (UNIX and Linux)
    • Database or application admin accounts
    • Cloud admin consoles for IaaS or PaaS (Amazon Web Services, Microsoft Azure, Google Cloud, OpenShift, Pivotal Cloud Foundry)
    • Application credentials
    • Secrets used by DevOps tools
    • Service accounts
    • SSH keys
    • Robotic process automations
  • Plans to integrate the following tools with CyberArk within the next 18 months:
    • Authentication (DUO or OKTA, RSA)
    • DevOps (Docker, Chef, Puppet)
    • SIEM (Splunk, Fortinet, LogRhythm)
    • Vulnerability management (Qualys, Rapid7, Tenable)

“I believe CyberArk offers very good products, with good customer support, and is a leading security technology.”

Results

The surveyed company achieved the following results with CyberArk:

  • Reports that since adopting CyberArk to manage their privileged accounts and credentials, they are now much more secure.
  • Reports that since adopting CyberArk to secure their privileged accounts and credentials, the time and cost of audit reporting has reduced a lot.
  • Reports that with CyberArk, the time required to manage and maintain privileged account and credential security has stayed the same.




About This Data

This data was sourced directly from verified users of CyberArk Products by TechValidate.

TechValidate verifies the identity and organizational affiliation of all participants that contribute to published research data. When research participants so desire, we also guarantee their anonymity so that they may share information honestly and freely.


More Research on CyberArk Products