32:59Guidance to a Well Defined Privileged Access Management Program
Download resourcesAbout this session
Michael Harlev, a customer success team member at CyberArk with over a decade in governance, compliance and risk, argues that a privileged access management (PAM) program succeeds only when the technology is paired with a well-defined, phased plan. He frames every attack around three risks a PAM program must reduce: credential theft, lateral and vertical movement, and privilege escalation and abuse, and pairs each with controls such as session isolation, removing hard-coded application credentials, credential boundaries by risk tier, password rotation, just-in-time access and least privilege. He then presents a five-stage blueprint ordered by risk impact versus effort to onboard, from stage one (domain and cloud admins, MFA on the PAM tool, third-party security tools) through operating systems, enterprise-wide credential boundaries and third-party vendor access, up to advanced work like mainframes, full service-account management and least privilege on domain controllers. He stresses that stages can be reordered around audits or incidents, that KPIs should be defined from stage one, and shows a real multi-year customer roadmap as an example.
We often see that the challenges associated with implementing a Privilege Access Management (PAM) program are not a result of a lack of technology. In order to have a successful PAM program, you must complement the technology with a well-defined program. Using a prescriptive approach based on three guiding principles, this session will show you how to develop effective and mature privileged access management programs, and articulate the value of the work you’re doing with privileged access management and why it’s important.
Key takeaways
- Pair PAM technology with a well-defined, phased program; owning the tools is not enough to build momentum, secure management buy-in or measure maturity.
- Design controls around three risks: credential theft, lateral and vertical movement, and privilege escalation and abuse, mitigating each at every stage.
- Sequence work by risk impact versus onboarding effort: start with domain and cloud admins, MFA on the PAM tool itself, and hard-coded credentials in security tools.
- Enforce credential boundaries by risk tier and use just-in-time access and least privilege so accounts cannot traverse from low-trust to high-value systems.
- Define KPIs from stage one to demonstrate value, and feel free to reorder stages to satisfy an audit finding or respond to an incident.
Speakers

As Customer Success Manager for CyberArk Canada, I serve as a technical advisor, working alongside Fortune 500 organizations to help them develop effective and mature privileged management and security strategies. With over 10 years of experience in… Read moreRead less
As Customer Success Manager for CyberArk Canada, I serve as a technical advisor, working alongside Fortune 500 organizations to help them develop effective and mature privileged management and security strategies. With over 10 years of experience in the security industry, I bring deep technical and business experience to his role, with a niche focus on compliance, governance & risk assessment.