This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Demystifying Privileged Access Management for SMBs

Download resources

About this session

Maurice Côté, product owner of the PAM offering at Devolutions, untangles privileged access management for small and mid-sized businesses that cannot afford analyst reports or enterprise suites. After surveying why privileged accounts matter (insider incidents, lost laptops, spear phishing and deepfake CEO fraud), he identifies the core tension: buyers such as CISOs think in accounts, compliance and the five Ws, while the IT staff who use the tool think in endpoints and closed tickets and see passwords as a hurdle. He then defines the modules found across vendor and analyst frameworks: the password vault with gated access, discovery and rotation; application-to-application password management for DevOps; basic session management with account brokering and SSO; advanced session shadowing and keystroke logging; privilege elevation and delegation; and privileged user behaviour analytics, the last two rarely affordable for SMBs. He defends shared and dual accounts as legitimate steps on a maturity scale, warns against buying features you will not use, and recommends building your own bite-sized roadmap, starting with domain admin or local admin accounts and reviewing it yearly.

Analyst firms focus on Fortune 5000 organizations, while typical PAM vendors usually present their own solution as the “definite” PAM. This presentation will focus on what features constitute a PAM while describing a pragmatic maturity scale where SMBs can not only identify where they currently stand, but also identify strategies to advance to the next level.
 

Key takeaways

  • Write down your own needs before looking at feature lists: a network-heavy shop and a cloud-native shop need different PAM controls.
  • Start with the vault and one or two account classes (domain admin, or local admin and service accounts), and turn on checkout workflows and session recording only later.
  • Shared accounts and dash-admin dual accounts are acceptable interim steps; monitor that privileged staff do not live in the admin account all day.
  • Sell the PAM to the IT team as much as to the CISO; if it feels like a wall, administrators will route around it and the project fails.
  • Review the roadmap yearly: segment flat networks, apply CIS benchmarks, onboard remote workers and contractors securely, and keep training against spear phishing.

Speakers

Maurice Côté
Maurice Côté
Vice-President of Products · Devolutions
I lead the Privileged Access Management Solution at Devolutions, . Having evolved in startups for the greater part of my career, although I am a developer by trade, I've had to learn infrastructure management and operational security since, well… Read moreRead less

I lead the Privileged Access Management Solution at Devolutions, . Having evolved in startups for the greater part of my career, although I am a developer by trade, I've had to learn infrastructure management and operational security since, well... there was no one else to do it! I work with analysts, customers, and partners alike and have acquired a deep knowledge of the PAM space.

Resources

Tags

More from GoSec 2020

Also from Maurice Côté

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.