Access control has reduced attack surface and supports secure remote work across multi-cloud
What is our primary use case?
My main use case for CyberArk Secure Cloud Access is that we have multiple clusters. We use CyberArk Secure Cloud Access with one of our clusters to reduce the attack surfaces, so a user cannot get access to the full network, and access is specific to approved resources. It also provides single sign-on as well as Zero Trust Network Access, which is called ZTNA.
In my day-to-day work, single sign-on and Zero Trust Network Access function as follows: instead of opening the whole corporate network through any VPN, CyberArk gives only specific applications or systems. For example, a developer only gets access to a particular Kubernetes or OpenShift cluster or any particular applications or database, not the full internal network, which reduces security risk significantly.
I would add that CyberArk Secure Cloud Access gives IT-based access control, privileged access protections, session monitoring, and recording. These are the most important features and use cases that we are using.
What is most valuable?
The best features CyberArk Secure Cloud Access offers include secure remote access, identity-based access control, privileged access protection, and support for cloud and hybrid environments. These are the main features.
Out of those features, support for cloud and hybrid environments has made the biggest impact for my team because we have multi-cloud clusters for AWS, Azure, GCP, as well as some on-premises data centers. This feature is available for all of the platforms, making it very useful for us.
CyberArk Secure Cloud Access has positively impacted my organization by reducing attack surfaces and improving compliance; it has helped us with ISO, SOC 2, and PCI DSS requirements. We have better visibility, and it has reduced VPN dependencies, which addresses many challenges that we face.
When I mention improved compliance and reduced VPN dependencies, I have noticed that traditional VPNs expose a large part of the network, so ZTNA is much safer, and that is how it reduces the VPN dependency.
What needs improvement?
CyberArk Secure Cloud Access can be improved as there is initial complexity and it is somewhat expensive.
I would elaborate that the learning curve needs to be very explainable or very easy because it is somewhat tough, so they need to work on this particular learning path as well.
I chose an eight because, as I explained, it is somewhat expensive, and the documentation part needs to be very easy; as of now, it is very complex. The initial complexity is present, and policy setup and integrations need proper planning.
For how long have I used the solution?
I have been using CyberArk Secure Cloud Access for the last two to three years.
What do I think about the stability of the solution?
CyberArk Secure Cloud Access is stable in my experience.
What do I think about the scalability of the solution?
Its scalability is very good because we are getting live documentation and everything.
How are customer service and support?
Customer support is very good, and I have had to contact them; my experience has been positive.
Which solution did I use previously and why did I switch?
We are using CyberArk Secure Cloud Access from the start, so we did not use a different solution before.
What about the implementation team?
Pricing, setup cost, and licensing are managed by the PAM team, and the setup is done by the CyberArk OEM, so I do not have much expertise on this.
What was our ROI?
I have seen a return on investment; from a security point of view, it helps us in terms of time as well as manpower.
Which other solutions did I evaluate?
We did not evaluate other options before choosing CyberArk Secure Cloud Access; we only chose this one.
What other advice do I have?
I would advise others looking into using CyberArk Secure Cloud Access that if they are heavily dependent on VPN and now want a good alternative with more helpful features related to ZTNA, as well as if they want identity-based access controls and secure remote access, they can choose this product. I gave this product a rating of eight.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Intuitive Interface with Unmatched Security
What do you like best about the product?
I like its interface which is very user-friendly. I also appreciate the security it provides, generating excellent protection. Additionally, I value that it offers minimal privilege access and allows the deletion of persistent accounts.
What do you dislike about the product?
The latency in provisioning was somewhat complex at the beginning.
What problems is the product solving and how is that benefiting you?
I use CyberArk Secure Cloud Access to offer least privileges to users, ensure secure connections to servers, and protect users and service passwords. Resolve user privilege access and enhance service security.
Centralized cloud access has strengthened identity control and simplified keyless logins
What is our primary use case?
CyberArk Secure Cloud Access is our primary solution for access identity management across different cloud platforms including AWS, Azure, and Google.
A specific example of how I use CyberArk Secure Cloud Access for access identity management across cloud platforms is when a developer signs in with their company identity and receives the appropriate permissions across the Azure cloud platform. Previously, the company was unable to track the changes or determine who logged into the virtual machines. CyberArk Secure Cloud Access enables access identity management that allows users to check what changes they have made, who has made changes, who has access, and audit trails can be easily tracked.
We use CyberArk Secure Cloud Access as one identity provider for cloud IAM roles and for different users. For example, a DevOps user builds pipelines that run twenty-four seven. Whenever someone updates the pipeline, runs the pipeline, or makes changes to the pipeline, it becomes easy to track who has made the changes. Another use case is that people outside of the organization cannot access the pipelines or anything deployed in CyberArk.
What is most valuable?
The best feature of CyberArk Secure Cloud Access is that private keys can be configured once and users can log in using CyberArk credentials. Instead of providing the private key every time into the system, it is not needed. With CyberArk, we do not require it and can directly use CyberArk credentials to access the virtual machines or run the pipelines.
Using CyberArk credentials instead of private keys has made things easier for our team because previously every user had to remember the private key and store it somewhere else and insert it whenever they attempted to log into the server. This was cumbersome. Instead, organizations use CyberArk to configure the private keys, which helps because it is no longer required for users to store it on their system or somewhere else to maintain security. This additionally prevents users without access to the server from logging in.
This feature of CyberArk Secure Cloud Access also reduces time and dependency on other people. Once a user is given access, they can be tracked anytime and anywhere. Access is revocable whenever people leave the organization.
CyberArk Secure Cloud Access has positively impacted our organization because we have observed many changes. One significant impact is that since implementing it, the dependency on people has drastically been reduced. Additionally, we do not need to log in or store the private keys every time as they can be automatically configured.
What needs improvement?
I do not think there are many improvements needed for CyberArk Secure Cloud Access. As of now, the configurations done to CyberArk are excellent and up to the mark.
One small thing I think could be made better or easier to use in CyberArk Secure Cloud Access is that it is continuously evolving. I do not think there are many improvements needed as it is now aligned with industry standards. As the AI generation is evolving continuously, whenever a user mistakenly provides any secure data into AI, that prevention needs to be handled in CyberArk, possibly in future scenarios.
For how long have I used the solution?
I have been using CyberArk Secure Cloud Access for the last two years.
What do I think about the stability of the solution?
CyberArk Secure Cloud Access is very stable.
What do I think about the scalability of the solution?
CyberArk Secure Cloud Access is highly scalable.
How are customer service and support?
The customer support for CyberArk Secure Cloud Access is pretty good.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
We had not used a solution previously. Once there was a breach in the organization, that is when the company attempted to implement secure access management.
When we were looking for products that provide secure access management to the organization, we moved directly to CyberArk Secure Cloud Access after the breach because we found that CyberArk is the most valued product.
We were using a single sign-on login, but that does not align with the industry standards now, which led us to choose CyberArk Secure Cloud Access.
How was the initial setup?
The experience with pricing, setup cost, and licensing for CyberArk Secure Cloud Access is that the setup cost initially will be higher as it needs to be integrated with different applications that the organization has. The initial setup cost may increase, but in the long run, that will drastically decrease.
What was our ROI?
I definitely would like to share the relevant metrics regarding the return on investment. We have seen a lot of time saved instead of saving the private keys over the system, which can be configured to CyberArk. Additionally, we have money saved in the long run on infrastructure costs. Fewer employees are needed for certain tasks, though it does require people to maintain the security policies and all those aspects that need to be upgraded every time.
What's my experience with pricing, setup cost, and licensing?
The experience with pricing, setup cost, and licensing for CyberArk Secure Cloud Access is that the setup cost initially will be higher as it needs to be integrated with different applications that the organization has. The initial setup cost may increase, but in the long run, that will drastically decrease. Additionally, pricing is aligned with industry standards.
Which other solutions did I evaluate?
Before choosing CyberArk Secure Cloud Access, we evaluated other options such as Okta single sign-on, but that does not have much value, so we chose CyberArk.
What other advice do I have?
My advice to others looking into using CyberArk Secure Cloud Access is that it is a must-go product if they want to have a secure platform and secure product, and integrate it with the different products that the organization is using or virtual machines. Whether it is a SaaS, PaaS, or IaaS, CyberArk is one of the market leaders and is a definite go. I would rate this product a ten out of ten.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)