TL;DR: Palo Alto Networks’ planned acquisition of CyberArk underscores a broader shift in privileged access security: vaults protect credentials, but real-time controls protect access itself, according to Silverfort. The practical break from vault-centric PAM is that identity teams now need enforcement at session time, not just stronger storage and rotation.
At a glance
What this is: This is an analysis of how privileged access security is moving away from vault-centric PAM toward real-time, identity-aware enforcement.
Why it matters: It matters because IAM, PAM, and NHI teams need to decide whether they are protecting stored credentials or controlling access at session time, which changes how zero trust and privileged access programmes are designed.
By the numbers:
- Palo Alto Networks will acquire CyberArk in a deal valued at approximately $25 billion.
Context
Privileged access security is the practice of controlling high-risk administrative access so that the right identity can reach the right system under the right conditions. The problem Silverfort highlights is that vault-centric PAM focuses on securing passwords after they exist, while modern environments need enforcement at the moment access is used.
The article argues that this gap is becoming more visible as organisations spread privileged access across cloud, on-premises, service accounts, scripts, and AI-driven automation. In that model, the governance question is no longer whether a credential can be stored safely, but whether access can be constrained without handing out reusable secrets first.
Key questions
Q: What breaks when privileged access is controlled only by a vault?
A: A vault controls where the credential sits, but not what happens after the credential is released. Once the password is checked out or exposed, attackers can use memory theft, malware, insider misuse, or session abuse to extend impact. Privileged access therefore needs inline enforcement, not only protected storage.
Q: Why do privileged access controls break down in hybrid environments?
A: Hybrid environments fragment identity evidence across clouds, endpoints, workflows, and ticketing systems. When privilege is distributed across those layers, no single control plane shows the whole story. Teams then spend more time proving access history than governing it, which is exactly where audits become slow and incomplete.
Q: How should teams handle privileged non-human identities without creating new vault sprawl?
A: Treat service accounts and automation as privileged subjects that need runtime policy, not just stored secrets. That means mapping each machine identity to its access purpose, reducing standing privilege, and removing manual checkout steps that do not scale across scripts, workloads, and automation.
Q: When should organisations keep vaults versus move to session-time controls?
A: Keep vaults where break-glass access, legacy systems, or compliance obligations still require password storage, but move primary enforcement to session-time controls whenever possible. The key decision is whether the vault is acting as a fallback repository or as the main security boundary.
Technical breakdown
Why vault-centric PAM stops at password checkout
Vault-based PAM was designed to protect privileged credentials by keeping usernames and passwords in a controlled store, then releasing them for use and rotating them afterward. The architectural weakness is that control is strongest before the login and then drops away once the credential leaves the vault. At that point, the password can be captured from memory, reused, logged, or passed through unmanaged paths. The model secures the secret, not the session. That matters because privileged access risk is not only about where a password lives, but about what happens once access has been granted.
Practical implication: Treat vault checkout as an exposure point, not a control endpoint.
Real-time privileged access security and inline enforcement
Real-time privileged access security shifts enforcement to the access event itself. Instead of checking out a password, the identity layer validates who is requesting access, in what context, and under which policy before and during the session. This model is closer to Zero Trust Architecture because it assumes every request must be evaluated continuously rather than trusted after a one-time approval. It also reduces the dependency on static secrets, which is especially relevant for hybrid estates where legacy systems, cloud resources, and third-party access do not all fit a proxy-and-vault pattern cleanly.
Practical implication: Build policy enforcement around the session, not around secret distribution.
Why non-human identities make vault-free PAM harder to ignore
The article extends the argument to NHIs such as service accounts, scripts, AI agents, and automation tools. Those identities often need privileged access without a human operator checking out a password, which exposes the limits of a vault-first model. If the system depends on a long-lived credential for every machine action, governance becomes brittle and hard to scale. Inline access controls let organisations broker privilege without assuming that every actor is a person following a manual login path. That changes privileged access from secret handling to runtime authorisation.
Practical implication: Map privileged NHI flows to runtime authorisation points instead of static credential storage.
Threat narrative
Attacker objective: The objective is to turn a single privileged credential into broad administrative reach across sensitive infrastructure and data.
- Entry occurs when an attacker steals or intercepts a privileged credential after it has been released from the vault, or abuses approval and MFA workflows tied to the checkout process.
- Escalation happens when that credential is reused to reach admin tools, infrastructure, databases, or other privileged systems that the vault was meant to protect.
- Impact follows when the attacker uses those privileges to move across sensitive systems, exfiltrate data, or operate as a trusted administrator inside the environment.
Breaches seen in the wild
- BeyondTrust breach 2024: A stolen BeyondTrust Remote Support API key let a China state-sponsored actor reset accounts and reach US Treasury workstations in 2024.
- Azure Key Vault Contributor escalation 2024: Datadog found Azure Key Vault Contributor could add itself to access policies and read every secret, key and certificate in a vault.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Vault-centric PAM is becoming a control point problem, not just a storage problem. The article describes a market shift where the security question is no longer whether a privileged password is stored safely, but whether access can be governed at the moment it is used. That is a meaningful change for IAM and PAM teams because the enforcement boundary moves from the vault to the session.
Real-time privileged access security is the more accurate control model for hybrid estates. Static checkout workflows were built for environments where privileged access was slower, more centralised, and more predictable. Modern estates mix cloud, on-premises, third-party, and machine-driven access, which means the control plane has to evaluate context continuously. Practitioners should read this as a signal to re-centre PAM around runtime policy.
Non-human identities turn vault dependence into governance debt. Service accounts, scripts, and AI agents do not fit cleanly into human checkout workflows, yet they increasingly carry privileged access. That means vault-first designs create exceptions, workarounds, and approvals that do not scale. The practitioner conclusion is that privileged access governance must account for machine actors as first-class privileged subjects, not edge cases.
Identity security is moving toward access-time enforcement, not secret-time protection. The broader market implication is that the centre of gravity is shifting away from protecting stored credentials and toward proving who or what is allowed to act right now. This validates zero-standing privilege thinking and challenges any programme that still equates PAM maturity with vault coverage alone.
Vault-free PAM does not eliminate vaults, but it changes their role. The article is right to keep break-glass and legacy use cases in view, because some environments still need password storage. But that is no longer the primary architecture for privileged control. Organisations should treat vaults as fallback infrastructure while building the main governance model around inline, identity-aware access decisions.
From our research library:
- 42% of machine identities have privileged access and 61% of organisations lack identity security controls for cloud workloads, according to CyberArk's 2025 Identity Security Landscape.
- Read next: Just-in-Time Access and Zero Standing Privilege Guide
What this signals
Privileged Access Security now has to be treated as a runtime control problem. Programmes that still define PAM success by vault coverage are measuring storage hygiene instead of access enforcement. The practical shift is toward continuous verification and session-time policy, because the password is no longer the only thing that needs protection.
Vault-free PAM becomes a governance model for privileged NHI behaviour as much as for humans. Service accounts and automation paths cannot be managed reliably through the same checkout workflow designed for people. That means identity teams need one control plane that can govern both human and machine privilege without assuming a password must be issued first.
Identity blast radius becomes the metric that matters. If a privileged credential can still be reused after checkout, the question is not whether the vault exists but how far a single compromise can travel. Organisations should reduce the time and scope in which privilege can be exercised, then verify that the access layer rather than the vault is doing the real enforcement.
For practitioners
- Reassess the PAM control boundary Document where your current programme stops enforcing policy after password checkout and identify sessions that remain effectively ungoverned.
- Prioritise session-time enforcement Apply inline controls that evaluate identity, context, and privilege before and during access rather than after a credential is released.
- Inventory privileged non-human identities Map service accounts, scripts, and automation paths that still depend on long-lived credentials or manual vault workflows.
- Keep vaults in a fallback role Reserve vaults for break-glass, legacy, and compliance-driven scenarios where password storage remains unavoidable, but do not make them the primary control plane.
- Align PAM with zero trust Tie privileged access decisions to continuous verification, least privilege, and context-aware policy instead of static credential release.
Key takeaways
- Vault-centric PAM protects the secret first, but privileged access risk now lives in the session where that secret is used.
- The article links a $25 billion acquisition to a broader market rethinking of whether password storage should still be the main control point.
- Practitioners should move privileged access governance toward inline, identity-aware enforcement while keeping vaults only for fallback and legacy use cases.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | The article centres on reducing standing privileged access for human and non-human identities. |
| NHI-07 — Long-Lived Secrets | Vault-centric PAM still depends on reusable passwords and other long-lived credentials. | |
| NHI-10 — Human Use of NHI | The article discusses humans handling credentials that are also used by service accounts and automation. | |
| Recommendation — Reduce standing privilege for privileged accounts and machine identities before they are checked out or reused. Replace long-lived privileged secrets with short-lived access where possible. Separate human access paths from machine identity usage so credentials are not shared across actors. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The shift from vaults to runtime enforcement is fundamentally about governing access decisions. |
| Recommendation — Apply PR.AA-05 to govern who or what can use privileged access at the point of authorization. | ||
| NIST Zero Trust (SP 800-207) | 3.2 — Continuous Verification | Real-time privileged access security aligns with continuous verification of identity and context. |
| Recommendation — Move privileged access decisions to continuous verification rather than one-time credential checkout. | ||
| MITRE ATT&CK | TA0006;TA0008 — Credential Access; Lateral Movement | The article's threat model centers on credential theft followed by broader privileged movement. |
| Recommendation — Map vault exposure to credential access and lateral movement paths in detection and response planning. | ||
| CIS Controls v8 | CIS-5 — Account Management | Privileged account lifecycle and access governance are central to the shift described in the article. |
| Recommendation — Use account management controls to eliminate unmanaged privileged accounts and stale access paths. | ||
Key terms
- Vault-centric PAM: Vault-centric PAM is a privileged access model that centers on storing, brokering, and controlling secrets from a secure vault. It manages credentials, session access, and rotation through a protected repository, reducing direct exposure of passwords, keys, and tokens while enforcing approval, auditability, and time-bound privileged use.
- Real-Time Privileged Access Security: An access-control approach that evaluates privileged requests as they happen, using identity, context, and policy instead of relying primarily on stored credentials. In practice, it shifts control from secret handling to runtime authorisation and continuous enforcement.
- Privileged Session: A live authenticated connection that can perform sensitive actions without re-entering credentials. For NHIs and admins alike, the risk is not only who signed in, but what authority the session carries before it expires or is revoked. Session control is therefore a practical security boundary.
- Break-glass Access: Break-glass access is an emergency path that bypasses normal access controls when standard authentication fails or a critical incident demands immediate intervention. It must be tightly time-bound, logged, and reviewed, because it exists to restore operations without becoming a permanent back door.
Deepen your knowledge
NHI governance, privileged access security, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM, PAM, or NHI programme, it is worth exploring.
Published by the NHIMG editorial team on June 24, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org