TL;DR: Palo Alto Networks’ planned acquisition of CyberArk underscores a broader shift in privileged access security: vaults protect credentials, but real-time controls protect access itself, according to Silverfort. The practical break from vault-centric PAM is that identity teams now need enforcement at session time, not just stronger storage and rotation.
Editorial analysis by NHI Mgmt Group, based on content published by Silverfort: “The future of privileged access is vault-free”.
By the numbers:
- Palo Alto Networks will acquire CyberArk in a deal valued at approximately $25 billion.
Key questions
Q: What breaks when privileged access is controlled only by a vault?
A: A vault controls where the credential sits, but not what happens after the credential is released.
Q: Why do privileged access controls break down in hybrid environments?
A: Hybrid environments fragment identity evidence across clouds, endpoints, workflows, and ticketing systems.
Q: How should teams handle privileged non-human identities without creating new vault sprawl?
A: Treat service accounts and automation as privileged subjects that need runtime policy, not just stored secrets.
Practitioner guidance
- Reassess the PAM control boundary Document where your current programme stops enforcing policy after password checkout and identify sessions that remain effectively ungoverned.
- Prioritise session-time enforcement Apply inline controls that evaluate identity, context, and privilege before and during access rather than after a credential is released.
- Inventory privileged non-human identities Map service accounts, scripts, and automation paths that still depend on long-lived credentials or manual vault workflows.
Bottom line: Vault-centric PAM protects the secret first, but privileged access risk now lives in the session where that secret is used.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Vault-centric PAM is becoming a control point problem, not just a storage problem. The article describes a market shift where the security question is no longer whether a privileged password is stored safely, but whether access can be governed at the moment it is used. That is a meaningful change for IAM and PAM teams because the enforcement boundary moves from the vault to the session.
A few things that frame the scale:
- 42% of machine identities have privileged access and 61% of organisations lack identity security controls for cloud workloads, according to CyberArk's 2025 Identity Security Landscape.
A question worth separating out:
Q: When should organisations keep vaults versus move to session-time controls?
A: Keep vaults where break-glass access, legacy systems, or compliance obligations still require password storage, but move primary enforcement to session-time controls whenever possible. The key decision is whether the vault is acting as a fallback repository or as the main security boundary.
👉 Read our full editorial: PAM is shifting from vaults to real-time privileged access security