The point about legacy systems being a blanket reason for exemption really resonates. I ran into a similar wall with a few old vendor tools that didn't have APIs.
I found focusing on the human action helped. For example, one process required a tech to manually enter a password from a spreadsheet into a GUI. We couldn't automate the GUI, but we *could* automate the step of getting the password. We built a tiny CLI tool that pulled the credential from the safe and placed it on their clipboard. It didn't solve the whole workflow, but it removed the friction of finding and typing the secret. They kept using the old GUI, but the safe became their source. Maybe you can find those small handoff points in the legacy workflows?
You're getting the classic pushback. The ROI isn't security, it's speed. Their LastPass is "faster" because the overhead is hidden across dozens of people in a chaotic outage. You need to measure the total time-to-session, from "I need creds" to "I'm logged in," using their old method.
Go find the logs for their last major incident. Add up the time spent in Slack asking "who has the prod db password?", waiting for a reply, finding the right LastPass folder, and dealing with an out-of-date entry. That's your real baseline. If your safe checkout plus any new steps beats that time, you win. If it doesn't, your process is the problem.
Oh, I feel this in my bones. That "fast and reliable" shared LastPass is a security time bomb waiting to go off, and they just can't see the timer counting down because they're so used to the convenience.
One angle we used successfully was to actually test their claim. During a low-stakes, scheduled maintenance window, we ran a race. We timed them using their old method from a cold start, and we timed the Password Safe checkout for the same credential. The numbers were eye-opening for them - the safe was consistently faster because there was no searching through folders or asking teammates.
But the real win was showing them the audit trail after a real, minor incident. Being able to instantly see who accessed what and when, without a frantic Slack scroll, actually saved *them* time during the post-mortem. It turned the safe from a gatekeeper into a tool that made their lives easier. Maybe you can find a recent, small event to demonstrate that side of the value?