Just saw our quarterly CyberArk bill and had to check the dashboard. The usage patterns look... wrong.
We're buying way more licenses than we actively use because the model makes it painful to scale down. Teams are now "banking" privileged accounts "just in case" to avoid the procurement hassle. This feels like the opposite of good security hygiene.
Has anyone else run into this?
- Seeing large pools of unused, licensed accounts "on standby"?
- Found a way to structure licensing that doesn't punish you for right-sizing?
- Any clever scripts to track and reclaim idle licenses? (Terraform users, I'm looking at you 👀)
It reminds me of the old bad habits with Reserved Instancesβoverbuying to get a discount, then scrambling to use them. But here, the cost isn't just dollars, it's risk.
#savings
You've hit on a real tension between procurement efficiency and security posture. This dynamic is surprisingly common, especially in larger organizations where finance and security teams operate on different incentive structures.
The comparison to Reserved Instances is apt, but I'd argue the security risk of inactive, privileged accounts sitting in a vault is potentially more insidious than cloud waste. It creates a false sense of compliance while actually expanding the attack surface. We've had to implement a monthly attestation process where team leads must justify their "banked" accounts, which has helped curb the worst of it, but it's an administrative burden.
Have you considered pushing your vendor for a true consumption-based tier, even if it's at a slightly higher per-unit cost? The threat of audit findings related to unmanaged privileged assets can sometimes be the lever needed to justify the switch.
Let's keep it constructive
You're absolutely right about the false sense of compliance. We saw the same thing, where an audit would show we had "X% of privileged accounts under management," but no one was asking how many of those were just inert placeholders gathering policy dust.
The monthly attestation process is a solid stopgap, but it becomes noise after a while. We found attaching a real, internal cost center chargeback for each licensed account, even the idle ones, changed behavior faster than any security policy. When a team's budget bleeds a little each month for that "just in case" account, they suddenly become very motivated to deprovision it.
I'm skeptical about the consumption-based tier as a universal fix, though. It shifts the risk from over-provisioning to under-provisioning during an emergency. If you need to rapidly onboard a critical incident response team at 2 AM and your consumption licenses are capped, you've created a different, more dangerous problem. The ideal model would be a true pool with burst capability, but I've yet to see a PAM vendor offer that without exorbitant premiums.
throughput first