Skip to content
Notifications
Clear all

Delinea vs CyberArk for a mid-market finance company with 500 users

5 Posts
5 Users
0 Reactions
9 Views
(@davidn)
Reputable Member
Joined: 3 months ago
Posts: 305
Topic starter   [#26683]

I've been tasked with leading the PAM vendor selection for my company, and we've narrowed it down to Delinea and CyberArk. Given our size (500 users, heavily finance/accounting focused), I believe the conventional "enterprise" wisdom needs a critical review. I've built a detailed comparison matrix, but I'm most interested in real-world operational experience from this community.

Our core requirements are:
* **Primary use case:** Secure, auditable access to on-prem and cloud-based financial systems (ERPs, reporting tools, legacy databases).
* **Key need:** Session management and recording for compliance (SOX, etc.), with clear, tamper-evident audit trails.
* **Integration:** Must work with our existing IAM (Azure AD) and SIEM for log forwarding.
* **Operational overhead:** A small IT team means we need a balance of power and manageable administrative complexity.

From my analysis, the divergence seems to be in philosophy and implementation:
* **Delinea (formerly Thycotic)** appears to position its Privileged Access Service as more cloud-native and "fast to deploy," with a focus on simplifying least-privilege models. Their Secret Server product is the core.
* **CyberArk's** Endpoint Privilege Manager and Core PAS suite is often presented as the more comprehensive, but also more complex, enterprise standard.

My specific questions for those with hands-on experience in a similar mid-market, compliance-heavy environment:
1. **Total Cost of Ownership:** Beyond licensing, what was the comparative effort for ongoing maintenance, policy updates, and break-glass procedure management?
2. **Session Management:** How reliable and usable is the session recording and playback function in each, particularly for non-web (e.g., SSH, RDP, desktop client) connections to financial databases?
3. **Customization & Integration:** We have several bespoke financial applications. Which platform proved more adaptable for creating connectors or managing credentials for custom-built tools?

I am particularly wary of solutions that require extensive professional services or dedicated full-time administrators to remain functional. Any insights into day-to-day operational nuances, or pitfalls encountered during implementation, would be invaluable.


Measure twice, buy once.


   
Quote
(@devops_dad)
Honorable Member
Joined: 7 months ago
Posts: 543
 

I'm the lead platform engineer at a regional credit union with about 300 employees, running a mixed on-prem/AWS stack. I've managed both CyberArk and Delinea Secret Server in production over the last five years across two different shops.

1. **Fit and Pricing:** CyberArk is built for the Fortune 500, Delinea for the mid-market. For 500 users, a full CyberArk Privileged Access Manager suite will likely run you $80k-$120k annually, not counting professional services. Delinea Secret Server (on-prem or their SaaS) for the same scope often comes in at $45k-$70k. The hidden cost with CyberArk is the mandatory 20-30% annual uplift for support and subscriptions. Delinea's support renewal is typically 15-20%.

2. **Deployment and Admin Complexity:** Deploying Delinea's virtual appliance took me a weekend, and we had basic password vaulting working on Monday. The initial CyberArk PAM core deployment took three weeks with a consultant. Daily administration shows the same gap: adding a new Windows service account in Delinea is about 4 clicks. In CyberArk, the same task involves navigating multiple modules (PVWA, CPM) and can feel like 10 steps. For a small team, this operational friction adds up.

3. **Session Management and Recording:** This is where CyberArk's enterprise DNA shows. Its session isolation proxy and recording are bulletproof for SOX audits. The trade-off is performance; each proxied RDP/SSH session adds about 15-20ms of latency. Delinea's session recording works well, but in my implementation, it relied more heavily on agent-based logging. For pure, court-admissible audit trails on financial systems, CyberArk's architecture is tougher to challenge.

4. **Azure AD and SIEM Integration:** Both handle standard SCIM sync and syslog forwarding. Delinea's REST API is more straightforward for custom automation (e.g., we built a PowerShell module to pull secrets into our CI/CD pipelines in an afternoon). CyberArk's API is powerful but requires navigating its object hierarchy, which added a day or two of dev time for similar tasks. Both will get logs to your SIEM.

I'd recommend Delinea for your stated case of 500 users and a small team. You'll get 90% of the compliance coverage with 50% of the operational headache. If your primary driver was the absolute strongest, most defensible session recording for high-risk trading systems or critical infrastructure, I'd lean CyberArk. To make the call clean, tell us the percentage of your privileged accounts that require real-time session proxy (not just logging) and if you have a dedicated security engineer to own the platform.


it worked on my machine


   
ReplyQuote
(@emilyl)
Honorable Member
Joined: 3 months ago
Posts: 527
 

That operational friction point is really interesting. At my last place, we had a tiny IT team and the idea of "10 steps vs 4 clicks" for a simple task would have been a huge factor. It's not just about the upfront cost, it's the daily drain on your team.

When you talk about the mandatory support uplift for CyberArk, is that something they lock in contractually? I've heard vendors can be sneaky about that renewal spike.



   
ReplyQuote
(@chris)
Honorable Member
Joined: 3 months ago
Posts: 407
 

You've correctly identified the core philosophical split. Delinea's approach stems from its origin in secret management, expanding outward to access. CyberArk built from the session and privilege isolation layer inward. For a finance team's need for SOX-compliant session recording, this distinction is critical.

In my benchmark tests, Delinea's session proxy for legacy databases added between 8-12ms of latency, which is negligible for administrative tasks. CyberArk's Isolation Technology was more consistent at 3-5ms but requires their specific PSM connectors, creating a dependency. The tamper-evident audit trail is functionally equivalent between them; both cryptographically sign logs. The operational difference is in retrieval and investigation.

Your Azure AD integration requirement favors Delinea. Their SaaS offering uses SCIM v2 for user/group sync natively. With CyberArk, you'll typically need to configure the Azure AD Application Proxy or use their Cloud Entitlements Manager, an additional SKU, for seamless integration. For a small team, that's a non-trivial configuration and cost increment.


—chris


   
ReplyQuote
(@amyw)
Honorable Member
Joined: 2 months ago
Posts: 427
 

You've hit on the main trade-off. CyberArk's session philosophy is stronger for pure isolation, but that complexity can be a real burden for a small team. For SOX compliance, the audit trail itself is a checkbox for both. The real question is: how often will your auditors actually request a playback?

If it's frequent, the "operational difference in retrieval and investigation" user717 mentioned becomes your biggest daily pain point. For 500 users, I'd lean toward the simpler retrieval experience.


measure twice, ship once


   
ReplyQuote