← Back to PAM Best Practice main site
PAM Academy › Module 2 — PAM Strategy & Operating Model

Module 2: PAM Strategy & Operating Model

Layla turns the breach into a PAM programme of strategy, ownership, lifecycle processes, enforced controls and a maturity path.

Story: “Ahmed Didn't Change. The Organisation Did.”
~55 minutes
Lead: Layla, PAM Programme Lead
PAM StrategyOperating ModelProcessesControlsMaturity
Included
Part of the PAM Best Practice Academy curriculum
Start Module 2 → ← Back to Module 1
  • 7-part narrated slide module
  • Follows Layla at Abby Steel
  • Practical, vendor-neutral PAM guidance
  • Key facts and real-world examples
  • 10-question knowledge check
Overview
Curriculum
Instructors
2
Module Number
7
Story Parts
55
Minutes
10
Quiz Questions
The question this module answers
How do you turn a decision to invest in PAM into a working programme?

The Monday after the incident, Layla inherits a crisis and a board mandate. Her first finding is that nobody owned privileged access: Ahmed didn't fail, the organisation did. She builds a strategy, an operating model, joiner-mover-leaver processes and five mandatory controls, then measures Abby Steel's climb from chaos to control.

What you will learn
▶
Distinguish a PAM programme from a tool or a project, and put strategy before technology
▶
Define a PAM strategy using five pillars aligned to business risk and compliance
▶
Assign ownership of access through an operating model where the business approves, security reviews and IT provisions
▶
Design joiner, mover and leaver processes and automate them in stages
▶
Apply the five core controls (least privilege, RBAC, segregation of duties, just-in-time access and MFA) and place an organisation on the five-stage maturity model
Module curriculum
1
Part 1: Incident and Realisation
Narrated slides
2
Part 2: Strategy
Narrated slides
3
Part 3: Operating Model
Narrated slides
4
Part 4: Processes
Narrated slides
5
Part 5: Controls
Narrated slides
6
Part 6: Reality Check
Narrated slides
7
Part 7: Maturity and Handover
Narrated slides
8
Knowledge Check10 questions · pass mark 8/10
Quiz
Part 1: Incident and Realisation

Layla reconstructs the breach and Priya's findings: 47 orphaned accounts and 89 over-privileged users. The root cause is that everyone touched PAM and no one owned it, so what's needed is a programme, not a tool.

Part 2: Strategy

Strategy comes before tools. Abby Steel's five pillars (Visibility, Control, Governance, Automation, Audit) are tied to business risk and compliance, given clear ownership and success metrics, and shaped with stakeholders before board approval.

Part 3: Operating Model

IT is the hands, security the eyes and the business the judgement. The business owner approves, security reviews and IT provisions, through a documented request process and a same-day leaver process, rolled out with proper change management.

Part 4: Processes

The joiner-mover-leaver lifecycle is completed with the often-forgotten mover step. It is wired to HR for automation and matured in stages, on the principle that access is based on role, not seniority.

Part 5: Controls

Five mandatory controls enforce the strategy: least privilege, RBAC, segregation of duties, just-in-time access and MFA. They extend to machine identities, third parties and break-glass accounts, and the section ends by showing strategy, operating model, processes and controls as one system.

Part 6: Reality Check

Abby Steel was not unusual. Industry evidence, three converging pressures (identity-based attacks, cyber insurers and regulators) and the cost of inaction show that doing nothing is the most expensive option.

Part 7: Maturity and Handover

A five-stage maturity model (Chaos, Visibility, Control, Automation, Governance) and a 12-month roadmap measure progress. Layla then hands the discovery mandate to Priya.

Key facts
  • Société Générale (2008): a trader who moved from the back office to the trading floor kept both perspectives and hid unauthorised trades, causing a loss of around €4.9 billion because duties were not segregated.
  • Target (2013): attackers used credentials stolen from its heating and air-conditioning contractor to reach the payment network, affecting around 40 million payment cards.
  • Colonial Pipeline (May 2021): attackers entered through a single dormant VPN account protected by a password alone, with no second factor.
  • Verizon's 2024 Data Breach Investigations Report found that 68% of breaches involved a human element, and stolen credentials appear in nearly a third of breaches over the past decade.
  • IBM's 2024 Cost of a Data Breach study put the global average cost at US$4.88 million, and breaches involving stolen credentials took around 292 days to identify and contain.
  • CyberArk's 2025 research found machine identities outnumber human identities by more than 80 to 1.
Knowledge Check
Q1: According to Layla's rule, in what order should a PAM programme be defined?
Tools, processes, operating model, strategy
Operating model, tools, strategy, processes
Strategy, operating model, processes, tools
Processes, strategy, tools, operating model
Q2: Which of these is one of the five pillars of Abby Steel's PAM strategy?
Visibility
Outsourcing
Perimeter defence
Encryption
Q3: In Abby Steel's operating model, who does what when access is granted?
IT approves, the business provisions, security records
Security approves and provisions, the business reviews
The requester's manager approves and provisions everything
The business owner approves, security reviews and IT provisions
Q4: What does the Société Générale case illustrate?
The need for multi-factor authentication
The danger of one person holding both sides of a process, i.e. no segregation of duties
The risks of third-party contractor access
Why machine identities must be vaulted
Q5: Why is the 'mover' step the one most organisations get wrong?
New access is granted, but old access is rarely removed, so privilege quietly accumulates
Movers are always denied the access they need
Mover requests go straight to the board
Movers are treated as leavers and lose all their access
Q6: Why doesn't Layla automate the access processes on day one?
Automation tools are too expensive for the first year
Regulators forbid automation of access decisions
Automating a broken process doesn't fix it; it makes it fail faster, at scale
HR systems cannot be integrated with PAM
Q7: What is the 'key process principle' that runs underneath every process in the module?
Senior staff receive broader access as a mark of trust
Access is granted based on length of service
Access is reviewed only after an incident
Access is based on role, not seniority
Q8: Why is a stolen admin credential far less useful to an attacker when just-in-time access is in place?
Because it carries no standing privilege; elevation is granted for a task window and expires automatically
Because just-in-time access encrypts all passwords
Because the account is deleted every night
Because just-in-time access blocks all remote logins
Q9: What does the Target (2013) breach teach about third-party access?
Contractors should share a single admin account
Your security perimeter includes every supplier you've given a login, so their access must be time-boxed, least-privileged, monitored and reviewed against a live contract
Third parties never need privileged access
Vendor access is the vendor's responsibility, not yours
Q10: Six months into the programme, where does Abby Steel sit on the five-stage maturity model?
Stage one: Chaos
Stage two: Visibility
Stage three: Control
Stage five: Governance
Requirements
Completion of Module 1 (recommended)
Basic understanding of IT administration or security concepts
Target audience: security and IT professionals, PAM practitioners and programme leads
No vendor-specific tool knowledge required — this module is vendor-neutral
Your instructors
NK
Nabeel Khaliq
IAM & Privileged Access Management SME · Founder, PAM Best Practice Ltd
Practitioner with deep hands-on experience implementing PAM across enterprise environments. Founder of PAM Best Practice Academy, a UK-registered education and community hub for PAM professionals. Arsenal and Middlesbrough fan.
AR
Adrian Russo
IAM & Privileged Access Management Architect
Senior PAM architect with extensive experience designing and deploying large-scale CyberArk and BeyondTrust implementations across regulated industries.
Your progress
Module 2 — PAM Strategy & Operating Model
Not started0%
Module breakdown
Part 1: Incident and RealisationSlides
Part 2: StrategySlides
Part 3: Operating ModelSlides
Part 4: ProcessesSlides
Part 5: ControlsSlides
Part 6: Reality CheckSlides
Part 7: Maturity and HandoverSlides
Knowledge Check10 questions
Up next
Module 3 — Discovery & Assessment
In Module 3, Priya, Abby Steel's Senior Security Analyst, leads Discovery & Assessment to find every privileged account the organisation has.
PAM Community
Join our network of PAM practitioners, mentors and industry partners across the UK.