The question this module answers
Which technology can deliver it?
Omar has designed the controls, Priya has shown the scale and Layla has the business backing. Now Abby Steel needs technology that can make the design real. Every vendor demo looks good; Sofia wants to know whether it works in Abby Steel's environment, with its old applications, network restrictions, cloud platforms, factories, approval processes and budget.
Sofia writes three rules on the board: requirements before products. Proof before promises. Total cost before purchase.
By the end you won't know which vendor is universally best, because there isn't one. You'll know how to test what your organisation actually needs before assumptions become expensive mistakes.
Module curriculum
1
Part 1: Requirements before productsScenes 1–2: The Evaluator · Start With the Problem
Narrated slides
2
Part 2: Why automate, and what it hidesScenes 3–5: Why Automate PAM? · Scale, Consistency and Least Privilege · The Single Pane of Glass... and What Sits Behind It
Narrated slides
3
Part 3: Where the platform livesScenes 6–8: Deployment Model One: On-Premises · Deployment Model Two: Cloud · Deployment Model Three: Hybrid
Narrated slides
4
Part 4: Scale and resilienceScenes 9–10: Performance: Test Year Five on Day One · Availability: When PAM Becomes the Outage
Narrated slides
5
Part 5: Integration and the deep estateScenes 11–13: Integration: Follow the Business Process · “Yes, We Integrate With That” · The Deep Estate: Where Easy Answers End
Narrated slides
6
Part 6: Total cost of ownershipScene 14: The Cost Nobody Put in the Licence Quote
Narrated slides
7
Part 7: The RFI and the vendor landscapeScenes 15–17: The RFI: Turn Assumptions Into Questions · Building the RFI: Ask What Engineers Will Need Later · The Vendor Landscape: Ignore the Accent
Narrated slides
8
Part 8: Proof, decision and handoverScenes 18–20: The PoC: Test What You're Worried Won't Work · The Decision: Product, Partner and Price · Buying It Was the Easy Part
Narrated slides
9
Knowledge Check10 questions · pass mark 8/10
Quiz
Key takeaways
Don't begin with “which vendor has the most features?” Begin with “what are we trying to achieve?”
Then establish:- What must integrate?
- What might not be supported?
- What additional infrastructure is required?
- What requires another licence, Professional Services or custom development?
- Who will implement it, and who will support it?
- What will it cost to operate?
- What happens when it grows, and when it fails?
- Can the vendor prove the difficult requirements in our environment before we commit?
When a vendor says “Yes, we support that”, ask: how? Native connector, API, script, Professional Services, partner or customer-built?
Knowledge Check
Q1: What is Sofia's first question in her first evaluation meeting?
Which PAM vendor is the market leader?
How much budget has been approved?
What problems are we trying to solve?
Which product has the longest feature list?
Q2: Vendors describe the same capability as just-in-time access, ephemeral privilege or zero standing privilege. What does Sofia recommend?
Ask what business problem the capability solves
Pick the vendor whose terminology matches yours
Standardise on the most common marketing term
Treat them as three separate requirements
Q3: What warning does Sofia give about automating PAM?
Automation always removes the need for approvals
Automation is only worthwhile above 5,000 accounts
Automated controls should never run outside office hours
Automation doesn't rescue a bad process; it can make it happen faster, so understand the requirement first
Q4: Abby Steel needs just-in-time access on Windows, Linux and a fifteen-year-old network appliance. What should Sofia ask a vendor?
Do you support just-in-time access?
Show me how you deliver it on these three systems
Is just-in-time access on your roadmap?
Which analyst report rates your just-in-time access highest?
Q5: The PAM control plane is in the cloud, but the furnace network cannot reach the internet. What does this show?
Infrastructure moves rather than disappears: connectors, gateways or proxies must still reach systems inside the plant
Cloud PAM cannot be used anywhere in a steelworks
The furnace network must be connected directly to the internet
Emergency access is no longer needed
Q6: What does 'test year five on day one' mean?
Sign a five-year contract before the proof of concept
Only evaluate vendors that have existed for five years
Test performance at the projected growth volume and find out what else must be bought if the estate doubles
Delay the purchase for five years
Q7: A vendor says, 'Yes, we integrate with that.' What should Sofia establish next?
Nothing more; the requirement is met
Whether the integration appears on the vendor's website
How many customers use the integration
Whether it is a native connector, API, script, services or customer-built, and who builds, supports and maintains it through upgrades
Q8: Why is the cheapest licence not necessarily the cheapest PAM programme?
Licence prices always rise after year one
Total cost includes implementation, infrastructure, recording storage, integrations, training, staff, support and upgrades
Cheaper products are always less secure
Vendors hide the licence price in the RFI
Q9: What should a PAM proof of concept focus on?
Onboarding a Windows server and rotating one password
The vendor's standard demonstration script
The awkward systems and scenarios you're worried won't work, tested by a real user
Features that won't be used until year five
Q10: Which three columns does Sofia use to make the final decision?
Product, delivery and operations
Price, brand and analyst rating
Features, roadmap and discount
Cloud, on-premises and hybrid
Requirements
Completion of Module 4 (recommended)
Basic understanding of IT administration or security concepts
Target audience: security and IT professionals, PAM practitioners and programme leads
No vendor-specific tool knowledge required — this module is vendor-neutral