Keeper Security has published its latest Inside Report, titled “Securing Privileged Access: The Key to Modern Enterprise Defence” (registration required). The key message from the survey is that 49% of organisations using Privileged Access Management (PAM) had fewer security incidents. It shows that when properly implemented, PAM is still a key part of security tooling for organisations.
The report also identifies several obstacles to deploying PAM. These include the complexity of implementation (44%) and the complication of cloud/multi-cloud environments (38%). Given that this technology has been around for decades, complexity should not be a significant issue.

Darren Guccione, CEO and Co-founder of Keeper Security, said, “Every system, whether in the cloud, on-premises or remote, is a potential entry point that necessitates adaptive and secure controls to defend against modern threats.
“Modern, zero-trust PAM doesn’t just mitigate risk; it enables organisations to shift from a reactive defence posture to proactive, pervasive control.”
What is PAM?
Privileged Access Management (PAM) is about protecting, controlling, and managing privileged accounts. These are accounts that have elevated privileges. Once applied solely to administrative accounts, the scope today is far wider.
One reason for that wider scope is the failure of organisations to limit and revoke access when individuals change roles. It means that people constantly accrue access across the organisation, increasing the number of privileged accounts.
Another challenge for PAM is that an increasing number of non-human accounts have significant privileges. That includes service accounts, software and devices. Many of those were installed years ago and are generally unmanaged.
With the arrival of cloud computing and Software-as-a-Service (SaaS), many accounts are not necessarily created or controlled by IT. That creates a situation where PAM is expected to manage accounts it has no visibility into.
With the rise of AI agents, PAM will need to adapt to a new group of accounts that have elevated privileges to work on behalf of users. How vendors adapt to that was not covered in this report.
The report shows that organisations are addressing some of these challenges with PAM. For example, 65% are using it to protect hybrid environments, while 54% are securing service accounts. Importantly, 53% are using it to provide secure remote access for third parties. Exactly what that level of access is, APIs, site access, service access or something else, isn’t given. This is because of a lack of qualitative research.
Why is PAM adoption an issue?
The report calls out a range of issues around PAM adoption. Some are related to the initial setup, but many more are related to ongoing management. The issues range from budgets to technical to cultural. The latter is a particularly difficult issue to change, but organisations need to overcome resistance at the employee level.
The biggest inhibitor to adoption is cited as implementation complexity (44%). However, the report fails to explain what those are. What it does provide, however, are other factors, such as budget constraints (38%), cloud/multi-cloud (34%), and a lack of personnel to implement/manage (31%).
It would have helped to know if the 34% reporting cloud/multi-cloud as an issue are all part of the main 44% blaming complexity. It would also have helped to know how many said they don’t have the staff and face budget constraints.
Issues with cloud and hybrid environments continue beyond deployment. More organisations reported problems managing PAM (46%) across the environments than installing it. Part of that may be that 53% struggle to integrate PAM with their existing security tools. Integration problems mean multiple interfaces, multiple places for things to go wrong and an increased risk to the business.
Meanwhile, 44% reported problems with employee resistance to new security flows. That’s a big number and cannot simply be about difficult employees. It is likely that a significant contributor here will have been lax controls with users having too much access. Taking it away always leads to pushback. Unfortunately, the report fails to look deeper at this issue.
Management is also a problem. 27% say that leadership does not prioritise PAM. Why that is, is unclear. Is leadership as dismissive of other security solutions? Has there been a lack of explanation of the importance of PAM to management?
Not all doom and gloom
Despite the issues with installing and managing, PAM can deliver significant benefits to organisations once it is installed. In a world of data theft and compliance, 53% say it has improved the protection of sensitive data. For compliance teams, PAM has improved their compliance posture, according to 49% of respondents.
But there are inconsistencies in responses. 47% say it has reduced the IT help desk burden but with employees resistant to new security flows and a lack of people to maintain it, that 47% seems high. This is, again, why this type of report needs qualitative research not just people ticking boxes.
The reduction in security incidents tied to privilege misuse (49%) is a number that many PAM supporters will cite. But it would have helped to know what the difference was between human and non-human accounts.
Two numbers that are key here are the 50% that saw greater efficiency in managing privileged credentials and the 49% that say it has enhanced remote connections to infrastructure. The latter almost certainly relates to service and non-human accounts, which links back to the 54% who implemented PAM to deal with that.
Enterprise Times: What does this mean?
From its beginning as a manual solution in the 1980s, PAM has evolved significantly. However, many of the problems it struggled with manually have not gone away. The complexity of IT environments has increased significantly over the decades, but the technology evolution hasn’t kept up.
However, continuing to use that as a challenge for deploying and managing PAM says a lot about how much has to be done for it to evolve further.
That said, there are some really positive numbers from this survey in the report. What is a shame is that so many of them beg to be investigated to provide much more detail on what they mean. Without that, organisations are still being asked to take it on trust that PAM will work.
Perhaps the most serious concern from this is the lack of engagement by management, and that includes budget issues. Maybe it’s down to spending too much on other tools that have promised the world. Maybe it’s just cybersecurity fatigue at the C-Suite. Whatever the cause, unless that gets resolved, many of the issues here will not go away.

















