A global entertainment company governed administrator access to its SOX servers through CyberArk. Multiple times a month, admins couldn't connect to the servers they needed. Most of those incidents traced back to CyberArk's Central Policy Manager, which failed to sync rotated passwords between the vault and Active Directory. With Venice, admins request Just-in-Time access, which is granted for the session and revoked when it ends. Each SOX production server took up to 2 minutes to onboard, and every one across the US, UK and Japan is now governed by Venice.
The problem: A vault that stood between admins and their servers
The company's SOX-scoped servers spanned Windows and Linux machines, SAP systems and databases in the US, UK and Japan.
"80 percent of the failures were tied to a CyberArk CPM failure," the company's Senior Director of Cybersecurity said of the access failures. Every failure had to be manually troubleshot before the admin could get back in. Admins also held access much longer than they needed it.
"They would go in there, they would check out a password and they would use it outside of CyberArk for seven days," the Senior Director said.
Audit prep was manual too. Each quarterly SOX report meant updating spreadsheets and taking screenshots from Active Directory.
The migration: every SOX production server onboarded
The team decided to replace CyberArk, starting with the SOX environment. Every SOX production server moved to Venice, across Windows, Linux, SAP and database systems. Each one took one to two minutes to onboard. Deploying CyberArk had taken far longer.
"About nine months from day one, once procuring it to implementation," the Senior Director said of the original CyberArk deployment.
"It takes less than 15 minutes to teach somebody Venice," the company's Senior Security Engineer said. "Within about 15 minutes, everybody understands what it's all about."
The results: no more lockouts or standing access
Access to SOX servers is now only available through the Venice platform. When an admin requests it, they receive it for the session and lose it as soon as the session ends. Admins are no longer required to check out passwords, so the rotation failures that caused the majority of the CyberArk incidents are no longer in the path. Admins have not lost access to a SOX server since the move.
"We replaced bulky CyberArk with agentless Venice and removed 99% of standing privileges on SOX servers, all while meeting audit requirements in record time," the Senior Director said.
The team is now extending the same model to local admin rights across the rest of its estate.
"You never have local admin until you need it. Go through Venice, get added to the group, do what you need to do. And then you get pulled out of the group," the Senior Director said. "Everyone's happy, there's no standing permissions."