Assessment of privileged account management maturity and CyberArk Privilege Cloud deployment for [REDACTED]. Covering account discovery, safe configuration, session recording, and Phase 2 onboarding pipeline. Engagement ref. ENG-2025-0560.
Plaidnox completed a deployment maturity review of [REDACTED]'s CyberArk Privilege Cloud implementation in Q1 2025. Of 1,204 discovered privileged accounts, 847 (70.3%) are vaulted with at least one access policy applied. The remaining 357 accounts . primarily middleware service accounts, legacy Windows scheduled tasks, and inter-system API credentials . remain outside PAM governance, creating unmonitored pathways to core banking and payment processing systems.
The most critical gap is 23 service accounts with direct access to the SWIFT messaging gateway that are not vaulted and have static credentials unchanged for an average of 847 days.
| Account Type | Total | Vaulted | Gap | Priority |
|---|---|---|---|---|
| Domain Admin / Tier-0 | 38 | 38 | 0 | Complete |
| Local Admin (servers) | 412 | 380 | 32 | Medium |
| Service Accounts (AD) | 284 | 197 | 87 | High |
| Middleware / API Credentials | 312 | 127 | 185 | High |
| SWIFT & Payment Gateway | 48 | 25 | 23 | Critical |
| Database Admin (DBA) | 110 | 80 | 30 | Medium |
| ID | Finding | Priority |
|---|---|---|
| PAM-G01 | 23 SWIFT gateway service accounts not vaulted . static credentials aged avg. 847 days | Critical |
| PAM-G02 | 185 middleware API credentials have no rotation policy . hardcoded in application config files | High |
| PAM-G03 | Session recording disabled for 63% of safes . limits forensic capability post-incident | High |
| PAM-G04 | No automated account discovery scan scheduled . new accounts created outside CyberArk not detected | Medium |
| Action | Timeline | Owner |
|---|---|---|
| Vault 23 SWIFT gateway accounts and enforce 90-day rotation | Wk 1-2 | IT / Plaidnox |
| Migrate 185 middleware credentials to CyberArk conjur / API key safe | Wk 2-6 | Plaidnox |
| Enable session recording across all Tier-1 and Tier-2 safes | Wk 1-3 | IT |
| Configure weekly automated discovery via CyberArk DNA scan | Wk 2-4 | Plaidnox |
| Onboard remaining 87 AD service accounts and 30 DBA accounts | Wk 4-12 | Plaidnox / IT |