• Understand why traditional PAM solutions fail SMB realities
• Learn what an IT-led PAM approach looks like in practice
• Identify realistic first steps to start PAM immediately
• Reduce complexity and implementation effort for lean IT teams
• See how PAM fits naturally into remote access workflows
• Build a PAM strategy that grows with your organization
Privileged Access Management is widely recognized as essential, yet many SMBs continue to delay adoption. Traditional PAM solutions are often too complex, time-consuming, and expensive for smaller IT teams. As cyber risks increase, this gap between security requirements and operational reality becomes harder to ignore.
New, IT-led PAM approaches rethink how privileged access is introduced and managed. By focusing on simplicity, incremental deployment, and integration into existing remote access workflows, modern solutions allow SMBs to improve security without disrupting productivity. The emphasis is on starting small, reducing friction, and scaling as needs evolve.
Alejandro Leal Analyst at KuppingerCole will provide an independent perspective on the evolving PAM market and its impact on SMBs. They will discuss common adoption pitfalls, emerging trends in IT-led PAM, and what IT professionals and security teams should prioritize when evaluating scalable, cost-effective PAM strategies.
Yannick Leblanc, Product Knowledge & Insights Analyst at Devolutions will break down the practical barriers that prevent SMBs from adopting PAM, including cost, complexity, and limited IT resources. Together with Maxime Trottier, Chief Operating Officer (COO) at Devolutions, he will share real-world guidance on starting PAM now, integrating it into daily IT workflows, and scaling securely over time.
Who Should Attend:
This webinar is designed for IT managers, system administrators, and security-minded professionals in SMB and mid-market organizations who want to improve privileged access security without adding unnecessary complexity or overhead.
Hello everyone and welcome to the webinar, Why Traditional PAM Fails SMBs and What to Do Instead. My name is Alejandro Leal, Senior Analyst at KuppingerCole Analysts, and today we'll have two experts from the Devolutions team joining me in this conversation. Hey guys.
Hey, hello, very excited to be here. Thank you, likewise. It's going to be a good and fun conversation, and you guys have a very cool setting, so maybe you could briefly introduce yourself.
Yeah, sure. Go ahead.
Yeah, my name is Max, I'm Chief Operating Officer here at Devolutions, been around for the last 14 years now at the company, so almost from the beginning. Yeah, and I'm Yannick, I'm a Product Knowledge and Insight Analyst. I've been at Devolutions for almost four years now, working then giving that insight to our internal teams about how people are using our products.
Awesome, great. Well, today we're going to have a different kind of webinar. It's going to be more of a fireside chat, more of a conversation, so I would like to encourage questions from the audience at any given time. We will be happy to answer and address those.
However, before we get into the topic, I will first set the stage for the first five to eight minutes to provide you with all the information that we've gotten based on our latest research on PAM, and then after five to eight minutes, then we will start the conversation. But before we get into that, I would like to remind the audience of just a few things. So all of you are muted centrally, there's no need to mute or unmute yourself. We will also be conducting a couple of poll questions. You will see them on the screen, and if you could answer those, that would be great.
It helps us in our research. Also, if we have time at the end, we are also going to discuss the results of those polls.
Questions, as I said, please be engaged with us. We're here for you. We want to talk about this topic, so just feel free to ask anything. And the recording, together with the slides, they will be available for download in the coming days.
So again, the agenda, setting the stage, fireside conversation, and then at the end, if there are more questions, we will also address those. Now, here's the first poll question. You should see it on the screen. Take your time, but in the meantime, we'll be proceeding to the next slide. All right. We're doing a Hanover ticket giveaway right now. So the first 10 people, we're going to send us an email to marketingatdelicious.net. We'll receive a free ticket to go and come see us at SecITICE in Hanover in about two weeks.
Yeah, exactly two weeks. So yeah, we invite you to send us an email, marketingatdelicious.net, and then we'll send you that details.
But yeah, please come and see us. We're going to have a booth at the SecITICE in Hanover. We have a team there of about four or five people, and I believe the team at Computer Go will be joining us as well for a few sessions. So very interesting to meet you guys and connect with you in Hanover. Awesome.
Thank you, guys. So now moving on, let's set the stage. So when we talk about security, I think it's something important to keep in mind that when we talk about attackers, they're not just trying to break into systems. They're trying to gain access, privilege access. Privilege access. That is the real price that they're looking for. So we know, we see it in the news, there are a lot of different threats that come from many directions.
Phishing and social engineering, especially with the use of GNI, software vulnerabilities, malware, identity threats, insider threats, and also advanced persistent threats, usually by state-sponsored actors. So these attack vectors, they may look different, but they often share the same objective. So once an attacker gains initial foothold, the next step is always the same, to escalate privileges and to move deeper into the organization's network. So with privilege access, attackers can bypass controls, they can move laterally, they can access sensitive data, and disrupt business operations.
So in other words, privilege turns a small breach into a potential major incident. And this is why PAM, Privilege Access Management, has become such a critical component in modern security strategies, because controlling privilege access means controlling what the attackers ultimately want.
And yet, despite the importance of PAM, we see that many organizations, especially small and medium-sized businesses, they struggle to implement PAM. So today, we will be exploring why that gap exists, and what can be done to close that gap.
But first, I would like to talk a little bit about the grouping and core identity fabric, because if the question is, how do organizations control that access effectively across today's environments, then we will see that the challenge is that modern IT environments are no longer simple or centralized. Organizations are now operating across hybrid infrastructures, cloud services, SaaS platforms, APIs, and an expanding number of human and non-human identities. So privilege access is no longer limited to a small group of admins. It can emerge anywhere in the environment, and often dynamically.
So this is why the grouping and core identity fabric is important, because we are looking at identity security through this lens. So the idea behind an identity fabric is to bring together different identity and access management capabilities, such as access management, PAM, IGA, Keem, into a cohesive architecture that can manage identities, entitlements, and access decisions across the entire environment. So the concept of identity fabric is not necessarily based on a single technology tool or cloud service, but it's more of a paradigm for architecting IAM within enterprises.
So within this broader identity fabric, PAM plays a critical role, because PAM governs the most sensitive actions and resources in the system. But as the identity landscape becomes more complex and more challenging, the way PAM is delivered and implemented also needs to evolve. So to better understand PAM and how PAM is evolving, I think it's helpful to look at the maturity journey. Look at PAM as a maturity journey rather than, let's say, a single product category.
So at the foundational level, PAM started with core access controls, like password vaulting, rotation, station recording, and audit capabilities. These controls established the basic ability to protect and monitor privilege accounts.
However, in the context of the identity fabric, PAM was isolated from broader IAM strategies. The next phase introduced integration and automation, particularly as organizations moved into cloud environments. And as those environments continued to change, we then entered a third layer focused on DevOps and machine identities. And looking ahead, we're beginning to see the emergence of AI-driven and autonomous PAM, where access decisions can be enforced dynamically based on risk, behavioral analysis, and policies.
But while this maturity stack reflects the direction of the market, it also highlights an important reality. And the reality is that as PAM capabilities expand and architectures become more sophisticated, the complexity of deploying and operating the system increases as well. And this is precisely where many smaller organizations start to struggle. Capabilities are expanding, and complexity is too. So we see that over the past few years, the expectations around PAM have expanded significantly. The term and meaning of privilege has also evolved.
So from a security perspective, the evolution makes sense. Organizations want tighter controls over privilege actions across their cloud infrastructure, workloads, applications, machine identities. But I think here is where we see some tension emerging, because enterprise-grade PAM solutions are becoming more broad, more integrated, and more powerful. But at the same time, they're often more complex and more resource-intensive, and also slower to deploy. So for large enterprises with dedicated security teams, this trajectory, it can be manageable. And I guess it's also necessary.
But for small and medium-sized businesses, it doesn't really work that well, because it widens the gap between security expectations and operational reality. So that brings us to the key question that I would like to introduce. So how can SMBs get strong privilege access control now and add advanced capabilities over time without inheriting enterprise complexity? So that brings us to the last slide, so then we can jump into the conversation. But traditional PAM solutions were not designed with SMBs in mind. The first issue is cost.
So enterprise PAM platforms often come with high licensing and operational overhead that assume dedicated and big security teams that are specialized in identity. But for smaller organizations, that cost structure can quickly become very difficult to justify. The second one is complexity. Many traditional solutions are packed with features designed for large enterprises. But for small IT teams, that often results in feature overload rather than efficiency. And it requires a lot of time to configure, to maintain, and to operate, and also to learn. The other issue is architecture.
So many PAM platforms are overengineering for SMB environments. This also affects onboarding. So in many traditional PAM deployments, organizations must first perform broad account discovery, mitigate credentials, define policies, integrate multiple systems, before they can even start protecting privilege accounts. So that onboarding process becomes very slow and resource intensive. And that also leads to limited support for modular phased adoption. So organizations are expected to deploy a full platform before seeing real value, rather than, let's say, starting small and spending over time.
And finally, there's the issue of time to value. Implementation cycles can take weeks or even months, which delays security improvements, and it can also discourage adoption. So while PAM is widely recognized as essential, many SMBs delay adoption, not because they doubt its importance, but because the traditional deployment model does not really align with their operation reality. So with that in mind, I would like now to move on to the conversation. But before we get there, just one last poll question that you will see on your screen.
And I'm very interested to see the results of this question. Maybe at the end, we can have a discussion about the results.
I mean, that's spot on. That's exactly what we're seeing in terms of adoption. You just mentioned starting small, right? And I guess this is where I would do my first step as an SMB. And I don't know if people can see in the chat, but we do provide a starter pack for all solutions there, which allows for up to five users using all our solutions, including PAM. And that's exactly where we are as a company right now, saying all the enterprise-grade PAM looks great. When you have time, you have resources and fundings and whatever to deploy it. But what about the rest of us, right?
And that's exactly why we're here today, right? Yeah, absolutely. And the term that we decided to choose was IT-led PAM. Because in small businesses, they don't have like a team of five IT people and then 20 security team members and offensive and defensive security. They don't have access to that. So the way that we thought about the PAM and the way that we want to approach it is we're trying to push it through people so that IT teams can deploy it in a matter of a couple of hours, let's say, and then get a quick time to value. Exactly.
And we've learned I'll bring PAM to SMBs throughout the 15 years we've been around the company, starting with the self-manager first. And the need for PAM solutions came up from our existing customers saying, hey, we also need those kind of tools for our smaller organizations. And how can Devotions help us reach that security level? So everything that we're talking about today is something that we've done with our customers, deployed it to our customers. So we have a very comprehensive experience deploying those solutions.
And by the way, SMBs can reach up to 1,000 employees, but we also serve in the market 5,000 employees and even more in that cases. It's just a matter of focusing on your exact need as an IT professional working sometimes within a team or three elements, having to take care of everything in those businesses. That's exactly the target we want to reach out to. Absolutely. Yeah.
I mean, trying to implement a PAM solution with all the, like, as we said initially, like all the features at once, it's just, it's too much. It's too much. And people think that going manual, like privilege access, manual patch rotations is good enough. Doing all the actions manually, that's something we hear from clients when we're talking about PAM sometimes. They're like, oh, no, we're doing it manually, and that's good for us. But the problem is that if you need to remember it, you're eventually going to forget it.
Well, password managers were awesome 10 years ago. I mean, I believe it's value, but as soon as you go into more of a enterprise business kind of scenario, you encounter many problems with standard password managers. And that's why today, what we say to our customers is if you're working as an IT admin, wherever you are, you should look at PAM first and then password management for all of the business users around. But for your own needs, password managers don't cut any more for IT professionals.
Now, they're not enough. They don't bring enough in terms of security. But one of the angles that we also go is in terms of productivity, because most password managers are web-based. You use that through a browser extension or through an app on your phone.
And then, yes, you can do some interaction, but when you need to copy and paste the password, I mean, it goes beyond the point of traditional PAM features and just the basic security idea that you don't want to see. Yeah, we saw here on the slide and we will move on to the next one soon. But credential injection is very interesting for us in terms of how we deal with remote connections. Our flagship tool is called Remote Desktop Manager. It's been around for more than 15 years now. And the whole point is managing remote connections to different endpoints.
And starting from that premises, that's where we started building features around that. So what you're going to find out in terms of password management for when you look at our solutions is first, we need to make sure that we have the control on the remote connections. And then we're going to inject passwords and we're going to take care of all the approval processes into the PAM product that we use and we offer. But the core basis of why we have the success that we have right now is mainly coming from the fact that we handle that remote connections for you.
Yeah, absolutely. And one of the things, I don't know if that's something that you also see on your side of the room, but one of the things that the privilege, we manage the privilege access, but like 90% of the time, those privilege accesses, there's someone logging in with those credentials to an asset to then do action, right? 90% of the time.
Yes, we handle it, you establish it at the beginning, like there are non-union identities that we need to rotate and have those. Then if we're talking about like typical IT infrastructures, you have services running some privilege accounts and stuff like that that you also need to rotate. But in the SMB in mind, the connection to an asset is like 90% of the reason why you want to have privilege access. So that's why I think our product and the way that we decided to design is because we merge the privilege access with the connection that you're doing. I like that approach, right? Yeah.
And why we believe this is the right way to go for our smaller organizations and professionals working in our teams. Earlier you talked about the approach.
So I would like to maybe shift gears a little bit and go to the next slide because this IT-led approach that you talked about earlier, I think it's interesting because instead of starting with large security-driven platform rollouts, this approach of IT-led BAM focuses on giving the IT teams the tools that they really need, the set of capabilities that they can deploy and operate quickly without needing, let's say, a full identity security architecture from day one. So I guess the idea is to align BAM with how IT teams actually work on a daily basis.
So for many admins, privilege access happens during remote sessions when they connect to servers, infrastructure, or endpoints. So integrating privilege controls directly into those workflows can make security much easier to adopt. Also another, I guess, important element is the speed of deployment. Instead of long implementation cycles, the goal is to allow organizations to deploy and start protecting accounts within hours or days. And that leads me to the next question for you.
So what does time to value realistically look like in SMB deployments compared to, let's say, enterprise implementations? Yeah, I mean, the first metric that we take a look at on our side is how much time does it take to start importing and rotating the first schedule, right? Because if you're aiming to try to rotate and implement all of the different identities that you want to manage, you're never going to do that. It's too much. So when we're talking about time to values, how long does it take you to implement the solution until you import the first account?
And once you get the first account and you've managed your policies and everything, the rest is just repeating the same process, just importing accounts that you think are relevant, are important to the target. What are those first accounts? And maybe Alejandro can switch to the next slide here. How would you identify those first five to ten privilege accounts that we see the most fit for going in a quickly time to value with our tools?
Yeah, I'll say there's two ways most IT teams are working. It's either generic service accounts or generic accounts. And if you're going with models like the domain admin, the enterprise admin, anything that has access to anything on the domain controller is the first thing. If you're in an Azure infrastructure, it's everything that's global or able to reset any password. And we see the other side of it where people have personal administrator accounts, like my Yannick admin account. It's those two that I think bring the most value to it.
I think going with a double account principle, going with my normal account, and the admin account is something that's given in most businesses nowadays. And if you aim to add those to a PAM solution, it's already a huge step forward. Yeah. So you import those, you create your vault within the PAM solution you're going to use, Devolutions or anything other else. And then you start controlling access and approve those access to these accounts, right? Yeah. And that's another thing.
Usually the approval process, something that's lengthy takes time to review, but in a good SMB tailored solution, like the review process, you should be able to see exactly what the person is going to do or request to do with the access and then approve it in a couple of seconds. In our solution, we push notifications on cell phones because keep in mind that most people who are approving those requests are not always at their desk. So I think that mobile is something that's really important.
But yeah, it's just be efficient, but just make sure that you did your due diligence. Well, the whole point here is, and we've established that pretty early here at Devolutions.
I mean, maybe like seven or eight years ago when we started offering PAM solution is, we need to make sure that productivity doesn't get left behind when you start working and increasing security within your environment. So in other words, if you want to apply those kind of tools, we need to make sure that it actually helps you being more productive and not the other way around when your steps make it decrease speeds in terms of how you want to actually work within your environment.
And that's the whole point of having this flawless experience when you just check out if everything's being recorded or audited, if you need log reports or whatever. And we can also, as I mentioned earlier, inject credentials on your behalf and you never get access to any kind of credentials with that scenario.
Yeah, absolutely. I think one of the things that we focus on when we're talking about IT like PAM is the access to the credentials and everything. You don't want to have access to those. You don't want to need to copy the password and inject them into sessions. And most PAM solutions, they focus on the credentials and the security of that credentials. I think we have a good vision and a good opportunity for IT people is that we focus more on the connection where you're going to.
I would say the image that I give to our customers and partners and people we work with is having this sort of huge kind of key holder where someone's going to give you access to the specific endpoints you want to get to and not having those keys into your own possessions or in your own vault. And we did some sort of a few years back, we did a video of exactly that thing. We can vault all your credentials in a very secure way, but when it's time to actually use them, you cannot just rely on copy-paste motions.
You need to get to that credential injection point, which we can allow with remote step management. I think the key message here is that organizations do not need to solve everything at once, but instead they can begin with a few focused, high-impact steps. But my question for you is, once those steps have been completed, how do you ensure that the company, the business can then scale and mature over time? That's a good question. We've been talking since the beginning about core functions, core things we want to implement. It doesn't mean that everything else is just optional.
Some of those things are really, really important to put in place. But focus on the first thing, import them, rotate, approve.
Next, add just-in-time elevation. That's one good feature that you can add. Implement it in the right way. It doesn't cause any problems, any productivity loss. So that's one thing. Session recording, auditing, and then making sure that when there's a specific action or someone accessing an asset maybe they shouldn't be accessing, you get some reporting on that. But one of the first ones is just-in-time elevation and making sure the accounts, when they're not in use, they abide by zero spending privileges. You might want to say a few words on that as well.
But we strongly believe that just-in-time should be the default way to go for admins in terms of how we end all privilege access. And maybe get rid of those dual accounts with the underscore Yannick account in the future. That might make two cents here.
Yeah, I'd say that the most practical approach is to begin with core controls and then from there organizations can gradually introduce more advanced capabilities such as just-in-time access, stronger policy enforcement, and even broader integration with identity and security systems. But now I would like to maybe switch to the next slide. So I guess so far there's one key takeaway from this discussion is that PAM for SMBs succeeds when it fits the reality of SMBs.
So security controls should not introduce unnecessary complexity or require long implementation cycles, but they should deliver value. They should solve the problems that those small companies need. In other words, I think effective PAM for SMBs is not about having the most complex architecture, but about introducing practical controls like the ones that we discussed in the previous slide, while keeping IT operations efficient. And I think that's the mindset behind the IT-led PAM approach that we've been talking.
But how would you differentiate between, let's say, and we already briefly talked about it, but I would like to, if you could elaborate more, how do you differentiate between the essential PAM capabilities and those that may be considered to be overkill for smaller organizations? That's a very good question.
We talked about it a bit earlier now, but I mean, from where we are, and you presented that a bit earlier into your model as well, and what we see on the market right now, especially in the SMB organizations, is people are actually looking at ways to get started into their PAM kind of journey, right? And from looking at a whole project and starting to look at this kind of big monster that can be the enterprise-grade PAM, and there are other great products in the market for enterprise, and that's very fine.
But when you start looking at those huge projects, that's where the projects tend to stall at some point, because it takes a lot of resources in terms of human resources, but also in terms of financial resources. So the very first steps should be the foundation core features is the five or six ones we just discussed in terms of having to import those accounts, creating sort of workflow approvals, and get to that just-in-time phase at some point.
That, for me, is the key of any kind of first steps into a PAM journey. I don't know if you agree or not.
Oh yeah, no, I absolutely agree. And other things that we're mentioning in the beginning that are great PAM features, like agent API PAM features, they're really great. But when you're talking about SMBs, these are the types of things that are overkill. They are overkill because if you don't go on the basics of the principal accounts that are critical to your business, trying to secure those is just noise. It's just a matter of what should come first before moving to that next step with non-human anonymities, with behavioral analytics.
And if you don't have those core features in place first, you're never going to be able to put that in place within the upcoming year or so. And the key here is, can I deploy those solutions within a few hours or even a few days? So it doesn't take me weeks and months to deploy other solutions. And so what you see is the ratio between what's my benefits in terms of what am I getting for the effort I'm putting into a solution, and that ratio should be somehow very lean. For the max benefits, a few hours, a few days, and I get the max benefits for my SMB kind of scenario.
And then once you get your feet wet, then you can start moving upwards in terms of other use cases. Yeah, absolutely. Great.
Yeah, that makes sense. And I believe that we talked about it last time we spoke. I was talking to an end-user organization the other day, and they told me that they see all these spam solutions, talking about NHIs, AI agents, but that's only background noise for them. They just need password rotation. So sometimes we just have to look at the basics. There are many organizations out there that are just looking for you to solve their problems. But let's now switch to the next slide.
And I guess another important aspect when thinking about PAM for smaller organizations is where privilege access actually happens in daily operations. For most IT teams, PAM, and I would say privileged credentials are primarily used when remotely connecting to infrastructure, whether it's the server or the network device or the cloud system. So I guess that means that the point of risk is often in the moment of a remote session is initiated. So this is where credentials are used, where privilege actions occur, and where visibility and control are most important.
Would you guys like to say anything on that? Yeah, I mean, we talked, you know, the term we used was the key to the kingdom, right? Which is one privilege, one domain and account, let's say, has access to everything part of the business. One domain and privilege account has access to everything. So if you focus on those, you limit the experience exposure that you have. And what we also see in our infrastructure is that generally, when we're talking about PAM, it causes loss of productivity, generally, in the broad sense of terms.
But in our solution, and in SMB focused solutions, it's actually the other way around. It makes you more productive.
Yeah, you don't have to retrieve any kind of credentials, information, IP addresses or whatnot. And by the way, we do support more than 60 different technologies within Remote Desktop Manager in terms of connecting to different endpoints and servers and whatnot. And that's a very interesting point that we've mentioned very quickly in the beginning, but actually having a solution that supports your workflow and not the other way around.
So what we say is, instead of getting a solution that changes all your workflows, you should look for a solution that actually adapts your actual workflow, right? Yeah, absolutely. Absolutely.
And, you know, remember, IT people, 90% of the time, they connect to us. So if we make that easier, if you're more productive using the application, the change management phase of making sure you're using it through it, and then you're not losing productivity, makes it much easier when you're implementing it in a business. Absolutely, yeah. And we talked about it earlier, again, that PAM is to protect credentials at the point of use.
So again, that's exactly what the example that we gave. There's more you can do protecting those credentials and passwords into this huge revolve that can be called an enterprise with PAM. But when it's the actual time to use those passwords, that's where there's a critical phase in terms of credential injection. If you gain access to this credential, even if you use passwordation at some point or whatnot, the less exposure you give those credentials and passwords, the better is your security strategy around it.
Yeah, absolutely. And making it easier is probably the number one thing we're aiming to do, making it easier to use. I remember back when I was working in IT before coming in here at Devolutions, let's say eight to 10 years ago, I was implementing password solutions and people wouldn't want to go into those password solutions because they couldn't see the value, they didn't see how it improved their day-to-day usage. It's the same idea with PAM. If you don't see how it improves how it works in the day-to-day, you're not going to use it. So try to make it as easy to use as possible.
It's probably the best way to get people into it. Yeah, that's correct. Absolutely. Now we can maybe move on to the next slide. So I guess, you know, we've been talking a lot about how organizations can gradually have this maturity path. So we said, you know, the foundation stage focuses on getting the basics right. So once those core controls are in place, organizations can strengthen their capabilities by adding more advanced capabilities. And this provides, let's say, greater visibility into how the practice is actually being used.
And over time, as maturity increases, organizations can move toward more advanced models, such as we discussed, just-in-time privilege elevation and zero-standing privileges, where access is granted dynamically only when needed. So I guess the key takeaway is that PAM maturity is a journey. Organizations can start with small practical foundations and then gradually expand their capabilities as their security needs and operational capacity evolve.
So I would like to hear maybe some practical recommendations, or maybe you can share some examples of how you guys have helped SMBs progress in their PAM journey from the foundational level to the mature level. Yeah, I mean, first thing we do, right, internally, is that we offer support to anyone who reaches out to us, right? That's the first thing. So we get into calls with clients who are looking to have those basic features in place, and we actually go from A to Z with them.
And when I say A to Z, there's also a whole bunch of things that they need to do on their own and learn the application. But we go from creating what we call the providers, what we call the connectors, creating a provider, starting discovering where are the accounts and where they are, and which one I want to import into the solution, and then putting in place the checkout policies and stuff like that. We accompany most, or actually anyone who reaches out to us, to put those into place so that it actually goes faster for them to go into there.
We always focus on the first thing, import five, ten accounts, add them, and then we go from there. Oh, you want to be able to inject those to a secure jump host or a secure gateway?
Well, we help them implement that gateway and then do that. You want to make sure you have those session recording in place?
Then, yeah, we add that to the other ones. And then afterwards, we implement things like just-in-time elevation and zero sending privileges. Once you have a proof of concept working, when you added those credentials, you did some connections, you see that the password rotated, then you know that it works, then you can simply go into zero sending privileges.
And then, our business model is focusing on small and medium-sized businesses, and our goal is to help, I would say, partner with as many as we can in terms of operational, in terms of features and functionalities. And the good part is there are thousands of SMBs in the market, right? So what we say is, we're going to work with you, but on your own turf, and we're going to respect the quickness or your workflows in terms of adopting those new technologies. So instead of being very pushy with our customers and different partners, we let them go at the speed they want to go, right?
So it's not unusual for us to start working with a partner or customers here for a few days, putting in place what we just mentioned, and talk again with those customers in six months from now to move to the next step, and a year from now to move to the next step again, and two years from now. We have customers here who have been around for the last 14-15 years, just mainly because we work with them on that specific kind of pace where we respect the resources you have within your organization.
Yeah, and as I said earlier, if you don't see the value, if it's too rushed, if you have too much pressure, if it's too big, you're not going to do it. Yeah, that's as simple as that. You're not going to do it. Sorry about that. My point is, since we can work with thousands of customers, we have more than 1 million users within the platform right now. We have the luxury, I would say, to say, hey, if you're not ready yet within your own specific terms, we're going to move on to the next 100,000 customers we can help.
So there's no rush for our customers to say, we're not going to be pushy with them in terms of, hey, can we close the deal now? Because, you know, there's not too many. On the enterprise market, what I'm trying to say is, every kind of larger account becomes very important for all those numbers. But for us, having access to thousands of SMBs worldwide, we're here to help businesses that are ready to get our solutions in place.
Yeah, and the other point is that, when we're going with an IT-led solution or focused around SMBs, is that, since they're more simpler in its use, a lot of people actually do it on their own. They don't even need our help to be able to put it. In some cases, it's self-explanatory enough that you can do it on their own. We call this product-led. There are like dozens of vendors out there in terms of spamming.
I would pretty much say that we're one of the best in terms of self-service employing those solutions into your infrastructure, mainly because it's simple and because our tools have been designed for that exact purpose. Yeah, absolutely. Thank you so much, guys, for sharing those insights. I'm conscious of the time and I already see that there are some questions in the chat. Maybe we can go to the last slide, the key takeaways.
So, you know, we can conclude this by saying that PAM is recognized as essential. There's no question. But traditional enterprise solutions are complex and they're not fitting the reality of SMB environments.
Second, a more practical path, as already discussed, can start with an IT-led foundation. And third, the most effective approach is often incremental. Start by securing a small set of high-risk privilege accounts, then gradually expand the scope and maturity of controls over time. Ultimately, the goal is to bridge the gap between growing security expectations and the operational constraints that many SMBs face. So that means making privilege access control simple to deploy, aligned with real IT workflows, and scalable as organizations grow.
Main takeaways, guys, so we can then jump into the Q&A section. Yeah, sure, there's a question in the chat from Max, right?
Nice name, by the way. I'm not sure if all the audience see the actual question, so we might want to rephrase it instead of, I'm running a PAM solution that piece of software now needs access to all private accounts in order to rotate the credentials. This makes an extremely attractive target, especially together with a self-hosted DevOcean server. So the question is, what measures are implemented in the software itself to make misuse of the PAM solution itself harder? That's a really good question.
First thing is that in the way that we architectured our PAM solution is that the privilege account that we call the provider doesn't need access to all the privilege accounts. It doesn't need that. It only needs access to the privilege account that you want to manage.
Now, it depends on how you, which type of identities you're trying to manage. If they're in intra-ID or let's say an active directory, if you're still on a local active directory, you can delegate access control and then give access to that provider to only the account that should be able to manage. So that's one way that you can scope out or restrict the scope of attack that can happen in there. That's the first thing. Second thing is that the provider itself can also be part of the PAM.
So if the provider itself is part of the PAM and it's able to be able to rotate its own password, it now is less of a security liability. I mean, there's always the risk when we're talking about identities and security identities that they can be breached and used in some ways. But if you implement password rotation on those specific accounts, even for the providers, then that's a liability.
Yeah, I mean, risk zero doesn't exist. Exactly. The point here is to have as many layers as you can to, I would say, to make sure that any attackers that comes into your infrastructure start having more and more and more and more problems doing those lateral movements that we saw at the beginning of the presentation where people are actually looking for a piece of the infrastructure you can work with and start moving to other larger and more important accounts.
And what you want to do here is exactly adding layer of security to make sure that it becomes harder and harder in order to actually get those motions rolling. There's another question in the chat. So how can PAM help manage third-party or vendor access securely? That's a great question and that's cool to have that question today because this week we released a feature for contractor access, for third-party access to our solution, right?
So with that, the way that we have it is that we can give access to an external contractor to your internal infrastructure securely by going through a gateway and then have that be a privileged credential so that it also gets rotated. They need to have an approval and do a checkout request and you can make sure that they don't have to install any software to have access to that. It's all web-based and clientless.
So again, similar to what I said before, if you make it easier on those contractors to access your internal infrastructure, they're going to respect the controls that you put in place. So yeah, that's nice to hear that question today. And in working with customers, there are a whole bunch of different, I would say, homemade solutions here. Right now it's kind of the chaos in terms of third-party access and contractors.
We also see things like vendor access management and a lot of organizations are actually relying on the homemade kind of solutions where they're going to give access to a VPN and then trying to figure out who has access to it and trying to make sense of all of those accesses. And we say, we found and not found, we've worked on in a very easy way, clientless way, you don't interact to install any piece of software on your third-party access contractor, let's say. You just give them access to the exact endpoints they need to work with within your environment.
And we're going to track everything they do in terms of accesses. And it's all being done through the Devolution PAM solution here.
Yeah, directly from the web interface. That's one thing. I remember, as I said, I have some experience working in IT, right? I worked in IT for, let's say, 12 years before coming to Devolutions and creating the VPN access and then making sure they have the right tool, the software to connect on it and everything. For contractor access, it's a pain to manage. So going with the clientless approach of just going into your browser, entering the address, finding the account, clicking launch, and then everything gets automated for the user is much more practical.
We have another question from Max again. How are these external users licensed exactly like internal users? And that's per seat or per named account. So every contractor needs a license to be able to reach out to the Devolution PAM solution. And I'm going to ask Laurence here to actually, if you want to copy paste the link to our online store here, you're going to have access to all the price lists. And it goes down to $20 a month for every contractor if you look at the remote access part of our offering.
So this allows you to get access to the, you mentioned earlier, Devolution server from an external user using the gateway and the web app. Yeah. And our remote access management license, in that context of contractor, is what allows them to be able to use those PAM credentials and then connect remotely. So you're going to need an actual PAM license from our offering to create those accounts and to manage, configure those accounts. But to read and have access, you just need to have this remote access management license here. Yeah.
And since I said at the beginning that we're actually getting into calls with clients and trying to help them get it installed and getting configured, if you're interested, please reach out to our support team and someone will get into a call and try to get that going with you. Yeah, absolutely. And the goal here is also in terms of, just to make sure that we're all up to par here, is in the SMB reality, you're some sort of a one-stop shop or a single vendor to manage all the different accesses makes total sense because you don't have the kind of resources the enterprise market have.
And having to deal with multiple vendors, multiple solutions that don't talk or don't integrate well within each other becomes a real pain, right? So in terms of business here, what we want to achieve is can we manage the accesses within your business for business users, for external users, contractors, IT admins, previous users, all into a single kind of platform that you can manage and have a visibility on, right?
Yeah, absolutely. There's one more question before maybe we take a look at the polls and then we conclude with the rest of the slides. So the question is, how can IT teams justify the investment in PAM to the executive leadership? And I like that question because there's always this stereotype that IT teams are not very good at communicating and especially in SMBs where budgets are constrained. In business terms, how would you justify investing in PAM?
I mean, first thing I'll say is that if the PAM solution actually saves you time, it's a no-brainer, right? If connecting to a privilege access is actually faster when going through the PAM solution as opposed to going manually and then creating the account, resetting the password and then giving it privileges, in my mind, that's a no-brainer. We actually polled our clients, by the way. We asked them generally, how many hours a week do you save using our product? And for our product, it's around five to six hours a week that an individual IT person saves using our product.
Mainly because of credential ejection, mainly because of what we mentioned earlier in terms of organizing all those connections around all those accounts, it becomes seamless for the users to actually work with those tools. So, to answer your question, instead of going the security route, I would go the productivity route, saying, hey, this tool not only increases my security posture, but at the same time, saves me a whole bunch of time, gives me access to give.
And you can either say, you can, just like we said, we can say, I'm going to get rid of maybe two or three vendors here and go with a single platform to manage all those accesses. I would go down that route very quickly in terms of, I would pitch a solution like PAM to my board or my Slivoy or whatever, and then security comes as a major benefit of having this in place.
So, it's kind of a win-win for everyone, honestly. But again, I'm not saying this is the right solution for all users, mainly because if you look at maybe the enterprise market, it's another story. But for the SMB market, the min market, I would go down that route very quickly. Increased productivity, increased profit.
Okay, we have one more question. Maybe we can just briefly address it, and then we can just jump in and wrap it up. The question is, what is the quickest measurable win after deploying PAM? It's being able to see what happened in a privileged session.
To me, it's the auditing phase of it. When you did all your actions, you have those rotations in place. As soon as you can stop being reactive to what happens and try to get ahead of those things, that's where you gain your win. That's where you have your first win, is when you saw what happened in a session and you were able to do it right away. Increased visibility, increased control over what's happening within your infrastructure.
That's, I would say, the aha moment, when you start realizing you have control of what's happening and you're not blindsided by any kind of technology or tool that you don't have good visibility on. It becomes very evident that this is the right solution that you have. Awesome. Maybe we can just take a look at one of the poll questions. The question was, how mature is your organization's PAM program? 47% of the audience said, we're just starting to define our PAM strategy. Only 7% said, we are adopting just-in-time and risk-based privilege management. Are you surprised by that?
Honestly, no, not at all. One thing that happens fairly often when we get into calls is people are reaching out to us and they're like, we want PAM.
I say, okay, but what do you mean when you say you want PAM? What they tell me is, I don't know. It actually happens fairly often. On that route, I try to explain the best time to value to have a security check checklist in place and then making sure that those things are put into place, but people don't even know where to start. They don't know what it should look like.
You guys, like I figured, do an incredible job. I believe that you guys understand exactly the difference between the enterprise market and the SMB market. When you look at different research or whatnot, you realize that by trying to promote PAM as this global solution, very complicated, complex, it fails for SMB very quickly. That's why we're at the point where people are saying, well, 7% only of the audience has just-in-time in place, mainly because we've bundled this feature into this incredible high-end solution that doesn't make sense for them.
When you start looking at those core features, like we just did for the past hour, you start realizing, well, maybe just-in-time isn't that far-fetched for our destination. That's the whole point of having this discussion today.
Again, we feel and we strongly believe that SMBs are looking for those solutions, don't know where to start, and here we are with that webinar. I assume it's going to be useful for you guys, but I'm not surprised about the results. What about you, Alejandro? Are you surprised? Not surprised at all. Not surprised at all?
No, it's always here as well. Moving on, thank you so much, guys. Here are some QR codes that you can check out. Just to remind the audience, you can find more related research on our website. We'll also be having the European Identity and Cloud Conference in May, taking place in Berlin. Would anyone from the Devolutions team be there? I believe Maurice is our head of products. He's currently in our newly-launched-we've opened an office in Spain recently, and Maurice is going to be there with the team. I spoke to him during my LC-PAM briefing, so it would be nice to catch up with him there.
Yep. Great, so that's all. Thank you so much, guys, for your time, for your insights. If you're watching this and you have more questions, just reach out to the Devolutions team. They'll be happy to help.
Yes, absolutely. Reach out to us, please. Love to have a chat. Awesome. Thank you.
See All Locations
See All Locations