In this presentation we would like to show the Siemens PAM Journey with its “Ups” and “Downs”, challenges and future plans to make Siemens more secure.
In this presentation we would like to show the Siemens PAM Journey with its “Ups” and “Downs”, challenges and future plans to make Siemens more secure.
Siemens describes an eight-year effort to build a global, centralized Privileged Access Management (PAM) service aimed at reducing cyber risk from credential misuse, especially involving privileged identities, while also meeting policy and legal requirements. Rather than treating PAM as a single tool, the approach is positioned as a unified framework: a system of processes, multiple tools, internal consulting, and continuous reassessment as threats, technologies, and business needs evolve. The motivation includes addressing a rapidly changing threat landscape—now extending to cloud workloads, DevOps, non-human identities, and agentic AI—while ensuring the program does not become static and regularly revalidates whether the organization is using the right tools and processes.
The journey formally began in 2018 with an explicit decision not to simply buy a PAM product, but to create a framework that can scale across Siemens’ diverse business units and operating model. Current scale includes about 9,300 privileged users and 200,000+ privileged accounts, with a target of 20,000+ users and roughly half a million credentials, expected to grow further due to cloud, DevOps, non-human identities, and AI agents. A major theme is that onboarding is as much organizational negotiation as it is technical work, because teams historically operated independently, application owners prioritized differently, and compliance expectations needed to be met without derailing operations.
Core PAM capabilities are treated as non-negotiable foundations: static credential rotation (still necessary alongside just-in-time and ephemeral access), least privilege with RBAC, and strong audit/reporting. Human interactive access remains central—covering elevation, delegation, approvals, check-in/check-out, and break-glass—while non-interactive access is highlighted as critical because machine-to-machine usage can bypass human approvals and must still be rotated, governed, and monitored rather than merely “vaulted.” The program expands into DevOps secret integrations to prevent hardcoding, cloud integrations to manage rapidly changing resources and privilege drift, and a need to harmonize PAM with Identity Governance and Administration (IGA) to scale AI securely without slowing business innovation.
Key challenges split into internal and external categories. Internally, the hardest obstacle proved to be changing administrator behavior and operational processes, not the technical integrations; adoption improved when PAM was presented as enabling faster, leaner, cheaper operations in addition to security. Policy enforcement remains a balancing act: overly strict policies lead to exceptions or risk acceptance that undermines implementation, while overly flexible approaches can fragment processes. Externally, Siemens’ complexity pushes vendor tools to their limits, exposing gaps in solution maturity, feature development, and the need for coexistence between “traditional” human PAM and emerging agent/AI-focused controls. Operational costs rise due to manual process overhead, multiple tools, varied expertise needs, and different deployment models, compounded by architectural constraints from a highly federated enterprise structure and dissatisfaction with support responsiveness, feature delivery, and security bug-fix timelines.
Next steps focus on continuing to build the unified PAM framework as a system (not a product), securely integrating AI with updated PAM processes, and continuously revisiting strategy to keep pace with new privileged-access scenarios. Acknowledging that exceptions and custom workflows cannot be fully eliminated, Siemens emphasizes reducing fragmentation by aligning PAM with business value—efficiency and usability—so compliance and security improvements become outcomes of better operations rather than purely enforced mandates.
Hello everyone, today we would like to show you our Siemens journey in the Privileged Success Management and thank you Alejandro for this wonderful presentation because it was showing also some of the issues we faced on our way and it's interesting to see that different people in different situations coming to the same conclusions. So we have two main goals for today's presentation. One is to show you our challenges, our story, our success and surprises and some solutions which we have in the Privileged Success Management, but also to initiate a discussion.
Because Privileged Success Management is not a static thing, it's constantly developing, the market developed in the last five years dramatically. So when we were last time evaluating the market, things were much different. So now it's in this changing world. So you need constantly to ask yourself if you're doing the right thing, if you're using the right tool, the right process and we would like to hear from you and if you would like to share with us your experience, we'll be also very happy about it. So what is our motivation?
So we actually were born as a service, a central service, already eight years ago and the base was the fact or the realization that on the constantly growing landscape of cyber security threats, so especially connected to the identities, the privileged identities and the solid part of the cyber threats are coming from the credentials misuse, from misuse of privileged access.
The realization was coming that to cover this constant landscape of threats, we need to build a solid, secure service which is available globally to the complete Siemens, to all business units which will take care about these topics and which will be not static, it will be constantly revisiting its own goals, it will be looking at its processes and catching up with the new risks, new technologies, new threats, which might be coming from the cloud workloads, might be coming from the AI agents, which was the main topic for the last, I think, day and will be the topic for the next.
And of course, so the adherence to the policies, so especially when it's coming from government, so legal policy is also very important, even if it's not their main goal, it's some kind of boring maybe, you can tell, it's also still important, and the vision of this service, which was back then and still available for now, it's building a unified PAM framework, which is not a tool, it's not just a service, it's a collection of processes, different tools, consulting inside the company, and embracing the business units to implement privileged access management, which is covering various topics in the company connected to the security of the privileged identities.
Now heading over to my colleague Shruti, and she will tell you about our roadmap and our main functionalities in our privileged access management system. Thank you Igor for that wonderful introduction. Good morning everyone. Here we speak about our journey from evaluation to launch. So we started this journey in 2018, it was driven with the perception that privileged access has to be structured, it has to be governed, and it has to build to last.
What you see is a roadmap, is a product roadmap, and it's eight years of us with aligning with the different technologies, adapting to it, and then making sure that it remains secure throughout our organization. What we did in 2018 was we didn't buy a PAM tool. We tried to build a unified PAM framework, and that is what makes it important. To show some realistic numbers of what we have done so far, we have 9,300 privileged users with around 200,000 plus privileged accounts, and that is as of today.
But we are targeting for 20,000 plus users with half a million credentials, and even more if you take into account all the new technologies like cloud, DevOps, non-human identities and AI agents. What this doesn't tell you is every account onboarding was a conversation in itself, right? Teams have been working their own ways, we have application owners who have been doing things in terms of their priorities, and then we have a brilliant PAM compliance framework. We had to make sure that PAM fits into all of this seamlessly and in a secure way.
Let's speak about what is required for an ideal PAM solution to work. And that is the core PAM functionality that we're talking about. So these are the things which should work flawlessly, without exception, to scale. Which is very important. And these functionalities are universal, static credential rotation. I know we are speaking about just-in-time, ephemeral access, but let's not forget, static credentials are a thing, and we still have it in 2026, and we'll have it based on the infrastructure we have on-prem and on cloud. Then least privilege and RBAC model, along with audit and reporting.
These are the core functionalities that we build every use case on, and it's a non-negotiable. Then our lovable, our very dear interactive access, the human-driven side of PAM, with privilege elevations, delegation management, approval workflows, check-ins, check-outs, break glass in certain scenarios.
Well, these are the standards, and again, this is something that we will not change our methods for. We know what we are doing with the human-driven side of PAM, and we'll keep it as it is. What again comes as our most beloved, which is the non-interactive access. It accounts for... The beautiful thing about the non-interactive access is there's no human in loop. There's no one requesting, there's no one approving it, there's no one acting on it. It's a simple machine-to-machine communication, an application-to-application integration using APIs, right?
An IT task that was automated and orchestrated. Now, the thing is that it is important that these accounts are also on-board in PAM. Not with the logic of dumping them into a vault and saying, oh, we are PAM secured. No. It has to be rotated. It has to be looked over. It has to follow all the core functionalities that we have for the human-driven access, and we should have it for a non-interactive access.
Now, here's the interesting part, which everyone has been talking about in this conference. The changing landscape, right? I'll speak about the topic DevOps.
So yes, we have DevOps secrets distributed across pipelines, repositories, and configuration files, right? One thing that we have to acknowledge is if we do not make this integration seamless, people are going to find ways to hard-code it or maybe store it in a different way. So it's very important that we integrate our native solutions, our native PAM solutions with the tools that the developers are using for DevOps. Then comes the cloud integration.
Now, this is where just-in-time and ephemeral access becomes important and empowers it. These cloud resources are spun and toned down every second, and along with it, the identities also. And these privileges can drift if not being overlooked and not being audited or governed by a solution like PAM or the security team. Then the icing on the cake would be the non-human identities and the agentic AIs that we have all been speaking about, right?
One thing that we need to know is it is easy to deploy such identities, but it's very important that we have a discovery and a proper onboarding process, just like we have for any other credential in our organization, right? It has to be... It has to ensure... So what I would suggest is having a harmony between PAM and IGA as a tool. What PAM brings into the table is which agent is authenticating it, which access these agents have, and whether these access are managed in PAM.
Now, what IGA brings into the table is what this agent is, what can it be, where is it used, and whether that usage has been governed and is it justified based as much the business evolves and as much the technology evolves. It's very important to harmonize these tools in order to grow in AI. This doesn't mean that we have to hinder the growth in terms of business development or AI developments as the organization demands. It only means that we are secure while we are doing this. It goes hand in hand, there's no question.
What we are looking for is if your product offers these extended use cases, then we would appreciate to have a conversation with you. I'll be here until tomorrow, and Igor would be here for the entire day. So we'd be happy to talk on these topics. Next is our learning that comes with it. So we have, of course, the use cases are easy. We have done it. We know how things work, how accesses work on different machines, be it on-prem or cloud. These use cases can become complex sooner. 60 to 70 percent, believe it or not, our efforts go into these automations.
But one thing that comes out of it and is worth is that once a user is onboarded to PAM, they just demand more, they want more, right? And this is what we are here to do that for, for them. It's a continuous expansion of PAM functionality. It's an alignment as much as it is about the technology that evolves with it.
With that, I hand over to Igor. Thank you so much.
Thank you, Shruti. Yeah. So as you see, so we have a great roadmap. So especially in the case of extended use cases. So there are a lot of things to do. So we would like to start the conversation about these topics as well. Some of them are already handled on our side.
For some, we are looking on the market. So what is available, interesting solutions. So it's very interesting to be here on this conference and to observe the development. Hopefully we can talk about that later. So what's coming to some parts of our journey. So challenges and challenges. So we divided into internal and external challenges, internal challenges, which we are facing. Maybe obvious, maybe for some of you will say you will not see them. Maybe this is unique to us as a big enterprise with a very specific and special structure. So maybe it will resonate in you.
So what was important from the beginning. So we wanted to bring the BAM to the business.
Yes, we wanted them to start using it. But it's obviously as every new cybersecurity process, technology whatsoever, it's causing the contradiction. So it's changing the process, changing the approach. I now need to do something different I used to do many years.
And one of our solutions in this user adoption and integration and IT and business processes was to not only show how secure your asset application, the process would be, but how it can be better, how it can be faster, how it can be more lean, how less effort can be used to administrate your application, give access to the sensitive data. And this was the right choice. So after we changed the approach and started to show the efficiencies of the BAM and not only the security part, which is still very important, then the things start rolling.
Enforcement, the policies which are supporting the BAM implementation was and is a big challenge because you cannot make it too hard, because as I heard in many conversations yesterday, but also today in the morning, that businesses are starting to accept the risks. So they will not implement your very complicated policy, will accept the risk, will make an exception. In the end, the implementation will not be done.
So it's a very complicated matter to keep the balance of your policies being available and supporting the implementation, but at the same time, not to make the overkill and to threaten the business and the application asset owners with that. And also the adoption of BAM as a universal solution, where you are, when you are taking care about your asset, that you are coming to us, you are asking us, so how you would recommend us to care about privileged access? Which solutions do we have?
So we are still on the way and hopefully this will be established in the broader manner in the future at Siemens, that nobody will invent their own bicycle, but will use existing secure processes in this area. Some of the external challenges we faced are mostly related to the fact that we as Siemens are using the single bit of the functionality of the solutions we're using. And when you basically saw the diversity of the use case, the complexity of the assets and the processes we have at Siemens, you're very much going to the edge of the possibilities of the solutions available on the market.
The maturity of the solutions is being basically reviewed very carefully on our side. And we see a lot of things which are, yeah, so being abandoned, not developed. Let's take this slide from Alejandro. So we see this old school PAM then developing through different stages to the agentic. They are coexisting. You are not having the human error PAM anywhere, going anywhere in the next year. So you need to have it coexisting with the solutions which will be securing the agents and they need to be developing as well. So you can have a configuration as a code is just to name one thing.
Also in the old, let's say, old school human PAM solutions. So which is regrettably not happening. And it's a big, let's say, challenge when you start managing, because it leads also to the operational cost escalation. So when you need to manage too many processes manually. But also operational less than cause escalation is coming from the part where to being able to cover the PAM landscape, we have to use various software solutions. Use various expertise levels, different deployment models and potentially different teams, which is causing the escalation, of course.
And that's why we are constantly revisiting. So what are we doing within PAM? Shall we use this or another tool? Shall we harmonize the processes? So which part of the other Siemens software suits we can use to cover PAM functionality? This is a big challenge. Because if you would have unlimited budget, maybe you can take for every single use case the best tool and make it. But the reality is a little bit different. Architectural constraints are also a challenge because of the business operating model and the high grade of federation available at Siemens.
And that also we need to keep it in mind. Also to not have, for example, the hundreds of service available for the PAM solution. So this was always our challenge from the beginning. And maybe last but not least, the support and maintenance quality. So because we are using the solutions very extensively, but not only because of that, we are facing complications when getting the support in time. So to getting the feature request implemented in time, to correct some security bug fixes, for example. So we are not very satisfied with what we have at the moment.
And this is also something we are looking forward to correct, to look at how it can be getting better, looking at internal and external processes. And the last point, so what are the next steps? So the three big points, which are interconnected with each other. So it's a building, a continued building unified PAM framework, which is not a tool. It's a system. It's a collection of processes, collection of the strategies. So how to cover every single privileged access scenario at Siemens, including the new challenges. Always secure AI integration with the support of new PAM processes.
And obviously, but still important, the continuous development. So not standing still, constantly revisiting the strategy and understanding what new things are coming to PAM and how to deal with them. Thank you a lot. We have questions. So don't run away. So first of all, thank you very much. Very impressive insight from reality and your journey. And at least time for one question. And I love this one. What was more difficult, the technical integration itself or changing admin behavior and operational processes? The admin behavior and the operational processes. Surprise. Yeah. Yeah.
That's a big surprise. Right.
So yeah, that is always going to be a challenge. And as I said, it has to be in alignment with the growing technology. One cannot happen without the other. We are technically smart to implement that. But it's important that we have the right attitude and the approach. And second question is, how do you prevent continuous privileged access management expansion from turning into a fragmented collection of exceptions and custom workflows over time?
Yeah, it's a very good question. So you cannot entirely mitigate it. But our approach, I mentioned in the challenges slide, the user adoption and integration to IT and business processes, it's to make PAM not only a security solution for the business, but also to use PAM as a potential to make the processes more effective, cheaper, faster, and go from this angle. And then additionally, you're also getting the whole security posture on top. So this is helping to integrate the business into the PAM process and have less exceptions.
So this is just pure pressure from the policies, from the cybersecurity rules, and telling, OK, be compliant, be compliant, be compliant. Compliance itself, it's not, at least in the eyes of some of the colleagues, it's not just the value itself.
Yes, you need to use it for something. So if everything will be extremely compliant, but not working and very slow, this is not happening. So when we started, we wanted to have extensive policies, and then we soon realized this is not the way. Perfect.
Again, thank you very much, Ruti and Igor. Thank you for having us. Thank you.
See All Locations
See All Locations