Try our new research platform with insights from 80,000+ expert users

CyberArk Privileged Access Manager vs IBM Security Secret Server comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 6, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

CyberArk Privileged Access ...
Ranking in Privileged Access Management (PAM)
1st
Average Rating
8.6
Reviews Sentiment
6.8
Number of Reviews
229
Ranking in other categories
User Activity Monitoring (1st), Enterprise Password Managers (2nd), Mainframe Security (1st), Operational Technology (OT) Security (3rd)
IBM Security Secret Server
Ranking in Privileged Access Management (PAM)
22nd
Average Rating
8.2
Reviews Sentiment
5.7
Number of Reviews
8
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of March 2026, in the Privileged Access Management (PAM) category, the mindshare of CyberArk Privileged Access Manager is 11.4%, down from 19.6% compared to the previous year. The mindshare of IBM Security Secret Server is 1.2%, up from 1.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Privileged Access Management (PAM) Mindshare Distribution
ProductMindshare (%)
CyberArk Privileged Access Manager11.4%
IBM Security Secret Server1.2%
Other87.4%
Privileged Access Management (PAM)
 

Featured Reviews

Atul-Gujar - PeerSpot reviewer
CyberArk manager at a comms service provider with 10,001+ employees
Secures critical infrastructures with essential user session audit records
A potential area for improvement is enhancing support for cluster environments and distributed Vaults. Clients in multiple countries that need central access have different challenges that require better solutions from CyberArk. For financial services, CyberArk can improve incident response by ensuring fast support for critical priority tickets to meet compliance requirements. Providing more documentation on CyberArk is recommended for new team members to enhance their troubleshooting capabilities. I understand it's up to the client, but 99% fail to change the demo key, so it's crucial for CyberArk to emphasize changing the key and documenting it as part of the installation process.
AsifIqbal - PeerSpot reviewer
Chief Information Security Officer at a insurance company with 501-1,000 employees
Privileged access monitoring has strengthened identity control and improved security posture
I find the monitoring and recording parts of IBM Security Secret Server to be the most valuable features. Password vaulting is somewhat typical, but I rate monitoring and recording as very good features, along with ease of deployment. The reporting tools in IBM Security Secret Server have helped me identify vulnerabilities. From the monitoring part, you can somewhat cover the identity vulnerability aspect. However, for identity vulnerability, I think the best approach is to use IAM rather than PAM. It is easy to integrate IBM Security Secret Server with cybersecurity frameworks, which is a very important aspect. When we are improving our attack surface, identity is the most important thing that we need to cover, and PAM will play a very crucial role in improving our cybersecurity framework and architecture. The main benefits that IBM Security Secret Server provides for me include complete control over the privileged identities, which are the main sources that can have the privilege to make numerous changes on the system. If we protect these identities through PAM and provide elevation on their accounts when required, then we can improve our security posture and infrastructure security.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The solution is highly stable."
"The established sessions on the target systems are fully isolated and the privileged account credentials are never exposed to the end-users or their client applications and devices."
"If properly set up, CyberArk Enterprise Password Vault has good stability, and is a very solid tool. It can run by itself. Its most valuable features are auto password recycling and PSM."
"Previously, we used to share passwords for service and normal admin accounts among team members. However, since we started managing it through the product, we've transitioned to individual admin accounts or implemented dual control for shared accounts. With dual control, exclusive checking and checkout options are available, and passwords are not stored in clear text anywhere in the credentials."
"CyberArk Privileged Access Manager has made our operations more streamlined."
"We have been able to manage application credentials in CyberArk, whether they come as a custom plugin or straight out-of-the-box."
"CyberArk Privileged Access Manager is the best solution for safeguarding sensitive patient data in healthcare, providing visibility and traceability that enhance compliance."
"It has helped from an auditing perspective identify who has access to privileged accounts."
"The live recording is a very useful feature."
"One of the most valuable features is scalability, and how it allows you to scale it without affecting the underlying core components."
"As a PAM solution, Secret Server performs all the use cases in our environment."
"What I like best about IBM Security Secret Server is its single-access console. It's also easy to manage and fulfills the requirements with the least resistance."
"The main benefits that IBM Security Secret Server provides for me include complete control over the privileged identities, which are the main sources that can have the privilege to make numerous changes on the system, and if we protect these identities through PAM and provide elevation on their accounts when required, then we can improve our security posture and infrastructure security."
"Stability-wise, I think it is a very good solution."
 

Cons

"CyberArk definitely needs to improve user experience and reduce complexity."
"The major pain point that we have is the capacity of CyberArk due to the sheer volume of NPAs that we are managing. We are a large organization and we have hundreds of thousands of non-personal accounts to manage. We have already found out that there are certain capacity limitations within CyberArk that might introduce performance issues. From my perspective, something that would be valuable would be if the vault could hold more passwords and be more scalable."
"I don't know if "failed authentication" is a glitch or if that was an update... However, since we are the CyberArk support within our organization, we need to know that the password is suspended and we won't know that unless we have the ITA log up. So when a user calls and says, "Hey, I'm locked out of CyberArk, I can't get into CyberArk," we have to go through all of these other troubleshooting steps because the first thing we don't think of right now is, "The account is suspended." It doesn't say that anymore."
"Making the reports more editable would be beneficial."
"What could be improved in CyberArk Privileged Access Manager is the licensing model. It should be more flexible in terms of the users. Currently, it's based on the number of users, but many users only log in once in four months or once in five months. It would be great if the licensing model could be modified based on user needs. We even have users who have not logged in even once."
"We require IAM (identify and access management) capability at the administrator level because we need more identification."
"My company always complains about the cost of CyberArk Privileged Access Manager because it's too high."
"The continuous scanning of the assets is limited to Windows and Unix. We like to have the solution scan any databases, network devices, and security devices for privileged accounts. That would be very helpful."
"It would be preferable if the full proxy was included in the IBM Security Secret Server."
"What needs improvement in IBM Security Secret Server is support. The local partner provides good support, but IBM itself doesn't. Most of the time, the IBM support team does not aggressively resolve issues reported through chat or the IBM website."
"I mention that password vaulting and password rotation in IBM Security Secret Server are basically the same thing, and it becomes somewhat complex when integrating a different system with them because it requires API development."
"Secret Server should have the ability to discover privileged accounts in the servers, like the administrator or users, from SQL and Oracle without having to import a script."
"The newer interface is more difficult to use than the previous one, and consequently, new users might need more training."
"The nonclustered index is working in an area with a problem that needs improvement."
 

Pricing and Cost Advice

"The solution is available at a high price"
"I would rate the tool’s pricing a six out of ten."
"It's an affordable platform."
"Although CyberArk Privileged Access Management is expensive, its protection capabilities outweigh the cost."
"They have two types of licensing: purchase and subscription. You have to pay for each admin user, such as Microsoft admin, mail admin, database admin, etc."
"There are additional features added to our CyberArk Privileged Access Manager license. For example, features that allow us to integrate into various kinds of platforms."
"The license CyberArk Privileged Access Manager is on an annual basis."
"I focus more on the technical side, but I hear customers say that if CyberArk was more affordable, they might have acquired more licenses. Some clients consider alternative solutions due to pricing concerns."
"My rating for the IBM Security Secret Server pricing is seven out of ten. It could be cheaper."
"The price could be better. I think it's a good price for the on-premises environment and the high availability for enterprises the solution provides."
"I believe that we paid 35,000 or 40,000 US dollars for it."
report
Use our free recommendation engine to learn which Privileged Access Management (PAM) solutions are best for your needs.
884,192 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
14%
Manufacturing Company
10%
Computer Software Company
8%
Government
6%
Insurance Company
23%
Computer Software Company
11%
Performing Arts
9%
Marketing Services Firm
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business59
Midsize Enterprise42
Large Enterprise174
By reviewers
Company SizeCount
Small Business4
Midsize Enterprise2
Large Enterprise2
 

Questions from the Community

How does Sailpoint IdentityIQ compare with CyberArk PAM?
We evaluated Sailpoint IdentityIQ before ultimately choosing CyberArk. Sailpoint Identity Platform is a solution to manage risks in cloud enterprise environments. It automates and streamlines the m...
What do you like most about CyberArk Privileged Access Manager?
The most valuable features of the solution are control and analytics.
What is your experience regarding pricing and costs for CyberArk Privileged Access Manager?
My thoughts on the pricing of CyberArk Privileged Access Manager depend entirely on the vendors' requirements. If they want their things to be secure, they have to spend accordingly. We have four t...
What needs improvement with IBM Security Secret Server?
I believe there is not much that can be improved for IBM Security Secret Server. Providing local support and local vendor availability would be beneficial so we are not dependent on international s...
What is your primary use case for IBM Security Secret Server?
IBM Security Secret Server serves multiple use cases for us, including the monitoring of privileged users, as well as the recording and password vaulting of their accounts, passwords, and need-base...
What advice do you have for others considering IBM Security Secret Server?
I mention that password vaulting and password rotation in IBM Security Secret Server are basically the same thing, and it becomes somewhat complex when integrating a different system with them beca...
 

Also Known As

CyberArk Privileged Access Security, CyberArk Enterprise Password Vault
IBM Secret Server, Secret Server, IBM Security Privileged Identity Manager
 

Overview

 

Sample Customers

Rockwell Automation
Information Not Available
Find out what your peers are saying about CyberArk Privileged Access Manager vs. IBM Security Secret Server and other solutions. Updated: March 2026.
884,192 professionals have used our research since 2012.