No more typing reviews! Try our Samantha, our new voice AI agent.

CyberArk Privileged Access Manager vs IBM Security Secret Server comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 6, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

CyberArk Privileged Access ...
Ranking in Privileged Access Management (PAM)
1st
Average Rating
8.6
Reviews Sentiment
6.8
Number of Reviews
230
Ranking in other categories
User Activity Monitoring (1st), Enterprise Password Managers (3rd), Mainframe Security (1st), Operational Technology (OT) Security (3rd)
IBM Security Secret Server
Ranking in Privileged Access Management (PAM)
22nd
Average Rating
8.2
Reviews Sentiment
5.7
Number of Reviews
8
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of May 2026, in the Privileged Access Management (PAM) category, the mindshare of CyberArk Privileged Access Manager is 10.4%, down from 18.5% compared to the previous year. The mindshare of IBM Security Secret Server is 1.3%, up from 1.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Privileged Access Management (PAM) Mindshare Distribution
ProductMindshare (%)
CyberArk Privileged Access Manager10.4%
IBM Security Secret Server1.3%
Other88.3%
Privileged Access Management (PAM)
 

Featured Reviews

Atul-Gujar - PeerSpot reviewer
CyberArk manager at a comms service provider with 10,001+ employees
Secures critical infrastructures with essential user session audit records
A potential area for improvement is enhancing support for cluster environments and distributed Vaults. Clients in multiple countries that need central access have different challenges that require better solutions from CyberArk. For financial services, CyberArk can improve incident response by ensuring fast support for critical priority tickets to meet compliance requirements. Providing more documentation on CyberArk is recommended for new team members to enhance their troubleshooting capabilities. I understand it's up to the client, but 99% fail to change the demo key, so it's crucial for CyberArk to emphasize changing the key and documenting it as part of the installation process.
AsifIqbal - PeerSpot reviewer
Chief Information Security Officer at a insurance company with 501-1,000 employees
Privileged access monitoring has strengthened identity control and improved security posture
I find the monitoring and recording parts of IBM Security Secret Server to be the most valuable features. Password vaulting is somewhat typical, but I rate monitoring and recording as very good features, along with ease of deployment. The reporting tools in IBM Security Secret Server have helped me identify vulnerabilities. From the monitoring part, you can somewhat cover the identity vulnerability aspect. However, for identity vulnerability, I think the best approach is to use IAM rather than PAM. It is easy to integrate IBM Security Secret Server with cybersecurity frameworks, which is a very important aspect. When we are improving our attack surface, identity is the most important thing that we need to cover, and PAM will play a very crucial role in improving our cybersecurity framework and architecture. The main benefits that IBM Security Secret Server provides for me include complete control over the privileged identities, which are the main sources that can have the privilege to make numerous changes on the system. If we protect these identities through PAM and provide elevation on their accounts when required, then we can improve our security posture and infrastructure security.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"CyberArk makes our environment more secure and prevents possible attacks by compromised accounts."
"Helped us meet our standards and requirements to help us comply with industry standards and banking regulations."
"CyberArk Enterprise Password Vault stability is good; if it's properly set up, it can just run by itself and is a very solid tool."
"Session recordings and timestamps are valuable features. They allow me to specifically select the time a particular command was executed, so I do not have to review the entire recording. I can click on events to determine where and when they happened."
"Within the solution, I love the fact that everything is recorded. The configuration capabilities are great, too."
"I have an affinity towards CyberArk; I find that it works out-of-the-box as a product."
"The integrations are the most valuable aspect of CyberArk Privileged Access Manager. The software offers pre-built integrations, and our team can also create custom connectors. This flexibility allows us to integrate with systems that we previously didn't consider integrating with, making it a significant advantage for us."
"It is a leading solution and one of the best SaaS solutions in the market."
"Access to privileged, shared credentials is simplified by optimizing the whole workflow and approval processes."
"It is one of the most well-known names in this field."
"What I like best about IBM Security Secret Server is its single-access console. It's also easy to manage and fulfills the requirements with the least resistance."
"The live recording is a very useful feature."
"One of the most valuable features is scalability, and how it allows you to scale it without affecting the underlying core components."
"Centralized Password Management: Our client has more than 400 geographical locations and approximately ten employees work at each location."
"This product has been able to cover most of the requests from our customers."
"Stability-wise, I think it is a very good solution."
 

Cons

"The architecture needs to be improved."
"The initial setup was a bit complex."
"It could be more user-friendly. Sometimes I encounter issues, and I do not know what the issue is."
"When I was a component owner for PAM's Privileged Threat Analytics (PTA) component, what I wanted was a clear mapping to the MITRE ATT&CK framework, a framework which has a comprehensive list of use cases. We reached out to the vendor and asked them how much coverage they have of the uses cases found on MITRE, which would have given us a better view of things while I was the product owner. Unfortunately they did not have the capability of mapping onto MITRE's framework at that time."
"The initial setup has room for improvement to be more straightforward."
"Upgrading the product is very difficult, so this could be an area for improvement."
"The solution's architecture could be improved. It requires installation on four to five different servers."
"We found a lot of errors during the initial setup. They should work to improve the implementation experience and to remove errors from the process."
"Secret Server should have the ability to discover privileged accounts in the servers, like the administrator or users, from SQL and Oracle without having to import a script."
"Although much has improved in last two years, the GUI for IBM products can be improved."
"The nonclustered index is working in an area with a problem that needs improvement."
"What needs improvement in IBM Security Secret Server is support. The local partner provides good support, but IBM itself doesn't. Most of the time, the IBM support team does not aggressively resolve issues reported through chat or the IBM website."
"If you have a hosted PIM in your local environment and you plan to migrate it to some cloud-based environment, then migration will become a painful task."
"The newer interface is more difficult to use than the previous one, and consequently, new users might need more training."
"The newer interface is maybe confusing old customer that using previous one from their point of views, I think they will need little pass of time to be familiar with."
"It would be preferable if the full proxy was included in the IBM Security Secret Server."
 

Pricing and Cost Advice

"The main problem for the tool is its licensing. I work for a really big company. When you try to develop this as a service, usually you work with leverage teams who are formed with dozens of members. You might dedicate one FTE, or less, for something, e.g., an antivirus administrator. You might have half an FTE's effort dedicated to administering the antivirus, but then you have a team of about 30 users who might access that ticket. The problem is that CyberArk eliminated the possibility of concurrent users years ago. This is a big problem for companies who work with leverage teams. You need to pay for everyone. 40 licenses are used by 20 or 30 people. This is a big problem because licenses are not precisely cheap."
"The product’s pricing is feasible for enterprise customers. The pricing is expensive for smaller businesses. You need to pay additional costs for service implementation and local support."
"It is in line with its competitors, but all such solutions cost too much money."
"It's an affordable platform."
"If you want a Ferrari, it will cost you. The solution is really nice, so it costs the client, but in the long run, it is very good. If you buy a solution that costs a lot to maintain because it is not stable, and you are frequently asking for consultant support, it costs more."
"I haven't seen the numbers. I know it is not cheap, but I don't know what it is. I would rate it a six out of ten in terms of pricing. It is definitely more expensive than the other product, but it also provides more functionality, and it is modular too. So, we pay for the functionality we're actually going to use, and that's nice."
"CyberArk is good at what they do, and the price reflects that. You have to pay the price for the same."
"I do not have any opinions to add about the pricing of the product."
"The price could be better. I think it's a good price for the on-premises environment and the high availability for enterprises the solution provides."
"I believe that we paid 35,000 or 40,000 US dollars for it."
"My rating for the IBM Security Secret Server pricing is seven out of ten. It could be cheaper."
report
Use our free recommendation engine to learn which Privileged Access Management (PAM) solutions are best for your needs.
895,151 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Manufacturing Company
10%
Computer Software Company
7%
Comms Service Provider
6%
Insurance Company
20%
Construction Company
11%
Computer Software Company
8%
Performing Arts
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business59
Midsize Enterprise42
Large Enterprise174
By reviewers
Company SizeCount
Small Business4
Midsize Enterprise2
Large Enterprise2
 

Questions from the Community

How does Sailpoint IdentityIQ compare with CyberArk PAM?
We evaluated Sailpoint IdentityIQ before ultimately choosing CyberArk. Sailpoint Identity Platform is a solution to manage risks in cloud enterprise environments. It automates and streamlines the m...
What do you like most about CyberArk Privileged Access Manager?
The most valuable features of the solution are control and analytics.
What is your experience regarding pricing and costs for CyberArk Privileged Access Manager?
My thoughts on the pricing of CyberArk Privileged Access Manager depend entirely on the vendors' requirements. If they want their things to be secure, they have to spend accordingly. We have four t...
What needs improvement with IBM Security Secret Server?
I believe there is not much that can be improved for IBM Security Secret Server. Providing local support and local vendor availability would be beneficial so we are not dependent on international s...
What is your primary use case for IBM Security Secret Server?
IBM Security Secret Server serves multiple use cases for us, including the monitoring of privileged users, as well as the recording and password vaulting of their accounts, passwords, and need-base...
What advice do you have for others considering IBM Security Secret Server?
I mention that password vaulting and password rotation in IBM Security Secret Server are basically the same thing, and it becomes somewhat complex when integrating a different system with them beca...
 

Also Known As

CyberArk Privileged Access Security, CyberArk Enterprise Password Vault
IBM Secret Server, Secret Server, IBM Security Privileged Identity Manager
 

Overview

 

Sample Customers

Rockwell Automation
Information Not Available
Find out what your peers are saying about CyberArk Privileged Access Manager vs. IBM Security Secret Server and other solutions. Updated: April 2026.
895,151 professionals have used our research since 2012.