Privileged Access Management (PAM): How to Choose a Solution and Where to Buy It — Softprom, Value-Added IT Distributor
Promotions | 22.09.2026
Privileged Access Management (PAM) is a category of cybersecurity solutions that controls who receives administrative access to critical systems and when, what happens during the session, and whether an auditable record remains afterwards. PAM keeps privileged passwords and keys in a vault, grants access for the duration of a task, records the sessions of administrators and external contractors, and rotates passwords automatically.
Softprom is a value-added IT distributor operating since 1999, headquartered in Vienna and covering Central and Eastern Europe, the Caucasus, and Central Asia: 33 countries, 14 regional offices, 120+ vendors, and — in cybersecurity — 90+ vendors and 30+ certified engineers. In the Privileged Access Management (PAM) category Softprom supplies Segura and Syteca — both featured in the KuppingerCole Leadership Compass: Privileged Access Management 2026 —, runs demonstrations and pilot projects with its own engineers, and works through partners: resellers, systems integrators and MSPs.
Three Situations Where the PAM Conversation Usually Starts
"Three contractors hold admin passwords to our ERP, and nobody knows whether they were changed after one of them left last year."
"The auditor asked to see who accessed the server with customer data over the past six months. We showed him a login and a password that six people know."
"We're not against PAM. We're against a nine-month project and a renewal that gets a third more expensive every year."
If one of these lines describes your Tuesday, the rest of this page will be useful.
Privileged Access Management (PAM) Is Neither IAM Nor a Password Manager
| Question | Password manager / IAM / PAM |
|---|---|
|
Who it is for |
Password manager: all employees |
|
What it controls |
Password manager: storage of passwords |
|
Session recording |
Password manager: no |
|
Time-limited access (just-in-time) |
Password manager: no |
|
Automatic rotation of admin passwords |
Password manager: no |
Rule of thumb: IAM answers "who is this?"; PAM answers "what did they do — and were they allowed to do it right now?". Both are needed; one does not replace the other.
Who Supplies Privileged Access Management (PAM) — the Softprom Portfolio
Solutions available through Softprom's partner network of resellers and systems integrators:
| Vendor / Best for | Key advantage · Independent evaluation · Availability |
|---|---|
|
Segura (360º Privilege Platform) |
Full platform: vault, sessions, just-in-time, certificates, DevOps secrets in one product; on-premises or cloud. |
|
Syteca (formerly Ekran System; PAM Platform, Privileged User Monitoring, Password Management) |
Fast start, session recording and privileged user monitoring at the core, licensing that mid-sized companies can understand. |
What Softprom does as a distributor — beyond supplying licences: pre-sales consulting before the vendor decision, demonstration and pilot project with its own engineers, project registration for the partner, contract and invoice from Softprom Distribution GmbH (Vienna).
Seven Criteria to Check Before You Decide
- Licensing model. Per user, per target system or per session? For a company with 20 administrators and 400 servers the budget differs by a multiple. Calculate both scenarios over a three-year horizon, renewal included.
- Where the secrets live. On-premises, a private cloud in the EU, or the vendor's SaaS. For the public sector and regulated industries this is often the first procurement question, not the last.
- External contractors. Can a contractor get access to exactly one system for exactly two hours — without a password handover, with the session recorded? This is the most common real-world scenario that starts an implementation.
- Audit-grade session recording. Not "there is a video", but search by command and action, immutability of the recording, export for the auditor.
- Time to first value. How many weeks until the first ten critical systems are under control? A project that only shows results after nine months usually stalls in month six.
- Integrations. MFA, directory (AD/Entra ID), SIEM, ticketing system for access approvals. Without a SIEM integration, nobody watches the session recordings.
- Regulatory context — as a checklist item, not the project goal. Control of privileged access and MFA are part of the risk-management measures under NIS2 and of Annex A of ISO 27001. PAM covers these points technically; the legal assessment of your obligations is made by your legal counsel or auditor, not by the supplier.
Who This Page Is For — and What Happens Next
For partners: resellers, systems integrators, MSPs
- Project registration to your company before the first customer meeting.
- NFR licences and a demo environment for your own lab (Segura and Syteca).
- A Softprom pre-sales engineer in the customer meeting and in the pilot.
- No minimum turnover to get started.
For end customers: CISOs, IT leadership, infrastructure owners
- Privileged Access Management (PAM) pilot from two weeks: up to five target systems, one external-contractor access scenario, session recording and review, a report with a licensing-model recommendation. The scope is agreed with a Softprom pre-sales engineer.
- A three-year licensing comparison based on your number of administrators and systems.
- Implementation through a certified partner in your country.
Frequently Asked Questions
A "safe with a video camera" for administrative access: passwords and keys sit in a vault, access is granted for the duration of a task, every session is recorded, and passwords are changed automatically after use.
IAM manages identities and the login of all users. PAM controls the small but most dangerous group — administrators, service accounts and contractors — and adds session recording, time-limited access and password rotation.
Through a Softprom partner — a reseller or systems integrator in your country. As a value-added distributor, Softprom provides pre-sales consulting, a demo and a pilot; the partner handles implementation and support. Write to us — we will match you with a partner and assign an engineer.
A pilot on the first critical systems takes from two weeks. A full rollout in a mid-sized organisation ranges from several weeks to several months depending on the number of systems and scenarios; the fifth selection criterion helps rule out solutions whose first value is months away.
If there is at least one external contractor with admin access, or an auditor asks who accessed a system — yes. Company size matters less than the number of privileged accounts and the systems they lead to.
Control of privileged access, MFA and logging are requirements of both. PAM is the technical means to meet them; whether and to what extent your company is in scope is assessed by your legal counsel or auditor.
Tell us in two sentences how many administrators and systems you have and whether external contractors hold access — we will propose a pilot format and a partner in your country. Or book a conversation with an engineer directly: Request a consultation.