Promotions

Privileged Access Management (PAM): How to Choose a Solution and Where to Buy It — Softprom, Value-Added IT Distributor

Promotions | 22.09.2026

Privileged Access Management (PAM) is a category of cybersecurity solutions that controls who receives administrative access to critical systems and when, what happens during the session, and whether an auditable record remains afterwards. PAM keeps privileged passwords and keys in a vault, grants access for the duration of a task, records the sessions of administrators and external contractors, and rotates passwords automatically.

Softprom is a value-added IT distributor operating since 1999, headquartered in Vienna and covering Central and Eastern Europe, the Caucasus, and Central Asia: 33 countries, 14 regional offices, 120+ vendors, and — in cybersecurity — 90+ vendors and 30+ certified engineers. In the Privileged Access Management (PAM) category Softprom supplies Segura and Syteca — both featured in the KuppingerCole Leadership Compass: Privileged Access Management 2026 —, runs demonstrations and pilot projects with its own engineers, and works through partners: resellers, systems integrators and MSPs.

Three Situations Where the PAM Conversation Usually Starts

"Three contractors hold admin passwords to our ERP, and nobody knows whether they were changed after one of them left last year."

"The auditor asked to see who accessed the server with customer data over the past six months. We showed him a login and a password that six people know."

"We're not against PAM. We're against a nine-month project and a renewal that gets a third more expensive every year."

If one of these lines describes your Tuesday, the rest of this page will be useful.

Privileged Access Management (PAM) Is Neither IAM Nor a Password Manager

Question Password manager / IAM / PAM

Who it is for

Password manager: all employees
IAM / SSO: all employees
PAM: administrators, service accounts, external contractors

What it controls

Password manager: storage of passwords
IAM / SSO: who someone is and where they may log in
PAM: what is actually done with elevated rights — and whether there is evidence

Session recording

Password manager: no
IAM / SSO: no
PAM: yes, searchable by action

Time-limited access (just-in-time)

Password manager: no
IAM / SSO: partially
PAM: yes

Automatic rotation of admin passwords

Password manager: no
IAM / SSO: no
PAM: yes

Rule of thumb: IAM answers "who is this?"; PAM answers "what did they do — and were they allowed to do it right now?". Both are needed; one does not replace the other.

Who Supplies Privileged Access Management (PAM) — the Softprom Portfolio

Solutions available through Softprom's partner network of resellers and systems integrators:

Vendor / Best for Key advantage · Independent evaluation · Availability

Segura (360º Privilege Platform)
mid-sized and large organisations, public sector, financial services; scenarios with external contractors

Full platform: vault, sessions, just-in-time, certificates, DevOps secrets in one product; on-premises or cloud.
KuppingerCole Leadership Compass: Privileged Access Management, 2026 · Available via Softprom in 25 countries — see the vendor page

Syteca (formerly Ekran System; PAM Platform, Privileged User Monitoring, Password Management)
mid-market organisations starting with session control and MFA; companies that need GDPR-compliant monitoring (pseudonymisation)

Fast start, session recording and privileged user monitoring at the core, licensing that mid-sized companies can understand.
KuppingerCole Leadership Compass: Privileged Access Management, 2026 · Available via Softprom in 20 countries — see the vendor page

What Softprom does as a distributor — beyond supplying licences: pre-sales consulting before the vendor decision, demonstration and pilot project with its own engineers, project registration for the partner, contract and invoice from Softprom Distribution GmbH (Vienna).

Seven Criteria to Check Before You Decide

  1. Licensing model. Per user, per target system or per session? For a company with 20 administrators and 400 servers the budget differs by a multiple. Calculate both scenarios over a three-year horizon, renewal included.
  2. Where the secrets live. On-premises, a private cloud in the EU, or the vendor's SaaS. For the public sector and regulated industries this is often the first procurement question, not the last.
  3. External contractors. Can a contractor get access to exactly one system for exactly two hours — without a password handover, with the session recorded? This is the most common real-world scenario that starts an implementation.
  4. Audit-grade session recording. Not "there is a video", but search by command and action, immutability of the recording, export for the auditor.
  5. Time to first value. How many weeks until the first ten critical systems are under control? A project that only shows results after nine months usually stalls in month six.
  6. Integrations. MFA, directory (AD/Entra ID), SIEM, ticketing system for access approvals. Without a SIEM integration, nobody watches the session recordings.
  7. Regulatory context — as a checklist item, not the project goal. Control of privileged access and MFA are part of the risk-management measures under NIS2 and of Annex A of ISO 27001. PAM covers these points technically; the legal assessment of your obligations is made by your legal counsel or auditor, not by the supplier.

Who This Page Is For — and What Happens Next

For partners: resellers, systems integrators, MSPs

  • Project registration to your company before the first customer meeting.
  • NFR licences and a demo environment for your own lab (Segura and Syteca).
  • A Softprom pre-sales engineer in the customer meeting and in the pilot.
  • No minimum turnover to get started.

For end customers: CISOs, IT leadership, infrastructure owners

  • Privileged Access Management (PAM) pilot from two weeks: up to five target systems, one external-contractor access scenario, session recording and review, a report with a licensing-model recommendation. The scope is agreed with a Softprom pre-sales engineer.
  • A three-year licensing comparison based on your number of administrators and systems.
  • Implementation through a certified partner in your country.

Frequently Asked Questions

A "safe with a video camera" for administrative access: passwords and keys sit in a vault, access is granted for the duration of a task, every session is recorded, and passwords are changed automatically after use.

IAM manages identities and the login of all users. PAM controls the small but most dangerous group — administrators, service accounts and contractors — and adds session recording, time-limited access and password rotation.

Through a Softprom partner — a reseller or systems integrator in your country. As a value-added distributor, Softprom provides pre-sales consulting, a demo and a pilot; the partner handles implementation and support. Write to us — we will match you with a partner and assign an engineer.

A pilot on the first critical systems takes from two weeks. A full rollout in a mid-sized organisation ranges from several weeks to several months depending on the number of systems and scenarios; the fifth selection criterion helps rule out solutions whose first value is months away.

If there is at least one external contractor with admin access, or an auditor asks who accessed a system — yes. Company size matters less than the number of privileged accounts and the systems they lead to.

Control of privileged access, MFA and logging are requirements of both. PAM is the technical means to meet them; whether and to what extent your company is in scope is assessed by your legal counsel or auditor.