Trasforma gli insight in azioni: Bitwarden Access Intelligence è ora disponibile Scopri di più >

Risorse Bitwarden

The problem with PAM: Why organizations are skipping this essential solution

84% of IT and security professionals agree: Securing privileged access management is important, but most report having no PAM solution in place

Bitwarden Privileged Access Management (PAM) report

Executive summary

Privileged accounts grant elevated access to IT and business environments, which makes them a primary target for threat actors. If compromised, these accounts can give attackers broad control over critical systems, enabling them to bypass the usual security protocols, move laterally throughout an organization, and grant themselves elevated access and privileges.

Privileged access management (PAM) solutions help organizations secure the accounts with elevated privileges that attackers most often target and are most catastrophic if breached. These include the accounts of human users, like IT admins, as well as accounts used by network, database, and other IT components. 

PAM solutions are increasingly critical for organization security. Palo Alto Networks Unit 42 found that preventable security gaps, including excessive privileges and inconsistently applied controls contributed to more than 90% of breaches. IBM reports the average cost of a data breach in the United States reached a record of $11.5 million in 2026. Yet most IT, security, and DevOps professionals surveyed by Bitwarden report that their organizations lack a PAM solution. For many of them, cost is a major barrier to PAM adoption.

Among respondents with PAM in place, most have implemented it because it was bundled with an existing package or software license — Microsoft more often than any other vendor. And even among respondents who have a PAM solution, cost remains a top concern. 

Compliance is a major driver for PAM adoption, and 71% of respondents are hoping for a PAM solution with compliance-ready audit logs. Many also seek credential rotation support and the ability to restrict access based on IP address or time of day. 

The survey’s findings point to demand for PAM that is cost-effective, compliance-ready, and easy to implement.

Key findings

  • 84% of respondents agree that securing privileged account access is extremely or very important, but 55% of respondents have no PAM solution in place today.

  • 64% of respondents say that meeting compliance requirements is extremely important or very important, and the top factor impacting the decision to adopt PAM was compliance, cited by 65% of respondents.

  • 40% of respondents without PAM cite cost as a leading adoption barrier, 30% say management doesn’t see a need, and 20% cite the required IT resources.

  • The chief problem for those with a PAM solution is that it's too expensive.

  • 20% of respondents have experienced a security incident due to overprivileged access, while 11% are unsure whether one has occurred.

84 percent

84% say securing privileged account access is extremely or very important

55 percent

55% don't have a PAM solution in place today

64 percent

64% say that meeting compliance requirements is extremely important or very important

40 percent

40% report cost as leading adoption barrier to PAM

The PAM implementation gap

The biggest surprise of the survey is that the vast majority of respondents (84%) consider securing privileged access to be important, but more than half (55%) still have no PAM solution in place. 

What accounts for this gap between stated importance and implementation?

Cost looms large as the biggest barrier, with complexity and speed of deployment also registering as issues for survey respondents. Among those who don’t have a PAM solution, 40% say that it’s because it would be too expensive. Another 30% say that management doesn’t see a need, and 20% say it would require too many IT resources.

Why doesn’t your organization have a PAM solution in place today?

Too expensive

0%

Compliance requirements is not a priority

0%

Slow to deploy

0%

Difficult to manage at scale

0%

Require too many IT resources

0%

Too many features we don't need

0%

Credentials would be managed across multiple solutions (not centralized)

0%

Privileged access is not a priority

0%

Management and leadership does not see a need

0%

Other

0%

One respondent noted that their reluctance was due to “a combination of things, [including] integration compatibility and complexity.”

Another respondent said: "Keeping the trust perimeter in-house was critical. None of the services we tested met our requirements, like full auditing abilities, auto credential rotation, easy workflow requests in Slack, etc.”

Even among those who do have PAM in place, cost remains the top concern. One-fourth of respondents said that cost was the biggest problem with their PAM solution, while 16% responded that the solution was too complex, and another 16% said it was too slow to deploy across the organization. 

The adoption gap can carry real consequences. The survey also found that 20% of respondents reported experiencing a security incident tied to overprivileged access, while another 11% are unsure whether one had occurred. That means almost a third of respondents have either had a privileged access-related incident or don’t know if they have had one — a large percentage that speaks to the need for better management of privileged access across many organizations.  

Compliance needs drive PAM adoption

Compliance with national, international, and industry standards is the biggest reason for having implemented PAM, or for wanting to have it in place. 

Respondents cited GDPR, HIPAA, CMMC, ISO 27001, SOX, and other regulatory requirements as key standards their organization is held to, depending on which industries and regions they operate in. Each of these standards comes with a dizzying array of security requirements that the companies subject to them must implement, and compliance can make the difference between being able to operate in a market or being locked out entirely. 

So it’s no surprise that 64% of respondents say that meeting compliance requirements is extremely important or very important to their organizations.

In a separate question, we asked respondents about the leading factor influencing their PAM adoption decisions. For this question, 65% cited compliance requirements, followed by cybersecurity insurance (44%) and company growth needs (41%).

What factors would influence or have influenced your decision to adopt a PAM solution in your organization?

Compliance requirements

0%

Internal security incident

0%

Security incident in the news

0%

Leadership mandate

0%

Cybersecurity insurance

0%

Company growth

0%

Growing AI agent usage in organization

0%

Other

0%

At the same time, the last thing IT and security admins want is another headache to manage on top of the compliance challenges they already have, as we’ll see in the section on what companies are looking for. It’s important that adding PAM into the mix doesn’t increase the complexity of the IT landscape for an organization. 

Many organizations go with a bundled solution

Most respondents (55%) reported that their organizations did not have a PAM solution in place. For those already using one, most selected it because it was already included or bundled with another solution, or because it was offered by a trusted security vendor.

No single product captures a majority of the market among our respondents, but Microsoft was the most popular PAM vendor reported by those who do have one, with respondents citing Entra ID, Azure, Microsoft 365, or Microsoft Privileged Identity Management.

Does your organization currently use a PAM solution? If so, which one?

No PAM solution in place today

0%

Delinea

0%

BeyondTrust

0%

CrowdStrike

0%

ManageEngine

0%

Netwrix Privilege Secure

0%

Keeper PAM

0%

Microsoft (PIM, Entra, Azure or other)

0%

Other

0%

“It's already part of our key environment,” one respondent noted. Respondents recognized that going with an already-trusted vendor lowers the barriers to adoption by eliminating the need for a separate vendor qualification process.

What companies really want in PAM

The survey reveals that many organizations would be ready to jump on the PAM bandwagon — if the right solution existed. However, given the fact that managing compliance is already a complex undertaking, respondents made it clear that they want a simpler solution. 

The top features requested by respondents were support for privileged remote access and secrets management, with 61% and 57% (respectively) ranking these in their top three. That was followed by credential rotation (38%), access restrictions based on IP address or time of day (35%), and compliance-ready audit trails (33%).

Regardless of which features are at the top of an organization's PAM list, the majority of respondents (71%) said compliance-ready audit logs were very or extremely valuable, reflecting the high importance of meeting compliance standards noted earlier in this report. In addition, large majorities also found credential access rules (67%) and credential rotation (65%) extremely or very valuable.

Enterprises have the largest number of privileged accounts to secure: 51% of enterprise respondents have 21 or more such accounts to worry about, and a few (15%) report over 100 privileged accounts. Meanwhile, 67% of respondents in midmarket organizations have 20 or fewer privileged accounts to secure. 

Advice from the pros

When asked about advice they would give other companies who are considering purchasing and implementing a PAM solution, IT and security professionals agreed on some common themes: Prioritize ease of use and integrations in vendor selection, explore all available options, build support across departments, and take a phased approach to deployment across your organization.

“Pick a PAM platform that fits your existing identity workflows, and roll it out in small, low‑risk phases instead of trying to onboard everything at once,” one respondent noted, adding: “Make sure admins actually like using it, because usability, automation, and clean processes matter more to long‑term success than any single feature.”

Another survey respondent emphasized ease of use: “Keep the solution simple and user-friendly. A PAM solution delivers the most value when it improves security without creating friction for users or administrators.” This sentiment was echoed by others, like this respondent: “Simplicity is the key — making an interface that’s intuitive but comprehensive.”

IT system administrator

Keep the solution simple and user-friendly. A PAM solution delivers the most value when it improves security without creating friction for users or administrators.

Conclusion

This survey reveals a gap between IT and security teams’ stated beliefs and their actions. 84% of respondents agree that securing privileged access is important, yet 55% have no PAM solution in place — and the reason isn't indifference. Cost is the dominant barrier (cited by 40% of non-adopters), followed by unclear ROI at the management level (30%), and IT resource constraints (20%).

Even organizations that have adopted PAM still report challenges with their current solutions.  A quarter report cost as the biggest problem with their solution, and another third mention complexity or slow deployment. Procurement considerations also shape adoption: Most respondents with a solution selected one because it was included in a bundle or licensed it from an already-trusted vendor. These paths can minimize procurement friction by building on existing purchasing arrangements and vendor relationships, but they also mean the solution was chosen for convenience, not fit.

Compliance looms as the largest driver of PAM adoption. Almost two-thirds (65%) cite compliance as their leading adoption driver, and 71% say compliance-ready audit logs would be extremely or very valuable — the single highest-rated feature in the survey. Credential rotation and access controls based on IP address or time of day are also strong drivers of adoption. 

Taken together, the data points to a looming market need for a cost-effective PAM solution that is simultaneously compliance-ready, satisfies core PAM functionality, and is simple to deploy.

Bitwarden 

Bitwarden is a trusted security leader for millions of users worldwide, empowering enterprises, developers, and individuals to securely manage and share sensitive information anywhere. Bitwarden makes it easy for all users to extend robust security across their devices with password management, secrets management, and passwordless and passkey innovations. 

Methodology

Bitwarden surveyed 95 small, mid-market, and enterprise customers, including 77 in IT, 25 in security, 16 in engineering, 11 in DevOps, and 3 others. Respondents included managers, department heads, executives, and engineers. Their responses were received from July 28 to August 13, 2026.