Customer Success Story | Automotive Industry

From Legacy PAM to Full Control: How a Global Automotive Leader Transformed Privileged Access

How Segura® led a global automotive manufacturer’s migration of 200,000+ privileged credentials from CyberArk on-premises to the Segura® PAM platform in 90 days, without disrupting production or business operations.

Industry

Automotive Manufacturing

Region

Global (Headquartered in Europe)

Solutions

PAM Migration, Cloud Entitlements, Cloud IAM, Workforce Password Management

Products

Segura® PAM, CIEM, Cloud IAM, MySafe

Executive Summary

A global automotive manufacturer needed a more reliable way to manage privileged access across complex, large-scale environments.

After seven years on CyberArk, fragmented access made consistent control difficult across critical systems.

Using the Segura® PAM platform, the organization brought privileged access under a centralized control model while maintaining continuity across global operations.

Before

Privileged access was fragmented across thousands of systems, making it difficult to maintain consistent visibility and control at scale.

After

A centralized SaaS PAM platform with clear control, consistent governance, and uninterrupted operations across global engineering and production systems.

Impact

200,000+ credentials migrated in 90 days
93% fewer access structures
(20,000 → 1,500)

The Situation

One of the world’s most recognized German automotive manufacturers, with €145.6 billion in revenue and 175,000 employees globally, needed to modernize privileged access across global engineering, manufacturing, and digital systems.

After seven years on CyberArk on-premises PAM, growing infrastructure and access across thousands of systems made it harder to maintain consistent visibility and control in an environment where disruption was not an option.

The Challenge

The migration involved a highly complex global environment with strict continuity requirements:

• 13,500+ privileged users

• 200,000+ credentials

• 20,000+ safes

• 95+ on-premises appliances

The SecOps team needed to complete the migration without disrupting critical systems, impacting compliance, or exposing sensitive engineering and production environments.

The Solution

A phased migration strategy was designed to maintain stability across a highly complex global environment.

Segura®’s approach:

• Centralize privileged access into a unified SaaS control model

• Replace 95+ on-premises appliances without disrupting operations

• Execute a large-scale, complex migration alongside internal teams

• Maintain continuity across critical engineering and production systems

The Results

The organization successfully migrated in 90 days a highly complex PAM environment, bringing privileged access under clearer control and making governance consistent and predictable at scale.

“ It was the best decision. The migration was very smooth, with a good migration plan”

- (IT Manager)

200,000+

Credentials migrated successfully, protecting all of the company's critical intellectual property and digital assets.

90 days

Full migration completed without disruption to critical systems

93%

Fewer privileged access structures (20,000 safes → 1,500 policies)

Read the Full Story

A Global Identity Environment Under Constant Pressure

One of the world’s most recognized German automotive manufacturers designs, builds, and supports vehicles on a global scale, with engineering teams, production facilities, and digital services operating across continents.

Behind that work is a vast and interconnected technology environment. Systems support everything from proprietary R&D and vehicle design to manufacturing lines and digital services used around the world. These systems must remain available, secure, and tightly controlled at all times.

With more than €145 billion in annual revenue and approximately 175,000 employees, the organization operates at a scale where even small disruptions can have real operational impact.

Privileged Access Complexity Growing Across Systems

After more than seven years using CyberArk on-premises PAM, security leadership began reassessing how privileged access could keep up with growing hybrid and cloud environments.

As the environment expanded, privileged access spread across thousands of applications, platforms, and teams. Maintaining consistent visibility and control required increasing effort from security teams already responsible for protecting highly sensitive intellectual property.

The team needed an identity model that could keep up with this growth without adding more pressure to day-to-day operations.

During the evaluation process, Segura® stood out through Gartner Peer Insights feedback from teams managing similar levels of complexity. The platform aligned with both the technical requirements and the need for a more manageable, long-term approach to access control.

When Legacy PAM Starts Working Against You

Over time, the PAM environment became harder to manage at scale.

More than 95 on-premises appliances supported privileged access workflows. Over 20,000 safes defined how access was structured across systems. Keeping everything aligned required constant coordination across regions and teams.

Security teams were responsible for protecting proprietary engineering data, production environments, and operational systems that could not afford downtime.

Every change required careful planning. Every migration step introduced risk.

The team needed to reduce infrastructure complexity while maintaining continuous protection of critical systems. They needed better visibility across privileged activity without slowing down the business. And they needed a partner who understood what was at stake.

Structured Migration from On-Prem PAM to SaaS

Segura® designed a phased migration strategy built to protect operational continuity from day one.

The goal was clear: consolidate privileged access into a centralized SaaS platform while global engineering and production systems continued running as expected.

Access governance was brought together across infrastructure, cloud entitlements, identity policies, and workforce credentials. For the first time, teams had a clear, unified view of both human and machine identities.

Segura® worked closely with internal teams throughout the project, providing hands-on support and making sure knowledge was transferred along the way. The focus was not just on completing the migration, but on making sure the team felt confident running the environment afterward.

The transition was completed within the required timeline, with critical systems continuing to operate without interruption.

“Skilled team delivers fast support and efficient resource access management”

- (IT Associate)

Improved Adoption and Visibility Across Privileged Access Management

Following migration, privileged session usage increased from approximately 400 sessions to 600 sessions, showing broader adoption across teams managing privileged access.

With fewer fragmented structures in place, permissions became easier to manage and more consistent across environments. Teams spent less time maintaining infrastructure and more time maintaining control.

Security teams gained clearer visibility into privileged activity and reduced the time and effort required to manage access across environments. As the environment became easier to operate, usage naturally increased.

“Segura® is an agile and scalable 360° platform that comprehensively meets PAM requirements, delivered quickly and seamlessly by a dedicated team.”

- (IT Manager)

Identity Governance Built to Support Long-Term Innovation

More than 200,000 credentials were consolidated into a centralized governance model designed to support continued growth across hybrid and cloud environments.

Privileged access structures were reduced from more than 20,000 safes to approximately 1,500 policies, making access easier to manage and far more consistent across the organization.

“I never expected such good performance. It was the best decision. The migration was very smooth, with a good migration plan. Fixes were made very quickly.”

- (IT Manager)

Today, the organization operates on a modern identity platform capable of supporting evolving digital services, complex engineering environments, and future innovation.

This project shows what can happen when identity security is treated as a shared responsibility, not just another deployment. What was once fragmented is now structured. What required constant coordination is now controlled and predictable.

Their environment is easier to manage, with clearer control over privileged access and stronger consistency across systems.

Explore more from Segura®

Segura® is the only PAM solution on the market that covers the entire privileged access lifecycle. Explore our suite of advanced security solutions:

Feature icon
Segura® DevOps Secrets Manager

A secure and efficient way for tools and applications to request confidential information such as secrets, credentials, and other sensitive data used throughout the DevOps lifecycle.

Product Tour ›
Feature icon
Segura® Endpoint Manager

Manage and monitor privileged sessions on workstations, ensuring secure access control, auditing, and compliance with IT security policies and regulations.

Product Tour ›
Feature icon
Segura® Certificate Manager

Centralize, manage, and automate the lifecycle of digital certificates, ensuring compliance and reducing operational risks.

Product Tour ›

Request a Demo or Meeting

Discover the power of Identity Security and see how it can enhance your organization's security and cyber resilience.

Schedule a demo or a meeting with our experts today.

  • icon

    70% lower Total Cost of Ownership (TCO) compared to competitors.

  • icon

    90% faster Time to Value (TTV) with a quick 7-minute deployment.

  • icon

    The Only PAM solution available on the market that covers the entire privileged access lifecycle.