Privileged Access Management (PAM) Selling to the CISO — 60-Min Training
PULSEKNOWLEDGE LIBRARY
Privileged Access Management sells to the CISO on audit defensibility, not vault features. Win by qualifying three buyers — CISO who funds, IAM architect who picks, cyber-insurance broker who enforces — then proving just-in-time elevation and session recording on the customer's real privileged inventory during a scoped proof of concept.
The two deployment philosophies you are actually selling between
Every Privileged Access Management conversation collapses into one of two architectural bets, and the seller who names the bet out loud in the first thirty minutes controls the rest of the cycle. The first is the vault-centric model: a hardened credential store holds every privileged secret, humans and machines check credentials out, and a proxy brokers the session. CyberArk built the category on this shape, BeyondTrust and Delinea compete inside it, and One Identity Safeguard and Wallix sell regional variants of the same idea. The second is the ephemeral-credential model: no long-lived secret exists to steal, an identity provider mints a short-lived credential at request time, and the credential dies when the task ends. HashiCorp Vault and Boundary, Britive, and Microsoft's Entra Privileged Identity Management for Azure roles all live here, and cloud-native infrastructure teams gravitate toward it because it fits the way they already ship software.
The distinction matters commercially because it changes who your champion is. Vault-centric deals champion out of the security operations and compliance side of the house — the people who get examined, who answer audit findings, who have to produce evidence when a regulator asks who touched the payments database at 2 a.m. Ephemeral-credential deals champion out of platform engineering — the people whose developers file tickets to get access and who measure their own success in how few tickets they field. If you build a business case aimed at the compliance officer and your champion is a platform engineer, the case will not survive the first budget review, because your champion cannot defend arguments they do not personally care about.
Most enterprises do not choose one philosophy. They run both, usually accidentally, and the accident is your wedge. The typical Fortune 1000 environment has a legacy vault deployed six to nine years ago covering Windows and Unix domain administration, plus a separate secrets-management install that the cloud team stood up without telling the identity team, plus native cloud role elevation used inconsistently across three cloud providers. Nobody owns the seam. Discovery that surfaces the seam — "who reconciles the accounts in your vault against the roles in your cloud tenants, and how often?" — usually produces a long silence, and that silence is the deal.

The third option nobody sells but everyone should qualify for is do-nothing-plus-process: the customer keeps standing privileges but tightens approval workflow in their ticketing system. It is cheap, it is genuinely better than nothing, and it fails the moment an auditor or an insurance underwriter asks for evidence that an approval was enforced rather than merely requested. Naming this option honestly in discovery buys you credibility, and it sets up the only comparison that matters later: your platform versus their status quo, priced against what the status quo costs them in examination findings, insurance premium loading, and engineer hours burned on access tickets.
Training note for the 60-minute session: spend the first eight minutes here and nowhere else. Put the two architectures on the whiteboard as two columns, have every rep in the room write the names of their three largest open opportunities under whichever column that account's champion lives in, and then ask which of them have built a business case aimed at the wrong column. In most rooms, roughly a third of the pipeline is misaimed, and the exercise pays for the hour on its own.
How to decide which motion a given account needs
The decision is not about which product is better. It is about which failure the customer is currently being punished for, because that failure is the only thing with budget attached. There are four common punishment patterns and each routes to a different sales motion.

The first is examination pressure. A bank, insurer, healthcare system, or public utility has taken a finding — an internal audit exception, a regulator's information request, a failed control test. The finding is usually specific and boring: privileged sessions on tier-one systems are not recorded, or shared administrator accounts exist without individual attribution, or service account passwords have not rotated in years. This account buys on evidence production. Your demo needs to end with the CISO holding a session recording with a timestamped annotation trail and an exportable attestation report. Time to close is often fast — sixty to ninety days — because the finding has a remediation deadline attached.
The second is insurance pressure. The cyber-insurance market has tightened materially since 2021, and multi-factor authentication on privileged accounts plus some form of privileged access control now appear routinely on underwriting questionnaires and renewal applications from major carriers and specialty markets. The customer is not shopping for security. They are shopping for a "yes" on a renewal application, and their broker is functionally a third buyer in the room. Your motion here is to get the broker on a call, ask what the underwriter's questionnaire actually says, and build a deployment scope that answers those specific questions rather than a full enterprise rollout. Scope small, close fast, expand at renewal.

The third is breach or near-breach pressure. Someone got in, or a red team got in, and the post-incident report named privileged credential abuse as the path. This account has emotional budget and a short attention span. Move fast, scope to the attack path described in the report, and do not try to sell the platform vision in month one — you will get the vision meeting in month nine when the fear has cooled and the champion needs a story for the board.
The fourth is engineering friction. No finding, no incident, no insurance deadline. Developers wait days for production access and the platform team is tired of it. This is a real deal but a slow one, priced against engineering time saved rather than risk avoided, and it usually needs a CISO co-sign it will not get unless you translate the friction story into an audit story. The translation is straightforward: standing access granted to make developers productive is standing access an attacker inherits, and every hour of unnecessary standing privilege is exposure the CISO will eventually have to explain.
Run this as a live exercise in the training. Give the room four short account descriptions, have them route each one, and then ask what the first email after the routing decision says. Reps who can route correctly but cannot write the routing-specific first email have learned a framework, not a behavior.

The numbers that hold up under CISO scrutiny
The single fastest way to lose credibility with a security executive is to quote a vendor-marketing statistic they have already seen dismantled. CISOs read the same reports you do and they are professionally skeptical for a living. So the discipline in this training is: bring the customer's own numbers, not the industry's.
Start with inventory math, because every PAM deal is ultimately priced off a count. Ask for four counts and expect the customer not to have them: human administrator accounts, service accounts, machine or workload identities, and third-party or vendor accounts with privileged reach. In most enterprises the service and machine counts exceed the human count by a wide margin, often by an order of magnitude in cloud-heavy estates, and the customer's mental model is anchored on the human number. When you surface that gap in discovery, two things happen. The commercial conversation gets larger, because most modern pricing keys off identities rather than human seats. And the risk conversation gets sharper, because the accounts nobody counted are the accounts nobody rotated.
Second, get baseline percentages rather than absolute numbers, because percentages survive the customer's own data-quality problems. What share of administrative sessions today are elevated just-in-time rather than run from standing entitlement? What share of privileged sessions on tier-one systems are recorded end to end? What share of privileged accounts carry phishing-resistant multi-factor authentication rather than push-based or one-time-code factors that adversaries have demonstrably bypassed at scale? What share of service accounts have rotated in the last ninety days? Write the four numbers on the call, read them back, and send them in the recap email. Those four numbers become the proof-of-concept scorecard, the business case, and eighteen months later the renewal narrative. They are the most valuable artifact you produce in the entire cycle.

Third, be honest about pricing shape rather than precise about pricing numbers you cannot verify. Published enterprise list pricing in this category is sparse and changes; quoting a per-user figure you read once and cannot source is how a rep gets caught. What is safe and useful to teach is the structure. Vault-centric enterprise agreements typically price per managed identity or per managed account, with separate line items for session management, secrets management, and endpoint privilege management modules — which is why the "one number" the customer remembers from the incumbent is almost never the number on the renewal invoice. Ephemeral-credential platforms more often price per workload, per cluster, or on a consumption basis tied to credential issuance, which is cheaper at small scale and can surprise the customer at scale. Cloud-native privileged identity features are frequently bundled into premium identity licensing the customer may already own, which is both a threat to your deal and, when you raise it first, a large credibility deposit.
Fourth, the cost the customer never counts: extraction friction. A vault deployment that has been running six years has custom connectors, scripts, break-glass procedures, and an operational muscle memory that a replacement has to reproduce. Budget realistically for it out loud — migration of accounts, re-onboarding of connectors, parallel run time, retraining of the operations team — because if you understate it and the customer discovers it in month two of the deployment, you have converted a reference into a detractor. Sellers who name migration cost honestly in the proposal win more multi-year agreements than sellers who hide it, because security buyers have been burned by rip-and-replace promises before and they are pattern-matching for the vendor who tells them the hard part.
Fifth, the discount structure. Multi-year commitments in this category carry real discount authority, and the trade you want in exchange for depth of discount is not just term length — it is reference rights, a joint case study, and named participation in your customer advisory board. Those have marketing value that justifies a deeper number internally, and they are much easier for a CISO to approve than a price concession that has to be explained to their own finance team as a favor. Structure it explicitly: incremental discount tied to a case study at a stated month, contingent on the customer hitting the adoption thresholds you both agreed to. Now your discount and their success are the same clause.

Running the proof of concept and the deployment sequence
The proof of concept is where most Privileged Access Management deals are actually decided, and it is where the least sales discipline is typically applied. Three failure modes recur.
Sandbox-only proofs. The vendor deploys into an isolated environment with synthetic accounts, everything works beautifully, and the customer learns nothing about their own estate. Ban it. The proof has to ingest a real slice of the privileged inventory — messy, duplicated, badly named, full of orphaned service accounts nobody will claim. The mess is the point. When the discovery scan surfaces two hundred accounts the identity team did not know existed, the deal stops being a product evaluation and becomes a remediation project with a deadline.
Human-accounts-only proofs. The team scopes to Windows domain administrators because that is easy to demonstrate, and never touches service accounts, CI/CD pipeline secrets, or cloud workload identities. Then the customer deploys, discovers half their privileged surface was out of scope, and the expansion conversation turns into a re-evaluation. Scope all three account classes — human, service, machine — into the proof even if the volume in each is small.

Unbounded proofs. Thirty days becomes sixty becomes a quarter, the champion changes jobs, and the deal evaporates without ever losing. Set an end date and a decision date in writing at kickoff and name the specific person who signs off on each success criterion.
The sequence that works looks like this. Before day one, run an inventory workshop — a working session, not a demo — where the identity architect exports what they have and you help them see what is missing. Customers routinely tell sellers afterward that this workshop alone was worth the engagement, which is exactly the position you want to be in during pricing. At kickoff, the customer's own platform team installs the connectors with your solutions engineer advising rather than driving; if your engineer does the install, you have proven nothing about whether their team can operate it. In the first week, demonstrate the full just-in-time cycle live on their environment: a real engineer requests elevation for a real task, an approver approves, the credential is minted, the session is recorded, and the entitlement disappears on completion. The moment the CISO watches a standing privilege get deleted and the work still get done is the moment the deal turns.
At the midpoint, run a scorecard call against the four baseline percentages from discovery and tune anything that is off-target before the customer complains. In the final week, put the recorded session in front of the CISO with annotations, produce the attestation export, and hold a joint call with the economic buyer where the pricing proposal lands the same day rather than a week later while momentum decays.

Deployment sequencing after signature follows the same risk logic. Tier-one crown-jewel systems first — the ones named in the audit finding or the insurance questionnaire — because that is what the budget was justified against. Service accounts and secrets consolidation second, since it is the largest hidden surface and the one that generates the most operational surprises. Cloud workload identity third. Third-party and vendor access last, because it requires contract changes with those third parties and will move at their pace, not yours.
The renewal is set here, not in month twelve. Three commitments belong in the kickoff document: a coverage target on tier-one session recording with a date, a phishing-resistant multi-factor target on privileged accounts with a date, and a standing monthly fifteen-minute scorecard call attended by both the CISO and the economic buyer. Accounts that hold that call renew. Accounts that let it lapse into a quarterly slide review are the accounts where a competitor's discovery call lands unopposed in month fifteen.

Coaching the room: what to drill in the last fifteen minutes
A 60-minute training that ends with a summary slide changes nothing. Spend the final block on reps talking, not you talking.
Drill one, the inventory question. Two minutes per pair. One rep plays a CISO who does not have the numbers and is mildly embarrassed about it. The seller's job is to ask for the four counts without making the buyer feel audited — the reframe is that nobody has these numbers, that the absence is the industry norm rather than a personal failing, and that producing them is the first joint deliverable. Reps who make the buyer defensive here lose the account.
Drill two, the incumbent question. The buyer says they already have a vault and it is fine. The wrong answer is feature comparison. The right answer is a question about the seam: what covers the cloud accounts, what covers the service accounts, who reconciles the two inventories, and when was the last time that reconciliation ran. You are not displacing the vault in this sentence — you are sizing the surface it does not cover, which is a much easier first sale and a much better second one.

Drill three, the bundled-alternative question. The buyer says their identity vendor includes privileged identity features in a license they already own. Do not dismiss it. Acknowledge that it genuinely covers cloud role elevation well, then ask what it does for on-premises domain administration, for service account credential rotation, for session recording on network devices and databases, and for evidence export in the format their auditor asks for. Precision here reads as expertise; dismissal reads as commission breath.
Drill four, the procurement single-thread. Procurement asks for a call without the CISO. The behavior to install is a polite refusal with a reason the buyer respects: pricing in this category depends on the identity counts and the deployment scope, and changing either without the architect in the room produces a number that will be wrong for both sides. Offer the joint call in the same breath so the refusal lands as diligence rather than obstruction.
Close the session by assigning one action per rep: the single account in their pipeline where they will get the four baseline percentages on record within seven days, sent to the manager by end of day. The training converts when the recap email goes out, not when the hour ends.
Related questions
How long should a PAM proof of concept run?
Long enough to cover human, service, and machine accounts on real inventory — commonly six to twelve weeks for a tier-one enterprise — with a written end date and a named decision-maker per success criterion. Open-ended proofs decay when the champion changes roles.
Who is the real economic buyer in a PAM deal?
The CISO usually holds the budget line, but the renewal veto often sits with a peer executive — CIO, CFO, or chief risk officer — who was not in the original evaluation. Get that person into the month-six scorecard call, not the month-eighteen renewal call.
Should we sell against the customer's bundled identity-provider features?
No. Concede where the bundled features are genuinely strong, usually cloud role elevation, and size the surface they do not cover: on-premises domain administration, service account rotation, session recording on databases and network devices, and auditor-format evidence export.
What does the cyber-insurance broker actually change in the cycle?
The broker converts a security preference into a renewal deadline. Ask for the underwriter's questionnaire, scope your deployment to the specific controls it names, and you get a smaller, faster first deal with a natural expansion path at the next policy renewal.
How do we handle a customer mid-contract with an incumbent vault?
Deploy where the incumbent is not — typically cloud workload identities and secrets in CI/CD pipelines — rather than forcing an early termination. Eighteen months of coverage data on that adjacent surface is the evidence base for the displacement conversation at their renewal.
FAQ
Should the training lead with privileged access or with secrets management?
Lead with whichever the champion owns. Security and compliance champions respond to privileged session control and evidence production; platform engineering champions respond to secrets consolidation and eliminating long-lived credentials in code. The two converge in the technical evaluation regardless of entry point, so the entry point should be chosen for champion fit, not product logic.
What is the most common reason a PAM deal stalls after a successful proof of concept?
Migration cost the seller never named. The customer builds an internal case on the platform price, then discovers connector rebuilds, parallel-run time, and operations retraining, and the project loses its sponsor. Put migration effort in the proposal explicitly. Naming the hard part is a credibility deposit that pays at signature.
How do we get real privileged inventory before the proof of concept starts?
Run an inventory workshop as a separate, scheduled working session rather than a prerequisite email. Most identity teams cannot export a complete inventory because no complete inventory exists. Helping them build one is a service they value and it converts you from vendor to advisor before pricing is ever discussed.
Is session recording still a differentiator when most vendors offer it?
Recording is table stakes; usable evidence is not. The differentiator is the export path — can the CISO hand an examiner a timestamped, searchable, attributable record in the format that examiner asks for, without an engineer building a report. Demo the export, not the recording.
How should reps respond when a CISO says the budget belongs to next fiscal year?
Do not discount into the current year. Use the interval to run the inventory workshop and lock the four baseline percentages so the business case is built on the customer's own data before budget season. Deals built on the customer's numbers survive budget review; deals built on vendor benchmarks do not.
What single metric best predicts whether a PAM account renews?
Whether the monthly joint scorecard call with the CISO and the economic buyer is still happening at month twelve. Coverage numbers matter, but a live scorecard cadence is what keeps a competitor's discovery call from landing unopposed during the renewal window.
Sources
- https://www.nist.gov/privacy-framework/nist-sp-800-53
- https://csrc.nist.gov/pubs/sp/800/207/final
- https://www.cisa.gov/zero-trust-maturity-model
- https://attack.mitre.org/tactics/TA0004/
- https://owasp.org/www-project-top-ten/
- https://www.cisecurity.org/controls/cis-controls-list
- https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-configure
- https://developer.hashicorp.com/vault/docs/what-is-vault
- https://cloud.google.com/iam/docs/workload-identity-federation
- https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html
Related on PULSE
- [ZTNA (Zero Trust Network Access) Selling to the Network Architect — 60-Min Training](/knowledge/st387)
- [Mobile Threat Defense (MTD) Selling to the CISO and Endpoint Management Lead — 60-Min Training](/knowledge/st403)
- [Cloud Security Posture Management (CSPM) Selling to the Cloud Architect — 60-Min Training](/knowledge/st391)
- [The Executive Access Workshop — 60-Min Training](/knowledge/st0079)
- [Top 10 executive access role-play scenarios for sales teams](/knowledge/st0558)
- [Top 10 executive access training drills for B2B sales reps](/knowledge/st0557)
This page will be disappearing soon. Save it to your device for $1 — or read it free while it is here.
@Kory-White- · if Venmo asks, the last 4 of my number are 2012









