In this blog post, we will explore how to strengthen the security of CyberArk by leveraging Hardware Security Modules (HSMs).
The CyberArk Privileged Access Security solution facilitates the management of privileged accounts for organizations and establishes a secure structure. It enables the protection, monitoring, detection of activities, and intervention in events of privileged accounts from a single center. It manages the passwords of many privileged accounts, including Unix, Linux, and Windows-based systems, databases, virtual systems, network devices, SaaS, websites, and social media, and records, isolates, and controls sessions through RDP and SSH Proxies.
At the core of the CyberArk Privileged Account Security solution is the CyberArk Digital Vault, which securely stores privileged account credentials, access control policies, identity management policies, and audit information. CyberArk keeps all sensitive information in the Digital Vault, which is the heart of the CyberArk solution. It prevents the malicious use of privileged user accounts and ensures the organization and protection of privileged accounts. The Digital Vault controls access to these accounts according to the privileged account security policy, determining who can access which passwords and when, thus automating the process and eliminating errors and security risks associated with manual management of privileged accounts, ensuring compliance with audit and compliance requirements.
As sensitive data is transmitted between systems, it may be exposed to attackers listening in on the network. To prevent attackers from capturing privileged account credentials from intercepted traffic, CyberArk ensures that all data entering and leaving the Digital Vault is encrypted during transit. To protect both the Digital Vault database itself and the data stored within it, a multi-layered encryption hierarchy using FIPS 140-2 compliant cryptographic algorithms is designed. Symmetric encryption is completed using a unique AES-256 key, and asymmetric encryption is completed using a unique RSA-2048 key pair. When this level of encryption is applied, attackers within the network can see traffic flowing between CyberArk components, but the traffic is undetectable and therefore unusable for attackers.
Cyberark uses two external key groups in encrypting stored sensitive data. At the top of this key hierarchy is the Server Key. Safe Keys are encrypted using the Server Key. Data stored on the Cyberark Vault server is meaningless without the Server Key because the Server Key is required to start the decryption process. Recovery Keys are used to recover data when the Digital Vault is not operational. This key should be used only in very rare failure situations. The Recovery Key consists of a Public Recovery Key and a Private Recovery Key, forming an asymmetric key pair. The Cyberark key hierarchy is also illustrated below.

Since these keys provide access to the server and the data stored within it, it is recommended to store the Server Key on Hardware Security Modules (HSMs) that meet the FIPS 140-2 Level 3 standard to enhance the security of the Cyberark Privileged Access Security solution. Including a FIPS 140-2 certified HSM in the identity management solution maximizes the security of the entire infrastructure and ensures the confidentiality, integrity, and availability of critical corporate data.
Hardware Security Modules (HSMs) are specialized security hardware devices designed to store sensitive cryptographic keys in a physical environment and perform cryptographic operations in the most secure manner possible. These devices ensure that applications operate securely.
Integration of Cyberark with HSM prevents vulnerabilities in the key security layer. Since the Server Key acts as the key used to open a physical vault, the server requires the key every time it is started. Therefore, with Cyberark HSM integration, the Digital Vault can access the key via the HSM whenever needed, allowing the vault to start without the need for additional operational processes beyond storing the key in physical hardware. The position of the HSM in the topology of the Cyberark Privileged Access Security solution is illustrated below. All Vault servers in the Cyberark structure must be able to communicate with the HSM device.

An HSM can be integrated with the Cyberark solution in two ways: the existing Server Key can be loaded onto the relevant HSM device, or, for added security, a new Server Key can be generated on the HSM device.
Integration of CyberArk Privileged Access Security Solution with HSMs;
CyberArk can be integrated with any PKCS # 11 compliant HSM such as CyberArk Thales nShield, SafeNet Hardware Security Modules, and Utimaco CryptoServer.
Thanks for reading! Share this post if you found it helpful.