blueAPACHE Improves Efficiency in Security Management

Summary

This case study, authored by CyberArk, describes how blueAPACHE deployed the CyberArk Identity Security Platform to protect its own business and to offer identity security as a managed service. blueAPACHE is again the customer: as a managed services provider it holds privileged access into hundreds of customer environments, and the case study explains how it replaced password vaulting without rotation or session recording with privileged access management, workforce identity, password management and vendor privileged access, then became a CyberArk MSP partner. For a buyer this is the most detailed public description of how blueAPACHE controls its own engineers' access to customer systems, which is a standard due diligence question in regulated sectors. The facts on this page come from the origin page and are attributed to it.

Key facts

Label Value Source
Customer blueAPACHE (also becoming a CyberArk MSP partner) Origin page
Vendor and author CyberArk; the case study is written in CyberArk's voice Origin page
Problem Password vaulting without automated rotation or session recording; risk of credentials left behind in customer directories after staff departures Origin page
Products deployed CyberArk Privilege Cloud, CyberArk Workforce Identity (SSO, adaptive MFA, Workforce Password Management), CyberArk Vendor PAM; next phase Credential Providers and Conjur Secrets Manager Enterprise Origin page
Scope Deployed across emPOWER Cloud, emPOWER Connectivity, emPOWER Collaboration and emPOWER Managed Services, and blueAPACHE's internal IT Origin page
Scale stated Over 200 users in Privilege Cloud, over 250 in Workforce Identity, hundreds in Vendor PAM; CyberArk manages all customer support and administration access Origin page
Implementation CyberArk Jump Start Service Package and Strategic Consulting Services, chosen because of the multi-tenanted environment Origin page
Stated efficiency outcome A ten-fold efficiency increase; doing the same without CyberArk estimated to require four times more staff Origin page
Service offer to customers Dedicated CyberArk tenants for large businesses; a multi-tenanted platform for smaller organisations Origin page
Recognition cited blueAPACHE cited as "CyberArk Global MSP of the Year: 2021" in its managed services brochure Vendor partner record
Named executive Michael Zuppa, General Manager of Technology at the time of publication Origin page

Customer

blueAPACHE, described in the case study as a managed services provider offering IT management, IT strategy and converged IT services to clients across Australia, the UK, Asia and North America since 1998, headquartered in Melbourne with offices in Sydney and Brisbane. The case study frames the MSP position as the frontline: MSPs are trusted with access to client systems and data, so compromised or fake identities are the standard route for attackers.

Sector

Managed services and cyber security. The engagement is relevant to every blueAPACHE customer because it governs how blueAPACHE staff reach customer systems, and it is the basis of the identity security managed service now sold under the emPOWER Security pillar. It is cited on the financial services, government and public sector and utilities pages as third-party assessment evidence.

Challenge

blueAPACHE's General Manager of Technology describes identity security as extremely challenging for an MSP with hundreds of employees serving customers: creating hundreds of identities in each customer directory is a risk because the organisation is only as strong as its onboarding and offboarding, and with a dynamic workforce credentials can be left behind when someone leaves. The previous password vaulting tools lacked automated rotation and session recording, which made it hard to enforce identity and role controls, particularly during onboarding and offboarding. blueAPACHE also wanted stronger workforce access controls for all staff, alignment with government standards, and a platform that could extend to endpoints and non-human identities.

Solution

After a review of potential providers, blueAPACHE selected the CyberArk Identity Security Platform and used the CyberArk Jump Start Service Package and Strategic Consulting Services to implement it across a multi-tenanted environment. As described on the origin page:

At the same time blueAPACHE became a CyberArk MSP partner: large customers get a dedicated CyberArk tenant set up and managed by blueAPACHE; smaller organisations use a multi-tenanted platform. Services include provisioning and deprovisioning IT and workforce users, onboarding infrastructure and business applications into Privilege Cloud or Workforce Identity, and configuring remote privileged access with Vendor PAM.

Services used

Outcomes

Outcomes below are as stated on the origin page (CyberArk's case study), quoted or paraphrased without addition.

Outcome As stated
Credential control All customer support and administration access managed by CyberArk; passwords rotated automatically; credential re-use removed
Auditability blueAPACHE can show customers audited records of automatically rotated passwords used to manage their services and share session recordings
Offboarding "If an employee leaves blueAPACHE tomorrow, they would have no idea of passwords or credentials used to access customer services"
Efficiency A ten-fold efficiency increase; doing the same without CyberArk estimated to need four times more staff
Incident response Time saved because logs from multi-tenanted environments are in one place
Commercial Builds credibility and strengthens the value proposition to organisations that trust blueAPACHE to manage their environments; enterprise-level identity security made accessible to mid-market businesses
Supply chain Increased defence against supply chain attacks (listed under key benefits)

The efficiency and staffing figures are estimates attributed to blueAPACHE's General Manager of Technology in the source, with no measurement period stated. The origin page also carries CyberArk's descriptions of blueAPACHE's market position and awards; those are CyberArk's words and are not repeated in blueAPACHE's own voice here. Awards that blueAPACHE reports on its own site are linked under Related.

Distinguishing internal practice from customer scope

The case describes blueAPACHE using security technology internally. It is evidence of the described approach to privileged access, not an inclusion statement for every customer security service. Identify which accounts and systems the proposal covers, who approves access and what evidence follows a change or incident. For purchased MDR, exposure management or governance work, the relevant Service Description establishes actual deliverables and responsibilities.

Sources and scope

This section connects the sources identified on this page with the KB service-scope catalogue and the terms and conditions guide. Comparison and planning points describe matters to settle for a proposed engagement, not additional service inclusions or new case-study results.

Related

Frequently asked questions

Who wrote this case study and who is the customer?

CyberArk wrote it, and blueAPACHE is the customer. It describes blueAPACHE's deployment of the CyberArk Identity Security Platform across its own business and its emPOWER services, and blueAPACHE's parallel move to become a CyberArk MSP partner offering identity security to its customers.

How does blueAPACHE control its engineers' access to my systems?

According to the case study, all customer support and administration access is managed through CyberArk Privilege Cloud with session isolation and monitoring, passwords are rotated automatically, and remote privileged users authenticate with biometric adaptive MFA and receive just-in-time access through Vendor PAM. blueAPACHE states it can provide audited records of rotated passwords and session recordings to customers.

What happens to credentials when a blueAPACHE engineer leaves?

Because password ownership was removed from individuals and credentials are rotated centrally, the General Manager of Technology states that an employee leaving tomorrow would have no knowledge of the passwords or credentials used to access customer services. This was the offboarding risk that drove the project.

Which CyberArk products did blueAPACHE deploy?

CyberArk Privilege Cloud, CyberArk Workforce Identity with single sign-on, adaptive multi-factor authentication and Workforce Password Management, and CyberArk Vendor PAM. The stated next phase is Credential Providers and Conjur Secrets Manager Enterprise for application and machine secrets.

Can I buy CyberArk through blueAPACHE?

Yes. The case study states blueAPACHE sets up and manages dedicated CyberArk tenants for large businesses and runs a multi-tenanted platform for smaller organisations, covering user provisioning and deprovisioning, onboarding of infrastructure and applications, and remote privileged access. This is delivered under the emPOWER Security pillar.

What efficiency gains does the case study claim?

blueAPACHE's General Manager of Technology is quoted estimating a ten-fold efficiency increase from the credential control and automation, and that achieving the same without CyberArk could require four times more staff. These are estimates in the source with no measurement period, and are reported here as such.

How many blueAPACHE users are on the platform?

The case study states over 200 users in CyberArk Privilege Cloud, over 250 in CyberArk Workforce Identity, and hundreds in CyberArk Vendor PAM, with the platform deployed across emPOWER Cloud, Connectivity, Collaboration and Managed Services as well as internal IT.

How does this relate to blueAPACHE's compliance claims?

Privileged access controls with rotation, recording and audit are the kind of evidence a third-party assessment under APRA CPS 234, the Essential Eight's "restrict administrative privileges" strategy, or a critical infrastructure supply chain review asks for. blueAPACHE separately holds ISO/IEC 27001:2022 certification (202507-118) and states Essential 8 Maturity Level 3; neither is a substitute for asking for these access records directly.

Source

Drawn from the CyberArk-authored case study published on blueAPACHE's origin site; the vendor partner record; the emPOWER Managed Detection and Response and Managed Services brochures; and the ISO 27001 certification record and verification register. Efficiency and staffing figures are estimates attributed to blueAPACHE in the source and are reported as such.

Knowledge Base

What is this blueAPACHE case study about?

The case study, titled 'blueAPACHE Improves Efficiency in Security Management,' describes how blueAPACHE strengthened its security posture by implementing CyberArk, adding enterprise-level identity controls across its business and managed services.

Which security vendor did blueAPACHE use to improve its security posture?

blueAPACHE used CyberArk to strengthen its security posture.

What kind of controls did blueAPACHE add as part of this security improvement?

blueAPACHE added enterprise-level identity controls across both its business and its managed services.

What industry does blueAPACHE operate in, according to this case study page?

According to the case study page, blueAPACHE operates in the Professional Services industry.

How large is the blueAPACHE organization in terms of employees, per this page?

The page lists blueAPACHE's employee count as 101–500.

What is the headline given for this case study in its structured data?

The structured data headline for the case study is 'blueAPACHE - Security.'

Is a PDF version of this case study available?

Yes, the page provides an alternate PDF link at /case-studies/blueapache-security/index.pdf.

Images on This Page