Delinea’s integration with Cyera — a data risk intelligence platform — signals an evolution in how privileged access management (PAM) vendors are thinking about the relationship between privileged access and data security. Traditionally, PAM has focused on who has access to systems; Cyera adds context about what data those privileged users can reach and whether that access represents elevated risk.
This integration addresses a fundamental gap in traditional PAM: visibility of data risk. A privileged user might have excessive access to a system, but without understanding what sensitive data resides on that system, security teams cannot adequately assess the actual risk. Data-aware PAM bridges this gap by integrating privileged account governance with data risk intelligence.
In the AI era, data-aware PAM becomes even more critical. AI agents and automated systems increasingly operate with privileged credentials to access data for training, processing, or inference. If those agents have access to sensitive data without appropriate governance, the risks compound: not only is the privileged access potentially excessive, but the data the agent can reach may be confidential, regulated, or critical to the organisation.
The integration allows security teams to answer questions that traditional PAM alone cannot: Which privileged accounts have access to high-risk data? Are those accounts over-privileged relative to the sensitivity of the data they access? Should access to certain datasets be restricted to specific privileged roles? These questions are becoming standard requirements in mature security programmes, particularly in regulated industries where data governance and access control are linked.
From a PAM market perspective, the Delinea-Cyera partnership validates the emerging consensus that PAM platforms must become data-aware to remain competitive. Vendors that can integrate data classification, risk assessment, and privileged account governance into a single workflow will be better positioned to serve organisations tackling the AI identity challenge — where machine identities need access to data without exposing that data to unnecessary risk.
For IAM practitioners, the takeaway is that PAM selection criteria should now include data-risk awareness capabilities. A PAM platform that governs privileged access but remains blind to data sensitivity is incomplete in modern threat environments.