Canadian Provisional Lottery Case Study

Expanding Privileged Access Management Across Gaming Infrastructure

Organization Profile

A Canadian non-profit organization with 250 employees which operates lottery and gaming-related activities for its government members in Western Canada.
A provincial lottery organization engaged Presidium Solutions to assess the state of its CyberArk Privileged Access Management (PAM) deployment. Despite having the platform in place for several years, adoption was minimal and delivering little value. Presidium developed and executed a roadmap to expand PAM coverage across critical systems, infrastructure, endpoints, and third-party access.

The Challenge

  • CyberArk PAM deployed but largely unused
  • Limited internal PAM expertise
  • Only a handful of users retrieving static passwords
  • No centralized control over privileged access
  • Increasing risk exposure across gaming systems and infrastructure
  • Consideration to decommission PAM due to low ROI

The Solution

Presidium Solutions conducted a full assessment of the existing CyberArk environment and implemented a phased expansion strategy:

  • Stabilized and optimized CyberArk for high availability and operational readiness
  • Integrated PAM with core gaming infrastructure, including:
    • Linux servers and SSH keys
    • Oracle databases
    • Windows workstations
  • Implemented Privileged Session Manager (PSM) to control and monitor access across all endpoints
  • Secured enterprise infrastructure, including:
    • Check Point firewalls
    • Cisco Firepower devices
    • Windows Servers and Microsoft SQL Server
  • Developed custom integrations:
    • Password change plugins
    • PSM connectors for web apps, thick clients, Oracle SQL Developer, and MMC tools (e.g., ADUC)
  • Deployed CyberArk Endpoint Privilege Manager (EPM):
    • Automated local administrator password management
    • Integrated into gold images and SCCM workflows
    • Enabled auto-discovery and onboarding of new endpoints
  • Implemented CyberArk Vendor PAM:
    • VPN-less, biometric-secured vendor access
    • Full session monitoring and recording via PSM
    • Eliminated need for vendor domain accounts and VPN provisioning

Results & Impact

  • Full privileged access coverage across gaming systems and infrastructure
  • Secured:
    • 50+ high-privilege domain accounts
    • 500+ Windows servers
    • Network devices and firewalls
  • Automated management of 600+ endpoint administrator accounts
  • PAM user adoption increased from 2 to 50+ users
  • Centralized password management, session monitoring, and auditing
  • Closed multiple internal audit findings related to privileged access
  • Enabled compliance with cybersecurity insurance requirements
  • Extended PAM capabilities to include endpoint and third-party vendor access

More Client Success Stories

US Telecom PAM Monitoring Case Study

Integrated CyberArk with Splunk to deliver centralized visibility, real-time monitoring, and proactive alerting across a large-scale telecom PAM environment.

Major Healthcare Provider IAM Case Study

Presidium Solutions implements SailPoint Identity Security Cloud at a large University Medical and Research Hospital, automating access to cloud and on-premises applications for employees, providers and students.

Credit Union IAM Case Study

Presidium Solutions modernizes Identity and Access Management for a California-based credit union, automating lifecycle provisioning and de-provisioning across cloud and on-premises applications for 225,000+ members.

Canadian Utility PAM Case Study

Presidium Solutions implements Privileged Access Management for a major Canadian electric utility, securing critical infrastructure and enforcing least privilege across 4,000+ endpoints.

Let’s Strengthen Your Identity Security Program

Whether you are beginning your journey, looking to expand your program, or struggling with a current implementation, we provide the expertise to move your security objectives forward with confidence.