The role of PAM solution in securing the information system of Sotteville-lès-Rouen ?

Success story

Mairie Sotteville-lès-Rouen

  • 4 in the IT department
  • Local authority
  • Public sector
  • Sotteville-Iès-Rouen
  • National

Could you introduce yourself briefly ?

I am a Systems, Networks and Security Administrator at Sotteville-lès-Rouen city. After gaining experience at an IT services company, I joined the town hall's IT department at the end of 2019.

My role primarily involves implementing the information system security policy and contributing to decision-making on network-related matters.

 

How is the IT department organised within the Town Hall ?

We are a four-person team managing day-to-day operations across networking (routing, equipment...), hosting, business application management, telephony, workstations, and more.

The municipality of Sotteville-lès-Rouen has approximately 30,000 inhabitants. It is the third largest municipality in the Seine-Maritime department in the Normandy region. As a local authority, we bring together a wide range of services (nurseries and schools, urban planning, libraries, police, etc.), meaning a large number of third-party providers may interact with our information system.

 

Why did you need to strengthen the traceability of sensitive access ?

Before discovering Rubycat's PROVE IT solution, we already had a privileged access management solution in place. The primary objective was to secure access to servers. We also used it to secure internal access. Within the local authority, we take a defence-in-depth approach to information system security.

As mentioned, we have providers who can intervene on our equipment and/or servers. The purpose of the administration bastion was also to restrict network access to a limited population and to track our providers' access.

As an example, some time ago, an action carried out by one of our providers caused an issue in our production environment — and it was thanks to the bastion that we were able to identify the source of the problem.

 

Why did you switch to PROVE IT ?

Our initial solution no longer met our needs. Support responsiveness was lacking, and following a few issues we had encountered, our confidence in the solution had diminished.

We decided to compare other French PAM solutions on the market, and our choice fell on Rubycat's PROVE IT, a solution holding ANSSI's CSPN security certification. Our selection criteria were: a reliable solution, rapid deployment, and a defined budget.

Before making a final decision, we tested two solutions, including PROVE IT. This solution won me over because it offers a licensing model based on the number of simultaneous sessions, which is particularly well-suited to the size of our organisation. The results of the solution's testing demonstrated its reliability, speed of deployment and minimal maintenance requirements.

 

What is your assessment after several months of use ?

We have been using PROVE IT since the end of 2022. Its integration into our information system went smoothly. Deployment was extremely fast, around 20 minutes ! The assessment remains consistent with what we observed during testing : very little ongoing operational maintenance required. Its adoption by the rest of the team within the local authority also went without a hitch.

I would also highlight the excellent responsiveness and attentiveness of Rubycat's technical support. This is something that is becoming increasingly rare when compared to the support offered by other solutions across the board.

It is a human-sized team with a genuine capacity to listen. They take the time to look into any issues encountered and our requests in detail. As proof of this, our feedback relating to product development is taken on board. This only reinforces our trust in our relationship with Rubycat.

 

Would you recommend the solution to another local authority ?

For all the reasons mentioned, I would not hesitate to recommend the solution to another local authority looking to raise their security level. PROVE IT is well-suited to this type of organisation and is constantly evolving. The roadmap is communicated in advance, we are eagerly awaiting the arrival of the RDP web portal this summer.

 

Testimonial collected on 8 August 2023

Discover PROVE IT PAM bastion

Our solution

Explore PROVE IT's features and discover how our PAM solution secures, controls, and traces all privileged access across your information system.