PACSEC3 v. CyberArk Software: Voluntary Dismissal After 41 Days
PACSEC3, LLC asserted US7523497B2 against CyberArk Software’s Privileged Session Manager in the Southern District of Texas. The case was voluntarily dismissed just 41 days after filing, with the public record silent on whether prejudice terms were attached.
Cyber-access patent claim against CyberArk ends in 41-day exit
On 19 December 2024, PACSEC3, LLC filed an infringement action against CyberArk Software, Inc. in the Southern District of Texas (Case No. 4:24-cv-05008), before Judge Lee H. Rosenthal. The asserted patent, US7523497B2, was directed at the accused CyberArk Privileged Session Manager and related components — a core product in CyberArk’s privileged-access management portfolio.
The case terminated on 29 January 2025 via a voluntary dismissal order, just 41 days after filing. Voluntary dismissal is a procedural exit that can be entered with or without prejudice. The public docket does not specify which condition applied, meaning it is not possible to confirm from the record alone whether PACSEC3 retains the right to re-file the same claims against CyberArk.
A 41-day lifespan is notably short even by NPE-versus-technology-company standards, and typically suggests an early resolution — whether through a licensing agreement, a covenant not to sue, or a strategic withdrawal — before the defendant had filed any substantive response. The precise driver of dismissal remains undisclosed on the public record.
Filing to Voluntary dismissal in 41 days
41 days — resolved well before any scheduling order or claim construction hearing
Voluntarily dismissed: what the record does — and does not — tell us
Voluntary dismissal: procedural exit with open questions
A voluntary dismissal is initiated by the plaintiff and closes the case without a merits ruling. Crucially, it can be entered with prejudice (barring re-filing) or without prejudice (preserving that right). The public record for this case is silent on which applied, so the exact legal effect on PACSEC3’s ability to reassert US7523497B2 against CyberArk cannot be confirmed.
No merits adjudicationWith or without prejudice? The record is silent
This distinction is commercially significant. A dismissal with prejudice functions as a final judgment — PACSEC3 could not re-file the same infringement claims against CyberArk. A dismissal without prejudice leaves the door open to future litigation. Because the public docket does not disclose the terms, neither outcome can be confirmed. Parties monitoring this dispute should track any subsequent filings by PACSEC3 against CyberArk.
Terms undisclosedPACSEC3 exits in 41 days — reasons undisclosed
PACSEC3 filed and withdrew within 41 days, before any substantive judicial ruling. This pattern is consistent with an early licensing resolution or a strategic withdrawal after evaluating the defendant’s likely response. Without a disclosed settlement or covenant not to sue, the outcome for PACSEC3’s monetisation of US7523497B2 remains unknown from public sources.
Outcome undisclosedCyberArk avoids a merits fight — for now
CyberArk Software was not required to mount a full defence before the case closed. If the dismissal was without prejudice, CyberArk retains exposure to re-filed claims on US7523497B2. If with prejudice, the risk from PACSEC3 on this patent is extinguished. Given the ambiguity, CyberArk and similarly-positioned privileged-access management vendors should maintain monitoring on US7523497B2 and PACSEC3’s litigation activity.
Exposure may persistFull party and counsel information
| Role | Name | Type | Detail |
|---|---|---|---|
| Plaintiff | PACSEC3, LLC | Company | Patent assertion entity — holder of US7523497B2 in the privileged-access/session management spaceSearch in Eureka ↗ |
| Defendant | CyberArk Software, Inc. | Company | CyberArk Software, Inc. — enterprise privileged-access management and identity security providerSearch in Eureka ↗ |
| Plaintiff counsel | William P. Ramey , III | Attorney | Counsel for PACSEC3, LLCSearch in Eureka ↗ |
| Plaintiff law firm | Ramey LLP | Law Firm | Representing PACSEC3, LLCSearch in Eureka ↗ |
| Defendant counsel | Thomas Christopher Trent | Attorney | Counsel for CyberArk Software, Inc.Search in Eureka ↗ |
| Defendant law firm | Trent & Taylor, LLP | Law Firm | Representing CyberArk Software, Inc.Search in Eureka ↗ |
| Presiding judge | Judge Lee H Rosenthal | Judge | Texas Southern District CourtSearch in Eureka ↗ |
Official order — verbatim text
The order of voluntary dismissal closes the docket without any judicial ruling on infringement, validity, or claim scope. Because the basis of termination is recorded simply as ‘Voluntary dismissal’ with no prejudice specification, the legal effect on PACSEC3’s ability to reassert these claims against CyberArk is unresolved from the public record. CyberArk received no formal adjudication in its favour, and PACSEC3 made no admission of non-infringement or invalidity.
US7523497B2 — privileged session management and access control
US7523497B2, filed under application number US10/841064, covers technology in the privileged session management and access control space. The patent’s claims are relevant to how secure sessions are established, monitored, or controlled for privileged users — a domain that sits at the core of modern identity and access management architectures. Its assertion against CyberArk’s Privileged Session Manager suggests the claims were mapped to session brokering or monitoring functionality.
Privileged access management has become one of the most commercially contested segments of enterprise cybersecurity. As zero-trust architectures proliferate, the technology covered by patents in this space intersects with products from multiple major vendors. US7523497B2 represents a potential monetisation asset for PACSEC3 across the broader PAM and identity-security ecosystem, suggesting that other vendors offering similar session management capabilities should assess their exposure.
Should your PAM product be assessed against US7523497B2?
Any organisation developing or deploying privileged session management, secure access brokering, or identity-governance products should consider whether their architecture intersects with the claims of US7523497B2. The fact that this patent was asserted against a leading PAM platform — and resolved without a merits ruling — means its claim scope has never been judicially tested. That ambiguity is a risk for competing vendors and OEMs in the same product category.
PatSnap Eureka’s FTO Search Agent can map the claims of US7523497B2 against your specific product features and prior art landscape in minutes. It identifies claim-level overlap, surfaces relevant prosecution history, and flags related family members that may carry equivalent risk — giving your IP and product teams the clarity they need before launch or licensing negotiations.
Run a freedom-to-operate analysis on US7523497B2 to assess your product’s exposure
Run FTO in Eureka →Similar patent cases in privileged-access management and identity security
Cases involving session management and identity-security patents in the Southern District of Texas and comparable federal venues, including other NPE assertions in the PAM sector.
Related patent case — similar technology
Comparable case in the same technology domain. Patent holder and defendant reached resolution after proceedings.
SettledRelated infringement action — same court
Comparable Cyberark Privileged Session manager and related components and products-adjacent infringement action. Patent enforcement dynamics analysed in depth.
Active · District CourtRelated invalidity challenge — appellate outcome
Combined invalidity and infringement action in the same technology space. Decided after substantive proceedings.
DecidedPACSEC3, LLC’s broader IP enforcement history
PACSEC3, LLC’s full litigation history covering prior enforcement, licensing activity, and inter partes review proceedings.
Portfolio viewWhat this case signals for the privileged-access management IP landscape
A 41-day voluntary dismissal against a major PAM vendor raises questions about patent monetisation strategy and sector-wide exposure to US7523497B2.
Short case duration suggests pre-answer resolution or tactical retreat
Cases that close before the defendant files an answer frequently resolve through a licensing payment, a covenant not to sue, or a plaintiff decision to withdraw after receiving early informal pushback. The 41-day window here did not allow for claim construction or dispositive motions, so any resolution was almost certainly commercial rather than judicial.
US7523497B2 remains a live risk for PAM vendors until prejudice terms are confirmed
Without a confirmed with-prejudice dismissal or a disclosed covenant, US7523497B2 could theoretically be asserted again. Vendors operating in the privileged session management, identity governance, or zero-trust access spaces should treat this patent as a monitored risk asset and consider FTO analysis relative to their specific product architectures.
PACSEC3’s litigation posture: serial assertion risk assessment
Patent assertion entities that file and quickly dismiss tend to either be testing claim viability, executing a licensing programme across multiple defendants, or responding to early settlement signals. Mapping PACSEC3’s full assertion history against US7523497B2 and related family members can help counsel anticipate the next target and the likely licensing ask.
CyberArk’s S.D. Texas exposure and venue strategy implications
Filing in the Southern District of Texas under Judge Rosenthal is a deliberate choice — this court has an active patent docket. If PACSEC3 re-files, understanding the procedural tendencies of this venue, including scheduling orders, claim construction timelines, and fee-shifting history, is material to defence strategy for any PAM or identity-security defendant.
PACSEC3 v CyberArk — key questions answered
PACSEC3, LLC filed a patent infringement suit against CyberArk Software in the Southern District of Texas on 19 December 2024, asserting US7523497B2 against CyberArk’s Privileged Session Manager. The case was voluntarily dismissed on 29 January 2025, 41 days after filing, without any merits ruling.
The public docket records the basis of termination as ‘Voluntary dismissal’ without specifying whether it was with or without prejudice. This means the legal effect on PACSEC3’s ability to re-file against CyberArk on US7523497B2 cannot be confirmed from publicly available information alone.
US7523497B2, filed under application US10/841064, covers technology in the privileged session management and access control domain. It was asserted against CyberArk’s Privileged Session Manager and related components, suggesting the claims were mapped to CyberArk’s session brokering or monitoring functionality. No judicial claim construction occurred before dismissal.
At 41 days, the case closed before CyberArk filed any substantive response. This duration is consistent with an early commercial resolution — such as a licensing agreement or covenant not to sue — or a strategic withdrawal by the plaintiff. The precise reason is not disclosed in the public record.
Potentially yes. Because the case ended without a merits ruling, the validity and scope of US7523497B2 remain untested. Other vendors offering privileged session management, identity governance, or zero-trust access products may face similar assertions. A freedom-to-operate analysis against this patent is advisable for companies in the privileged access management sector.
Assess your PAM product’s exposure to US7523497B2
With no merits ruling in this case, US7523497B2 remains an unresolved risk for the privileged-access management sector. Run an FTO search in PatSnap Eureka to map claim exposure and monitor PACSEC3’s next moves.
PatSnap Eureka searches patents and litigation data to answer instantly.