What is our primary use case?
In our company, which creates decentralized finance applications, the platforms we create for enterprises... we need robust security measures to address and protect against web application vulnerabilities.
CloudGuard WAF helped us to provide protection by leveraging its contextual AI to detect and prevent threats. So it also helps us to check against the OWASP Top 10 vulnerabilities and zero-day exploits. It can help secure our applications, as dictated by our company, against injections, cross-site scripting, cross-site request forgery and CloudGuard's AI-based approach also helps us to detect and mitigate threats with more accuracy.
Also, it helps us to secure our APIs so only authorized requests are processed, preventing unauthorized access, data misuse, and other API-related vulnerabilities.
Its automation capabilities also help streamline security processes within our blockchain environment by automatically detecting and responding to threats. This reduces the burden on security teams and allows us to focus on strategic tasks.
Also, its ability to adapt to our applications and ensure our security policies are followed is a big plus.
So, main use cases include securing web applications, automation capabilities, and the ability to adapt security policies.
How has it helped my organization?
It helps us prevent different attacks by cyber hackers, such as SQL injections and cross-site scripting attacks. Its AI-driven feature helps us to detect and mitigate other threats, which is very useful.
Also, we've faced network trouble managing endpoints, and CloudGuard WAF managed that quite smoothly. It also smooths down API integration processes and detects API availability.
Additionally, it completely prevents and secures our products. It helps us rate-limit any malware attacks on our APIs and enables blocking of malware, phishing, or similar elements in the system. It is very worth it. It's very versatile and deployable, helping us create virtual and deployable products for any kind of IT variety.
the integration feature is really nice. It integrates with the other solutions we use. The integration process is very good, which is a key point for this solution.
What is most valuable?
One of the features I like is results-driven threat detection. This feature allows our company to analyze various factors such as user behavior, session patterns, and application interactions to actively update risk assessment for each endpoint while leveraging AI with context.
It helps us effectively detect and prevent a wide range of attacks, including the OWASP Top 10 vulnerabilities and zero-day exploits, without the need for extensive manual rules and tuning. This not only enhances the security posture of our applications but also reduces false positives, ensuring legitimate traffic on the website or apps is not blocked.
Overall, its security and AI features make it a powerful tool for acting against modern threats.
The reporting capabilities are really nice in CloudGuard WAF. It has AI-driven features which help us to identify issues. As it reports, we were able to find out more features as well. The platform generates comprehensive reports whenever we detect security events. These reports are customizable.
Also, because of its security features, it provides us with threat analysis and historical data, so we can track our security performance over time and make informed decisions. So, the reporting features provide visibility into our applications and help us to stay ahead of emerging threats.
What needs improvement?
There is room for improvement in the pricing strategy. By reducing their cost and extending the trial period, Check Point can attract more partnerships and customers, keeping up with other vendors in the field. It has a trial period, but they can extend it so we can better evaluate how it's working in our environment and how well it is suited.
It should be converted to activate some discounts on buying standard versions. This will attract more of us, and we'll get more time to check the application and how it works.
Additionally, their effort to involve IT teams would mean continuous adaptation to meet business requirements. This can help with the price picture and increasing the trial period so we can better evaluate the cost-effectiveness.
Also, Check Point need to continue developing new features and arrangements in line with changing business requirements.
The analysis time while it analyzes itself is very time-consuming. They need to improve the latency and minimize the steps involved.
Also, the documentation needs to be updated, more improved, and simplified... so that even a beginner can start with this application. It can make things more beginner-friendly.
Also, Check Point can bring some updates to the integration features with other security solutions, making it easier to integrate. For instance, it needs to integrate with solutions someone might have various firewall solutions from IBM and others, depending on which ones the business wants to integrate with.
For how long have I used the solution?
I have been using it for one and a half year.
What do I think about the stability of the solution?
It's quite stable in deploying with the firewall. Sometimes there is some instability, but it gets fixed later.
I would rate the stability a six out of ten.
What do I think about the scalability of the solution?
I would rate the scalability an eight out of ten. We have about five to six end users. It is AI-driven, so it's more of an automated system. We don't need that many users for it.
How are customer service and support?
The customer support are very nice. Whenever we face a problem, they guide us with the solution. They're also very experienced and helpful. If we ever encounter any difficulty, there is quick support for IT needs.
How would you rate customer service and support?
How was the initial setup?
The deployment process was very well-documented with clear instructions, which made it easy to follow. The integration with our existing cloud environment was seamless. CloudGuard's team led us to an easy deployment and helped whenever we faced any issues.
The configuration, with guidance on necessary settings and automatic features, minimized the overall manual intervention required.
Once automated, we didn't need to do much. For setup, it saved us a fraction of the time. It allows us to keep the setup without any waste of time, unlike what I've seen in other applications.
I would rate my experience with the initial setup an eight out of ten, with ten being easy to set it up.
The deployment didn't take much time. It was very quick, about a couple of hours.
What was our ROI?
We have seen a significant improvement in our ROI. Our security operations became more efficient with a reduction of 35% in the time spent on rule tuning and threat detection. This efficiency gain led to 25% increase in productivity for our security team.
Additionally, the reduction in false positives has decreased incident response times by 20%. Overall, it has enhanced our security posture, and the ROI from implementing CloudGuard Secure was impressive.
What's my experience with pricing, setup cost, and licensing?
The pricing is not that expensive considering what it offers. So, it is moderate price. Per day it costs around $0.91.
It costs about $1.145 per hour. So for a year, it will cost about 8,988 euros.
What other advice do I have?
Overall, I would rate the solution an eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
*Disclosure: I am a real user, and this review is based on my own experience and opinions.