Share your experience using ShieldX

The easiest route - we'll conduct a 15 minute phone interview and write up the review for you.

Use our online form to submit your review. It's quick and you can post anonymously.

Your review helps others learn about this solution
The PeerSpot community is built upon trust and sharing with peers.
It's good for your career
In today's digital world, your review shows you have valuable expertise.
You can influence the market
Vendors read their reviews and make improvements based on your feedback.
Examples of the 84,000+ reviews on PeerSpot:

Ilaria Buonagurio - PeerSpot reviewer
Head of Corporate Information Security Prevention at Luxottica Group
User
Top 20
Good monitoring, compliance, and reporting of remediation actions
Pros and Cons
  • "The feature that I value the most about Check Point CloudGuard CNAPP is the possibility of checking compliance with different standards. This compliance check can be performed for each subscription or service that we have on all the different cloud providers that we use."
  • "One feature of the product that I would like to enhance is the possibility to connect to vulnerability management platforms so that the issues that emerge from the scans can then be ingested directly into the vulnerability management process."

What is our primary use case?

We use it as a CSPM (cloud security posture management) solution. In particular, the main use case it to identify misconfigurations in our cloud environments. 

We have different cloud providers, and it monitors all of them: Google Cloud Platform, Amazon Web Services, and Microsoft Azure. For each workload or subscription, Check Point Cloud Guard checks whether the configuration is in line with the sector standards and guidelines or not. 

It also checks for each subscription to see if it is compliant with a given policy. It has multiple policies for Europe, the USA, and even Australia.

How has it helped my organization?

With Check Point CloudGuard CNAPP, we are able to monitor the security of all of our cloud environments. Moving to a more and more cloud-centric environment is vital for us to ensure security. 

In addition, we have to comply with some standards that require us to guarantee compliance and overall data security and safety in the cloud environments that host our exposed applications, databases, servers, and virtual machines. 

With Check Point CloudGuard CNAPP, we are able to identify which remediation actions need to be taken in order for us to be compliant with the standards and to secure our environments better.

What is most valuable?

The feature that I value the most about Check Point CloudGuard CNAPP is the possibility of checking compliance with different standards. This compliance check can be performed for each subscription or service that we have on all the different cloud providers that we use. The result of the compliance check is having a list of issues, misconfiguration, or vulnerabilities that need to be fixed and addressed. The list is detailed with severity, description of the issue, risk, and how to mitigate it. It also points out the exact bit that needs to be addressed, so there is no guessing game, and when we address the issue to the technical team, they already know what needs to be done

What needs improvement?

The service is already top-notch; both on the commercial side and on the technical side. I had the luck to be put in contact with a very talented and skilled technical after-sales team that guided us step by step through the configurations. Also, the commercial team was very comprehensive with our situation and allowed us to create a package that best fit our needs.

One feature of the product that I would like to enhance is the possibility to connect to vulnerability management platforms so that the issues that emerge from the scans can then be ingested directly into the vulnerability management process. It would be very nice to provide, on top of API connections, built-in plugins for the major ticketing systems.

For how long have I used the solution?

I've used the solution for three years.

Which solution did I use previously and why did I switch?

No, we have not used any solution before.

What's my experience with pricing, setup cost, and licensing?

The setup cost is really low compared to the license cost. However, it's a good investment if you want to secure the cloud ecosystem.

Which other solutions did I evaluate?

We evaluated other options, among which Prisma Cloud and Orca Security.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
Nishant_Mishra - PeerSpot reviewer
Infosec Module Lead at a tech vendor with 201-500 employees
Real User
Improved our web application security
Pros and Cons
  • "We utilize Google Cloud Armor alongside our Cloud Load Balancer to safeguard against DDoS attacks. This setup acts as a local Layer 7 proxy provided by Google, allowing us to predict and mitigate DDoS threats effectively."
  • "I believe Google Cloud Armor can benefit from enhancements of AI and automation."

What is our primary use case?

We decided to deploy the application firewall, and Google offered Cloud Armor as the solution. We adopted it and currently have it running at a production level.

How has it helped my organization?

Since implementing Google Cloud Armor, our web application security has seen a significant improvement. We now have better visibility into potential attacks, thanks to detailed logs and the ability to create and enforce security policies. Integration with chat channels has streamlined our incident response process, enabling us to swiftly block any attacking IPs.

What is most valuable?

We utilize Google Cloud Armor alongside our Cloud Load Balancer to safeguard against DDoS attacks. This setup acts as a local Layer 7 proxy provided by Google, allowing us to predict and mitigate DDoS threats effectively. The solution includes features like rate limiting and throttling to enhance protection. The customizable policies within Google Cloud Armor, including predefined and custom rules, have been particularly effective in bolstering our web attack protection. 

What needs improvement?

I believe Google Cloud Armor can benefit from enhancements of AI and automation. Incorporating more proactive suggestions and predictive capabilities related to attack mitigation would be beneficial. While the current adaptive protection feature offers some suggestions, a more advanced AI-driven approach that can interpret attacks in real-time and provide actionable insights during incidents would be valuable. integrating more monitoring metrics into Cloud Armor for better visibility and analytics could further enhance its effectiveness.

For how long have I used the solution?

I have been using Google Cloud Armor for the past 2 years. 

What do I think about the stability of the solution?

Its been running smoothly with high stability, rated at around 9.5 out of 10.

What do I think about the scalability of the solution?

The scalability is impressive, rated at 9 out of 10, which has positively impacted our workflow. Currently, there are no users directly using the solution; instead, it's safeguarding approximately six hundred containers for backend applications.

Which solution did I use previously and why did I switch?

Before adopting Google Cloud Armor, our previous solution was Azure, primarily focused on security incidents and possibilities. We transitioned to Cloud Armor due to its XDR capabilities and high scalability, which was a crucial factor for us. 

How was the initial setup?

Setting up Google Cloud Armor was initially a bit challenging with a learning curve, but it became smoother once I grasped the configuration nuances. It took around four months to deploy Cloud Armor, primarily because we first observed traffic patterns in preview mode before fully enforcing the rules. 

What about the implementation team?

I managed the deployment and ongoing maintenance myself as the information security lead, although now I have a junior infrastructure engineer assisting with maintenance tasks and providing recommendations for rule adjustments.

What was our ROI?

I would rate the return on investment from Google Cloud Armor around 8 on a scale of 10. The investment has shown significant benefits in terms of ease of deployment, requiring fewer personnel such as DevOps engineers and security operations center staff to manage and monitor the system. This streamlined approach has resulted in cost savings and increased operational efficiency, contributing to the overall positive return on investment.

What's my experience with pricing, setup cost, and licensing?

I would rate the pricing of Google Cloud Armor around 7 on a scale of 10. As for the licensing costs, I'm not directly involved in billing, so I don't have specific details on that aspect. We have a partner agreement with Google, which gives us a discounted price for using Cloud Armor. 

Which other solutions did I evaluate?

We didn't extensively explore other options because our infrastructure is predominantly on Google Cloud, and we anticipated seamless integration with our existing components, especially with Google Workspace.

What other advice do I have?


My recommendation for others considering this solution would be to thoroughly review the Google Docs related to Cloud Armor, especially understanding how to create custom rules. This step is crucial post-deployment. In terms of integration with other Google Cloud services, Cloud Armor seamlessly integrates with Cloud Balancer, providing easy access to logs and monitoring metrics without any significant obstacles or resistance.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate