What is our primary use case?
My main use case for Cequence Security is that my company is an integrator for Cequence Security, so we deliver this product to our customers in financial, banking, healthcare, and other sectors.
A specific example of how one of my customers is using Cequence Security is that most of them do not know how many APIs they have or how many are exposed to the internet, such as the dev environment or the HTML environment, which we call Shadow APIs. Most of them do not know what is hidden from their infrastructure. Cequence Security helped them create an inventory of all their APIs.
What is most valuable?
The main difference from other products available on the market from Cequence Security is the bot protection inline, which is a feature that only Cequence Security has inline. They have a baseline ML working on their environment, and this is a game-changing aspect for customers because they do not need to wait for a possible risk to come since Cequence Security is already blocking at the first hit.
In my opinion, the best features Cequence Security offers are discovery, which shows everything without installing anything, making it really useful for customers who do not have anything, and the vision about compliance, which is also very useful because you have a report for the CISO. You have the full engine for integration with the pipeline and full integration with Jira and other applications that you can use in your ITSM, and the bot protection inline is something exceptional for this company.
The discovery feature is really useful for small companies becoming mid companies because most of them do not have anything to secure this surface. It helps them understand where to invest their money over their environment since you have the vision of what an actual attacker will see through the internet. It also helps them with compliance reporting which is really useful when you need to report or ask for money from your CISO or your CTO because it assists you and your team to sell the product or buy more security applications.
Cequence Security has positively impacted our organization by giving us a lot of visibility from the market point of view since it competes with much bigger companies such as Akamai, Salt, and Imperva. Through its go-to-market strategy, Cequence Security has been a great asset for our customers when they see it in our portfolio because it is something kind of new for them. The WAF is kind of new for the customer, but it is such an intelligence feature that this is really a game changer as they feel it represents innovation from a marketing perspective.
What needs improvement?
Cequence Security can continue evaluating and evolving the machine learning and the AI that they have because attackers are using more AI, making it faster to learn how to attack APIs and business logic. When Cequence Security invests in their AI, they will provide quicker protection that our customers need, and the way that attackers think can be translated into security measures on Cequence Security workflows and baseline.
They need to improve faster in the AI environment because the possibility of attackers is growing, which is something that must be improved continuously as we need quicker releases since the market demands it.
Regarding accuracy and reliability, the AI has a baselining that allows it to learn from attacks, but it needs to improve more because in the Brazilian market, we have a creative environment for attackers who are familiar with the business logic of our customers, making it easier for them to imitate legitimate users during attacks. Thus, they need to enhance behavior analysis to differentiate themselves from all other products on the market.
Latency can be a significant issue in bigger environments, especially since the architecture requires uninterrupted traffic to ensure customers can finish transactions. The defender component managing inline traffic holds all traffic and has mechanisms to control latency, allowing fallback during high-risk situations, but the sensor used for mirroring traffic is outdated and does not work properly.
For how long have I used the solution?
I have been working in my current field for seven years.
What do I think about the stability of the solution?
Cequence Security is stable in my experience.
What do I think about the scalability of the solution?
The scalability of Cequence Security is good as it operates in a Kubernetes environment, making scaling easy.
They definitely need to educate customers on managing on-prem installations as scaling may significantly increase infrastructure costs.
How are customer service and support?
The customer support from Cequence Security is amazing.
Which solution did I use previously and why did I switch?
We were a strong partner, the number one partner of Akamai here in Brazil, and we previously used Akamai for these integrations but switched to Cequence Security due to the lack of required lock-in.
How was the initial setup?
Cequence Security's integration with our existing security tools and workflows is mostly smooth. They have plenty of documentation for these integrations, and many can be done independently using the UI console, although understanding how your environment should handle these requests is important since you may need to open specific IPs or pools of IPs, which you learn through the integration process.
What about the implementation team?
Cequence Security is good on documentation and shares a lot, and the people from Cequence Security are very accessible when you need them. They have a really good customer success process, but they need more people from around the world since it is getting huge for them and they require materials in other languages besides English.
What was our ROI?
The return on investment came after two years for one customer, meaning it took that long for us to convince them that the installation was worth it and the process was now under control. We had to attribute the delay to them as they had no inventory before, requiring much time to identify all APIs and inform them about their functionality. It became apparent their flaws existed in their processes, not just in the tools, ultimately demonstrating a return in saved money.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing is that licensing is easy to understand as they sell by modules, making it clear for explanation to our customers. However, the setup costs vary between SaaS and on-prem deployments and should specify these differences early, especially since on-prem solutions often entail significant infrastructure costs for customers. I find the pricing fair and comparable to other vendors.
Which other solutions did I evaluate?
Before choosing Cequence Security, we evaluated options available in the market such as Salt and Noname, which was acquired by Akamai.
What other advice do I have?
I can give Cequence Security a rating of 10 because this product genuinely makes a difference for our customers, and they do not need to lock in to Akamai does, which is significant for our customers when they need to buy it as an addition to their security tools, composing a much more secure environment.
I chose 10 for Cequence Security because I enjoy working with them. I think the product is really useful, the interface is easy to understand, and it is a product made by people who genuinely use it daily and listen to our feedback as integrators and customers, making this proximity valuable and deserving of a 10.
My advice to others looking into using Cequence Security is to utilize this product to monitor all your traffic and understand customer behavior, as good customers follow the same paths through APIs while bad ones attempt to manipulate them. You can observe this on Cequence Security with straightforward arrangements on the dashboards, which require minimal effort to detect bad behavior and can help you block it and learn about customer actions.
I wish Cequence Security all the luck in the market and hope they achieve first place soon. I am providing an overall rating of 10 for this review.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?