No more typing reviews! Try our Samantha, our new voice AI agent.
Cybersecurity Engineer at Altia Group
Real User
Top 5
Aug 14, 2025
Integration and threat prevention impress while user experience needs refinement
Pros and Cons
    • "There is a lack of functionalities and usability."

    How has it helped my organization?

    I assess the effectiveness of Check Point CloudGuard CNAPP in preventing misconfigurations across cloud environments as an important part.

    The ability of Check Point CloudGuard CNAPP to secure multi-cloud environments has impacted my customer's compliance efforts; it is not the priority, but it is an important solution.

    What is most valuable?

    Check Point CloudGuard CNAPP is effective. It is not as powerful as Harmony and Collaboration, but it is a challenging solution.

    Check Point CloudGuard CNAPP has some advantages over its competitors.

    One of the best features is easy integration.

    The automated threat prevention of Check Point CloudGuard CNAPP is impressive. It uses the same model and engine as antivirus or Harmony and Collaboration, making it effective.

    I find false positives to be the most valuable metrics for threat detection. The number of false positives is important.

    I assess the role of Check Point CloudGuard CNAPP in providing real-time visibility into cloud infrastructure depending on the client, and we usually do a business case to address that.

    What needs improvement?

    There is a lack of functionalities and usability. I used to compare it with another solution that is focused on specific features. All solutions have some gaps, and we are looking for the best one in every single scope.

    I believe improvements could be made to the notification system, ease of use, and integrations.

    The interface could be simplified and more focused on user experience. It appears somewhat unrefined in its current state.

    If they improve their interface and integration capabilities, I would give them a higher rating.

    How are customer service and support?

    The technical support provided by Check Point is really good.

    I would rate their technical support as eight out of ten.

    Buyer's Guide
    Check Point Cloud Firewall (formerly CloudGuard Network Security)
    August 2026
    Learn what your peers think about Check Point Cloud Firewall (formerly CloudGuard Network Security). Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
    911,473 professionals have used our research since 2012.

    How was the initial setup?

    I find the initial setup easy to integrate. The main challenge is maximizing the solution's potential.

    To get the full power of the solution, you need to fine-tune it extensively to achieve the expected behavior.

    What other advice do I have?

    I consider the pricing of Check Point CloudGuard CNAPP to be average.

    On a scale of one to ten, I rate Check Point CloudGuard CNAPP a seven.

    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
    PeerSpot user
    Information Security Officer at Cargus
    User
    Top 10
    Mar 27, 2025
    Provides in-depth insights and identifies risks with an easy setup
    Pros and Cons
    • "I value the comfort and the ability to receive proper insights almost hands-off."
    • "I would appreciate a way to receive periodic updates, like through email. I am the kind of person who likes to receive data passively."

    What is our primary use case?

    I use the solution for some cloud applications, which are cloud-native.

    How has it helped my organization?

    The solution helps increase security posture and provides a greater scope for protection. 

    What is most valuable?

    I value the comfort and the ability to receive proper insights almost hands-off. It sends us the information of interest. It offers very good security posture management capabilities. We're receiving the information of interest, like security posture, details, settings, and so on. And the solution is spot-on. There are capabilities to check actions to mitigate and measures and controls that come with these features are valuable.

    It's providing compliance rule sets and security best practices.

    One of the main reasons we use the solution is that it is great at identifying risks that are critical to our business. It saves us time at identifying risks. I might save one FTE continuously checking in. 

    We use the CDR (the intelligence capabilities). It's helpful and does the job.

    The solution detects anomalous behavior. We don't have any issues. 

    What needs improvement?

    I would appreciate a way to receive periodic updates, like through email. I am the kind of person who likes to receive data passively. It would be nice to have periodic updates on what people should do, maybe with some analysis or something.

    For how long have I used the solution?

    I have used the solution for about four months.

    What do I think about the stability of the solution?

    The stability is good. It does its job.

    What do I think about the scalability of the solution?

    It was good in terms of scalability.

    How are customer service and support?

    I found the customer service to be very professional, great, and very spot-on.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    We did not previously use a different solution. 

    How was the initial setup?

    The initial setup was very easy.

    What about the implementation team?

    I completed the implementation together with a colleague from Check Point. The experience was very professional.

    What's my experience with pricing, setup cost, and licensing?

    We had the 60-day evaluation already. It's now something we have to pay.

    Which other solutions did I evaluate?

    I did not consider alternate solutions.

    What other advice do I have?

    I would rate the solution ten out of ten although I have no other comparison.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Microsoft Azure
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Buyer's Guide
    Check Point Cloud Firewall (formerly CloudGuard Network Security)
    August 2026
    Learn what your peers think about Check Point Cloud Firewall (formerly CloudGuard Network Security). Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
    911,473 professionals have used our research since 2012.
    Senior consultant at a consultancy with 10,001+ employees
    MSP
    Top 20
    Mar 25, 2025
    Provides us with unified security management across all environments but had a complex setup
    Pros and Cons
    • "The solution provides me with unified security management across all environments."
    • "The deployment was not easy."

    How has it helped my organization?

    Scaling the solution is very easy.

    What is most valuable?

    The best features are: 

    • database inspection
    • threat prevention
    • enhanced security.

    The solution provides me with unified security management across all environments. It has a single interface that can help us get integrated with the normalized management server. It also gives us security and integrity.

    It does what it’s supposed to do. I would say that it created a reduction of 25% in organizational risk.


    What needs improvement?

    We haven’t seen any kind of problems so far.

    We generally used everything on-premise, but now it's all in the cloud through CloudGuard. The transition was a bit challenging. Maybe they could improve their services by including more tutorials and labs on migration.

    For how long have I used the solution?

    I have been using the solution for one year. We have just recently implemented the solution, and so fa,r everything is good.

    What do I think about the stability of the solution?

    We haven't experienced a lack of stability.

    What do I think about the scalability of the solution?

    The solution is scalable, and it can handle the traffic whatever the requirement might be. It is capable of meeting the necessary demands effectively.

    How are customer service and support?

    The technical support and customer service are very good, they’re very nice.


    How would you rate customer service and support?

    Positive

    How was the initial setup?

    The deployment was not easy. We did not use any help from outside. The deployment was made in-house and if we ever had a question, we contacted the Check Point team.

    What was our ROI?

    From a technical perspective, the return on investment is in its helpfulness and how it’s shaping our future.

    What other advice do I have?

    I would rate it a seven out of ten. We had some issues we encountered at the beginning. It is a work in progress.

    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
    PeerSpot user
    System administrator at a consultancy with 201-500 employees
    Real User
    Top 20
    Feb 14, 2025
    Provides unified security management and improves our security posture
    Pros and Cons
    • "It gives us all-encompassing security and overview. Previously, we did not have any kind of overview of what was happening with the network."
    • "CloudGuard Network Security provides unified security management across hybrid-clouds as well as on-prem."
    • "Right now, I am not sure what improvements are needed. We are having occasional issues related to gateways, but we are still analyzing it."
    • "We have had occasional issues with two gateways that used to break or are broken. We are not sure yet."

    What is our primary use case?

    We are using CloudGuard Network Security for comprehensive security. We have hardware appliances from Check Point, and we also have their firewall installed.

    How has it helped my organization?

    CloudGuard Network Security provides unified security management across hybrid-clouds as well as on-prem. It has improved our security posture. 

    CloudGuard Network Security helped reduce our organizational risk. It has not yet helped us save time and costs because we are understaffed. However, it has helped to see what is happening and what we should mitigate or allow to happen.

    What is most valuable?

    It gives us all-encompassing security and overview. Previously, we did not have any kind of overview of what was happening with the network.

    The interface is unifying all the data in one place. I can see the network side and the policy attached to using USB devices. Everything is stored and related.

    What needs improvement?

    A Check Point problem was that there were different solutions, and each had its own interface, section, and logs. Things are going great with the new feature that consolidates all the data from those systems in one place. Right now, I am not sure what improvements are needed. We are having occasional issues related to gateways, but we are still analyzing it.

    For how long have I used the solution?

    I have been using CloudGuard Network Security for the past six months since I joined the company.

    What do I think about the stability of the solution?

    Until now, it has been stable, but we have had occasional issues with two gateways that used to break or are broken. We are not sure yet. We are still analyzing it. We might be sending it to the warranty team.

    What do I think about the scalability of the solution?

    We implemented it keeping in mind all the requirements in terms of licenses, hardware, and other things. Everything is pretty much as we needed. We have no plans to upscale it. However, I am waiting for the OS version R82 to see how we can add more data on the fly.

    How are customer service and support?

    So far, customer service has been almost great. We have had some issues, such as needing to escalate every time because one gateway was not working at some point. We had an endless loop of emails trying to fix this, and the suggestion was to reinstall the gateway and do it from scratch, which was not an option at that point because it would leave that specific location without access, and business hours did not permit it. Other than that, things went smoothly most of the time.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    Previously, we only had security with a basic VPN and firewall in place.

    What other advice do I have?

    I would rate CloudGuard Network Security a nine out of ten.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    GeorgeGeorgiou2 - PeerSpot reviewer
    Head DB Management & Systems Support at a financial services firm with 51-200 employees
    Real User
    Top 5
    Feb 13, 2025
    Detection capability ensures compliance and evidence provision in cloud integration
    Pros and Cons
    • "The initial setup was straightforward."
    • "My overall product rating is ten out of ten."
    • "I don't have any notes for improvements."

    What is our primary use case?

    The solution is for used for protection of workloads.

    What is most valuable?

    It offers good detection. This capability allows us to effectively manage compliance. 

    It helps us find misconfiguration. We use it to try to find possible storage accounts that may be misused or other misconfigurations.

    The effectiveness of its cloud security posture management is good. It's really helpful for us and allows us to comply with various standards.

    It helps our company identify risks that are most critical to our business. It not only saves us time, it provides us with the visibility we need to manage the cloud.

    What needs improvement?

    I don't have any notes for improvements. I'd need some more time to work with it.

    For how long have I used the solution?

    I have used the solution for one year.

    What do I think about the stability of the solution?

    The stability is good.

    What do I think about the scalability of the solution?

    We haven't had issues with scalability.

    How are customer service and support?

    We have not had any issues with customer service so far.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    This was the first solution I tested. I have not used a different solution. 

    How was the initial setup?

    The initial setup was straightforward.

    What's my experience with pricing, setup cost, and licensing?

    The pricing is decent.

    Which other solutions did I evaluate?

    We only really tested the capabilities of native tools before we implemented this solution.

    What other advice do I have?

    My overall product rating is ten out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Yokesh Mani - PeerSpot reviewer
    Deputy Manager at Computer Age Management Services Pvt. Ltd.
    Real User
    Feb 1, 2024
    Easy to write custom rules and policies in the UI with limited coding knowledge
    Pros and Cons
    • "We like the GSL Builder feature. When you're running a security operations center, you spend a lot of time monitoring endpoint activity to ensure there is no malicious traffic or anonymous access in the environment. The GSL Builder is helpful for deep investigations of a particular reason for an incident. You can use it to get more information."
    • "The user interface could be improved. Sometimes, the visibility is not immediately available for the environment. We have the native servers that come with the solutions, but we cannot see them in the Check Point log. Another issue is with the integrated file monitoring. It would make sense to have stuff like file integrity monitoring and malware scanning available within this module because we don't want to integrate another product."

    What is our primary use case?

    CloudGuard is a posture management and workload protection platform. We're also using it for data and risk management.

    How has it helped my organization?

    Our environment includes a hybrid cloud and three public cloud providers: GCP, AWS, and Azure. CloudGuard enables us to manage all the cloud providers from one dashboard. It enables a team approach, so we're more flexible and operationally efficient. The solution provides a holistic view from a single dashboard, making posture management and threat prevention more effective. Detection is not a significant challenge. When I block a particular incident, CloudGuard will implement some kind of prevention activity so that those types of activities are prevented automatically in the future. Prevention is more beneficial for us.  

    When managing our service partner, CloudGuard enables easier enrollment and allows us to consolidate all those rules and privileges. It will give them complete visibility of the identities that I am using for all the services, whether it's privileged user access or a normal user. It's based on user suggestions. CloudGuard helps me handle my user identities.  

    Another benefit is posture management. We are governed by four regulatory entities in India. We need to stay in 100 percent compliance by avoiding any misconfigurations on our platforms, and this tool helps us.  It also helps with virtual protection of our code by adding another layer of security and an extra step. It can detect abnormalities in the image and register, enabling us to identify and fix compromised packages before any major release. 

    As a regulated entity, we receive a monthly external audit from the agency, and we always pass them using CloudGuard because we have a  single dashboard for multiple services for user activity reviews and policies that we have set for the user levels. It's easy to demonstrate our compliance posture using this portal and any incidents with compromised credentials or NetFlow security. 

    CloudGuard allows us to do more work with fewer people. A team of six people can manage our entire enrollment. CloudGuard covers a huge footprint. It saves a lot of resources, but I cannot measure that in time saved. Onboarding and learning the product took six months, and it took us another year to address all of the solution's findings. The third year should be focused on monitoring. I can't quantify how much time is consumed in days or weeks, but if I had to rate it on a scale of one to 10, I would say nine. 

    A reduction in human error is part of posture management. When we first onboarded to the posture management platform, we had to customize and build some rules for enrollment. We fixed the issues we found, and we don't need to run the posture management tool again. Instead, we run the GSL builder and cross-check the findings. Before addressing the finding, we must create a default rule set in the GSL  Builder. We copy what's in the builder and execute it on a particular enrollment, and we'll say it is good to go. We can save time building custom rulesets with GSL builder, but it's hard to say how much. 

    What is most valuable?

    We like the GSL Builder feature. When you're running a security operations center, you spend a lot of time monitoring endpoint activity to ensure there is no malicious traffic or anonymous access in the environment. The GSL Builder is helpful for deep investigations of a particular reason for an incident. You can use it to get more information.

    We have more than 30 AWS accounts and use more than 16 versions with some different tenants. I don't want to turn on each enrollment and app one at a time in the application. With GSL Builder, I can select multiple accounts from one place and execute the commands. I can see the results of which entities passed and failed.

    It's easy to write custom rules and policies. I have limited coding knowledge, but I can make policies from inside the UI. It will show what services are available in the cloud provider, and I can go through and check the ones I need. It requires no scripting knowledge. If you have experience in the industry, you can immediately learn GSL Builder and adapt it. 

    Auto-remediation is a module you can enable at the enrollment level. It detects and fixes human errors or misconfigurations.  For example, we can't create a bucket that is exposed to the internet for compliance reasons. CloudGuard can prevent that bucket from being created, ensuring compliance. 

    With effective risk management, we can identify every asset and assign a score to each network violation or process. We will flag the most critical assets and bring them to private subnets. There's also a graph, which is useful if we need to explain things to developers and administrators.

    What needs improvement?

    The user interface could be improved. Sometimes, the visibility is not immediately available for the environment. We have the native servers that come with the solutions, but we cannot see them in the Check Point log. Another issue is with the integrated file monitoring. It would make sense to have stuff like file integrity monitoring and malware scanning available within this module because we don't want to integrate another product. 

    For example, let's say it's showing a process violation. It should be able to do some additional malware scanning in that particular bucket to get some additional information. I don't want to integrate with another third-party tool or go to the native server to check something. It would be helpful to have integrated monitoring and malware scanning for the file types. 

    There are a few flaws with the security management portal where I have limited visibility into the workload protection features. There is no error visibility where I can see the communication and workflow between services. Some of the dashboards need to be fine-tuned if they are not customized. For example, I cannot customize anything on the effective risk management dashboard. Some of the information is not correct for my tenant. With respect to passwords and user management, there are no policies I can measure at the user level. If the user was created more than six months ago, you don't need to worry about that password or do anything like two-factor authentication associated with that user. They can still log in after six months or one year. 

    It's also a challenge to use CloudGuard's agentless workload posture with AWS. An Azure storage is summed up with a CNAPP encryption by default. We tried onboarding this data, but the problem is the attachment is not done. After a few days, we identified that it was impossible to do the encryption detection. But CloudGuard's default rules say that this has to be encrypted. 

    The AWS module says that we cannot access this volume with this encryption, so we cannot use an agentless workload posture with AWS because of this. It is a best practice to ensure that all the volumes are being encrypted. Without the encryption, how can I do this? It is a big challenge for CloudGuard.

    For how long have I used the solution?

    I have used CloudGuard for 14 months.

    What do I think about the stability of the solution?

    We only see downtime when there is a global outage. It typically only lasts a few minutes. Also, we sometimes see latency issues when accessing this portal. We double-checked that with the team also, and they asked us to check on our network side. We are in the office network, so we could not refer to that. 

    Some of CloudGuard's modules are slower. For example, if I go and click on the posture, it loads immediately within 30 or 50 seconds, but workload protection might take more than a minute. There are some differences in the latency between the services within the cloud version.

    What do I think about the scalability of the solution?

    We don't have any issues with CloudGuard's performance or scalability. 

    How are customer service and support?

    I rate Check Point support 10 out of 10. Their customer service is fantastic. We have premium support, so I don't know what their standard support is like. When we open a ticket, they immediately call us back regardless of the severity. 

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    We have Prisma Cloud, which is not fully implemented, so we need to use Check Point simultaneously. Prisma Cloud excels in terms of UA, visibility, and user-level policies and management. CloudGuard is more cost-efficient but not as user-friendly as Palo Alto. At the same time, having the GSL Builder makes it more efficient to make CNAPP rules without much background knowledge.

    How was the initial setup?

    Generally, the deployment is pretty easy. We have a template, so it's automatic. However, we run into problems when we're supporting multiple CSPs. AWS supports CloudGuard 100 percent, whereas for Azure, it's 75 or 80 percent. Some Azure services, like user identity, are not supported, which is a challenge. It should be available in Q1. 

    Deploying the threat intelligence for AWS was fine, but we had problems with Azure. I'm part of the security group, which is onboarded into the AWS. The next time I create a new security group, it automatically discovers the asset and will put it in the log. For Azure, a new network security group must be added manually. If I'm doing that manually, I want to completely remove the onboarded threat intelligence, which means I want to completely remove what we added from the portal. That is one problem we face doing the onboarding of Azure.

    What's my experience with pricing, setup cost, and licensing?

    I don't know the initial proposed amount, but the procurement team looked at the market and compared Prisma and CloudGuard, then settled on one solution.

    What other advice do I have?

    I rate Check Point CloudGuard CNAPP nine out of 10. Any advice I could give to potential users would be completely based on their use cases. You must look at various criteria, like your environment and enrollment level, but my general advice for implementing a CNAPP solution is to get a cloud dev. 

    If you are using AWS with multiple CNAPPs and you don't have a control tower or any other landings in the budget, you want to do policies at each enrollment level. But we're using this out that what we do is, like, we build guardrails where we can apply it at the enterprise level itself. 

    For example, we'd want to allow any data to be researched outside the area. I'll create one policy and apply it at the organizational level. I set a policy so that any user in my enrollment could not create an SD bucket or any volumes outside using their agent. If you have multiple CSPs, AWS accounts, or Azure subscriptions, this is one solution where you can cover your entire organization's accounts.

    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    PeerSpot user
    reviewer2244411 - PeerSpot reviewer
    Security Architect/Staff Engineer at a consultancy with 10,001+ employees
    Real User
    Top 5Leaderboard
    Jul 30, 2024
    It centralizes all these cloud functions on a single tool, but the reporting could be improved
    Pros and Cons
    • "Most of the features are pretty valuable, whether that's a description of the attacks or the attack graph showing the vulnerabilities. If a single tool does all this work, the value is centralizing all these functions on a single tool. These are the cloud-native applications we talk about — containers, Kubernetes, and cloud infrastructure — and all those things are the primary focus of the CNAPP solution."
    • "CloudGuard's reporting could be better. It's good now, but there is room for improvement. If you're looking for a centralized platform, there are a lot of features that can be appreciated. However, you want complete security integration with SaaS, DAST, secret scanning, etc., and a single platform for all these features."

    What is our primary use case?

    CloudGuard CNAPP has many use cases depending on your business requirements. If your organization's infrastructure is spread across various cloud vendors, such as AWS, GCP, and Azure, you can implement CNAPP. 

    Our use case entails gaining visibility into cloud components. We have an infrastructure platform where our resources are deployed. We are now focusing on having a clear visibility of all the cloud platforms, whether it is AWS, Azure, or GCP.

    How has it helped my organization?

    CloudGuard expands your visibility. If your infrastructure is segregated across AWS, Azure, and GCP, it can track all the resources deployed on these cloud vendors. It covers any cloud devices like S3 buckets, containers, etc. You get clear visibility of all those resources, and it helps to check for misconfigurations. 

    For example, if you have an S3 bucket exposed publicly, that is a security concern. You need to do things to ensure that your S3 bucket is kept private when configuring it. It will evaluate your security configuration with respect to the deployed resources and give you the scores. CloudGuard will tell you where your resources stand regarding configuration, security scores, compliance checks, etc. It gives you all the visibility within the single platform. 

    It also protects your workload. The features of the traditional CSPM can be varied. If you have deployed an application running on a Kubernetes cluster, it will give you visibility into all clusters and the workloads deployed and running in the background if you want to scale the workloads.

    When you perform all the activities on the back end, there are a lot of chances that you misconfigure. Any misconfigurations within the namespace of the Kubernetes cluster can lead to a security vulnerability. When it's exposed publicly, it can add some more risk. All of those things can be easily tracked in some of the recent cloud vendors. 

    Wiz is one of the industry contenders within the CNAPP solution. In addition, there are a couple of other vendors like Orca. All of these vendors provide workload protection in addition to the typical CSPM.

    If most of your resources are deployed in CloudGuard, one of the bigger concerns
    is the failure to monitor your devices. You can only protect the things you can see. You cannot take action if you don't have visibility into how your resources are deployed or distributed. 

    Regardless of scale, it gives any cloud-dependent organization an edge over the other technologies so that they can track their infrastructure. You can see where your resources are deployed and how they perform regarding health checkups, security misconfigurations, compliance checks, etc. So it gives you better visibility. 

    What is most valuable?

    Most of the features are pretty valuable, whether that's a description of the attacks or the attack graph showing the vulnerabilities. If a single tool does all this work, the value is centralizing all these functions on a single tool. These are the cloud-native applications we talk about — containers, Kubernetes, and cloud infrastructure — and all those things are the primary focus of the CNAPP solution. 

    I think EDR, MDR, and any of those systems do a great job at the endpoint level, but you need CDR if you want to use those features on a cloud level. For example, if a VM is deployed, it can also detect all misconfiguration there. In addition, if any of these are critical, it will show you the attack graph. 

    It shows you all the pictures from the attacker's perspective, such as if there is some loophole at your gateway level and if the traffic is coming from the Internet. If you have misconfigurations at the gateway level, it will give you the attack path the attacker can use to enter your organization. If you enter, it shows how you can move laterally if some additional new points can be exploited within your infrastructure. It gives you a list of any misconfigurations in terms of user access.

    Regarding the response part, the onus is on the department or the team implementing those technologies because you need to have strong processes, policies, and procedures. For example, if you can address some of the detections or vulnerabilities at the application or cloud level, you should have a policy to prioritize those things in your organization. Once you have those policies, you can lead in those scenarios and maybe collaborate with different teams responsible for addressing those new issues. 

    It involves some coordination and collaboration as well. At the end of the day, you want to make things easier, so you can provision access for the various teams within that platform if they want to consume these things directly rather than getting the information via a report or any other mechanism. Let's say there's a problem with your S3 bucket, and you need to fix issues inside that rather than fixing them in the CNAPP solution. CNAPP is something that gives you an overview, but you need a process for the remediation.

    What needs improvement?

    CloudGuard's reporting could be better. It's good now, but there is room for improvement. If you're looking for a centralized platform, there are a lot of features that can be appreciated. However, you want complete security integration with SaaS, DAST, secret scanning, etc., and a single platform for all these features. 

    Check Point is known for its firewall. Six or seven years ago, it used to be a good thing because most businesses were on on-prem. If your business is on the cloud, you do not need a firewall because most of the cloud vendors already have that built into their cloud premises, and you can configure the rules there. You can do everything as a network security engineer. 

    It depends on your business model. Some companies are segregated and most of their things are on-prem. They have physical outlets in multiple countries. Managing everything in these business environments and deploying the Check Point firewall would be a good investment. However, it doesn't make sense if your business is totally in the cloud. 

    It depends on how Check Point sees things in the market. If they want to compete with all these vendors in terms of CNAPP, they need to first understand their audience. Once they have some visibility into who their audience is, they need to maintain their business. 

    For how long have I used the solution?

    I am evaluating CNAPP vendors for my organization, and Check Point Cloudguard is one of them. I have evaluated all the other vendors, so I have the experience.

    Which solution did I use previously and why did I switch?

    One vendor I worked with in the CNAPP market was Rapid7. They have a CSPM tool called InsightCloudSec that offers similar visibility of all cloud resources. The various cloud vendors are populated over the platform, and you can see the same things. However, some features are available in other vendors, like Wiz or Orca that are missing in Rapid7. They are trying to incorporate some of the features they lack, but there's still a long way to go. 

    It's more about how you leverage the APIs of the cloud provider so that you can get the data and make things as easy as possible for the end user. You do not want to overwhelm them with so much data. You want the information that's necessary for your organization to take action. Wiz and Orca are the industry standard for CNAPP solutions. I would rate Wiz nine out of 10 and Orca eight out of 10, but Rapid7 ICS would receive five out of 10. In terms of CNAPP features, I don't think Check Point is a competitor here. Check Point generally focuses on things related to the firewall, such as VPN, etc. 

    How was the initial setup?

    Deploying CloudGuard is pretty straightforward. You don't need to invest much time because the deployment model isn't rigorous. You establish the connection with your CloudGuard vendor, and it takes a few hours. There are additional steps if you want to configure more in-depth to get more visibility into your Kubernetes cluster. It doesn't require any agent to be installed on your resources, which is a good thing.  

    If you're running a serverless architecture like AWS Lambda and you want better visibility in those complex scenarios, there are some additional configurations that require you to check some documentation that you need to go through. However, it takes only a few hours to achieve visibility into the typical cloud resources, such as EC2 instances, S3 buckets, containers, and user accounts. 

    What's my experience with pricing, setup cost, and licensing?

    All these technologies are expensive. Wiz is the most expensive. You might have seen that Google is making overtures toward acquiring Wiz. It's valued at $12 billion, but it may go as high as $24 billion, which would make it the most expensive acquisition in Google's history. The bottom line is that you need to spend a good amount of money to implement these things and it depends on your organization's priorities. 

    What other advice do I have?

    I rate Check Point CloudGuard CNAPP six out of 10. 

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    PRASHANT GARJE - PeerSpot reviewer
    Manager - Enterprise Architecture and Cloud at Axis Bank
    Real User
    Jun 16, 2024
    Cost-effective, supports automation, and provides good security
    Pros and Cons
    • "The most important feature is that we are able to use Check Point CloudGuard Firewall for our cloud security. We can make the deployment automated. We do not require manual intervention."
    • "We have done a lot of automation with the firewall, but sometimes, there are some failures because of some bugs. The fixes for them are still not available. We have daily or weekly communication with the Check Point people giving support in the India region, but we have not seen much improvement or response to our requests for some additional features."

    What is our primary use case?

    We are using Check Point CloudGuard as a firewall. Along with the firewall, we have incorporated multiple blades. Initially, the firewall used to be a single security device, and along with that, we required antibot, antivirus, IPS, and IDS devices. Check Point CloudGuard is a combination of all the devices and functionalities in a single device. It is a next-generation firewall. The main use case of this firewall is to protect our entire cloud and provide perimeter cloud security at L3 and L4 levels.

    How has it helped my organization?

    It is a next-generation firewall. Threat prevention and threat detection blades are available with the firewall. As soon as you enable the blades and you have the license for it, you are good in terms of threat prevention. You do not need to do any specific settings. You just need to enable the blade, and the firewall will take care of the rest of the things. That is how it works.

    We are using the Check Point CloudGuard firewall with autoscaling in the AWS and Azure cloud. We have a minimum capacity of two firewalls and a maximum capacity of ten firewalls. If the CPU utilization increases or the memory utilization increases, the capacity will be increased to three from two. Till the service comes down to the threshold level, it will keep on adding more firewalls, so we have ease of operations. We do need not to worry about what we will do if a firewall fails.

    When I joined my organization, we were using this CloudGuard firewall in the active/standby firewall cluster. In such a setup, the firewall that is active processes your traffic. The other firewall is in the standby mode. It is not processing the traffic, but it is still costing you. Even though it is not being used, it is still cost-consuming at the cloud level. We changed the setting to autoscaling. After adopting the autoscaling mode for this firewall, we need a lower number of CPU and memory. All the firewalls are active, so we need not worry about the standby firewalls and all those things. So, we have transitioned from these conventional active/standby firewalls to autoscaling firewalls. With this, we are able to save costs and improve performance. All the firewalls are active/active but with fewer CPU cores. When we have fewer CPU cores, we need less number of licenses, so we were able to save the cost. The performance has also been great.

    What is most valuable?

    The most important feature is that we are able to use Check Point CloudGuard Firewall for our cloud security. We can make the deployment automated. We do not require manual intervention. With the help of automation, we are able to deploy it within minutes, and we are able to discard it within minutes. We can do hardening and create policies. All those things are very advanced.

    Secondly, Check Point is one of the big OEMs available in the world from the firewall perspective. It is better than Palo Alto and Juniper firewalls. It is one of the best firewalls available in the industry.

    What needs improvement?

    We have done a lot of automation with the firewall, but sometimes, there are some failures because of some bugs. The fixes for them are still not available. We have daily or weekly communication with the Check Point people giving support in the India region, but we have not seen much improvement or response to our requests for some additional features. We are moving to infra as a code, so we are expecting more advancements in this product. Just installing the patches is not going to help us. They need to focus on this area.

    I expect Check Point CloudGuard to come up with some AI/ML integration. A firewall is the first L3 security device available to you. It is the single point that manages or processes the traffic for an organization. There is a possibility that the device goes down or gets rebooted for any reason. The integration of artificial intelligence with the devices can help us to know in advance that there might be a surge in traffic. There might be a spike in the traffic, so we can have some additional firewalls integrated. This predictive analysis has to be there. This way, if required, a second, third, or fourth firewall can come into the picture. All the firewalls will process the traffic simultaneously. I am expecting such capability. This sort of feature is available with AWS. We are deploying all the firewalls on AWS, but it would be easy if, in the future, such a feature is available from the OEM or Check Point itself. It will be very helpful for the organization.

    We have had a couple of outages because of some misconfiguration. They were human errors but there were no prior indications that if we were making these sorts of changes, this would happen. People making the changes on the firewall were not aware of this, and that is the reason why the outage happened. In a financial organization, an outage of even five minutes can cost a lot.

    For how long have I used the solution?

    In our organization, we have been using it for more than four or five years, but I have hands-on experience with it for the last three years. 

    What do I think about the stability of the solution?

    I would rate it an eight out of ten for stability.

    What do I think about the scalability of the solution?

    It is scalable. I would rate it a ten out of ten for scalability.

    How are customer service and support?

    I would rate their support a five out of ten because I never got good support. Whenever I have raised a TAC case, their support has not been great. It is not as good as others.

    They need to improve from a knowledge perspective. I had a couple of issues, and they could not understand those issues easily. They should not just take the logs and analyze the logs. They should be providing a solution. Being a financial organization, we cannot afford a long downtime. We expect a faster resolution. If a support engineer is not capable of handling a case, he or she should escalate it to a higher level, but they are not doing that on a regular basis. They make you lose days by dragging the case.

    How would you rate customer service and support?

    Neutral

    Which solution did I use previously and why did I switch?

    In my organization, we have two different Infra teams. We have the Network Security Infrastructure team that manages the on-premises setup, and then we have the Cloud Network Security team that manages the cloud. I am a part of the Cloud Network Security team, and we are using the Check Point firewall. The on-premises team was using Juniper and Palo Alto firewalls, and they are now using the Check Point firewall. It is one of the most effective products we have ever used, and that is the reason why that team has moved from other OEMs to Check Point CloudGuard.

    How was the initial setup?

    We have deployed it on the cloud. We have AWS, Azure, and GCP clouds.

    The deployment was done with the help of AWS CloudFormation templates which are very generalized. I just downloaded the templates and customized them as per our requirements. I faced a few challenges because I was not completely knowledgeable about CloudFormation, etc. It was not very challenging from the Check Point side. It was an easy deployment.

    I faced a couple of challenges while integrating it with our existing ecosystem. Even though Check Point is the OEM, we have third-party vendor support here in India. The challenges that I was facing at the time were also new for them, so I sorted out those issues myself by referencing some online articles on Check Point. I was able to overcome those challenges at the time. It was not a big deal. There was no huge challenge.

    What about the implementation team?

    Initially, we involved people from Check Point and the third-party vendor of Check Point, but at later stages, we were capable enough to develop things in-house, so we did it ourselves.

    The Cloud Network Security team has ten people. I am handling the AWS cloud deployment along with a colleague. Other colleagues are involved in Azure and GCP deployment. Overall, there are ten people for deployment and management, but mainly, two or three people are involved in the deployment at a time.

    We have deployed it in two regions. It is deployed in the Mumbai and Hyderabad regions of AWS in India.

    What was our ROI?

    We have seen 70% to 80% ROI. 

    What's my experience with pricing, setup cost, and licensing?

    I do not know the exact price, but it is fairly priced. It is neither cheap nor costly.

    As compared to other OEM vendors in the market, it is cost-effective for us. There are multiple things we need to consider while selecting a certain product. We have AWS, Azure, and GCP clouds, and we have multiple firewalls. All of our firewalls are Check Point CloudGuard firewalls. The cost can vary based on the licenses that you are using. For IPS, IDS, antivirus, antibot, and other capabilities, additional licensing costs might be there. When it comes to security, it gives us great security. Considering that factor, it is cost-effective for us.

    Which other solutions did I evaluate?

    I have not evaluated other solutions. Based on the input from my seniors, this is the best solution available in the market. I have heard that Palo Alto also has a cloud-based product called Prisma Cloud, which has some advanced features integrated by using AI/ML technologies. I would love to evaluate Prisma Cloud.

    What other advice do I have?

    I feel confident using this product. In fact, I have completed a few certifications related to Check Point CloudGuard. I am a Check Point certified administrator, and I am also a Check Point Certified Cloud Specialist. I have also been working with automation-related things, and sometimes, we do some bash scripting and shell scripting to make things easier for us. Traditionally, you can only access the firewall via a CLI. That is the basic level, and at the next level, you should be able to do a few daily things in an automated way. I am very good at that.

    I would recommend this solution, but it also depends on the requirements. It is a cost-effective solution. If you are a small organization or a startup, you do not need to have this solution. If you are a big organization with 5,000 to 10,000 users, you can go ahead with it. The ROI for our organization was up to 80%, but it necessarily would not be the same for other organizations.

    Overall, I would rate it a nine out of ten.

    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    PeerSpot user
    NikhilKrishnan - PeerSpot reviewer
    Senior Manager Enterprise Cloud at Axis Bank
    Real User
    May 16, 2024
    Highly reliable, great visibility, and centralized management
    Pros and Cons
    • "The number of options it gives for deployment or security is valuable. When it comes to security, it has a feature that is super awesome for zero-day-based attacks. Their IPS is also very capable. We tested other firewalls, and we understood that it is the best one in the market."
    • "The main issue that I have noticed is that for deployment, it still requires a dedicated management server, and the gateway is completely different. That sometimes can cause issues."

    What is our primary use case?

    Basically, we are using Check Point CloudGuard firewalls everywhere. We are using them at the perimeter and internally.

    By implementing this solution, we wanted to protect our perimeter. We are using Check Point along with other solutions to protect our perimeter. We also have many application-level use cases that can be solved with Check Point. 

    How has it helped my organization?

    Most of the things that we have are on the cloud. Its main benefit is reliability. We have tested so many firewalls on the cloud, but when it comes to reliability, other firewalls fail miserably. Check Point is very good. It is a very reliable solution. With other vendors, when you move something to the cloud, the features that they are offering might only work partially. We never faced any such issue with Check Point. They offer features that will work completely. Apart from that, they have solutions for almost every cloud use case. That is another thing we love.

    CloudGuard Network Security provides unified security management across hybrid-clouds as well as on-prem. They have a centralized management server. There is a process called CME. If you have multiple clouds, such as AWS, GCP, and Oracle, and you are deploying CloudGuard across all the clouds, you have single management to take care of everything. This is why they provided a unified management solution. CME takes care of scaling and integration. It has a zero-touch approach. It takes care of everything. You just need to deploy it, and the connectivity should be there. It then takes care of everything. It drastically reduces the deployment time and administration overhead.

    When any incident happened, it was able to tell us the particular packet associated with that. Based on its internal intelligence, it identifies everything. We were not even aware that there was an attack like that, but it gave us complete clarity about what happened and what was the attack journey. Visibility-wise, it has been very good.

    It makes us confident in our security. We have proper visibility into the network. We can see exactly what is happening. We get this level of clarity. Especially when we offload the SSL capability on the firewall, we have unparalleled visibility on even the SSL traffic.

    What is most valuable?

    The number of options it gives for deployment or security is valuable. When it comes to security, it has a feature that is super awesome for zero-day-based attacks. Their IPS is also very capable. We tested other firewalls, and we understood that it is the best one in the market. 

    When it comes to the firewall capabilities, the level of information that it offers for any security incident is very good. It gives a very good clarity about what happened and at what time. It is very good.

    There is centralization. You can manage everything in a single pane, and you have support for all the software. If it is a Kubernetes, you have a solution for it. If it is IOT, you can cover that. You have gateways as well for network security.

    What needs improvement?

    The main issue that I have noticed is that for deployment, it still requires a dedicated management server, and the gateway is completely different. That sometimes can cause issues. If it loses communication with the management server and you want to push any sort of critical policy, that would be affected. Apart from that, I do not see any issues. Everything else is going well.

    For how long have I used the solution?

    We have been working with Check Point firewalls for more than ten years. We are currently using Check Point CloudGuard firewalls.

    Check Point also has NGFW firewalls. They are hardware-based firewalls. All the features are identical. The only difference is that one is on a virtual platform, and the other one is on a physical platform.

    What do I think about the stability of the solution?

    It is reliable.

    What do I think about the scalability of the solution?

    We are only using auto-scaling firewalls. The good thing is that it scales well. Within seven to ten minutes, it gets integrated with the management server. If there is a failure, the firewall will be ready within ten minutes.

    We have a team of around seven people who take care of the network security part. Our environment can go up to 3,000. If you combine the server users and the end users, there are more than 10,000 users.

    How are customer service and support?

    We work closely with Check Point support when there is any issue or limitation. When we face any issues related to processing, scale-out, or delay, we definitely connect with the Check Point support. They usually provide the solution quickly.

    I would rate their support an eight out of ten. The reason why I am not giving them a ten is that we are connected through a third party. We cannot directly engage with Check Point. We usually contact this third party, and they engage Check Point support. We have a technical person assigned directly, which is a good thing, but this is how we initiate the process.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    We are mostly relying on TerraForm. For us, the deployment is very straightforward. When you deploy, it will automatically integrate with its management server, so you do not need to put in any effort. The only thing is that you should have the connectivity between the gateway and the management server. Once you deploy, it automatically gets added to the management. The policy push is automatic. That is very good. So, when it comes to deployment, after pushing the code, you do not need to do anything. Everything will come online. That is the best part.

    We do have a couple of gateways in management, but I do not take care of that part. I am mostly on the cloud side.

    It takes five to ten minutes for initialization and then there is the management part. At the maximum, it will go up to 30 minutes. I usually see everything happening within 15 to 20 minutes and not more than that, but if there is any connectivity issue or any other error, then the duration will get affected. If it is straightforward, it will take a maximum of 30 minutes and not more than that. Because the integration is automatic, I do not need to onboard the gateway to the management server. There is a functionality called CME that takes care of the entire thing.

    In terms of maintenance, it does not require any maintenance. The only catch here is that because it is a cloud version, when it comes to upgrades, you cannot upgrade the existing versions to newer versions. We simply deploy the new one. It is not a complicated task. This is the only thing when it comes to maintenance.

    What about the implementation team?

    I was the main person who took care of the deployment engineering part. 

    What was our ROI?

    I do not have visibility on the ROI, but we are completely satisfied with the performance. We will continue with Check Point in the future. We have been renewing their licenses without thinking about any other firewalls. I consider it as a good investment, but this aspect is managed by a different team.

    What's my experience with pricing, setup cost, and licensing?

    We have an enterprise licensing team that works closely with Check Point. I know that we have an enterprise agreement with Check Point. That gives us some benefits, but I do not have more information about that.

    Which other solutions did I evaluate?

    We tried the Azure Firewall. It was good, but zero-day, URL filtering, and NAC capabilities were not there. It was a native firewall, but it was not able to fulfill our use cases. The main competition was against Palo Alto. When we did the comparison, we found Check Point to be more reliable. With the Palo Alto firewall, we had issues with autoscaling. It was not working as expected. These were the two that we tested. Being a bank, we cannot test everything. There was a discussion with Cisco as well, but we did not go with Cisco.

    The advantage that Palo Alto has over Check Point is the GUI. They do not require a dedicated management appliance to be deployed to access the firewall capability. They do have that platform, but the individual gateway can be also accessed via a dedicated GUI. With Check Point, you have to have the software called SmartConsole. It is very good, but a company like ours has too many gateways. When you have so many gateways onboarded to the management, it will be slightly slow, but it is not a show-stopper. The GUI is good, but you require the client applications to be installed on your laptop. From the GUI itself, you would not be able to access them. That is one advantage of Palo Alto. You can straightaway access them through the GUI. The software that you need to install for Check Point is a huge one, so the performance depends on the machine. If you have many gateways associated, it can be a bit slow at times.

    Check Point is a number one vendor based on the NSS labs and other regulators. In terms of performance and security, Check Point is always number one. Irrespective of how many firewall vendors are there, Check Point will always be number one. Check Point's capability to identify an incident is also very good. Its performance is also good. We were worried that if we moved to the cloud, unlike on-prem, we would not have any dedicated hardware to accelerate something. However, when we migrated to CloudGuard, we did not face any issues. 

    What other advice do I have?

    When it comes to the cloud, I would definitely recommend the solution. One main thing is reliability. I appreciate Check Point for that. For an organization like ours, security is the main thing. Check Point has been able to protect us from various attacks. Autoscaling and other things are also working perfectly. We were able to achieve all of our use cases with the Check Point CloudGuard firewall. I do recommend this solution.

    For zero-day attacks, I know there is technically no single solution, but our observation is that for most of the sophisticated attacks, if it is not already there, Check Point will have a solution within a day. When it comes to DDoS and bot-level attacks, Check Point has a sophisticated approach to prevent them in most cases.

    Overall, I would rate this solution a nine out of ten. 

    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    PeerSpot user
    Associate Director at Virtusa Global
    MSP
    Oct 24, 2023
    Provides a complete overview of all our cloud security solutions, supports a wide range of automation capabilities, and reduces effort
    Pros and Cons
    • "I can take proactive actions based on an alert without having to interact with the platform directly."
    • "Adding a feature that allows me to easily identify the changes that have been made to the CIS benchmark and update my own policy accordingly would be a valuable addition to Check Point CloudGuard Posture Management."

    What is our primary use case?

    We are a multi-cloud service provider that leverages all major cloud providers, such as AWS, Azure, GCP, and OfficeLab, for our internal consumption and for our customers. Managing and monitoring the compliance of the platform across hundreds of accounts can be challenging, especially without a solution like Check Point CloudGuard Posture Management, which continuously scans and alerts us against policy violations. If the policy is violated, we are alerted, the issue is identified, and we are assisted in resolving it.

    How has it helped my organization?

    It is easy to write custom rules and policies using the GSL Builder. We do not need to learn any programming language or structured query language to write back queries. GSL Builder enables us to click and drag to build our own rules. For example, if we want to fetch all the servers that are accessed publicly, we can simply put down the servers where access is public. GSL Builder creates an easy-to-use interface so that administrators no longer need to know a specific language to make this happen. Therefore, once the query is ready, we can quickly test it to check its effectiveness, modify it quickly, and then start using it.

    Non-technical people can learn to use the GSL Builder in less than ten hours.

    We have reduced human error using GSL Builder by 20 percent. For example, if I have to write a query, I could make a typo or omit spaces, which could cause the query to be structured incorrectly. With GSL Builder, the only thing humans need to do is drag and drop logic from existing utilities. This means that I can simply click and select when to perform an action, and the system will generate the query for me. This reduces the amount of human input required and, consequently, the likelihood of human error.

    The GSL Builder has saved us a significant amount of time. What used to take several hours now only takes a few minutes to complete.

    Automatic remediation is very helpful. When an alert is raised, it allows us to trigger bots that can automatically fix the issue. For example, if I'm granting server access to the public, I can create a remediation rule to monitor this. If the rule is violated, the bot will automatically disable public access. This has been very efficient for us.

    We have created custom policy checks for our organization, leveraging industry standards such as CIS and SIPAA. We also perform custom assessments against the policy based on our regulatory requirements. Overall, this helps us to mitigate risks and ensure compliance integrity. It also helps us to build cloud solutions correctly and detect and respond to unauthorized authentication changes and security compromises.

    Unified Security Management provides a single pane of glass view, eliminating the need to toggle between different consoles and service providers to get a complete picture of our security landscape. The solution provides all the answers we need on a single dashboard. Simply connect to the portal to get all the information we need. For example, if we need to understand the details of a specific cloud, such as its name, configuration, and additional attributes, we don't need to log in to the cloud or another service provider. We can simply look up the server within the Unified Security Management dashboard.

    Check Point CloudGuard Posture Management has helped our organization achieve almost 100 percent compliance from zero visibility. I'm proud to say that we upgraded hundreds of thousands of tools and assets against the policy set, and we are now close to 99.6 percent compliant. CloudGuard Posture Management has been very effective for us. In an ever-changing landscape, we ensure that we meet our compliance requirements. Once we have achieved compliance, we can change our policies to make them more stable, and then we strive to meet those standards again.

    We have strong in-house capabilities and a team of developers who have a deep understanding of CloudGuard Posture Management. Using the solution's APIs, we can automate our security. We have been able to segregate workloads, accounts, and assets by department, business, cloud provider, and responsible stakeholders. We can then secure these assets according to our internal business requirements. All of this has been achieved and made possible by the CloudGuard Posture Management platform.

    The best thing about agentless workload posture is that it doesn't impact our production workloads. Other solutions install agents on our system and continuously scan them, which can sometimes cause performance problems. CloudGuard Posture Management, on the other hand, takes a snapshot of our current workloads and scans it offline, which is a more efficient process.

    The solution has helped us reduce our compliance and audit activities. I used to spend a week capturing all the data required for an audit and now I can do it in a couple of hours. With a click of a button, we can run reports to show auditors our compliance for anything in the last run mode. We can also download, share, and view all the details, including how many views are assessed against an account, the outcomes, and the current posture. All of this information is clearly presented in black and white, so we don't have to manage any data ourselves. If we want to report against certain clients, such as those covered by HIPAA, we can get a comprehensive report that we can easily share with our auditors.

    CloudGuard Posture Management has reduced a lot of effort. Before implementing the solution, I had to write a separate script for each platform. Once I had the data, I needed to spend time understanding the output of the scripts and identifying the compliance aspects of compliant assets. I also had to segregate the data for all clouds and then work on it. Finally, I had to repeat the same exercise to see if things had remained secure. This was a very tedious process, but CloudGuard Posture Management has saved us a lot of time.

    CloudGuard Posture Management has saved our SecOps team time. It is connected to our alerting systems and is accessible to all of our security teams. This includes the security team, the operations team, and the backend team. All of these teams have access to the solution and can see the changes that they are implementing and whether or not they are segregating properly. They are also constantly monitoring the alerts that are raised to take corrective action.

    What is most valuable?

    Check Point CloudGuard Posture Management provides a complete overview of all our cloud security solutions. It offers a single-pane-of-glass view of our entire cloud inventory across all cloud service providers.

    Another advantage is that CloudGuard Posture Management supports a wide range of automation capabilities and has access to APIs that we can leverage. For example, I can take proactive actions based on an alert without having to interact with the platform directly.

    What needs improvement?

    The ability to help organizations modify their own policies is essential. For example, consider the CIS benchmark 1.5 for AWS. In the past, I would have added the CIS rulesets to my custom policy, along with my own rules for Internet requirements. This created a custom policy that was tailored to my specific needs. However, the CIS benchmark is constantly changing, and it can be difficult to keep my custom policy up-to-date. As a result, I now have to recreate my entire policy whenever the CIS benchmark is updated. This is a time-consuming and manual process. Adding a feature that allows me to easily identify the changes that have been made to the CIS benchmark and update my own policy accordingly would be a valuable addition to Check Point CloudGuard Posture Management. This would save me a significant amount of time and effort.

    For how long have I used the solution?

    I have been using Check Point CloudGuard Posture Management for seven years.

    What do I think about the stability of the solution?

    Check Point CloudGuard Posture Management is stable.

    What do I think about the scalability of the solution?

    Check Point CloudGuard Posture Management is scalable.

    How are customer service and support?

    Check Point's support needs improvement. Given our extensive knowledge gained over the years, my team has found that we get better support from Check Point's higher-level team than from their basic support team. We only reach out to Check Point support for serious issues, such as product bugs or encounters. We find that basic support is not adequate and that we only get proper support when our issues are escalated.

    How would you rate customer service and support?

    Neutral

    How was the initial setup?

    The initial deployment was straightforward. Two admins from our organization along with some solution architects and one consultant from Check Point helped us with the proof of concept, and we were able to acquire the solution after the POC.

    What was our ROI?

    We have seen close to a 40 percent return on investment with Check Point CloudGuard Posture Management.

    What's my experience with pricing, setup cost, and licensing?

    The pricing is extremely competitive.

    What other advice do I have?

    I would rate Check Point CloudGuard Posture Management ten out of ten.

    If an organization is in the market for a cloud security solution, then it needs a solution like CloudGuard Posture Management. Otherwise, if they are sticking to a specific platform or to a specific service provider like AWS, their tool sets and their solution will be focused on one platform. If they go to Azure, GCP, or any of the other cloud providers, they will be limited. Therefore, I believe that a solution should have flexibility and the ability to function across multiple clouds. Additionally, it should be a solution that grows and evolves. In the time that I have seen Check Point CloudGuard Posture Management, it has grown leaps and bounds and has always stayed ahead of its time. For example, even if an organization has a unique need, CloudGuard Posture Management likely has an academic solution built with the platform. I have not seen this kind of responsiveness from other products.

    Our company is spread across four different cloud platforms, which are located in regions around the globe. All departments use these platforms, which include 550 employees.

    I highly recommend Check Point CloudGuard Posture Management. It has been very helpful to our organization, and we have gained many benefits from it. We have had a positive experience with Check Point CloudGuard Posture Management.

    Which deployment model are you using for this solution?

    Public Cloud
    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    PeerSpot user
    Buyer's Guide
    Download our free Check Point Cloud Firewall (formerly CloudGuard Network Security) Report and get advice and tips from experienced pros sharing their opinions.
    Updated: August 2026
    Buyer's Guide
    Download our free Check Point Cloud Firewall (formerly CloudGuard Network Security) Report and get advice and tips from experienced pros sharing their opinions.