Try our new research platform with insights from 80,000+ expert users

Check Point CloudGuard CNAPP vs Netskope comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Apr 6, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Zafran Security
Sponsored
Average Rating
9.4
Reviews Sentiment
8.2
Number of Reviews
5
Ranking in other categories
Vulnerability Management (18th), Continuous Threat Exposure Management (CTEM) (2nd)
Check Point CloudGuard CNAPP
Average Rating
8.6
Reviews Sentiment
7.4
Number of Reviews
71
Ranking in other categories
Vulnerability Management (9th), Cloud and Data Center Security (9th), Container Security (9th), Cloud Workload Protection Platforms (CWPP) (5th), Cloud Security Posture Management (CSPM) (5th), Cloud-Native Application Protection Platforms (CNAPP) (5th), Data Security Posture Management (DSPM) (6th), Compliance Management (6th)
Netskope
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
46
Ranking in other categories
Cloud Access Security Brokers (CASB) (3rd), Secure Access Service Edge (SASE) (4th)
 

Mindshare comparison

Vulnerability Management
Cloud Access Security Brokers (CASB)
 

Featured Reviews

Israel Cavazos Landini - PeerSpot reviewer
Weekly insights and risk analysis facilitate informed security decisions
I appreciate the weekly insights Zafran provides, which include critical topics for networks and IT security, allowing us to evaluate which insights apply to our environment. The organization score feature is valuable to keep the leadership team updated on how our infrastructure fares security-wise. The applicable risk level versus base risk level feature is beneficial because prior to Zafran, we only used the base risk level, but now understand that risk depends on the asset itself. Zafran is an excellent tool.
Bart Coddens - PeerSpot reviewer
Evolved cloud security with active monitoring but needs interface consistency
The user interface needs work. Sometimes, it is a transition from the old tool to the new CNAPP Two that I currently have, and remnants of the old environment can still be detected. I require consistency in the user interface to ensure everything is streamlined into the same look and feel. More work is needed in fine-tuning the threat data towards your CSPM and activity logs, aligning them with business intelligence, which requires a cohesive console interface. My assessment of CloudGuard CDRs in intrusion detection and threat hunting capabilities is that it still needs some work. All the threat data that comes in, you need to fine tune it a bit.
Benjamin Naranjo - PeerSpot reviewer
Provides secure remote access and web navigation protection with highly customizable features
The most helpful features in Netskope are the data loss prevention module, the anti-malware module, and the integration that it has with Information Rights Management from Microsoft. It has better categorization and more granular features regarding web protection, as it allows me to control HTTP methods. I can publish WhatsApp web for my users as read-only, for example. Other providers cannot; they are only on and off, and do not have the granularity for a website to be read-only. That comes with a downside, which is that they need to regularly update their controls to support those features in those websites.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Overall, we have seen about eighty-seven percent reduction of the number of vulnerabilities that require urgency to remediate, specifically the number of criticals."
"Zafran has become an indispensable tool in our cybersecurity arsenal."
"We saw benefits from Zafran Security almost immediately after deploying it."
"We are able to see the real risk of a vulnerability on our environment with our security tools."
"Zafran is an excellent tool."
"Most of the features are pretty valuable, whether that's a description of the attacks or the attack graph showing the vulnerabilities. If a single tool does all this work, the value is centralizing all these functions on a single tool. These are the cloud-native applications we talk about — containers, Kubernetes, and cloud infrastructure — and all those things are the primary focus of the CNAPP solution."
"On Dome9, you can have reports on compliance, users created, and EAM access to the cloud infrastructure. For example, if some machine is exposed to the Internet, importing and exporting to the Internet when it shouldn't, we get immediate alerts if someone does this type of configuration by mistake. Dome9 is very important because AWS doesn't protect us for this. It is the client's responsibility to make sure that we don't export things to the Internet. This solution helps us ensure that we comply with our security measures."
"Dome9 wraps our FTP infrastructure with its network security configurations, and this also gives us the ability to monitor FTP activity."
"I love the work involved in maintaining and scaling security services and configurations across multiple public clouds using this solution, versus using native native cloud security controls. It is so much better. The different cloud platforms all have their own way that they handle a lot of the stuff that Dome9 handles. Even within their platform, they are in a lot of disparate places, e.g., in AWS, there are five different tools. You have to jump between them to get the same information that you can just pull in automatically on Dome9, which is just one platform. We are using multiple platforms, so that makes it even more complicated and time consuming if you had to just rely on them to get all of your information. Whereas, it's all just summarized and put together on the Dome9 end."
"People implementing this solution are concerned with addressing a significant risk, and within the AWS realm, this tool does de-risk substantially."
"The new scanning function is a valuable feature that wasn't available until recently."
"Visibility is a key feature. It helps me to validate my overall network posture."
"The cloud security posture management identify the risks that are the most critical to our business. We can define certain key assets that are your crown jewels. And whenever something hits on these crown jewels, you get a very high score. So you can really fine tune towards protecting your risk based assets in the cloud."
"Netskope started with a cloud-first approach, which makes it adaptable to the day-to-day changes that the cloud will generate."
"The most valuable features of the solution are that the support is very good and the dashboards are easy and intuitive to use."
"Technical support is good. They are very helpful and quick to resolve any issues we have."
"It is a very scalable tool."
"It has hundreds of features and many of them are useful."
"Amazing reporting and tracking mechanisms."
"The tool provides extensive DLP features."
"The interface is good."
 

Cons

"I think the ability to have some enhanced reporting capabilities is something they can improve on, as they have good reports but we have asked for some specific reporting enhancements."
"Initially, we were somewhat concerned about the scalability of Zafran due to our large asset count and the substantial amount of information we needed to process."
"The dashboarding and reporting functionality of Zafran Security is an area that definitely could use some improvements."
"Their service needs improvement."
"The security of Check Point CloudGuard Posture Management could improve. There are always new security issues coming out."
"Streamlining the user interface would greatly improve the user experience."
"I would appreciate a way to receive periodic updates, like through email. I am the kind of person who likes to receive data passively."
"Timely updates and upgrades to meet modern technological changes could help improve performance and limit the chances of downtime."
"Currently, worldwide, there are many companies of all sizes that do not understand the value that their data has, but even with all existing clouds, they also do not understand what the shared responsibility model is. They only assume that by having a cloud, the provider must ensure safety, when the truth is that the providers only secure their sites. Everything we do in the cloud and how we configure it is actually our responsibility."
"The price of this solution should be reduced so that it is more affordable to scale."
"Check Point tools need to improve the latency in the portal since they take a long time to load."
"The solution's documentation still needs to be improved."
"Accuracy could be improved."
"Netskope's pricing is very high compared to other vendors, and compared to Zscaler, Netskope has less capability."
"I would like to see the product improved, especially in monitoring and security monitoring. It should be more effective so we can better identify cloud access and understand how users are accessing it. We need better visibility on security and cloud storage access."
"Compatibility with other proxy polars would be helpful."
"The threat protection features must be improved."
"They could add endpoint security features."
"Technical support and the user interface could be improved."
 

Pricing and Cost Advice

Information not available
"Check Point CloudGuard Posture Management is expensive."
"It is a very straightforward licensing model that is based on the number of assets you are discovering and managing with the solution."
"The license for CloudGuard Posture Management is about $80 a year, and it's based on your cloud footprint, not the number of users. So you could have a million users, and it doesn't matter."
"We have the enterprise-level license and we renew it annually because it is worth the cost."
"The licensing and costs are straightforward, as they have a baseline of 100 workloads (number of instances) within one license with no additional nor hidden charges. If you want to have 200 workloads under Dome9, then you need to take out two licenses for that. Also, it does not have any impact on cloud billing, as data is shared using the API call. This is well within the limit of free API calls provided by the cloud provider."
"The license fee is high."
"The pricing is extremely competitive."
"​They support either annual licensing or hourly. At the time of our last negotiation, it was either one or the other, you could not mix or match. I would have liked to mix/match. ​"
"Licensing fees are paid annually."
"The price of the solution is fair but it depends on your use case."
"They should work on licensing costs."
"It is an expensive solution."
"Pricing is a little expensive but it is affordable."
"The pricing is competitive."
"On a scale from one to ten, where one is expensive, and ten is cheap, I rate the solution's pricing a six out of ten."
"The tool's pricing is not too cheap or expensive. However, it can be costly for a small business."
report
Use our free recommendation engine to learn which Vulnerability Management solutions are best for your needs.
860,592 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
11%
Financial Services Firm
11%
Manufacturing Company
7%
Healthcare Company
6%
Financial Services Firm
13%
Computer Software Company
13%
Manufacturing Company
8%
Educational Organization
5%
Computer Software Company
16%
Financial Services Firm
13%
Manufacturing Company
9%
Insurance Company
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for Zafran Security?
The current pricing of Zafran Security is fair overall. They were good to work with to accommodate our organization w...
What needs improvement with Zafran Security?
The dashboarding and reporting functionality of Zafran Security is an area that definitely could use some improvement...
What is your primary use case for Zafran Security?
Zafran Security is helping reduce the amount of critical vulnerabilities in our environments that require prompt reme...
Which is better, Zscaler internet access or Netsckope CASB?
We researched Netskope but ultimately chose Zscaler. Netskope is a cloud access security broker that helps identify ...
What do you like most about Netskope CASB?
The product's analytics part is pretty fine.
 

Also Known As

No data available
Check Point CloudGuard Posture Management, Dome9, Check Point CloudGuard Workload Protection, Check Point CloudGuard Intelligence
Netskope CASB
 

Overview

 

Sample Customers

Information Not Available
Symantec, Citrix, Car and Driver, Virgin, Cloud Technology Partners
NetApp, Genomic Health, Caterpillar, Apollo, Pandora, Continental Resources, Fractal, infinera, Tesla
Find out what your peers are saying about Qualys, Wiz, Tenable and others in Vulnerability Management. Updated: June 2025.
860,592 professionals have used our research since 2012.