Try our new research platform with insights from 80,000+ expert users

Check Point CloudGuard CNAPP vs Red Hat OpenShift Container Platform comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 13, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Zafran Security
Sponsored
Average Rating
9.6
Reviews Sentiment
7.8
Number of Reviews
6
Ranking in other categories
Vulnerability Management (16th), Continuous Threat Exposure Management (CTEM) (1st)
Check Point CloudGuard CNAPP
Average Rating
8.6
Reviews Sentiment
7.3
Number of Reviews
72
Ranking in other categories
Vulnerability Management (9th), Cloud and Data Center Security (9th), Container Security (10th), Cloud Workload Protection Platforms (CWPP) (5th), Cloud Security Posture Management (CSPM) (5th), Cloud-Native Application Protection Platforms (CNAPP) (5th), Data Security Posture Management (DSPM) (6th), Compliance Management (6th)
Red Hat OpenShift Container...
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
51
Ranking in other categories
Container Management (1st)
 

Mindshare comparison

Vulnerability Management Market Share Distribution
ProductMarket Share (%)
Check Point CloudGuard CNAPP1.5%
Wiz11.7%
Tenable Nessus8.4%
Other78.4%
Vulnerability Management
Container Management Market Share Distribution
ProductMarket Share (%)
Red Hat OpenShift Container Platform20.0%
VMware Tanzu Platform12.5%
Amazon EKS11.5%
Other56.0%
Container Management
 

Featured Reviews

Israel Cavazos Landini - PeerSpot reviewer
Weekly insights and risk analysis facilitate informed security decisions
I appreciate the weekly insights Zafran provides, which include critical topics for networks and IT security, allowing us to evaluate which insights apply to our environment. The organization score feature is valuable to keep the leadership team updated on how our infrastructure fares security-wise. The applicable risk level versus base risk level feature is beneficial because prior to Zafran, we only used the base risk level, but now understand that risk depends on the asset itself. Zafran is an excellent tool.
Bart Coddens - PeerSpot reviewer
Evolved cloud security with active monitoring but needs interface consistency
The user interface needs work. Sometimes, it is a transition from the old tool to the new CNAPP Two that I currently have, and remnants of the old environment can still be detected. I require consistency in the user interface to ensure everything is streamlined into the same look and feel. More work is needed in fine-tuning the threat data towards your CSPM and activity logs, aligning them with business intelligence, which requires a cohesive console interface. My assessment of CloudGuard CDRs in intrusion detection and threat hunting capabilities is that it still needs some work. All the threat data that comes in, you need to fine tune it a bit.
Rifat Rahman - PeerSpot reviewer
Integration and automation have transformed deployment and maintenance
Regarding the learning curve, the customers actually do not need the technical nitty-gritty details; they need to know about the containerization journey because they are not familiar with it. They know it as a theory, but they don't understand anything about its practical implications. That's the main challenge. The solution itself doesn't require a high learning curve; it is actually quite good to manage. However, application developers and managers have to understand the beauty of it, and that is the challenge. If Red Hat can execute some programs regarding that, it will help. Regarding Red Hat OpenShift Container Platform, it is expensive according to market feedback. Notably, the platform plus is perceived as quite expensive and some features from an infrastructure perspective are lacking.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Zafran is an excellent tool."
"We saw benefits from Zafran Security almost immediately after deploying it."
"We are able to see the real risk of a vulnerability on our environment with our security tools."
"Zafran has become an indispensable tool in our cybersecurity arsenal."
"Overall, we have seen about eighty-seven percent reduction of the number of vulnerabilities that require urgency to remediate, specifically the number of criticals."
"The most valuable feature is the separate environment."
"We know the vulnerability in advance, so we can take some action for that vulnerability."
"The CDR helps detect anomalous behavior and respond to threats before they become an issue."
"The most valuable feature is the ability to work with the APIs to integrate into our own backend systems."
"Its monitoring and alerts are triggered by a failure or non-compliance with policies. It helps us to be able to act effectively and quickly."
"Cloud security posture management is the feature we've been using the longest."
"The product enables us to check the information that goes out of the company."
"Dome9 continues to be a major piece of our cloud security architecture and has given our senior leadership team a high degree of confidence in our ability to protect our cloud environment."
"Everything is packaged into OpenShift Container Platform."
"Autoscaling is an excellent feature that makes it very simple to scale our applications as required."
"OpenShift provides tools that tell me everything I have on a container, and I can make it on-premise or on a cloud infrastructure."
"The solution's security throughout the stack and the software supply chain is very reliable. When it was on-prem, it was by default secured by our company firewalls and security tools, and now it's in the cloud, which has its security and systems in place. This provides stability to our infrastructure."
"The most valuable feature of this solution is its scalability on demand, which allows for potentially lower costs, and Built-in resiliency."
"The operating system has a live update and is more secure than any other. It's made for Atomic OS, a lightweight OS new to the market. I also like the source-to-image capabilities. The customer can directly deploy their applications from the repository. It's a highly flexible and easy way to deploy into production."
"It is very lightweight and can be deployed very fast, especially when it comes to containers."
"The initial setup process is easy."
 

Cons

"The dashboarding and reporting functionality of Zafran Security is an area that definitely could use some improvements."
"Initially, we were somewhat concerned about the scalability of Zafran due to our large asset count and the substantial amount of information we needed to process."
"I think the ability to have some enhanced reporting capabilities is something they can improve on, as they have good reports but we have asked for some specific reporting enhancements."
"The biggest thing is the documentation aspect of Dome9 is a little lacking. They were purchased by Check Point about a year and a half to two years ago. When they integrated into Check Point's support system, a lot of the documentation that they had previously got mangled in the transition, e.g., linking to stuff on the Dome9 website that no longer exists. There are still a lot of spaces with incomplete links and stuff that is not as fully explained as it could be."
"In Dome9, there should be a policy validation option where we can validate the policy before we push it into production."
"The reporting dashboard responds slowly, which leads to late report compilation."
"Dome9 should also support deployments that are on-premises and in a hybrid cloud."
"Making basic rules is easy, but it's complex if you want to do something a little more nuanced. I've been unable to make some rules that I wanted. I couldn't evaluate some values or parameters of the components I look for. I haven't always been able to assess them."
"We were demotivated by the lack of native automation modules for the Terraform and Ansible tools."
"The Check Point Infinity admin portal sometimes freezes."
"Check Point must provide a multi-cloud facility where AWS, Azure, and GCP can seamlessly work together and display posture in an integrated manner."
"The interface has numerous UI bugs that need addressing."
"In my experience, the issues are not always simply technical. They do stem from technical challenges, but they struggle with the topic of adoption. When you encounter all of the customer pull, there are normally several tiers of your client pop that can adopt either the fundamental features or a little more advanced ones. The majority of the time, the challenge is determining how to drive adoption, how to sell the product to the customer, and how much time they can spend to really utilize those advanced features. If we get into much more detail, but this is from my perspective as the platform engineer and not the end customer, the ability of the end user to be able to debug potential issues with their application That is arguably the most important, let's say, work throughput in my area."
"The initial setup can be hard."
"The support costs are too high."
"It can take 10 to 15 minutes to deploy a microservice. The CI/CD process takes a long time, and if it's because of OCP, that is something that can be changed."
"OpenShift has a pretty steep learning curve. It's not an easy tool to use. It's not only OpenShift but Kubernetes itself. The good thing is that Red Hat provides specific targeted training. There are five or six pieces of training where you can get certifications. The licenses for OpenShift are pretty expensive, so they could be cheaper because the competition isn't sleeping, and Red Hat must take that into account."
"It is difficult to deploy the OpenShift cluster in a bare-metal environment."
"There is room for improvement with integration."
 

Pricing and Cost Advice

Information not available
"It is a very straightforward licensing model that is based on the number of assets you are discovering and managing with the solution."
"In the beginning, the price of Dome9 was cheap, whereas now it is not."
"CloudGuard is fairly priced."
"We have the enterprise-level license and we renew it annually because it is worth the cost."
"The licensing and costs are straightforward, as they have a baseline of 100 workloads (number of instances) within one license with no additional nor hidden charges. If you want to have 200 workloads under Dome9, then you need to take out two licenses for that. Also, it does not have any impact on cloud billing, as data is shared using the API call. This is well within the limit of free API calls provided by the cloud provider."
"The price is on the higher end."
"It is difficult to contextualize the pricing because we are used to Indian pricing and licensing."
"The license for CloudGuard Posture Management is about $80 a year, and it's based on your cloud footprint, not the number of users. So you could have a million users, and it doesn't matter."
"I'm not familiar with pricing or financial aspects. In terms of effort versus benefit, it's worth it."
"Its licensing is completely incomprehensible. We have special people within our company. They discuss with Red Hat subscription managers. It is too complex, and I do not understand it. We are from the government, and we are trying to be as cheap as possible. Sometimes, I am just amazed at the amount of money that we have to pay. It is crazy."
"It largely depends on how much money they earn from the application being deployed; you don't normally deploy an app just for the purpose of having it. You must constantly look into your revenue and how much you spend every container, minute, or hour of how much it is working."
"The pricing and licensing are handled on an upper management level, and I'm not involved in that, but I understand the solution to be somewhat pricey."
"We have to pay for the license."
"The product is expensive."
"OpenShift Container Platform is highly-priced."
"OpenShift with Red Hat support is pretty costly. We have done a comparison between AWS EKS (Elastic Kubernetes Services) which provides fully managed services from AWS. It's built on open-source-based Kubernetes clusters and it is much cheaper compared to Red Hat, but it is a little expensive compared to ECS provided by AWS."
report
Use our free recommendation engine to learn which Vulnerability Management solutions are best for your needs.
866,300 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
11%
Computer Software Company
10%
Manufacturing Company
7%
Healthcare Company
5%
Computer Software Company
13%
Financial Services Firm
11%
Manufacturing Company
8%
Educational Organization
6%
Financial Services Firm
21%
Computer Software Company
11%
Government
8%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business54
Midsize Enterprise16
Large Enterprise56
By reviewers
Company SizeCount
Small Business14
Midsize Enterprise4
Large Enterprise39
 

Questions from the Community

What is your experience regarding pricing and costs for Zafran Security?
Since we stood Zafran Security up in our private cloud, we handle the maintenance on our side. As we opted not to use...
What needs improvement with Zafran Security?
In terms of areas for improvement, Zafran Security is doing a really great job as a new and emerging company. Oftenti...
What is your primary use case for Zafran Security?
My use cases for Zafran Security revolve around two primary areas. One is around vulnerability management and priorit...
Which is better - OpenShift Container Platform or VMware Tanzu Mission Control?
Red Hat Openshift is ideal for organizations using microservices and cloud environments. I like that the platform is ...
What do you like most about OpenShift Container Platform?
The tool's most valuable features include high availability, scalability, and security. Other features like advanced ...
What is your experience regarding pricing and costs for OpenShift Container Platform?
The current licensing cost for this solution is around $23,000 per year, per month. Regarding the current licensing c...
 

Also Known As

No data available
Check Point CloudGuard Posture Management, Dome9, Check Point CloudGuard Workload Protection, Check Point CloudGuard Intelligence
No data available
 

Overview

 

Sample Customers

Information Not Available
Symantec, Citrix, Car and Driver, Virgin, Cloud Technology Partners
Edenor, BMW, Ford, Argentine Ministry of Health
Find out what your peers are saying about Check Point CloudGuard CNAPP vs. Red Hat OpenShift Container Platform and other solutions. Updated: October 2024.
866,300 professionals have used our research since 2012.