No more typing reviews! Try our Samantha, our new voice AI agent.

Cisco Security Cloud Control vs Skybox Security Suite comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Feb 8, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cisco Security Cloud Control
Ranking in Firewall Security Management
12th
Average Rating
8.2
Number of Reviews
14
Ranking in other categories
No ranking in other categories
Skybox Security Suite
Ranking in Firewall Security Management
8th
Average Rating
7.6
Reviews Sentiment
6.2
Number of Reviews
38
Ranking in other categories
Vulnerability Management (50th)
 

Mindshare comparison

As of September 2026, in the Firewall Security Management category, the mindshare of Cisco Security Cloud Control is 4.3%, up from 1.5% compared to the previous year. The mindshare of Skybox Security Suite is 7.8%, down from 9.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewall Security Management Mindshare Distribution
ProductMindshare (%)
Skybox Security Suite7.8%
Cisco Security Cloud Control4.3%
Other87.9%
Firewall Security Management
 

Featured Reviews

FS
Security Engineer at Metrobank
Automation reduces intervention and speeds up threat prevention
Our primary use case for Cisco Defense Orchestrator is the automation of playbooks. We primarily use it for this purpose to streamline processes The most valuable feature is the automation, as it reduces user intervention and allows us to focus on other tasks. Since the system is automated,…
AnoopBhat - PeerSpot reviewer
Security Architect at a tech vendor with 5,001-10,000 employees
Firewall policy management has improved access control but still needs simpler setup and upgrades
The features that I appreciated the most in Skybox Security Suite were not comparable with Tufin, as Tufin was far ahead in terms of the technology and the user interface. The effectiveness of the vulnerability management in Skybox Security Suite is an area I have not used that much. The firewall management feature has streamlined rule configuration and compliance in Skybox Security Suite and has evolved over time, but Tufin is far better. In terms of comparison between both tools, only the licensing part of Skybox had an edge. We were not renewing the licenses of Skybox every year, but in the case of other tools, we would have to renew if we wanted to use those tools. The disadvantages and weaknesses of Skybox Security Suite include the interface, complexity with setup, and upgrading. There are some smaller issues as well that would take more time to discuss, but there are ways around them. We use this tool to implement a new policy on the firewall by going to Skybox, creating a flow there, and then using an approval mechanism in place. There are two different levels of approvals which we have to go through, and once both approvers approve the request, we are ready to implement it. A specific challenge is that if we have to create a new object group and place ten different objects in that and use that object group in two different rules, we have to create the object group in the first rule and add the ten new objects. Then if we have to create another rule, we do not get an option to recall or reuse that same group which we created in the previous rule. We have to create a new object group again and then add the objects into it again. If we had created an object group once, we should have gotten an option to recall that or call that object group in the new rule, and that should have made the process easier.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"This product provides excellent centralized device controls and reporting."
"The main return on investment is time, and the first time a firewall went down the savings probably exceeded what CDO costs."
"It is saving us at least a week's worth of work because we can log in and instantly see what version all the ASAs are at and which ones need to be upgraded."
"The most valuable feature is being able to do centralized upgrades on the ASAs. We can select all of those ASAs, and say, "Upgrade these ASAs at this scheduled time." It will copy down the ASA image, ASDM image, and then do the upgrade and failovers, and then put it all back into service as required at a scheduled time. It automates that process for us."
"The most valuable feature is the automation, as it reduces user intervention and allows us to focus on other tasks."
"We are using this solution for filtering and blocking some websites, as a firewall, and as the main tool for network segmentation and intrusion prevention, blocking malware and malicious activity."
"We have quite a few Active Stone by pairs. If they fail over... I'll see that there's a change on it and I'll have a look. The only change on it is that now this one is the standby, it took over the active role. I can go into that firewall and find out what happened... and troubleshoot based on that. That's pretty cool too."
"Before CDO, we had to spend hours and hours to update ten devices, but now, with one simple click, we select the devices, set them to update on a given day, save different configurations, and it's pretty simple and a great feature for us."
"The solution's most valuable and unique assets are the vulnerability management and change management solutions because they identify mistakes in the network before implementation which reduces risks."
"It's very supportive and very user-friendly."
"What we have done is found a lot of misconfigured stuff on firewalls."
"I really like the product."
"Skybox deployment is simple, and it's very useful."
"The solution offers very nice dashboards and they've recently added a very good Java-based web interface."
"Network path analysis is the most valuable feature."
"Security review is the most important feature, because it offers a single pane of glass to analyze multiple firewalls."
 

Cons

"If I make a change locally to the firewall, CDO gives an alarm or an error message and says there's a change in compliance: "The firewall has this configuration but the last time it was compiled it had that configuration." That view of new changes versus the old could be better... I had to log in manually, locally on the firewall, to check which version, which configuration was actually running. I couldn't see it in CDO."
"We had some MX devices that were blocking Windows Update from happening. We found out it was a Meraki issue, but it would have been nice if it had been flagged for us: "Hey, these updates are failing because the MX is blocking it." It wasn't a huge problem, but there was a loss of our time as well as the fact that the updates didn't get pushed out... It would have been nice if CDO had let us know that that was an issue."
"Cisco Defense Orchestrator should be made more user-friendly overall. Currently, to use it effectively, one must be specific with the rule set that needs to be set up."
"There could be some slight improvements to navigation."
"They can also provide an on-premises solution. Currently, Cisco Defense Orchestrator is just for cloud deployments, not for on-premises deployments."
"If I had to say anything negative it's the price point."
"There could be some slight improvements to navigation. In some of the navigation you've got to go back to be able to get into where you need to be once you've made a change. If I make a change, I've then got to go back to submit and send the change."
"The main thing that would useful for us would the logging and monitoring. I have to check it out, to get the beta, because I don't have access to them... I wanted CDO to be a central place so where I could do everything but right now I don't think that's possible. I really don't want to go back and forth between this and FMC. Maybe the logging portion, when I look at it, will give me some similarities."
"There is room for improvement in the product's user interface. It could be more user-friendly."
"The solution does not support certain devices or vendors in some regions or countries due to regulations."
"The support could be improved."
"If anything could be improved it would be staying on top of the collector scripts, but I understand that's a very tough challenge."
"Skybox Suite is an unstable solution."
"The dashboard's UI is not interesting; it is quite normal. It would be better if something more attractive or similar useful information found in AlgoSec was available."
"I've had issues with licensing where, when they were expiring and I asked for the updated licenses, I would the wrong ones. I think their process needs to be straightened out a little bit - I don't know if they fixed it already, it has been awhile. It wasn't as straightforward as it could have been."
"The solution was quite technical. It would be easier to manage if the solution was more specific about aspects of the solution and provided more advisory around how to use it effectively. It would help users a lot if they were more clear about everything."
 

Pricing and Cost Advice

"After our free trial was done we got a subscription for three years and it was under $3,000 or so. It's part of the EA we already paid for, so I don't know what it would be if it was a la carte."
"It is about a $100 per year for an ASA 5506 firewall, and from there it keeps going up if you have a bigger box. For example, the 5516 is $200 to $300 per year."
"If you compare to what is available on the market, they are in the same range with respect to pricing."
"I work with a lot of clients, and the price or value of the Cisco Defense Orchestrator can vary from one client to another. If you have a lot of Cisco solutions, the price of the Cisco Defense Orchestrator is justified. Whereas if you have some security components from other vendors, such as Check Point or Palo Alto. This solution would be a pretty expensive proposition considering that they don't integrate with them well."
"It's around £500 per unit for a three-year license."
"It is covered under the CIsco Enterprise License Agreement (ELA). So, it is licensed and ours."
"Licensing is normally on a yearly basis. There may also be a perpetual license. Normally, the customers ask for a lower price. If you want to sell more, you have to think about it."
"I think the price is fair."
"The price of the Skybox Security Suite can be expensive."
"The software is expensive. I rate its pricing an eight out of ten."
"The pricing has increased exorbitantly in the last few years, so now it is questionable. Now, it makes me want to review other products."
"Skybox comes with extra licenses and has a change management license. The licenses are expensive, but they come with extra value."
"I've seen the pricing of every solution on the market. When you compare apples to apples, where Skybox becomes exceedingly expensive is if you look at it compared to something like FireMon that only does a fraction of what Skybox does. But if you include everything that Skybox does, it becomes way more expensive than the competition, but you're also not comparing apples to apples. If you look at FireMon, and you look at like just the firewall assurance piece, they are fairly comparable and, actually, Skybox comes in a little bit cheaper in some cases, depending on which product you're looking at."
"Pricing is on the higher side. In terms of licensing, you should buy the complete suite rather than buying only the Change Manager. I think Change Manager with Vulnerability Control is something that would be interesting to look at."
report
Use our free recommendation engine to learn which Firewall Security Management solutions are best for your needs.
913,806 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
14%
Manufacturing Company
11%
Construction Company
10%
Comms Service Provider
6%
Financial Services Firm
15%
Manufacturing Company
9%
Computer Software Company
8%
Construction Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business6
Midsize Enterprise3
Large Enterprise5
By reviewers
Company SizeCount
Small Business21
Midsize Enterprise4
Large Enterprise21
 

Questions from the Community

What needs improvement with Cisco Defense Orchestrator?
Cisco Defense Orchestrator should be made more user-friendly overall. Currently, to use it effectively, one must be specific with the rule set that needs to be set up. Additionally, I suggest impro...
What is your primary use case for Cisco Defense Orchestrator?
Our primary use case for Cisco Defense Orchestrator is the automation of playbooks. We primarily use it for this purpose to streamline processes.
What advice do you have for others considering Cisco Defense Orchestrator?
Those who want to use Cisco Defense Orchestrator should build their own use case and see if it fits their environment. The most significant benefit for us is the response time because it automates ...
What is your experience regarding pricing and costs for Skybox Security Suite?
From a commercial perspective, AlgoSec is more expensive compared to Skybox Security Suite. Skybox Security Suite is cost-effective.
What needs improvement with Skybox Security Suite?
The features that I appreciated the most in Skybox Security Suite were not comparable with Tufin, as Tufin was far ahead in terms of the technology and the user interface. The effectiveness of the ...
What is your primary use case for Skybox Security Suite?
Skybox Security Suite is primarily used for allowing access on firewalls and getting the access to allow some connectivity on the firewall.
 

Also Known As

Cisco Defense Orchestrator, CDO
No data available
 

Interactive Demo

Demo not available
 

Overview

 

Sample Customers

Insurance Company of British Columbia, Shawmut
ADP, Blue Cross Blue Shield, BT, USAID, Delta Dental, EDF Energy, EMC, HSBC, Johnson & Johnson
Find out what your peers are saying about Cisco Security Cloud Control vs. Skybox Security Suite and other solutions. Updated: September 2026.
913,806 professionals have used our research since 2012.