We have implemented it on an industrial network to monitor the production of medicines. This is something that is very controlled by Brazilian regulations and we have to keep an audit trail for this data. Trying to enable it on SQL Server - that was our client's main server - the load would go so high that they couldn't use the application anymore. They are using Guardium now so they can produce that audit trail for audit compliance.
Cyber Security Architect at a tech services company with 11-50 employees
Our clients use Accelerators to help with PCI and GDPR compliance
Pros and Cons
- "We have integrated IBM Guardium with IBM Watson Curator. They access Curator to identify and correlate other actions the user is doing to determine if this is a legitimate action or not."
What is our primary use case?
How has it helped my organization?
We have integrated IBM Guardium with IBM Watson Curator. They access Curator to identify and correlate other actions the user is doing to determine if this is a legitimate action or not.
In terms of advanced features, our clients are starting to implement it on an order basis so they can get to GDPR and the like; those Accelerators. They also use it a lot for PCI, to get access to credit cards.
Guardium has saved us time and money, mainly on the discovery process and senior management is aware of this, of course.
What is most valuable?
The Audit Trail.
What needs improvement?
They could improve the Data Masking a little.
Buyer's Guide
IBM Security Guardium Data Protection
September 2025

Learn what your peers think about IBM Security Guardium Data Protection. Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
868,759 professionals have used our research since 2012.
What do I think about the stability of the solution?
Stability is quite good. We had some problems, but support is very effective so we were able to solve them very quickly.
We had instability with reports, they were giving some errors. I don't know exactly what had happened because I wasn't the one involved, but we couldn't access reports.
How are customer service and support?
Tech support is very good.
Which solution did I use previously and why did I switch?
We knew we needed to switch because of that problem with the audit trail, that SQL couldn't keep up with what we needed to do for auditing. That's why we had to search for a new solution.
How was the initial setup?
It's very easy.
What other advice do I have?
I would rate it an eight out of 10 because it is very stable; we had some problems but they were solved, and we can do what we need to do.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner.
President at a tech vendor with 1-10 employees
Helps us support security initiatives and compliance policies like HIPAA and PCI
Pros and Cons
- "It provides a comprehensive security for databases, both on-prem and on the cloud. Among the advanced features we use automatic backups, DR."
- "More predictive, using Watson AI would be good."
What is our primary use case?
To provide cyber security for databases.
It has performed very well.
How has it helped my organization?
It has made us more responsive and more productive, more efficient.
We use Guardium to support security initiatives and compliance policies. We are in the healthcare world, so it helps us with HIPAA compliance. It has also helped us with PCI. We haven't gone with GDPR.
We have not yet integrated Guardium with other systems we use.
It has saved us time and money by definitely making us more productive. Senior management is aware of this.
What is most valuable?
It provides a comprehensive security for databases, both on-prem and on the cloud.
Among the advanced features we use automatic backups, DR. We'd like to implement more predictive, using Watson.
What needs improvement?
More predictive, using Watson AI would be good.
What do I think about the stability of the solution?
It's very stable.
What do I think about the scalability of the solution?
It's scalable.
How are customer service and technical support?
We sometimes use technical support from IBM. It has been good, very good.
Which solution did I use previously and why did I switch?
We were using traditional cyber security stuff. But this is a pretty good product. We became an IBM business partner, we are a cyber security business partner for IBM. We have other products besides Guardium that we are marketing.
The most important criteria when selecting a vendor are their
- stability
- quality
- support.
How was the initial setup?
It was straightforward.
What other advice do I have?
Buy it.
Disclosure: My company has a business relationship with this vendor other than being a customer. IBM Business Partner.
Buyer's Guide
IBM Security Guardium Data Protection
September 2025

Learn what your peers think about IBM Security Guardium Data Protection. Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
868,759 professionals have used our research since 2012.
Database Administrator at a financial services firm with 11-50 employees
Automates detection of access to restricted data across our multiple platforms
Pros and Cons
- "It does not require our involvement to run it. It runs in the background and the people that do the reporting do so. The reports go to the directors who are in charge of the various data areas. It's pretty clean. Clearly there is some setup, but after you get it set up it just goes."
- "This is a multi-platform solution that consolidates everything and centralizes support for it."
What is our primary use case?
It's a security product that works across multiple platforms, in our case it's the mainframe and the midrange. We use it to detect when somebody accesses restricted data and report on it.
So far it has performed quite well, we're happy with it.
How has it helped my organization?
We used to use cobbled-together scripts, different products and different pieces on different platforms. This is one consolidated tool so one report comes out for each director and it's clean and easy. There is some scripting involved to tell it what is important and what is not important - which is important to us.
In terms of security initiatives and compliance policies within our organization, that's basically what we use it for: the reporting of who touches what data. And that goes up to the directors and they approve or get mad at you and ask you why you did something.
IBM Guardium probably helps us comply with industry regulations like SOX, PCI, or GDPR, but the big driver was more internal and audit-related, rather than industry-related.
We haven't integrated Guardium with other systems we have.
It has saved us time and money. As I mentioned, we had a bunch of cobbled-together scripts that were manually maintained for different platforms. This solution automated all that and made it such that the security administrators can run it themselves and not involve us. So there is less "people effort." Senior management is aware of the savings.
What is most valuable?
It makes the auditors happy.
It does not require our involvement to run it. It runs in the background and the people that do the reporting do so. The reports go to the directors who are in charge of the various data areas. It's pretty clean. Clearly there is some setup, but after you get it set up it just goes.
I have no idea what the advanced features are, so we're probably not using them.
What needs improvement?
Lower pricing would always be good but apparently we're getting our money's worth or we wouldn't be using it.
What do I think about the stability of the solution?
I'm pretty impressed with the stability. There was medium-sized initial effort getting it configured and set up and doing what we wanted it to do, but it just runs and we don't have to deal with it.
What do I think about the scalability of the solution?
We run it on the mainframe and on the midrange platforms and we haven't had any performance issues of any kind. We haven't really had to scale it. We pick and choose what's important to us, so we don't monitor everything. If we were going to monitor everything it would probably be an issue, something we would have to address.
How are customer service and technical support?
I have not used tech support personally. We did have some support help at the beginning, learning it and getting it set up.
Which solution did I use previously and why did I switch?
We were previously using homegrown scripts. We decided to switch primarily because this is a multi-platform solution that consolidates everything and centralizes support for it.
When selecting a vendor, we reviewed two other products, but the main reason was that this is a multi-platform solution and it worked well in our environment.
How was the initial setup?
I was not directly involved but I was involved somewhat since I had worked with some of the systems in the past, so maybe some requirements gathering.
The setup seemed pretty straightforward to me.
What other advice do I have?
We're very happy with it. It depends on what your needs are, but it meets our needs.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Guardium Engineer
Helps make us more compliant with regulatory requirements but cost outweighs benefits
What is our primary use case?
We want to protect our data. That's the primary use case.
So far, performance has been okay.
How has it helped my organization?
We are able to identify who does what, when, and we are able to go back to them and say, "Is this an authorized activity? Is it not an authorized activity?" Why are they doing it? Is there an outlier? Go back and find out if that is normal, unusual? It has helped the overall perspective of making our operations more compliant with the regulatory requirements.
We use Guardium to support security initiatives and compliance policies in our organization. For example, we create reports that tell us how often is a password locked, how many exceptions we are getting, how many failed login items we are getting. We send those reports to the compliance and auditing folks. We do vulnerability assessments, detect vulnerabilities and send reports.
Currently we are not focused on GDPR because we are mainly a US-based company. I don't think I would say that Guardium has saved us time or money.
What is most valuable?
It does the monitoring of access very well, although we currently don't use any of the advanced features.
What needs improvement?
Get rid of the collectors. Stream the data directly from the agents to the Big Data link.
What do I think about the stability of the solution?
The solution is very stable, but it has its challenges.
How are customer service and technical support?
I would rate tech support about seven out of 10.
Which solution did I use previously and why did I switch?
This was a management decision. I think when they found Anthem was getting breached they decided, "Hey, let's try something else."
When selecting a vendor, the most important criteria for me are the
- reliability of the vendor
- name recognition
- support model
- cost, of course.
How was the initial setup?
If you know it, it's pretty straightforward. Otherwise, there is a little learning curve.
What's my experience with pricing, setup cost, and licensing?
The biggest challenge is the cost associated with the product, and the cost of maintaining. Everything is not translated directly to the benefits we see. There are benefits, yes, but if I were writing the check, would I buy Guardium? No.
Which other solutions did I evaluate?
It's pretty good. We have the latest version, so we are able to scale.
What other advice do I have?
I would rate this solution six out of 10. The benefit to the cost is not justified, in my opinion.
I would say Guardium is a good product. It's a very good product, but you want to weigh how much you want to implement. Do you want to focus on only certain applications? Certain databases? Don't do it across the enterprise. So think about that.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Security Manager at a healthcare company with 10,001+ employees
We use it to support security initiatives and combine policies within the organization
Pros and Cons
- "Our ability to see when users are accessing sensitive data."
- "We use IBM Guardium to support security initiatives and combine policies within the organization."
- "The front-end works very well."
- "Gathering the data works very well. "
- "One of the limitations that everyone who uses Guardium knows is its ability for back-end reporting. The ability to collect it sometimes is easier than the ability to retrieve it, use it, or give a good representation of it for incidence response or questions which come from the different people who want to use the data."
- "Using the data in native Guardium is difficult, at best."
What is our primary use case?
Primarily re-monitoring sensitive data and privilege user access.
How has it helped my organization?
One of the greatest benefits for using Guardium is our ability to monitor sensitive data. With current policy and GDPR for international, then audited compliance for monitoring access to sensitive data, it is very critical for our industry in healthcare.
We use IBM Guardium to support security initiatives and combine policies within the organization. We have many initiatives that come up and we have what are called action plans. Guardium comes up in quite a few of them when it gets related to database monitoring and controlling sensitive data.
IBM Guardium helps us comply with industry regulations, such as GDPR, local US standards, and then the current New York cyber laws, which are very specific about controlling access to data.
Guardium is integrated for data. It is integrated across our big data, then for cyber security. It is integrated in our security stack.
What is most valuable?
- Our ability to see when users are accessing sensitive data.
- The front-end works very well.
- Gathering the data works very well.
We are using quite a few of the advanced features. Some of those include some scripting for integration with our other security tools in the environment along with data collection, and the ability to use large data formats for monitoring and information.
What needs improvement?
One of the limitations that everyone who uses Guardium knows is its ability for back-end reporting. Guardium in and of itself is a big data platform. It creates big data all by itself. The ability to collect it sometimes is easier than the ability to retrieve it, use it, or give a good representation of it for incidence response or questions which come from the different people who want to use the data.
Then, it goes back to the use of the data. Using the data in native Guardium is difficult, at best. I know there are current advancements. I know they are integrated with jSonar, which used to be a partnership. However, it is now integrated into the company, which is nice, but we are far beyond that. We have already purchased and implemented other solutions, so now we have to go back and retroactively add that, which would be a good addition, but we are just not there today.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
Guardium is very stable. The only outages that we have had have been self-induced, which is hard to admit. As a platform, it provides great stability.
What do I think about the scalability of the solution?
Guardium should meet our needs going forward.
We have only been using Guardium for a short period of time, so we had some growth problems. It is just like growing into your body. Your knees start to hurt after a little while, but once you get through that growth spurt, you get your win and you keep going and you are able to grow and expand. I think the way we have it implemented, we will be able to grow and scale as the organization grows.
How is customer service and technical support?
We use technical support very frequently. We actually have a weekly call with our sponsor where we go through all of our different support questions. We are on a week-to-week basis where we follow-up with all our questions. We are on the leading edge for Guardium implementations. The version that we are on, it makes us a Fortune Six organization with the current version for all of our data. It requires a lot of support as we grow and mature with the product and with our organization's growth.
How was the initial setup?
Our initial setup was pretty straightforward because we were just figuring out how it worked. Over the last two years, we have introduced our own complexities to accommodate our requirements. Would I say that it is complex to us today? No. To the average Guardium user? Yes, it would be complex.
Which other solutions did I evaluate?
We did evaluate other vendors. Guardium was a large purchase. We did our due diligence as we were responsible for the purchase process. Guardium won mostly because of our scope and scale. It was able to perform at the scale that we wanted to use it.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Database Administrator at a healthcare company with 10,001+ employees
It tests security to support SOX compliance
Pros and Cons
- "It supports our audit compliance."
- "It tests security to support SOX compliance."
- "I would like them to support cloud services."
- "Sometimes the performance is not good, and also sometimes we have sudden bugs causing difficulties."
What is our primary use case?
It tests security to support SOX compliance.
How has it helped my organization?
It supports our audit compliance. We use IBM Guardium to support security initiatives and compliance policies within our organization. We have a lot of self controls which require the database to be monitored, especially for the privileged user.
What is most valuable?
- Its band monitoring. We just started to use it.
- The mobility assessment
What needs improvement?
I would like them to support cloud services.
What do I think about the stability of the solution?
It is pretty good, though we have had some issues. Sometimes the performance is not good, and also sometimes we have sudden bugs causing difficulties. Therefore, it is hard for IBM to fix.
What do I think about the scalability of the solution?
Scalability is good.
How is customer service and technical support?
My experience with technical support depends. Sometimes, with Level 1, it is not good. However, when the case goes to Level 2, the support is pretty good.
How was the initial setup?
The initial setup was pretty straightforward.
What was our ROI?
Senior management is aware that Guardium has saved the organization time and money
Which other solutions did I evaluate?
We just talked to IBM. If we have a problem, maybe they can offer us something new, new features, etc.
What other advice do I have?
IBM Guardium is good.
Most important criteria when selecting a vendor: reliability.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Systems DBA at a insurance company with 1,001-5,000 employees
We are more efficient in demonstrating compliance but the reporting features need work
Pros and Cons
- "Our internal audit is keeping an eye out, and making sure that we're in compliance. Having the Guardium solution and its reporting helps us get through that process a lot more quickly and efficiently."
- "The most valuable feature for me, in my role as systems DBA, is the expediting of internal and external audits."
- "The one thing that I would like to see improved, but I don't think it's going to be in the next release, is its reporting capabilities. I think that's been offloaded to another third-party product that I think IBM actually endorses for that."
What is our primary use case?
To protect the data. We're trying to monitor privileged users, get an idea of what's normal access, and to make sure that service account usage is only coming from the appropriate places, not being used by people from their own work stations.
How I would describe how well it's performing is that we are taking a slow and steady approach to it. Right now, I would say we're going from crawl to walk as far as usage goes; not using any of the sophisticated features, more getting the base implementation in place.
How has it helped my organization?
I think we have a better handle on who is accessing our data.
We use Guardium to support security initiatives and compliance policies within our organization. Our internal audit is keeping an eye out, and making sure that we're in compliance. Having the Guardium solution and its reporting helps us get through that process a lot more quickly and efficiently.
We're not using any of the workflow yet, but I would say yes, it is helping with compliance reporting. We're making sure that we're monitoring the usage of privilege accounts, managing the use of the service accounts.
We have not integrated Guardium with any other systems.
It has made us more efficient in demonstrating that we are in compliance, and enables to get through audit processes more quickly, which saves time and money.
What is most valuable?
Probably the most valuable feature for me, in my role as systems DBA, is the expediting of internal and external audits.
What needs improvement?
The one thing that I would like to see improved, but I don't think it's going to be in the next release, is its reporting capabilities. I think that's been offloaded to another third-party product that I think IBM actually endorses for that. It was built by the guy who helped develop Guardium but left IBM and spun up his own company. They found a need and they filled it. I think they filled it better than at least IBM thinks they can do for now.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
I'm not the administrator of the product so I don't know that I would be the best one to answer this. But from more of a consumer's perspective, the fact that the S-TAPs and such run on my systems, it has not caused us any problems; a little bit in the SQL Server space, but overall it has been good.
What do I think about the scalability of the solution?
I think that it's very scalable. You can spin up new Collectors and Aggregators as needed so, I'd say it's sufficient.
How are customer service and technical support?
I do not have experience with technical support. I know that our main Guardium guy is the head of the user group, so, he has used it. He has connections. He usually gets quick feedback because they know he is very visible.
Which solution did I use previously and why did I switch?
We had rolled our own stuff to do some of what Guardium does, but I think it was organizational recognition that switching was something that needed to be done. The monitoring and reporting was lacking in our organization. We had pockets where we had built our own, but now we're able to use one platform to do that monitoring for all of our database environments.
We went with IBM because it was a combination of functionality and familiarity, in that we have a lot of IBM products in-house, and it fit the criteria.
How was the initial setup?
It was straightforward.
Which other solutions did I evaluate?
We did evaluate others, but I couldn't tell you what they were because that was a couple of years ago.
What other advice do I have?
It does a good job for what it's designed to do. You may want to look into the enhanced reporting that's available by the third party, because some of the report-building features are not as nice as some of the third party's.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
App Mainframe And Storage at a financial services firm with 1,001-5,000 employees
It's one of the first to encrypt DB2 databases, but the technology needs to mature a little more
Pros and Cons
- "It's one of the first to encrypt DB2 databases."
- "It was difficult implementing it, configuring it, getting it up and running and in production. However, since then, I believe it has stabilized."
What is our primary use case?
We acquired Guardium to encrypt certain databases to meet a customer requirement.
It has been performing to spec.
How has it helped my organization?
We use Guardium to support security initiatives and compliance policies within our organization. The encryption meets a requirement. It was a requirement of a customer. I don't think it is a compliance requirement, but it did come through as a request from a prospective client, so we implemented it.
I don't know if this solution has helped us to comply with Industry regulations like SOX, UCI or GDPR. We have not integrated it with other systems we use. I would not say it has saved us time or money.
What is most valuable?
I understand that it's one of the first to encrypt DB2 databases.
I'm not able to answer whether we're using any of the advanced features.
What needs improvement?
This would be a question for one of the technical folks, probably not for me.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
It was difficult implementing it, configuring it, getting it up and running and in production. However, since then, I believe it has stabilized.
What do I think about the scalability of the solution?
We haven't really tested the scalability with it as yet, we're really only encrypting a very small percentage of our data.
How is customer service and technical support?
Technical support is interesting because, when we implemented Guardium, it was a partnership of IBM with the company that, I think, Guardium either partnered with or acquired since then. So, even though support was funneled through IBM, it was actually performed by the third-party software company, and it was difficult and challenging at times. There was a layer of interpretation between IBM and Rocket Software, and sometimes that was helpful and other times not so much.
What other advice do I have?
In terms of advice, I would say allow the technology to mature a little more. I think we were one of the first, if not the first, to implement Guardium. And, like I said before, it was kind of painful, but let the maturation process run it's course. I'd say learn from other people's mistakes or, not so much mistakes, just experiences. Benefit from other peoples' pain, bumps, and bruises.
I rate it seven out of 10 only because it's a unique, niche offering that is not, that I know of, offered elsewhere in the marketplace. It fills a need, which is good. I don't know how prevalent the need is in the marketplace but it's nice to have an offering there that, when needed, you can implement something.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free IBM Security Guardium Data Protection Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2025
Product Categories
Database SecurityPopular Comparisons
Imperva Data Security Fabric
Oracle Audit Vault
Protegrity’s Data Protection Platform
DataSunrise Database Security
Trustwave DbProtect
Oracle Database Vault
IDERA SQL Compliance Manager
Informatica Secure@Source
Buyer's Guide
Download our free IBM Security Guardium Data Protection Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- IBM Guardium vs Imperva SecureSphere Database Security
- IBM Guardium Data Protection vs. Vormetric Application Crypto Suite for a tech services company
- How does IBM Guardium Data Protection compare with Imperva SecureSphere Database Security?
- What are the differences between IBM Guardium and Imperva?
- When evaluating Database Security, what aspect do you think is the most important to look for?
- IBM Guardium vs Imperva SecureSphere Database Security
- What is the difference between "data protection in transit" vs "data protection at rest"?
- Audit Vault vs. InfoSphere Guardium?
- Database security tools comparison report?
- Why is Database Security important for companies?
Easy to use.