- DDoS protection
- CDN
- WAF
- Good API for managing services
System Administator at a tech services company with 201-500 employees
With the WAF, our web services can't be exploited remotely.
What is most valuable?
How has it helped my organization?
Thanks to Incapsula, we got easily manageable DDoS protection; HTTP2 and SSL certificates for all the services; CDN in good locations; and we're now sure that our web services can't be exploited remotely because of the WAF feature. Also, we can chose to whitelist/blacklist network(s) access to specific services/resources.
For how long have I used the solution?
I have used it for a few years.
What was my experience with deployment of the solution?
We have not encountered any deployment issues.
Buyer's Guide
Imperva Application Security Platform
September 2025

Learn what your peers think about Imperva Application Security Platform. Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
867,497 professionals have used our research since 2012.
What do I think about the stability of the solution?
We had a few hiccups in the past, but they were small with no impact to important services.
What do I think about the scalability of the solution?
We have not encountered any scalability issues.
How are customer service and support?
They need to work on the customer support; in my opinion, this is their weakest point. Some of their support representatives really have no idea how their service works.
Which solution did I use previously and why did I switch?
We did not previously use a different solution.
What about the implementation team?
An in-house team implemented it.
Which other solutions did I evaluate?
Before choosing this product, we did not evaluate other options.
What other advice do I have?
Try it.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Application Security Architect at a hospitality company with 10,001+ employees
The WAF can identify, block, whitelist or blacklist as needed.
What is most valuable?
Hands down, the WAF is the most valuable feature; being able to identify, block, whitelist or blacklist as needed, are all valuable.
How has it helped my organization?
We now have visibility into our traffic in a scope that we never had before, especially being able to review bot vs human traffic and country of origin.
What needs improvement?
Reporting and the main Sites dashboard could use refinement. We have a lot of sites, and scrolling through the dashboard becomes cumbersome.
For how long have I used the solution?
I have used it for six months.
What was my experience with deployment of the solution?
The only deployment issue we encountered was getting Incapsula and Akamai to play nice. However, the Incapsula engineers were very helpful in helping us configure our sites in the WAF correctly.
What do I think about the stability of the solution?
We have not encountered any stability issues.
What do I think about the scalability of the solution?
We have not encountered any scalability issues.
How are customer service and technical support?
Customer Service:
I have yet to need customer service.
Technical Support:I rate the level of technical support as very high.
Which solution did I use previously and why did I switch?
We had not used a WAF before deploying Incapsula.
How was the initial setup?
The setup was straightforward and simple.
What about the implementation team?
We implemented it ourselves with the guidance of the Incapsula team.
What was our ROI?
It is too soon to tell regarding ROI.
What's my experience with pricing, setup cost, and licensing?
Know your bandwidth requirements.
Which other solutions did I evaluate?
Before choosing this product, we evaluated so, so, so many other options.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Imperva Application Security Platform
September 2025

Learn what your peers think about Imperva Application Security Platform. Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
867,497 professionals have used our research since 2012.
Head of Cyber Defense & Offensive Security at Habib Bank Limited
I like the content monitoring feature which I haven't seen in other WAF solutions.
What is most valuable?
Content monitoring is a marvelous feature that I haven't seen in other Web Application Firewalls. It also has a good content filter. We do a lot of penetration testing on our servers, and the Imperva standalone solution for identifying a payload and its signature by deep analysis was very good.
How has it helped my organization?
We never used to know about threat and attack signatures. By using Imperva WAF, we could identify our weak points where an attacker was trying to gain access.
What needs improvement?
They could improve by minimizing false positive results. Although this occurs less with Imperva, we would like to see some further improvements.
We have been using this product for last 1 years, it's result is very impressive. But due to the excessive load on the Web site where thousands of requests are generated from legitimate users, however the request in which any sequential or specialised characters are requested would be directly blocked by impreva . Currently imperva blocks the special character request generated from the user, as I conduct a test where I am parsing the encoded html values of the same special characters to the input field, imperva bypasses these encoded values for example : ' i.e. %27 or / i.e %2F, the WAF bypasses these encoded characters. I hope that this device should have a capability to detect the pattern which is associated with Xss or Xsrf, rather then by not blocking the request which contains any special characters.
For how long have I used the solution?
I have used it for one year.
What do I think about the stability of the solution?
We did not encounter any stability issues.
What do I think about the scalability of the solution?
We never encountered any scalability issues.
How are customer service and technical support?
We were impressed with the technical support.
Which solution did I use previously and why did I switch?
We have examined different vendor WAF solutions but this solution was unique.
How was the initial setup?
Initial setup was straightforward.
What's my experience with pricing, setup cost, and licensing?
Pricing was a little higher but when compared to performance; it's very cheap.
Which other solutions did I evaluate?
We evaluated Akamai and F5.
What other advice do I have?
Imperva Incapsula WAF is an awesome solution for implementing a WAF with good support and reliable hardware performance.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Sr. Consultant at a tech services company with 51-200 employees
Scan policies allow us to group multiple targets and standardize our database scanning. Technical support is probably the biggest drawback.
What is most valuable?
The most valuable feature is the grouping of multiple targets via the scan policy. It is valuable because of the large number of targets and governmental requirements to conduct periodic scans.
How has it helped my organization?
With acquisition of a license to use the product, we received the ability to standardize database scanning and data protection across the enterprise around one product.
What needs improvement?
Many features are buried under not-straight-forward options and, at times, hard to find screens. Very few import features have clearly defined format requirements. Agent installation for data usage/blocking activities on target boxes requires the involvement of OS admins and DBA’s, which complicates coordination of installation and delays implementation. The discovery feature does not accurately discover the instances and instead identifies auxiliary end points (SQL – 1434) and TCP listeners (Oracle – 1521).
For how long have I used the solution?
I’ve used and administered Imperva SecureSphere for 2 years.
What do I think about the stability of the solution?
Periodically, the site stops functioning and the appliance requires a reboot to restore functionality.
What do I think about the scalability of the solution?
Scalability capabilities are well thought through by product development. Installation of additional MX servers and gateways on remote networks ensures coverage of scanning and data usage monitoring/data protection capabilities.
How are customer service and technical support?
Technical support is probably the biggest drawback. No contact with technical support ever results in an immediate response and the solution is usually preceded with series of emails, going on for up to a week, before a live person gets on the phone. But, even then, their task is to observe the manifestation of the problem and request a collection of additional information (logs, traces, etc.) without any attempt to solve the problem during the call/WebEx session. Their technical support staff has at most two or three engineers that have a good working knowledge of the product, but most of the time, a level one technician is running the case. When support staff finally gets on the phone, their first statement is a disclaimer that they are on the call ONLY to collect information and that the customer should not expect any resolution.
This pattern of providing technical support greatly differs from what IBM offers for their Guardium product (competitor solution).
Which solution did I use previously and why did I switch?
We attempted to use several previous solutions. One was Tenable SecurityCenter with its custom, XML-like scripting where each check had to be written by the Database Security Specialist (myself). We also attempted to use AppDetectivePRO, though its performance, lack of customization, scalability, and licensing costs prevented us from continuing with it.
How was the initial setup?
The setup is very straightforward considering that it’s either a physical or virtual (OVF template) appliance. The wizard-like initial setup and configuration are somewhat awkward, but can be completed after reviewing the instructional videos available to the customers.
What's my experience with pricing, setup cost, and licensing?
Licensing should be chosen based on the current infrastructure setup and growth plans. Purchasing appliances of different types may lead to unnecessary/unjustified expenditures and ultimately lead to complications in administration.
Which other solutions did I evaluate?
The product that was evaluated and was chosen as the recommendation was IBM Guardium. Unfortunately, its licensing cost was a lot higher. Therefore, the management decided not to proceed with the purchase.
What other advice do I have?
Be prepared to obtain every piece of documentation that comes with the product. Thoroughly research it to obtain a clear understanding of how to implement the product and ensure you have a dedicated Imperva first-response engineer that can answer your questions without going through a normal support channel. Be patient when encountering a bug or a feature failure, as well as discrepancies between the product interface and/or behavior with the accompanied documentation. Their support is not prepared to jump in and start working on a fix or update the documentation.
In many cases, the documentation remains outdated referring to old releases regardless how long you’ve been asking for an update. Their instructional videos are also out of date, but references to them are consistently sent by their support whenever you may have a question. And finally, thoroughly document your deployment and license-related information, because every email to technical support is responded with an automated reply requesting this information. Not replying to this automated email with correct info will lead to further delays.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Network and Security Engineer at a consumer goods company with 1,001-5,000 employees
The dashboard shows us traffic, security, and real-time utilization. The default configuration usually does the trick for us.
What is most valuable?
- Very easy to configure, which quickly allows us to add significant security to our websites.
- Nice dashboard, which shows us details about traffic, security, performance, real-time utilization and an activity log.
- Easy to configure caching, content optimization and other advanced settings, which allows us to improve the customer experience if necessary, or keep the defaults if any change is unnecessary.
How has it helped my organization?
With our IT infrastructure more secure, our customers receive a great website experience without encountering website defacements and other fallout from attacks on our web servers. Our IT department is not spending the time we used to on website remediation after attacks.
What needs improvement?
An Incapsula website configuration instance can be in a "Pending DNS changes" state, where further work is needing to be done by the customer, while website access is otherwise fully functional. While in this state, the PCI Compliance Report for the website in question, which I have set to email me monthly, doesn't get generated and sent. Imperva should decouple the "Pending DNS changes" state from the process that periodically emails the PCI Compliance Report. Until that happens, the workaround is to manually generate the report monthly.
For how long have I used the solution?
Since May 2014.
What do I think about the stability of the solution?
We haven’t had any stability issues. I get emails about internal Incapsula technical issues that they’re working on. However, they haven’t ever impacted me as an administrator and I’m unaware of any customers experiencing issues getting to our websites.
What do I think about the scalability of the solution?
Incapsula scales nicely.
How are customer service and technical support?
Technical support is excellent.
Which solution did I use previously and why did I switch?
Prior to Incapsula, we only used inline IPS, anti-virus, etc. Incapsula is our first web application firewall.
How was the initial setup?
Initial setup was very easy. The default configuration usually has done the trick for us. We simply haven’t needed to deviate much from default. Online documentation is good and if we still had questions, we contacted support who helped us make configuration changes to address our needs.
What's my experience with pricing, setup cost, and licensing?
Gain an understanding of pricing for the various advanced features and figure out what features you need to meet your objectives. We have done very well with the first tier feature package to address the needs at our two data centers and our cloud environments.
Which other solutions did I evaluate?
We got a feel for pricing and capabilities of other competing systems. However, Incapsula came highly recommended by our trusted security VAR as they had many customers who experienced great results with it. With that ringing endorsement, and the reasonable cost, we tried it out, loved it, and have been using it ever since.
What other advice do I have?
Do a proof-of-concept. It’s quick and easy to set up, and you’ll have Incapsula support to help you if needed. Embrace the ease-of-use of the administrative interface and marvel “can a WAF really be this easy?!”. Monitor the dashboard and enjoy the results. The ease of testing Incapsula and then implementing it into production is one of the most remarkable product experiences in my IT career. It’s clear that Incapsula engineers are busy behind the scenes, which is in contrast to my appreciation of what I would otherwise be doing tuning other WAF options.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Service Manager at a tech services company with 51-200 employees
Provides PCI-level IDS/IPS.
What is most valuable?
- Easy-to-set-up CDN with PCI-level IDS/IPS
How has it helped my organization?
We offer Incapsula for every customer project we host, as a default.
What needs improvement?
The default service is great!
For how long have I used the solution?
I have used it for two years.
What was my experience with deployment of the solution?
Sometimes, the SSL setup can be a bit slow/inconsistent.
What do I think about the stability of the solution?
There was only one minor incident with service availability, if I remember correctly.
What do I think about the scalability of the solution?
Nope; we have not encountered any scalability issues.
How are customer service and technical support?
Customer Service:
Some tickets seem to hang for some reason and some of the more-technical tickets seem to go through lot of different people before they get solved, but generally the customer service has been good.
Technical Support:General documentation is good enough that we haven't needed technical support that much, but the answers have been good once you go through the "Off-the-shelf" answers.
Which solution did I use previously and why did I switch?
We did try CloudFlare, but the pricing didn't suit our use case too well.
How was the initial setup?
The initial setup is fairly straightforward for a technical person.
What about the implementation team?
An in-house team implemented it all the way.
What was our ROI?
ROI is ~90%.
What's my experience with pricing, setup cost, and licensing?
Pricing is a good match for the features we use.
Which other solutions did I evaluate?
Before choosing this product, we also evaluated CloudFlare because it appeared first in Google.
What other advice do I have?
Basic setup is simple but, as with any caching/WAF setup, there are tricks you need to learn. But it works really nice out of the box!
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Systems & Infrastructure Architect at a insurance company with 1,001-5,000 employees
Provides bad-IP blocking and signature-based blocking. Management of policies and rules can be complicated.
What is most valuable?
- Bad-IP blocking and signature-based blocking for web application security
How has it helped my organization?
- Security compliance and temporary remediation of application vulnerabilities
What needs improvement?
Management of policies and rules can be complicated and the physical setup of the product has implications on HA.
For how long have I used the solution?
I have used SecureSphere for 3-4 years.
What do I think about the stability of the solution?
Performance of the smaller boxes can be sluggish depending on the load.
What do I think about the scalability of the solution?
We haven’t had any scalability issues.
Which solution did I use previously and why did I switch?
We did not have a previous solution.
How was the initial setup?
Initial setup was straightforward, but ongoing management of rules and policies are time-consuming and complicated.
What's my experience with pricing, setup cost, and licensing?
Try to use a cloud-based and/or managed solution instead of managing a WAF internally; that should be the first preference.
Which other solutions did I evaluate?
Before choosing, we also evaluated F5 ASM.
What other advice do I have?
While implementation is not hard, the process and resources for ongoing management should be thought through and agreed to before implementation.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Technical Consultant at a tech services company with 10,001+ employees
Provides valuable cache control features like cache purging and cache rule propagation. The dashboard is not accessible on occasion.
What is most valuable?
- Extensive cache control like cache purging and cache rule propagation
- Availability features
- Cross-datacenter solution (active and passive environments)
- CDN and DDoS protection with 24/7 support
How has it helped my organization?
Automatic failover between primary and secondary sites enables high availability and accelerates disaster recovery. As soon as it detects that the primary site has gone down, it automatically kick-starts our standby data center.
What needs improvement?
The dashboard is not accessible on occasion. This is probably due to a high load. However, the sites’ protection seems intact.
For how long have I used the solution?
We have been using this solution for four years.
What do I think about the stability of the solution?
There are no stability issues as of now.
What do I think about the scalability of the solution?
There are no scalability issues, but the custom SSL has a terrible price point that puts it out of range for our clients. If they need custom or EV SSL, they are paying significantly more than their overall hosting.
How are customer service and technical support?
The technical support is impressive.
Which solution did I use previously and why did I switch?
We used Akamai previously, but due to full PCI DSS compliance, we needed a proprietary solution for two-factor authentication. We then switched to Incapsula.
How was the initial setup?
The setup was so straightforward. It didn’t require to us to make any major changes.
What's my experience with pricing, setup cost, and licensing?
If you don't have custom SSL, get it!
Which other solutions did I evaluate?
We switched to Incapsula from Akamai.
What other advice do I have?
Imperva has a very impressive core feature set. Imperva has made security analysts scratch their heads. We allow them in from the inside so they can actually hit something worthwhile.
We are very confident in the reports we get from Imperva. Its bot identification has allowed us to plan bandwidth appropriately.
Identification for good bots (people who hit our site using automation, but for good business reasons) has allowed us to work with our customers who use our services in new ways.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free Imperva Application Security Platform Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2025
Product Categories
Distributed Denial-of-Service (DDoS) Protection CDN Web Application Firewall (WAF) Bot Management API SecurityPopular Comparisons
Prisma Cloud by Palo Alto Networks
Cloudflare One
Microsoft Azure Application Gateway
Azure Front Door
F5 Advanced WAF
Fortinet FortiWeb
Cloudflare Web Application Firewall
Akamai App and API Protector
Buyer's Guide
Download our free Imperva Application Security Platform Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- F5 vs. Imperva WAF?
- Imperva WAF vs. Barracuda: Which One is Better?
- Which Web Application Firewall (WAF) would you recommend? R&S or Imperva?
- Can Imperva Bot Management protect against advanced bot threats, such as credential stuffing and content scraping?
- Can Imperva Bot Management protect against API attacks? Are APIs more susceptible to bot attacks?
- What is a zero-trust cybersecurity model and what would some of its key aspects be?
- We are looking at managed DNS providers and want to know what others are using
- Prolexic vs. Arbor Networks: How do they compare?
- How does a WAF help to protect against DDoS attacks?
- Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
A much more mature product in this regard is BeyondInsight. Highly customizable and flexible when it comes to scanning.