We use Imperva for our web applications that we have hosted to protect them.
Manager, Information Technology Network Security at a financial services firm with 201-500 employees
Enhance security with ease through user-friendly administration and comprehensive threat prevention
Pros and Cons
- "It is easy to use and has good security."
- "If they can bring in generative AI features, that would be useful."
What is our primary use case?
How has it helped my organization?
With our deployment setup, the benefit is regarding the security and how threats have been blocked. It's not studied in terms of resources or speed. The threat prevention is the aspect we are monitoring.
What is most valuable?
Empower administration is user-friendly, and we do not need much for managing day-to-day operations. It is easy to use and has good security. Also, it is very customizable, especially for controlling web browsers and devices.
What needs improvement?
I would prefer AI integrations for user administration, visualization, log analytics, and risk analysis. If they can bring in generative AI features, that would be useful.
Buyer's Guide
Imperva Application Security Platform
October 2025
Learn what your peers think about Imperva Application Security Platform. Get advice and tips from experienced pros sharing their opinions. Updated: October 2025.
872,846 professionals have used our research since 2012.
For how long have I used the solution?
I am working with Imperva at the moment and have been using it for maybe six to seven years.
What do I think about the stability of the solution?
It's very stable. We haven't had any issues.
What do I think about the scalability of the solution?
Scalability is not a problem since we have enough resources as it's an on-premises version.
How are customer service and support?
We have escalated to tech support and it's quite good. I would rate them a seven point five out of ten.
Which solution did I use previously and why did I switch?
We didn't use any WAF product before Imperva.
How was the initial setup?
The initial deployment was seamless, and there weren't many complexities.
What about the implementation team?
The deployment was done by a separate company within the company.
Which other solutions did I evaluate?
I do not have much understanding about F5 yet as I am currently evaluating their solution.
What other advice do I have?
I suggest looking for a cloud-based solution rather than on-premises, which might improve availability, stability, and security.
I'd rate the solution nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Director, Information System Security at a financial services firm with 201-500 employees
Hosts a complete range of features and gives a comprehensive overview of network traffic
Pros and Cons
- "The WAF itself has been very valuable to me because it has such a complete range of features. Another reason why I like it is because it also takes care of the total overview of the traffic over the network."
- "They recently separated the WAF and the DAM management gateways in order for each of these to be managed from different areas, so I believe it now requires additional investments for what was previously a single complete solution."
What is our primary use case?
At my previous workplace in the banking sector, we used Imperva WAF for the monitoring of our internet banking traffic, and we also used Imperva's DAM for the database activity monitoring.
Our deployment of Imperva WAF was situated on-premises and it was in use throughout the whole organization, which included around 3,500 clients.
How has it helped my organization?
Imperva Web Application Firewall has improved security of my organization through enhanced visiblity as well protecting malicious IPs, applications and unknown users as well.
What is most valuable?
The WAF itself has been very valuable to me because it has such a complete range of features. Another reason why I like it is because it also takes care of the total overview of the traffic over the network.
What needs improvement?
Imperva's product is very good, but when it comes to procuring the software in my country it can be somewhat expensive. I don't recall the exact amount, but in comparison with other countries it is a huge investment.
They recently separated the WAF and the DAM management gateways in order for each of these to be managed from different areas, so I believe it now requires additional investments for what was previously a single complete solution.
Although the vendor support from Imperva is not bad, getting a response from them can be a lengthy process at times.
For how long have I used the solution?
I have used Imperva WAF for about three years.
What do I think about the stability of the solution?
The stability is mature enough, in my experience. In fact, I would give it a 5/5 for stability.
What do I think about the scalability of the solution?
Scalability-wise, there is one issue we encountered that I want to mention. At some point, Imperva, moved their account takeover prevention features from the on-premises edition to the cloud-based edition, and we discovered that this step would take yet another integration, seeing that we were using Imperva on-premises. These account takeover prevention features, however, were already part of our subscription, but since the features moved to the cloud, we missed out on them. So, in this sense, I would say the scalability strategy isn't as solid as it should be, and for this reason I would rate the scalability a 3.5/5.
On the other hand, when it comes to how many users we were able to scale up to, we actually had the whole organization using it, including around 3,500 clients in total.
How are customer service and support?
The support from the vendor side could be improved because their response times weren't great and the process of obtaining the proper support was a long process sometimes. That said, the support itself was not bad.
How would you rate customer service and support?
Positive
How was the initial setup?
The setup was actually quite an advanced process. It was a good experience, but all in all it took about one year to get everything fully set up, when you take all the fine-tuning activities and such into account.
What about the implementation team?
We deployed the Imperva WAF with the help of organizations in South Africa who acted as consultants and implementation partners for Imperva. Our experience with them was good, and the full implementation required two professionals from the consultant's side and about five people from our own organization. The vendor itself was not part of the implementation process.
What's my experience with pricing, setup cost, and licensing?
The pricing is somewhat expensive. It is actually a huge investment when compared to other countries.
Not only that, but Imperva went on to separate the WAF and DAM management gateways, making it so that each would have to be managed and licensed separately, incurring the cost of additional investments.
On a related note, there was another licensing issue we encountered where we had a subscription for account takeover prevention features, but these features had been moved by Imperva from the on-premises instance to the cloud. Since we had not moved to the cloud at that point, we did not have access to these features anymore.
What other advice do I have?
I can highly recommend Imperva WAF for financial institutions. It's a good solution and I think it's important for financial institutions, particularly those who conduct online banking, to make use of a solid WAF such as this.
I would rate Imperva WAF a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Imperva Application Security Platform
October 2025
Learn what your peers think about Imperva Application Security Platform. Get advice and tips from experienced pros sharing their opinions. Updated: October 2025.
872,846 professionals have used our research since 2012.
Solutions Engineer at a tech services company with 1,001-5,000 employees
A proactive security solution that protects web applications and APIs and enables easy administration
Pros and Cons
- "We can prevent attacks or issues even before they happen."
- "Sometimes, support tickets don't get addressed quickly."
What is our primary use case?
The solution is used by SMBs and enterprises that have a lot of websites that they need to protect.
How has it helped my organization?
Since the product is categorized in Gartner as a Web Application and API Protection tool, it protects APIs and web applications. It provides bot and client-side protection. I have done POCs. Once the platform is configured to block DDoS attacks, no traffic regarding DDoS or bots gets into the application.
What is most valuable?
If the clients have requirements for APIs and microservices, we can offer such services with the help of the solution. We can offer it as a security solution that protects APIs and microservices. Imperva’s real-time monitoring makes it very easy for administrators to monitor their existing web applications.
What needs improvement?
My clients raised a concern that even if they need the tool only for DDoS protection, they still have to buy the WAF license. It’s difficult to position the tool if the client already has a WAF solution and needs Imperva only for DDoS protection.
For how long have I used the solution?
I have been using the solution since June last year.
What do I think about the stability of the solution?
I rate the tool’s stability a ten out of ten. Since I've been onboarded, I haven't had any issues.
What do I think about the scalability of the solution?
I rate the tool’s scalability a ten out of ten. Imperva allows only clean traffic. The scalability is based on the clean traffic and not the overall bandwidth of the client. Our clients are mostly enterprise businesses. I have some SMB customers.
How are customer service and support?
Sometimes, support tickets don't get addressed quickly. However, the support team gets to it eventually.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is very easy. I rate the ease of setup a ten out of ten. The time taken for deployment depends on the number of applications we want to onboard. Usually, we can do it in a day.
What was our ROI?
Imperva is a very proactive solution. It is not reactive. We can prevent attacks or issues even before they happen. It is something people must consider since many enterprises are facing DDoS attacks, and their data is getting compromised.
What's my experience with pricing, setup cost, and licensing?
I rate the solution’s pricing a seven out of ten. Some solutions are cheaper than Imperva. Imperva’s pricing is a bit higher in the market since it offers a full-blown WAF.
What other advice do I have?
We are partners. I rate the product's integration with our client's IT infrastructure a nine out of ten. It is easily integrated since many configurations are needed to onboard Imperva into a client’s infrastructure fully. Overall, I rate the product a nine out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Application Security Engineer at a insurance company with 10,001+ employees
A reliable and stable product with automatic bot mechanism
Pros and Cons
- "I am impressed with the product's automatic bot mechanism. It also gives us the control to create our own custom bot rules."
- "The tool needs to include artificial intelligence and machine learning. It also needs to improve profiling."
What is most valuable?
I am impressed with the product's automatic bot mechanism. It also gives us the control to create our own custom bot rules.
What needs improvement?
The tool needs to include artificial intelligence and machine learning. It also needs to improve profiling.
What do I think about the stability of the solution?
The tool is stable.
How was the initial setup?
The product's setup is pretty easy.
What's my experience with pricing, setup cost, and licensing?
The tool's pricing is good.
What other advice do I have?
The solution is a reliable product. I would rate the tool an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Reliable with an impressive three-second SLA and reasonable pricing
Pros and Cons
- "The three-second service level agreement is already better than the competition."
- "There’s nothing that’s missing in terms of features."
What is our primary use case?
They provide end-to-end data security, so everything to do with applications, APIs, et cetera.
We've got a Telco client, and they'll be partnering with us to use the DDoS solution with their clients.
It's primarily for DDoS attacks. It's looking at anything that's trying to remove the ability of the company to operate, usually volumetric, however, since it's got a three-second SLA, it's better than the competition.
What is most valuable?
We can look after an entire what used to be a Class C network/24. Now, they could do single IP addresses, so they can protect a single IP address, and they have a three-second SLA to stop an attack. They back that up with a very large amount of money as well, so you've got a guarantee on it.
What needs improvement?
It’s hard to think of an improvement. The three-second service level agreement is already better than the competition.
You would ordinarily say something like API protection. However, they've got that with another product. It's not that DDoS protection does everything. It's that within their family of products, they've got a solution for everything. That's what I like about it, the whole integrated service. There’s nothing that’s missing in terms of features.
For how long have I used the solution?
We've been working with Imperva for about a year, and we've been working on a particularly big client at the moment as well.
What do I think about the stability of the solution?
The product is stable. It's resilient architecture. If one site is down for maintenance, then another site will take over the load.
What do I think about the scalability of the solution?
It's very, very scalable. They've just added a lot more capacity to it. It's something like six or nine terabytes per second of protection capacity, which is more than the biggest attack there's ever been by quite a margin.
How are customer service and support?
Technical support is very, very responsive. They're very good and they've got strength in depth. Across the world, they've got people. We deal with the local guys in the Netherlands, and they're pretty good.
How would you rate customer service and support?
Positive
How was the initial setup?
The setup itself is straightforward.
It's quite quick. It can be done as a reactive solution. Therefore, if somebody rings up and says I'm being attacked, we can get them onboard very quickly.
You only need one person to handle the deployment. It's all done virtually. We're working with the Telco and the Telco sends out the BGP VPNs and we just reroute traffic. It’s all very easy.
There's no maintenance as such apart from reports on traffic utilization. If you are using it as a continuous service, if you're running it continuously rather than just invoking it when there is a DDoS attack, then you get reports basically on your utilization of traffic and the types of traffic that you're transporting, et cetera. It helps you improve your security.
What about the implementation team?
We're doing the deployment for the client.
What was our ROI?
The ROI depends if you're being attacked or not. If you're the sort of organization that gets regularly attacked, then the ROI is extremely high as you could be down for quite some time with a DDoS attack. What usually happens these days is they don't have long attacks. They have very short attacks. However, the idea is to take down parts of the infrastructure to attack other parts. Therefore, it’s a diversion attack in many cases. Due to that, it's one of those products. It's very difficult to say what the ROI might be since it depends on what people are trying to do. However, it's the precursor to a lot of attacks.
What's my experience with pricing, setup cost, and licensing?
The solution is very affordable. It's based on the traffic utilization, the average traffic utilization, not the DDoS traffic. Therefore, if you're being DDoSed, you don't pay extra for the absorption of the DDoS traffic. It's purely based on your average traffic.
What other advice do I have?
We're an end-to-end Imperva partner. We're an Imperva reseller.
We're building an MSP at the moment, and it starts with a number of solutions. We then add on for those that have cloud exposure. We’ve added CloudWave DDoS and the API Protection and Bot Protection, and then for companies that have GDPR requirements, we've got the database side.
We use a cloud deployment with a variety of cloud providers. The telco, for example, is on the Equinix cloud. They're on a variety of data center sites. A lot of it is Equinix. I can't remember the name of the other providers, however, that's not relevant to us particularly since we are bringing in another Telco partner.
I’d rate the solution eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Lead Client Service Manager at Nexagate Sdn Bhd
A self-managed service that is easy to deploy and offers regular updates
Pros and Cons
- "One good thing about Imperva Web Application Firewall is it can be on the cloud and also it can be on-premise."
- "I don't really use it and therefore can't speak to areas of improvement."
What is our primary use case?
We primarily use the solution as a firewall.
What is most valuable?
One good thing about Imperva Web Application Firewall is it can be on the cloud and also it can be on-premise. Either way, you can use it, and it's quite easy.
It's quite easy to deploy. It is also a self-managed service. It's quite straightforward.
They do provide updates on a quarterly or half-yearly basis.
What needs improvement?
I don't really use it and therefore can't speak to areas of improvement.
For how long have I used the solution?
We've been using it for probably three or four years.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
Scalability-wise, it is not so scalable as the solution is quite straightforward. There's not much you can scale with the solution.
Mainly, the IT department uses the solution and there are ten to 20 of them.
How are customer service and support?
Technical support is quite helpful and responsive. They support us well and they are available worldwide so it's quite easy to get help.
How was the initial setup?
The product is very easy to deploy. It's simple and straightforward. It's not an overly complex solution.
Within half a day you can have it up and running. You just need two people to deploy and maintain the solution.
What other advice do I have?
We are users and also we are resellers.
The version we are using is the latest version.
It has many valuable options or features. You just need to know what you need for your organization. If not, Imperva will probably tend to sell you almost everything. You just need to know what are the options that you need for your organization. Apart from that, the whole process is quite fast and it's quite reliable.
I'd rate the solution an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Customer/Reseller
IT Senior Manager at a outsourcing company with 10,001+ employees
Enables us to monitor all web activity, which is passed through WAF cloud services
Pros and Cons
- "The most valuable features are DDoS protection."
- "Incapsula services also provides load balancing services for their service IP address environment. So far, with monitoring their services, the IP address was only changed once."
What is our primary use case?
All our web services go to the Incapsula cloud application environment for monitoring on the production service.
All the web application protection is under Incapsula because they provide the WAF protection services. Our web services are registered under their cloud environment so all our customers visit our web services. All the web services are under the web application firewall protector.
I think it's from their own cloud solution. I don't think the cloud solution is from Amazon because the IP address does not belong to Amazon. It belonged to Incapsula themselves, so their solution is under their own network cloud environment. Our own data center environment is using the Incapsula cloud service. I think it's a hybrid cloud to include all the private and the public services.
What is most valuable?
The most valuable features are DDoS protection. The Incapsula environment helps us monitor all the web activity. All the web activity is passed through their WAF cloud services, then that can help us to monitor those activities. That can help protect against DDoS hacking.
For how long have I used the solution?
We started implementing WAF under Incapsula in 2019 or 2020.
What do I think about the stability of the solution?
It's very stable because Incapsula services also provides load balancing services for their service IP address environment. So far, with monitoring their services, the IP address was only changed once. Their services are very stable.
What do I think about the scalability of the solution?
We implement the WAF production environment, or the web services, which is needed to provide traffic to the customer. We implement those services under the Incapsula WAF protection.
We have about one thousand people using the solution globally.
How are customer service and support?
If the scale is 1 to 10, technical support is a 9. Our global service team is more than 10 people. We have a whole Incapsula service team as well as our all global staff team.
Which solution did I use previously and why did I switch?
We are using our own firewall with the web application services. We used our own firewall before implementing with Incapsula, but we are also implementing it now under Incapsula cloud solutions.
How was the initial setup?
It's very simple because the domain name service is done with the CNAME. We just registered back in our DNS environment. After that, if the domain is resolved by our customer, then they will resolve the domain name which is provided by the Incapsula environment. That means all the network traffic will go through the Incapsula cloud services, and all the network activity can be monitored and protected by Incapsula WAF.
Deployment is simple and very fast. After they define the domain and service, we do some changes, and it takes within one hour. Within 15 minutes, it can transfer all the services from our site. All the network routing paths will pass through the Incapsula WAF cloud environment. It's very fast.
What's my experience with pricing, setup cost, and licensing?
The license is on a yearly basis.
What other advice do I have?
I would rate this solution 9 out of 10.
Because of all these services, you need to look at the company's services budget. If you have the budget and you can implement the web application for tech, or if you just want to move to the cloud, or you're just using your own firewall to do all those protections, Incapsula is a good option. This one just depends on the IT infrastructure budget in your own company or environment.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Global Network and Cyber Security Project Manager at a manufacturing company with 10,001+ employees
Easy to operate
Pros and Cons
- "The configurability of the tools and the ease of operation to be the most valuable feature of Imperva."
- "Imperva Web Application Firewall is very expensive."
What is our primary use case?
We use the latest version with all the functionality, not only WAF. Additionally, we use all the security capability that is possible to enable on Imperva including device security tools like API security.
We use this solution to protect the website for the company.
What is most valuable?
I find the configurability of the tools and the ease of operation to be the most valuable feature of Imperva.
For how long have I used the solution?
I have three years of experience with Imperva Web Application Firewall.
What do I think about the stability of the solution?
This solution is very stable.
What do I think about the scalability of the solution?
Scalability is very good.
How are customer service and support?
Imperva's technical support is very good.
Which solution did I use previously and why did I switch?
I used to work with Fortinet Web Application Firewall but it was not good.
How was the initial setup?
The initial setup of Imperva is easy to do and only takes a few minutes to deploy.
What's my experience with pricing, setup cost, and licensing?
Imperva Web Application Firewall is very expensive.
Which other solutions did I evaluate?
I have worked with Azure and find both solutions good. However, Imperva does have more advanced features than Azure.
What other advice do I have?
I am very happy with this solution. I would rate the technical aspect a 10 out of 10, however because of the financial cost, I rate it an 8 out of 10.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Imperva Application Security Platform Report and get advice and tips from experienced pros
sharing their opinions.
Updated: October 2025
Product Categories
Distributed Denial-of-Service (DDoS) Protection CDN Web Application Firewall (WAF) Bot Management API SecurityPopular Comparisons
Prisma Cloud by Palo Alto Networks
Cloudflare One
Azure Front Door
Microsoft Azure Application Gateway
F5 Advanced WAF
Fortinet FortiWeb
Cloudflare Web Application Firewall
Akamai App and API Protector
Buyer's Guide
Download our free Imperva Application Security Platform Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- F5 vs. Imperva WAF?
- Imperva WAF vs. Barracuda: Which One is Better?
- Which Web Application Firewall (WAF) would you recommend? R&S or Imperva?
- Can Imperva Bot Management protect against advanced bot threats, such as credential stuffing and content scraping?
- Can Imperva Bot Management protect against API attacks? Are APIs more susceptible to bot attacks?
- What is a zero-trust cybersecurity model and what would some of its key aspects be?
- We are looking at managed DNS providers and want to know what others are using
- Prolexic vs. Arbor Networks: How do they compare?
- How does a WAF help to protect against DDoS attacks?
- Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?













