Most of the configuration is out-of-the-box and it offers very granular security policies. Deployment and configuration is very easy. Once initial setup has been configured, all the rules and polices are applied automatically and we can start viewing the logs.
Security Engineer at a tech company with 1,001-5,000 employees
Most of the configuration is out-of-the-box and the security policies it offers are granular.
What is most valuable?
How has it helped my organization?
We are able to prevent and protect external and internal threats by using Imperva’s complete product line.
What needs improvement?
I would like to see some more granular audit logs for database activities.
For how long have I used the solution?
I have been using it for 5-6 years.
Buyer's Guide
Imperva SecureSphere Database Security
June 2025

Learn what your peers think about Imperva SecureSphere Database Security. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
857,028 professionals have used our research since 2012.
What was my experience with deployment of the solution?
I have not encountered any issues with deployment, stability or scalability issues. Deployment is very easy, and it offers more stability and scalability.
How are customer service and support?
There are delays in responses from technical support, but you do get a response per SLA.
How was the initial setup?
Initial setup was pretty straightforward.
What about the implementation team?
Anyone can implement this solution if you study the guides.
What was our ROI?
It is worth the investment for retail, banking, government and IT organizations.
What other advice do I have?
It is the best product for cyber security & forensic investigation for external and internal threat identification and prevention.
Disclosure: My company has a business relationship with this vendor other than being a customer: My company has a distribution partnership with Imperva.

ERS Consultant at a consultancy with 10,001+ employees
It covers the legal obligations for Turkish banks and fulfills requirements for our clients.
Valuable Features
- Easy agent setup
- Big data
- SIEM tool integration
Improvements to My Organization
SecureSphere covers the legal obligations for Turkish banks. According to Turkish banking regulations, database activities (especially admins' activities) should be monitored and alerted.
Room for Improvement
Syslog size for transferring data should be increased.
Use of Solution
I used it from September 2015-May 2016.
Deployment Issues
I remember that SecureSphere stores limited data according to the number of the data structure type that is defined in the server configuration files. If a customer does not realize this, data taken with the policy that has a max data structure type is interrupted.
Customer Service and Technical Support
The vendor’s local partners, NGN Company and Bulent Daldal, were very supportive whenever my company needed their help.
Initial Setup
I supported NGN when SecureSphere was set up. Although I only experienced this setup process once, I can now setup SecureSphere DAM and agents on my own. I mean, it was easy and feasible with guidance.
Implementation Team
A vendor team implemented it.
Other Solutions Considered
I did not evaluate other solutions, but I have heard from my clients (Deloitte clients) who have used Guardium before that SecureSphere is better.
Other Advice
SecureSphere fulfills so many requirements for our clients. Additionally, if they want to evaluate and correlate data more comprehensively, they can use this product with SIEM tools such as ArcSight or Splunk.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Imperva SecureSphere Database Security
June 2025

Learn what your peers think about Imperva SecureSphere Database Security. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
857,028 professionals have used our research since 2012.
Security Professional with 501-1,000 employees
With the audit log system, it can secure an audit trail from privileged users with user logs on a physical server, but the UX is not great and sometimes confusing.
Valuable Features
There are many features that are valuable, it depends on the purpose. If the purpose is compliance or auditing, the most valuable feature are the audit log system, as it helps you to secure an audit trail and from user to action even if the user are privileged and even if the user logs in on the physical server. If the purpose is security the most valuable feature are the way it can drop and prevent the access of sensitive table/data set by rules and policies. Lastly, if the purpose is availability, the most valuable feature is the way it can drop connections set by rules and policies.
Improvements to My Organization
If the purpose is compliance or auditing, ex PCI-DSS you need a system like this to pass part of the compliance. As I help customers with compliance, this is a great tool to make it all "simple" and the report part makes the lives easier for the users/auditors.
If it's used for security, this, or systems like this, are the last line of defence, and you will prevent incursions, or at least know what happened, and what was stolen.
If it is to be used to monitor availability, you will only know the real ROI if you are a victim of a large attack, then you can pat yourself on the back and say "Yay! We prevented that". This cannot be achieved solely on the Imperva system and you need the full suite of WAF.
Room for Improvement
This product needs a good team of UX people, because it's not always that understandable, and sometimes it's straight up confusing.
Deployment Issues
They did have some issues with HA and Clustered environments, but it is supposed to be fixed in v12, which I have not tested.
Stability Issues
No issues encountered.
Scalability Issues
There are issues, but it is supposed to be fixed in v12, which I have not tested.
Customer Service and Technical Support
Customer Service:
It's good, but it's a big company, so you need to know the paths to get the most out of it.
Technical Support:It's very good.
Initial Setup
This is a complex system, and all other in the same league are just as complex. There are no workarounds to simplify it.
Pricing, Setup Cost and Licensing
It's expensive, and their licensing is kind of strange, but it is what it is.
Other Solutions Considered
We also looked at IBM InfoSphere Guardium.
Disclosure: My company has a business relationship with this vendor other than being a customer: We are a partner/vendor.
Officer- Informations Systems Security Audit at a government with 501-1,000 employees
It provides you with audit logs for changes to the database.
What is most valuable?
- Database activity monitoring
- Web application firewall
How has it helped my organization?
This product has limited attacks to the core tax collection application. It also provides audit logs for changes to the database and gives user account details.
What needs improvement?
None so far.
For how long have I used the solution?
I've used it for over two years.
What was my experience with deployment of the solution?
I was not around during the implementation, but reports do not show any issues noted.
What do I think about the stability of the solution?
None so far.
What do I think about the scalability of the solution?
None so far. Our solution has not had bottlenecks so far
How are customer service and technical support?
Customer Service:
Customer service has always been available.
Technical Support:Technical support is rated highly.
Which solution did I use previously and why did I switch?
Only a firewall was in place before. WAF was needed for web application specific protection as firewalls are not the best solution.
How was the initial setup?
No issues noted in the implementation reports.
What about the implementation team?
A third party vendor was used to implement the product and to get the IT security staff trained.
What was our ROI?
We have had a high ROI with this product.
What's my experience with pricing, setup cost, and licensing?
Budget for licenses in synch with your financial years, and it's best to have licenses covering over a year so that planning for procurement of new licenses is done earlier. Of course, if you operate in AWS cloud, its much easier to justify as you can pay for three or more years at once.
Which other solutions did I evaluate?
I am not privy to procurement details, but we use Gartner as a source. Imperva is the sole leader in its field.
What other advice do I have?
Implement this product across all systems running applications as access to one unprotected system can be elevated to a protected one. Also, have reports produced frequently using the tools available in the system and analyze them to know and investigate the sources of attacks the WAF has blocked. That's because they could be internal indicating a compromise or a malicious user within. Ensure that your SharePoint environment is also protected as though it may be internal, attacks can be directed at it.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Security Compliance Manager at a financial services firm with 10,001+ employees
This is a very complex solution with a wide range of capabilities.
What is most valuable?
The database activity monitoring module used for real time database monitoring and integrated into the security event and incident monitoring solution. Most importantly for our critical legacy databases that cannot be encrypted and require real time a activity monitoring.
How has it helped my organization?
It provides a more granular monitoring of database activity at the column and row level as opposed to high level database management system logs.
What needs improvement?
The professional services and customer training aspect needs to be improved.
For how long have I used the solution?
I've used it for four years.
What was my experience with deployment of the solution?
The first implementation was not tailored to our specific requirements and the system was basically an expensive log collector until the vendors came to capture our requirements and then made modifications. This was then followed up with training.
What do I think about the stability of the solution?
No issues encountered.
What do I think about the scalability of the solution?
No issues encountered.
How are customer service and technical support?
Customer Service:
It's moderate.
Technical Support:It's moderate.
Which solution did I use previously and why did I switch?
I used a different solution with a former employer.
How was the initial setup?
We are a large organization with about 100 critical heterogeneous database servers. This means that one configuration does not fit all, and that made the implementation very complex. Combined with protection of sensitive information that could be logged by the solution.
What about the implementation team?
We used a vendor and their level of expertise was between moderate and high.
What was our ROI?
The ROI based on the number of prevented, and detected, information security incidents can be classified as high.
Which other solutions did I evaluate?
We also looked at Sentrigo Hedgehog by McAfee.
What other advice do I have?
Ensure the vendor clearly captures your specific database monitoring requirements and that might include importing the metadata of the database for proper monitoring. Training should be included in the implementation budget as this is a very complex solution with a wide range of capabilities.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Database Administrator II at a pharma/biotech company with 501-1,000 employees
It's a pretty decent product but the learning mode feature should be improved.
What is most valuable?
The alerts on threats and system statuses.
How has it helped my organization?
I can drill down/troubleshoot errors much quicker.
What needs improvement?
Design/ease of the learning mode feature.
For how long have I used the solution?
I have used the product for about a year.
What was my experience with deployment of the solution?
No, the engineer did a very smooth job at deployment.
What do I think about the stability of the solution?
No I have not.
What do I think about the scalability of the solution?
No I have not.
How are customer service and technical support?
Customer Service:
8/10.
Technical Support:I haven’t had an issue in the year I have used the product.
Which solution did I use previously and why did I switch?
I did, and I switched because of the poor level of customer service and the solution wasn’t meeting my expectations.
How was the initial setup?
The setup was pretty straightforward as right away, I was very familiar with the architecture.
What about the implementation team?
Their rep did the initial setup and I shadowed him.
What was our ROI?
If I calculated the man hours trying to figure out the alerts I would say a few thousand hours a month have been saved
Which other solutions did I evaluate?
I did evaluate about four other similar products –
- Gardium
- Application Security
- Sentrigo
- Veracode
What other advice do I have?
It's a decent product.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Operations Consultant at a financial services firm with 10,001+ employees
Sometimes convincing the engineering team that there was a problem was a bit harder than it should have been, but the on-site engineers who supported the implementation were excellent.
What is most valuable?
We utilise the following components:
- Database activity monitoring of Oracle/SQL/Sybase databases - we did have UDB running, but that was decommissioned
- Assessment scans using mostly custom checks to check for security settings - we did expand this at one point to check for best practise, but this was discontinued
How has it helped my organization?
It hasn't really improved the way we function, but it has allowed us to meet several audit issues that were outstanding for many years. We tried another product, but we found it did not meet our requirements.
What needs improvement?
- Capacity management of application needs significant improvement
- Task management functionality is pretty basic, with not a lot of functionality
- I would also like to be able to replace IP addresses with DNS names for easier recognition of host machines
- The SOM feature could also be dramatically improved to allow central management of the entire feature set
- The ability to manage lifecycle of agents could be improved via central deployment of upgraded agents
For how long have I used the solution?
I started using the database auditing/risk areas of the product in mid-2011. We use agents for monitoring database activity. We do not use the gateways for collecting data via the network.
What was my experience with deployment of the solution?
We had several performance issues on high throughput applications due to outdated, old hardware/non-ideal settings in the agents. These were mostly on our end.
What do I think about the stability of the solution?
We had a few minor issues with stability, but it has not impacted our service. We did have an agent cause a reboot of a host server, but this was quickly fixed via an upgrade of the agent.
What do I think about the scalability of the solution?
Capacity management is a major issue with the application. There is no easy way to identify when new hardware is required, or if a modification to the configuration could solve the issue. This may have been due to our method of deployment though.
How are customer service and technical support?
Customer Service:
We had a service provider in-between Imperva and our organisation. It did not make things easy. When dealing directly with Imperva I had good experiences with the vendor, and real issues were escalated quickly and getting access to the relevant engineering sections of the vendor was possible.
Technical Support:Technical support was hit and miss. Sometimes we received excellent support, and other times it was not so good. Sometimes convincing the engineering team that there was a real problem in the software was a bit harder than it should have been. Overall, compared to other vendors, support was good.
Which solution did I use previously and why did I switch?
We previously used another solution, and that product was different depending on the DBMS that was being monitored. Technical expertise in DBMS technology with that vendor was poor, so we switched..
How was the initial setup?
The initial setup was easy, but some of the specific requirements we had required some work. Deploying the hardware during the initial setup did not require and specific customisation for our organisation. The audit policies and assessments obviously did require customisation, but it was relatively simple. Later on, we did find some issues that were due to the setup of the site hierarchy that was not brought to our attention until one to two years later.
What about the implementation team?
We used on-site vendor engineers to support the internal implementation. Their level of expertise was excellent.
What was our ROI?
This is not relevant to the production selection, as we were required to close off auditing items.
Which other solutions did I evaluate?
We compared IBM Guardium and Imperva SecureSphere via a POC process. We did a paper evaluation of other products to choose two products for the POC.
What other advice do I have?
Go through the POC process and test all ITIL processes to ensure you understand what will be required for the entire lifecycle of implementation/support. Engage with DBA teams to provide DBA support and knowledge. If it's possible, ensure there are people who understand databases on the SecureSphere support team.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Data Analyst at a tech services company with 11-50 employees
The tool has good database reporting features, but setup and licensing are quite expensive
Pros and Cons
- "Database reporting features are valuable to us."
- "The GUI is bad."
How has it helped my organization?
The solution helps us with monitoring the databases, servers, and activities.
What is most valuable?
Using the product is a good experience. Database reporting features are valuable to us.
What needs improvement?
The GUI is bad. The product must focus on improving its reporting features and the dashboard.
For how long have I used the solution?
I have been using the solution for nine months.
What do I think about the stability of the solution?
I rate the tool’s stability a five or six out of ten. The glitches and errors have recently been quite high because they allow connection to databases without verifying or discovering the database. We have to keep in mind that we must monitor all the time.
What do I think about the scalability of the solution?
The scalability is pretty good. I rate it a seven out of ten.
How was the initial setup?
The setup can be a little complicated.
What was our ROI?
For the pricing that the solution provides, the return on investment is good for large companies. It's quite expensive for small to medium businesses.
What's my experience with pricing, setup cost, and licensing?
Overheads like physical databases and servers can be a little bit expensive. The setup and license are quite expensive.
What other advice do I have?
I would not recommend the product to small and medium businesses. Overall, I rate the tool a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free Imperva SecureSphere Database Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Product Categories
Database SecurityPopular Comparisons
IBM Security Guardium Data Protection
Oracle Audit Vault
DataSunrise Database Security
Trustwave DbProtect
IDERA SQL Secure
Buyer's Guide
Download our free Imperva SecureSphere Database Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- IBM Guardium vs Imperva SecureSphere Database Security
- DDoS AMP attacks - should we go with Imperva SecureSphere?
- What is the performance parameter of Imperva X10K versus BIG-IP i2600?
- How does IBM Guardium Data Protection compare with Imperva SecureSphere Database Security?
- What are the differences between IBM Guardium and Imperva?
- When evaluating Database Security, what aspect do you think is the most important to look for?
- IBM Guardium vs Imperva SecureSphere Database Security
- What is the difference between "data protection in transit" vs "data protection at rest"?
- Audit Vault vs. InfoSphere Guardium?
- Database security tools comparison report?