No more typing reviews! Try our Samantha, our new voice AI agent.

Orca Security Valuable Features

Nykole Denoo - PeerSpot reviewer
Nykole Denoo
Cyber Security Analyst at BNY

The features of Orca Security that stand out to me from my experience are that it allows agentless deployments. Since it is integrated into my AWS environment, it gives me comprehensive visibility across my whole AWS environment. With that kind of visibility, I am able to detect vulnerabilities or misconfigurations. I can do risk prioritizations and compliance monitoring through that. These capabilities of Orca Security align closely with the work I do when it comes to vulnerability management or security, cloud security assessments, or even regulatory compliance. Those features help with my day-to-day activities.

Orca Security goes beyond just basic vulnerability detection when analyzing risks contextually and holistically. I think it adds a strong contextual understanding. Instead of treating each finding in isolation, it correlates risk across cloud assets, identities, network exposures, or workload configurations. That really helps provide a more holistic view of the attack path and potential business impact.

View full review »
Krishnakumar Mahadevan - PeerSpot reviewer
Krishnakumar Mahadevan
CISO at Spink Solutions Private Limited

Orca Security excels in identifying risks. If posture management is configured well, the tool performs effectively in identifying risks. I appreciate the tool as it finds various issues. In today's AI era, we see many new challenges, including tool poisoning and broken paths, which Orca Security identifies effectively. The tool captures all the risks related to entitlement management as well, focusing on the segregation of duties to minimize risks.

We use AI across the cloud environment, which helps in automating and remediating issues while enabling organizations to connect fragmented data for faster investigations and prioritizing measurable risks. Orca Security has seven distinct positive risks, including token theft and command injections, which are vital for security posture management.

View full review »
reviewer2800203 - PeerSpot reviewer
reviewer2800203
Assistant Manager at a manufacturing company with 10,001+ employees

The standout part of Orca Security is the package approach. When they provide remediation or alerts, they also provide the exact path for a particular vulnerability or alert. They show us the specific path that needs to be fixed in order to remove the vulnerability or alert. They provide path information directly from the systems, so sometimes we don't need to log in directly and investigate ourselves. This feature is valuable, though there are occasional false positives, which is a normal part of security.

Regarding prioritization and assigning risk, Orca Security was good at analyzing risks contextually and holistically. As the tool and product mature, they will definitely announce new features. On a scale of ten, I would rate this around seven or eight. I have not given a ten because there are a few false positives and some areas where the product needs improvement on a regular basis. Sometimes they release the product, but modifications could still be required on their side.

It is good to prioritize risks with Orca Security because they are not only targeting the CVSS score but also the EPSS, which is the Exploit Prediction Scoring System. They monitor particular assets based on both approaches. On the CVSS side, they reference the National Vulnerability Database, and on the EPSS side, they target the Exploit Prediction Scoring System. So they are targeting both risk-based approaches as well as the CVSS approach.

View full review »
Buyer's Guide
Orca Security
August 2026
Learn what your peers think about Orca Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
910,350 professionals have used our research since 2012.
reviewer2799597 - PeerSpot reviewer
reviewer2799597
Soc Analyst at a tech consulting company with 11-50 employees

One of Orca Security's main features is its agentless architecture, enabling it to conduct cloud security gap analysis and vulnerability scans without installing agents. The tool offers visibility into attack paths and predicts potential impacts if an exploit occurs. Furthermore, it includes identity and risk access analysis, CIEM, and Kubernetes cluster scanning. The product integrates well with CI/CD pipelines for identifying IaC misconfigurations. I appreciate its side scanning and workload visibility, which is valuable for analysts involved in security posture management and audit evidence collection.

View full review »
RicardoEscriba Robles - PeerSpot reviewer
RicardoEscriba Robles
Co E Cloud Security at Banco de Crédito BCP

I find Orca’s secret scanning and 'Shift Left' capabilities to be most valuable. The platform integrates directly into our GitHub and Azure DevOps pipelines, which allows us to automatically analyze pull requests for hardcoded passwords, API keys, and other sensitive credentials.

View full review »
Fabricio Galdino - PeerSpot reviewer
Fabricio Galdino
Cyber Security Analyst Ii at Grupo PRIMO

What I love most about Orca Security is the easy integration with other tools. I really like it because it's very easy to integrate with other tools that are important for the company. It's already set up in the platform easily. I don't need to do unusual modifications or create a script. It's pretty easy to integrate these tools.

It is easy to prioritize risks using Orca Security because they have already been categorized. The severity of some risks is delivered from Orca Security, and I can set some kind of high-value asset designation. I can define what is a high-value asset or not. The attack paths also help me to understand the prioritization of the risks of these assets.

Orca Security has helped my company reduce the time it needs to address cloud security alerts and make it faster. When one critical risk or high risk is identified in my environment, I already receive notifications, even in email or in Teams, Slack, or any channel that is integrable to Orca Security. I receive a very fast notification to address the vulnerability and security issues to the teams.

View full review »
Anurag Jat - PeerSpot reviewer
Anurag Jat
Cyber Security Analyst at Accenture

I find the filters of Orca Security very beneficial, and the GUI is also very beneficial. The migration support provided by Orca Security across multiple clouds, including AWS, GCP, and Azure, gives a wide range for searching.

All risks are timely identified in Orca Security and timely notified, with alerts triggering over the ticketing tool, providing good risk identification and incident handling.

Orca Security provides a very holistic approach and holistic view of what has happened, with things categorized accordingly.

Orca Security generally has a rating based on risk parameters. If the risk level is high, the rating is based on a zero to five star scale, and high-risk items generally have a rating of 4.5 or above, which is very beneficial for judging incidents based on their rating.

Orca Security helps much in defense and gives notifications prior to the alert, providing a more detailed view for proper investigation.

Orca Security provides a very holistic approach and a very user-friendly GUI while supporting multiple clouds, which is helpful for security personnel to identify and mitigate risks.

Orca Security helped us reduce the false positive rate. When changes in instances are made by a historical user or the user to which the instance is assigned, I can set a query in Orca Security and the alert is not triggered. However, if changes have been made by a malicious person, the alert triggers. This means not every change triggers an alert, only malicious ones do, reducing the false positive rate by approximately 10 to 20 percent.

View full review »
Evgeny Shulga - PeerSpot reviewer
Evgeny Shulga
CTO /Director at OPLIUM

The best features of Orca Security include automation and compatibility, which I really appreciate, and many of my clients value them as well. We have access to many features that differentiate this solution from other systems offering the same capabilities. For me, the most important aspect is how deeply you can investigate situations with this technology, including checking for leaks or similar issues.

In our opinion, Orca Sensor is the best solution available at the moment, and it significantly affects the visibility and protection of environments.

View full review »
AG
AvrahamGoldwasser
Cyber Security Tech Lead & Architect at a insurance company with 51-200 employees

Orca Security offers good security as a CSPM, runtime security with the real-time security agent on Kubernetes, and excellent visual representation to see what is really going on. The visual representation helps me understand where our gaps are and what needs to be fixed through remediations. In terms of AppSec, it provides entire connectivity with some missing parts, but mainly the Git parts with the repos allow me to see everything, how it is integrated, and to assess its risks. The SCA with the SAST is also crucial.

The feature that stands out the most for me is that it is agentless, so I have simple connectivity where I can see everything in one place. If there are misconfigurations, security risks, or misconfiguration gaps, I can be alerted and set up custom alerts and non-custom alerts, allowing our security team to observe these alerts and take action.

Orca Security has positively impacted my organization mainly through use by the security team, but we also use it for compliance reports. We can set the compliance standards we want to adhere to in Orca Security, and then I can check in which areas of each resource or organization-wide efforts comply with those standards. This is really useful to know where our compliance gaps are.

Risk detection and identification capabilities of Orca Security are great and really useful. They had too many false positives in the past, but over time, with their improvements, probably due to UBA or something similar, it has really improved.

View full review »
Guilherme Ferreira Mury - PeerSpot reviewer
Guilherme Ferreira Mury
Senior Penetration Tester at a wholesaler/distributor with 501-1,000 employees

What I appreciate the most about Orca Security are the AI features for solving false positives and tackling some cases that are not entirely clear for my team, which helped greatly for investigating and dealing with those situations and proved to be highly accurate.

View full review »
reviewer2806824 - PeerSpot reviewer
reviewer2806824
Cybersecurity Recruitment Specialist at a tech services company with 51-200 employees

Orca Security is a really strong product because it has a lot of different differentiators. Orca Security is based on agentless side scanning, so it has the ability to scan cloud workloads including virtual machines, containers, and serverless infrastructure all without installing any software or agents. This results in zero performance impact on production, which I think is the most important thing in the market share or in an eventual Gartner Quadrant.

Orca Security helps in preventing risks and attacks across the application lifecycles by scanning not only the apps in production, but also the apps or microservices in development. This provides complete visibility to your infrastructure.

View full review »
Logan Gray - PeerSpot reviewer
Logan Gray
Manager, Security at BenchSci

Orca Security helps me decide what to prioritize for patching and upgrading with its workload protection features that work really well and help contextualize and prioritize the issues it finds.

The best features Orca Security offers are cloud security and its shift-left features. The shift-left features of Orca Security help detect issues earlier in the software development lifecycle, benefiting my team day-to-day.

Orca Security has positively impacted my organization by helping us become more secure by flagging and prioritizing issues.

My impressions of the risk detection and identification capabilities of Orca Security are that they are very good because it helps contextualize and prioritize the issues for us to work on.

Orca Security has helped in preventing risks and attacks across my application lifecycle by highlighting insecure configurations or vulnerabilities that do not yet have an exploit so that we can resolve those issues before they become more critical.

My impression of Orca Security's ability to analyze risks contextually and holistically is that it seems quite good because it has visibility of our entire cloud infrastructure and can gather additional context to help prioritize and inform on issues.

View full review »
Kaue Ribeiro - PeerSpot reviewer
Kaue Ribeiro
Cybersecurity Architect Lead at a consultancy with 11-50 employees

I appreciate Orca Security because I can see CSPM, KSPM, and DSPM. Orca Security works with major frameworks on security, such as NIST and CIS, allowing me to see comprehensive insights on my cloud environment. I appreciate the Orca Security CI/CD integration, the shift-left configuration, which helps me improve cloud maturity and DevSecOps maturity. From my perspective, Orca Security is a complete CNAPP platform with the most capabilities to work with cloud security.

View full review »
RiteshWalia - PeerSpot reviewer
RiteshWalia
Senior Specialist at a tech vendor with 10,001+ employees

The best feature I appreciate about Orca Security is its reporting functionality. The dashboard is very clear and concise, and it helps filter multiple accounts by issue type. Exporting the dashboard into an Excel sheet provides a good user experience.

To ensure we remain compliant, Orca Security's dashboard is really helpful in tracking the issues we have, with the end goal of always being compliant with our compliance standards and organizational requirements. It helps significantly with that.

Orca Security has helped our organization become compliant and maintain high standards because any organization with multiple products needs to be compliant, especially when it comes to underlying infrastructure and cloud resources. Orca Security helps tremendously in that regard.

View full review »
reviewer2817672 - PeerSpot reviewer
reviewer2817672
Gerente De Arquitectura De Ciberseguridad at a financial services firm with 5,001-10,000 employees

In my opinion, the best features Orca Security offers include the integration to our cloud services, which is smooth, easy, and plug and play, along with its effectiveness in prioritizing risks, taking into account all of the different factors that make a risk—not only vulnerabilities but also if you have sensitive data or if you have your cloud resources exposed, giving you the risk based on that context, which helps you to prioritize the risks to know where to mitigate first.

This has changed the way my team works and responds to threats because it saves us a lot of time and helps us to focus on the real risk rather than all of the alerts that we receive, as we have a lot; therefore, we cannot fix everything and need to prioritize, making the way that Orca Security prioritizes the risks key for us.

Orca Security has impacted my organization positively by giving us visibility on what is happening in the cloud and helping us detect risks fast. Before Orca Security, we did not have that visibility, and we had to manually check our cloud to understand if we had risks. Today, with Orca Security, we are comfortable and feel that we have the visibility that we need in the cloud to be sure that we do not have risks there.

View full review »
Marcus Cassilia - PeerSpot reviewer
Marcus Cassilia
Cyber Security Consultant at ShieldSec

The best feature is Orca Side-Scanning. Because of this feature, the platform does not need to use agents for the detection of virtual machines, containers, and hosts. It can connect via a cloud-native API and perform out-of-band scanning using read-only access. Orca Side-Scanning has made things both easier and faster for security teams and for the people who have to act on findings. This platform is very useful for the maintenance of vulnerability in cloud environments, with the impact on the security team's workflow being a much faster time-to-value.

The Attack Path feature is a great option for the capabilities of Orca Security's strengths because it models network exposure, permissions, vulnerabilities, and trust relationships. This feature helps security teams think like attackers and identify high-impact risks.

View full review »
HG
Harsh Goenka
Cloud Architect at a outsourcing company with 51-200 employees

The main feature that I appreciated about Orca Security is that it is 100% agentless and context-aware, meaning it understands what it is doing.

The primary benefit is that it provides us with CVEs, through which I can identify the vulnerabilities in our security posture.

In the long run, as a security tool, it has helped us improve our security posture.

View full review »
reviewer2879382 - PeerSpot reviewer
reviewer2879382
Dev Ops Security Engineer at a computer software company with 10,001+ employees

The best feature Orca Security offers is a remediation solution. What I appreciate most about the remediation solution is that it provides a fast fix for the vulnerabilities in my day.

Orca Security has positively impacted my organization by improving our security posture and hardening our services and resources.

View full review »
Rafael Bueno - PeerSpot reviewer
Rafael Bueno
Consultor De Segurança Da Informação at a tech services company with 1,001-5,000 employees

The AI fix for vulnerabilities that we found is the best feature because it gives us more time to focus on other things.

The dashboards were very helpful, and I could personalize them for our case, which helped me show my leadership where the main points were and how to address them, allowing us to focus on what was really important. It was very easy to change the dashboards and personalize everything.

OrcA Security improved our collaboration because we could explain better to everyone at the company what we were doing and how it positively impacts our security posture. We could also measure our risks and vulnerabilities better, enabling us to think more strategically about improving our cybersecurity posture.

We have faster fixing of vulnerabilities with our DevOps team, and we could have fewer attacks.

It was really good because we could see threats coming before they materialize, which I think is a really good way to protect ourselves, our resources at the company, and all our assets.

We are a small team, and I did not feel any difficulty in the work using Orca Security, so I believe it saved us more employees and other costs, helping us save in different ways.

View full review »
DM
Danny Mishkit
Software Developer at a tech vendor with 1,001-5,000 employees
Orca Security's multi-tenant architecture helped the organization ensure consistent security coverage across different servers. Since we use different servers for our company, it helped balance out everything and work in a single environment. It helped localize everything in a comfortable way, which I really appreciated, because whenever we used different levels of our product, it helped us maintain things in a more comfortable way.

I assessed the effectiveness of Orca Security's content, malware prioritization system, and evaluated alerts based on severity and business impact, but I don't remember getting any alerts, which is presumably a good thing. The whole process of logging on, which is extensive in a good way, helped us maintain a high level of security with features such as two-step authentication. This created a sense of security when working from home or abroad.

View full review »
Rodrigo Americo - PeerSpot reviewer
Rodrigo Americo
Security Enginner at a financial services firm with 1,001-5,000 employees

The vision related to security frameworks is very valuable for us, and we use that to be compliant with standards such as PCI DSS. The way to create dashboards is very useful for us as well.

It is easy for us to have one place to check things, and when we need to create some report for our teams or for another team, we use these compliance visuals to see what is compliant and what is not compliant.

View full review »
CHINTAN MEHTA - PeerSpot reviewer
CHINTAN MEHTA
Cloud Security Automation Engineer at a financial services firm with 10,001+ employees

The best features of Orca Security include its ability to perform a lot of security controls without requiring any installation of agents, making it very easy to set up. This feature allowed us to replace a lot of tools with one comprehensive platform, enhancing our ability to consolidate the security footprint on a large scale. 

It provided us with visibility from a central point, increasing our view from the previous thirty percent to a full one hundred percent of our cloud environment. This comprehensive view facilitated improvements in our security posture.

View full review »
reviewer2593152 - PeerSpot reviewer
reviewer2593152
Senior Information Security Engineer at a computer software company with 10,001+ employees

One of the valuable features of Orca Security is its design and options that allow flexible filtering and user-friendly visualization. 

Additionally, it covers a large scope of vulnerabilities, CVEs, malware, and misconfiguration. It also helps identify compliance issues in our cloud environments like AWS or GCP.

View full review »
reviewer2618748 - PeerSpot reviewer
reviewer2618748
Vulnerability Assessment Analyst at a computer software company with 501-1,000 employees

One aspect that stands out is the seamless integration. Once our organization is configured, any cloud account under that organization is automatically detected in Orca Security, along with all the assets associated with it. 

Another valuable feature is the side scanning technology using a snapshot mechanism. This technology allows for coverage of almost all cloud assets without interrupting their operations.

View full review »
Krishnakumar M - PeerSpot reviewer
Krishnakumar M
enterprise architect at a tech services company with 1-10 employees

The GUI features are very good. Threat intelligence is also very good. 

View full review »
SS
Srinath Swarna
Works at Ultraviolet Cyber

I find Orca Security's CIEM feature invaluable, as it focuses on entitlement and posture management, identifying assets with older OS versions, and asset misconfiguration. 

The CDR feature is also critical, focusing on detection and response, triggering alerts like brute force attacks and malware. It provides alert and asset details, which include multiple remediation actions. It combines functionalities of multiple security tools and collects alerts and logs from them.

View full review »
Cédric Thian-Meng - PeerSpot reviewer
Cédric Thian-Meng
Presales Security Engineer / CSM at Cybersel Group

Orca Security has patented technologies. It's an agentless solution, so you don't need to install an agent. Instead, it contacts your account provider and fetches metadata, eliminating the need for snapshots or reserved space to copy client infrastructure.

The multi-cloud capability displays essential information and potential vulnerabilities with granular detail. For instance, it identifies paths that attackers might exploit to gain root or admin access to machines.

It is comprehensive, covering a wide range of software needs. They also integrate with CI/CD pipelines, enabling developers to ensure security from the early stages of code deployment. This integration provides a 100% guarantee on security, safeguarding images, configurations, and other crucial information throughout the development process.

View full review »
GT
GuilhermeTeles
Cloud Security Contractor at TripAdvisor
The reporting and automated remediation capabilities are valuable to me. They're real game-changers. View full review »
reviewer2201862 - PeerSpot reviewer
reviewer2201862
Information Security Engineer at a university with 1,001-5,000 employees

Recently, Orca Security has updated its interface, making it more user-friendly. I find it particularly useful as it allows me to easily navigate the dashboard and prioritize actions based on severity and criticality. 

This feature makes it easy for me to look at prototypes and determine the necessary steps to take, focusing on critical issues first. I love the interface dashboard.

View full review »
Rooshan Naeem - PeerSpot reviewer
Rooshan Naeem
Security Engineer at Eon Health

The most valuable feature of Orca Security is the automated scanning tool, user-friendliness, and ease of use.

View full review »
it_user1768188 - PeerSpot reviewer
it_user1768188
CISO at a recruiting/HR firm with 11-50 employees

Orca gives you great visibility into your assets. It shows you the issues and the things that you need to attend to first, by prioritizing things. You can see a lot of information that is not always visible, even to DevOps, to help you know about the machines and their status. It's very easy to see everything in a single dashboard. That makes it a very useful tool.

The fact that it prioritizes vulnerabilities and findings, and doesn't present you with hundreds of unuseful findings, is important. They focus the information and make you concentrate on the high-priority items. This is something that differentiates it from the others.

They also now have the ability to filter findings based on best practices, like CIS, PCI, and even GDPR. That means you can filter your environment based on a specific filter, and that helped us when doing our PCI audit. We were able to show the auditors what our environment looks like from a PCI perspective. That's another great feature that it offers.

It's also very easy to use, very intuitive, and very detailed.

Another new feature shows you outliers and abnormalities for IAMs and access. It focuses on users with too many permissions and provides you with recommendations on what to do as a result.

There is a feature that searches for secrets on your infra and what can be done with those secrets.

You can also do very complex search queries to find assets that you think may be relevant. For example, searching for Log4g references in the infrastructure was very easy.

I also like the fact that the solution includes the most potentially painful parts, out-of-the-box, like malware and secrets scans, IAM, attack vectors, and benchmarks against CIS and other best practices. That full suite is something that every security professional needs. It solves the issue of having to run multiple tools, such as a vulnerability scanner, a secrets scanner, and a role management/permission/authorization tool that searches for abnormalities. I think it's a no-brainer, given that it runs everything, and you don't need to pick and choose anything. Everything comes out-of-the-box and is very easy to use, plug-and-play, and you get an instant view of things on the dashboard.

View full review »
it_user1731741 - PeerSpot reviewer
it_user1731741
CISO at a financial services firm with 51-200 employees

We like that Orca is continuously monitoring our environment. When you open the tool, you instantly get an overview of your current state of affairs. You see everything happening across your multi-cloud environment in one view. When you're working on GCP or Azure, and you also have some other elements within AWS, it isn't easy to have a tool that spans all these cloud environments. It's great to have a single dashboard that puts all your cloud environments at your fingertips.

Orca tool spans all our environments and gives us a compliance report. It can tell us where there are vulnerabilities within our environment and provide us with access to the logs of specific assets.

View full review »
reviewer1729920 - PeerSpot reviewer
reviewer1729920
Co-founder at a tech services company with 1-10 employees

The compliance dashboard is one of the features that our customers find very interesting. Instead of having to run checklists and provide access to auditors, you can just generate a report from Orca.

The automation and alerting capabilities are very good. When there is a new vulnerability or a new issue, you can get an automated alert in Microsoft Teams or in Slack.

The visibility that Orca gives into the environment is really in-depth because of their site-scanning technology. They provide full visibility into everything running in the cloud environment. They can look at virtual machines; they can look at serverless; they can look at the configuration of users and roles. They can also see, for example, that a specific administrative user has no multifactor authentication configured. It covers the full stack and not only one specific item.

The alerting capabilities are now being added, which is a very good evolution.

The integration with SIEM tools is now in place, which is a nice feature.

View full review »
MH
Morey Haber
Chief Technology Officer & Chief Information Security Officer at BeyondTrust

The most valuable features are vulnerability management and attack detection.

The vulnerability management does not require network scanning or agent technology, so I don't need to modify any of my products in order to do vulnerability assessments.

The monitoring of logs and attack scenarios are basically hands-free. It's a non-intrusive approach.

View full review »
it_user1700292 - PeerSpot reviewer
it_user1700292
CISO at Lemonade Inc.

Orca's dashboard is excellent. My team needs to be able to focus on specific areas for improvement in our cloud environment. Most recently, we've started to get good use out of sonar, the search capabilities, and the alert creation. We plan on using that to automate notifications and remediations. So we have high hopes for that, but we haven't used much of that yet.

The visibility Orca provides is excellent. Orca allows agentless data collection directly from the cloud, so I assume there is no performance impact. It's important for a product not to get in the way of performance, but it's not my biggest concern. I mainly care about coverage. It was important for us to have a SaaS solution, but it wasn't critical. We prefer not to manage a service ourselves, so it matters.

View full review »
TS
Ty Sbano
Chief Security & Trust Officer at SiSense

With its Cloud Security Posture Management capability, we have the ability to read across all of our cloud-based environments, which includes AWS and Azure. We have visibility into those environments. Seeing all vulnerabilities and configurations is really powerful for us, but ultimately, the ability to use the API to query across the fleet to understand what is the current state, what is the patch level, which ones are potentially exposed for a new CVE that just came out is even more valuable. It allows us to gather really specific intelligence through simple queries.

Given the agentless deployment, its time-to-value is less than 24 hours. It took less than 24 hours, and we had intelligence and insight. Ultimately, it is getting access to the API, and then from there, it is about getting the side channel scanning going on. Once that is complete, the real-time proprietary nature of new assets pops up. We also have the visibility if an old asset has been sitting out there unused for a really long time.

View full review »
it_user1697910 - PeerSpot reviewer
it_user1697910
Chief Risk Officer at a financial services firm with 51-200 employees

Orca provides X-ray vision into everything within the cloud properties, whereas normally, this would require multiple tools. As an analogy, for on-premises equipment, you would need different tools to be able to see the performance of a system, determine what versions of software applications are installed, and look at the security. You would need yet another one to give you a holistic view of all of the hardware inside of the system.

From this one platform, we can get visibility right down into the hardware through all of the applications, and through the operating system. One application provides an entire view of our security. Gartner coined the name Cloud-Native Application Protection Platform, in reference to this product, because Orca created did not exist previously. Orca literally invented a whole new way to view security in the cloud.

Because the interface is so simple, you don't need people that have tons of experience. You can take a lower-level person and give them basic instructions on what to watch for. If anything comes up with a high-level or medium-level alert, then they have to contact somebody else. It's literally that easy.

View full review »
reviewer1696863 - PeerSpot reviewer
reviewer1696863
CISO at a media company with 201-500 employees

Orca's SideScanning is the biggest feature. It's the "wow" factor. There are a few other solutions with that kind of functionality, but before Orca, nobody would do it. They would say, "You just have to put an agent somewhere, and we have to read your logs," and there was a lot of overhead and you had to make sure you kept these requirements happening. You always had to configure things to work. With Orca's SideScanning, they just need permissions for your account and that makes it so simple. It just works. And you get the insights that are super important.

Another valuable feature with Orca, something that's not talked about enough, is its ability to rank your gaps and your tasks. The one resource that's very finite is your engineers' time. Every CISO has the same problem: they have engineers, but not enough of them, and their engineers don't have enough time. Because of these limitations, the engineers need to focus on the most important tasks, and they need help to do that. The fact that Orca can take something that looks like a 10 out of 10, a critical CVE, and say, "Wait a second. It's not that important, because of A, B, C, D, E, and F reasons. You can delay it for your next patching cycle. But this issue, the one that's only a CVE 7, is explosive on the internet." That kind of ranking is super important because of the limited resources and time. I need to make sure that everybody is focused on the most important things. The ability to see that, seamlessly, along with the ranking, makes Orca a very good product.

One thing that has been really surprising to me is its ability to give us container posture. Everybody is talking about containers and there are so many container-specific companies. At one point we were wondering if we needed a container solution. We talked to Orca and started testing what's out there, and we were surprised to see that Orca is very strong in containers as well, including Kubernetes and Docker. The way they see it, it all has to do with your posture and how secure you are. That's their goal: that you will have the most secure cloud possible, based on best practices.

The fact that it's a cloud solution is also important. In the same way that I'm happy that Amazon maintains data centers and I don't have to, and that a lot of my solutions are maintained by their engineers, Orca allows my team to focus on more relevant tasks. I don't want anything on-prem. I don't want my team to deal with anything if they don't have to. Anything that would require in-house maintenance for us, is a no-go. The only admin with Orca is when you have a new account or there is a change to your account. You have to configure the Orca with it, but you can run an automation that helps you out with it.

Orca is also very good at keeping our data safe and masking it and not picking anything they don't need to pick. In that sense, it's also good.

View full review »
reviewer1694079 - PeerSpot reviewer
reviewer1694079
CISO at a tech services company with 501-1,000 employees

The visibility Orca provides into my environment is at the highest level. I was super skeptical about Orca when I interviewed the Orca team. When they told me that you can just drop their software in and you don't need to log in to the machines, nor do they need to be powered on, I said, "How the heck are you doing that?" When they told me how it worked I said, "Woah, that's pretty simple. Why didn't I think of that?" When I dropped them into the environment, from the very get-go I had more insight into the risks in my environment than I had had during the entire two and a half years I had been here.

View full review »
Mauro Restante - PeerSpot reviewer
Mauro Restante
Cybersecurity Customer Service Manager and Technical Account Manager at Cybersel

One of the most valuable aspects is the agentless feature. Orca Security doesn't use agents at all.

View full review »
Buyer's Guide
Orca Security
August 2026
Learn what your peers think about Orca Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
910,350 professionals have used our research since 2012.