Try our new research platform with insights from 80,000+ expert users
it_user1258575 - PeerSpot reviewer
Governance Test and Compliance Officer at Thales
Real User
We are able to filter alerts by security level so our teams understand which situations are critical
Pros and Cons
  • "I was looking for a vulnerability scanner and I was looking for one place in which I could find everything. This tool not only does vulnerability scanning, but it also gives me an asset management tool."
  • "We would like it to have more features from the risk and compliance perspectives."

What is our primary use case?

I was looking for one tool which, as a WAF, could provide me with information regarding applications  and with features where I can oversee things.

We use the solution's ability to filter alerts by levels of security and it helps our teams understand which situations are the most critical. Based on the priorities that I get for my product, I can filter the notices the team needs to work on, to those that require immediate attention. That means it's easier for me to categorize and understand things exactly, on a single dashboard. I can see, at one point in time, that these are my 20 applications that are running. Out of them, I can see, for example, the five major vulnerabilities that I have — and it shows my risk tolerance — so I know that these five are above my risk tolerance. I know these need immediate attention and I can assign them to the team to be worked on immediately.

How has it helped my organization?

Instead of going for multiple tools, this tool has helped me to have one platform where I can have all the features and information I'm looking for.

The tool is working on the principles of governance, risk, and compliance as well. It even helps me in application-level firewall security. It's not just a single tool. It has helped me find out details about multiple things.

The integration with user tools is pretty easy; it's user-friendly.

In terms of a reduction in alerts, it has helped me out in not putting unnecessary time into a couple of things, which can be figured out at a glance. I would estimate the reduction in alerts at about 40 percent.

What is most valuable?

I was looking for a vulnerability scanner and I was looking for one place in which I could find everything. This tool not only does vulnerability scanning, but it also gives me an asset management tool.

It has been good in my test environment when it comes to scanning my infrastructure.

What needs improvement?

We would like it to have more features from the risk and compliance perspectives.

On the governance side of it, we did want it, but the licensing costs for that are so high. As a result, I have to integrate this solution with a couple of additional tools. For example, suppose I wish to assign something to an organization or to another person. To do that I have to integrate it with something like JIRA or Confluence where I can ask them to provide the pieces of information. If the licensing costs were a little lower, I would have been able to assign it then and there. As it is, though, I need to assign it from one platform to another platform, one where the team of engineering people is working. I still need to go to multiple platforms to check if something was assigned, and I have to keep checking between the two platforms to see whether it's not done or not.

Buyer's Guide
Prisma Cloud by Palo Alto Networks
April 2025
Learn what your peers think about Prisma Cloud by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
849,686 professionals have used our research since 2012.

For how long have I used the solution?

We have been using Prisma Cloud by Palo Alto Networks for five months, testing it and evaluating it during that time. We are planning to purchase it.

I have been evaluating this product from the point of view of DevOps. I have not been evaluating it from the security operations point of view.

Prisma Cloud actually has two solutions. One is a cloud-based solution and the other is their on-premise solution. I have had a look at and tested both of these tools.

What do I think about the stability of the solution?

It's a stable product.

What do I think about the scalability of the solution?

It's scalable. We discussed that with them. We also discussed the scenario where I want to move from one cloud environment to another, or if I make some other changes. How flexible is the tool as far as working with different cloud environments goes? And it is perfectly fine in that regard.

If we deploy it, I will be using it quite extensively for my day-to-day vulnerability scans.

How are customer service and support?

I would rate their technical support at nine out of 10. They have been very supportive. Every time I have called them they have been there for me.

Which solution did I use previously and why did I switch?

I was using multiple tools from here and there: one tool for vulnerability scans, one for risk management. But this has provided me an answer for not just one tool but for multiple requirements that I have.

How was the initial setup?

The initial setup was easy. I got to help from their technical department and the device is more or less plug-and-play. If you have specifications which are required by the cloud, and your products are running on those specific cases, then it becomes quite easy. You just have to install it and it's good to go in your infra.

Since I did it for my development center only, I just had to install one installer and then the agents were installed automatically after running a script. For the whole environment, it could not have taken more than a day or two.

What's my experience with pricing, setup cost, and licensing?

Security tools are not cheap. This one is a little heavy on the budget, but so are all the other security tools I have evaluated.

There are no additional costs to the standard licensing fees for Prisma Cloud.

Which other solutions did I evaluate?

I looked at Trend Micro Cloud One Workload Security. Both it and Palo Alto Prisma Cloud are good for container-level security and scanning. But the financial part of it and budgeting play an important role.

With Prisma, it's not just one feature. It has also provided me with solutions for a couple more of my requirements. That was not the case with Trend Micro. In addition, Prisma Cloud was easy for me to figure out. The only con I see in Prisma Cloud is that because of its cost, I have to use multiple tools.

What other advice do I have?

It's a good tool. I would tell anybody to give a shot. It's easy, it's user-friendly; it's like a plug-and-play tool.

I am a single point of contact for this solution, right now. I'm working on it with my entire management to review things. I have to coordinate because of the multiple platforms they have. Roles have been assigned at different levels. There is a consultant's role, a reviewer's role, and there is an implementer's role. The latter is supposed to be working with them.

Root cause analysis needs to be done at my own level. The solution does inform me that a predicted vulnerability exists and this is the asset where it could be happening. But the intelligence has to be provided by the security consultant.

If something becomes visible during the build phase, we already have a pretty good area where we can change the product so that it does not impact the production environment.

The solution provides an integrated approach across the full lifecycle to provide visibility and security automation and, although we have not started using that part of it yet, it will definitely enable us to take a preventive approach to cloud security when we do use it.

Overall, it provides all the pieces of information that you require, in one place and time. I think it's going to be good to work with them.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer2237982 - PeerSpot reviewer
Senior Engineer at a tech vendor with 201-500 employees
Real User
Enables us to know what security threats are happening in the background but the UI could use improvement
Pros and Cons
  • "Palo Alto enables us to know what security threats are happening in the background."
  • "The UI is the worst."

What is our primary use case?

Our primary use cases are for container security and for auditing purposes. 

We have multiple clusters. 

How has it helped my organization?

Palo Alto enables us to know what security threats are happening in the background. 

It provides the visibility and control we need regardless of how complex or distributed our cloud environment becomes.

Prisma Cloud provides us with a single tool to protect all of our cloud resources and applications, like what we need to manage and reconcile security and compliance reports.

We have been enabled to reduce runtime.  

Prisma Cloud provides risk clarity at runtime and across the entire pipeline. It shows issues as they're discovered during the build phases.

What is most valuable?

The most valuable features are code security and container security.

It gives us awareness about any security breaches and if there are any vulnerabilities. 

Palo Alto provides security scanning for multi and hybrid cloud environments. We need to know where there is a threat. Palo Alto monitors and reports it.

It can be integrated into any alerting tool that has enough automation and capability. It can pull some of the metrics without an agent.

Prisma Cloud provides risk clarity at runtime and across the entire pipeline, like, showing issues as they're discovered during the build phases.

What needs improvement?

There are some operational issues but testing it is good. 

The UI is the worst. 

For how long have I used the solution?

I have been using Palo Alto Networks for two years.

What do I think about the stability of the solution?

The stability is good. I would rate it an eight out of ten. 

What do I think about the scalability of the solution?

The scalability is good. 

How are customer service and support?

Their technical support isn't on an expert level. They need to improve. 

How would you rate customer service and support?

Neutral

How was the initial setup?

The deployment time takes around two to four weeks. The understanding of the product takes around six months.

The initial setup was straightforward. 

It does not require regular maintenance. You need to do maintenance around every six months by updating the agent. 

What other advice do I have?

I would rate Prisma Cloud by Palo Alto Networks a seven out of ten.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Buyer's Guide
Prisma Cloud by Palo Alto Networks
April 2025
Learn what your peers think about Prisma Cloud by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
849,686 professionals have used our research since 2012.
reviewer2173338 - PeerSpot reviewer
Solutions Architect at a tech services company with 501-1,000 employees
MSP
Top 20
Good inventory reporting and security posture management
Pros and Cons
  • "Prisma Cloud's inventory reporting is pretty good."
  • "The information presented in the UI sometimes doesn't look intuitive enough."

What is our primary use case?

I generally use Prisma Cloud to dive deeper into any security findings generated by Prisma. It's also a good way to get a complete inventory of all our cloud assets spread across different cloud platforms.

How has it helped my organization?

The customers that we work with have really benefited from Prisma Cloud by including it in their workflows and security audits. Prisma Cloud has really helped them improve their security posture.

What is most valuable?

Prisma Cloud's inventory reporting is pretty good. If you have multiple clouds or platforms, you can have a list of all your cloud resources within Prisma. The security posture management is also great.

We continuously work with our security teams to find any issues with their infrastructure. Prisma continuously monitors the infrastructure, which helps us locate those resources and patch those findings.

What needs improvement?

The information presented in the UI sometimes doesn't look intuitive enough. For instance, if I want to look at all the resources that are affected by a certain finding, sometimes it's not easy to locate how to look at all those resources in one place. But that's just a UI quirk. However, API-wise, Prisma Cloud is pretty good for locating what you're looking to find.

For how long have I used the solution?

I have been using Prisma Cloud by Palo Alto Networks for the past six months.

What do I think about the stability of the solution?

It is a stable product. I haven't seen any outages with Prisma Cloud.

What do I think about the scalability of the solution?

It is a scalable product.

How are customer service and support?

Prisma Cloud's customer service is pretty great.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We used a different solution before switching to Prisma Cloud. The decision to switch to Prisma Cloud was a strategic decision made by the enterprise.

How was the initial setup?

The initial deployment was pretty straightforward. We primarily use it with our AWS cloud, and it's pretty easy to set up cross-account roles to get access to Prisma. Prisma Cloud uses cross-account IAM roles in AWS. You just set those roles up using a stack SAT across your entire set of AWS accounts, and Prisma can access all those accounts immediately.

What about the implementation team?

We implemented in-house.

What was our ROI?

Prisma Cloud has really improved our productivity and freed up resource time from manually hunting for findings to automating it.

Which other solutions did I evaluate?

Before choosing Prisma Cloud, we did a few POCs for products like DivvyCloud, Dome9, and Cisive. All these products pretty much do the same thing with a few differentiating factors, but not enough to really stand out.

What other advice do I have?

I rate Prisma Cloud an eight on a scale of one to ten for ease of use. It is pretty intuitive, except for not being able to locate resources affected by a certain finding individually.

Prisma Cloud has helped free up staff to work on other projects. Previously, we used to do ad hoc scripting to find different resources affected by a certain finding. However, we no longer have to do that because everything is automated.

At least ten hours each week were freed up because of the Prisma Cloud.

Meeting with all the industry professionals at the RSA conference is a great feeling. We get to learn about the latest trends in cybersecurity, all the new products that are coming up to tackle all the challenges, and especially the role of AI and machine learning in cybersecurity.

We've been looking at improving our hybrid connectivity solutions and making them more secure. We explored a few solutions at the RSA conference, which will come into play when we decide.

Overall, I rate Prisma Cloud an eight out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Senior Principle at a tech services company with 5,001-10,000 employees
Real User
Secures data and allows large volumes of data to be secured and exposed within a tight and well-founded community
Pros and Cons
  • "Its ease of integration is valuable because we need to get the solution out of the door quickly, so speed and ease matter."
  • "The area for improvement is less about the product and more about the upsell. If we've already agreed that we'd like your product x, y, or z, don't try to add fries to my burger. I don't need it."

What is our primary use case?

We were implementing and expanding a system that we had internally. We were creating a system called Midas, which was about keeping data safe. It was cloud-based. We wanted to keep data safe and provide an analytics environment on the cloud.

How has it helped my organization?

We now have a service offering that secures data and allows large volumes of data to be secured and exposed within a tight and well-founded community.

It helped to reduce downtime in our organization.

What is most valuable?

Its ease of integration is valuable because we need to get the solution out of the door quickly, so speed and ease matter.

What needs improvement?

The area for improvement is less about the product and more about the upsell. If we've already agreed that we'd like your product x, y, or z, don't try to add fries to my burger. I don't need it.

For how long have I used the solution?

The firm has been using it for about two years. My direct interaction with it was about a year ago.

What do I think about the stability of the solution?

I didn't notice any kind of instability, but there are foibles and little nuances.

How are customer service and support?

We are happy with it overall. I'd rate them an eight out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We had a number of different solutions and still do.

How was the initial setup?

It was in-between in terms of complexity. We leveraged our Palo Alto friends to help us get over the humps, and they did a great job.

What about the implementation team?

We didn't take help from any third party. Palo Alto implemented it.

What was our ROI?

We have not seen an ROI in this case, but we didn't buy it for a return on investment.

Which other solutions did I evaluate?

We evaluated multiple solutions. They have a well-known product line in the industry, and we stopped and talked with them and picked them because of their capabilities and competencies.

In terms of providing a unified platform that natively integrates all security capabilities, I'm not expert enough to say that it supplies everything, but it's well-known. There are a number of different features and capabilities in their suite.

What other advice do I have?

To a colleague at another company who says, “We are just looking for the cheapest and fastest firewall," I would say that it's never the cheapest and the fastest. You always need to lay down what your needs are and then go after who has the right level of capabilities, competencies, and price point.

Palo Alto embeds machine learning in the core of the firewall to provide inline, real-time attack prevention. Every vendor needs to be considering how they're going to appropriately integrate both generative AI and machine learning. As we move forward, it's going to be table stakes.

In terms of the value I receive from attending an RSA Conference, I have two hats. I'm working for an organization. It's federally funded research and development. Attending an RSA Conference helps me keep a finger on the pulse of that, but I also am a security blogger, so I make sure that I'm keeping up to date. Talking to people is another important part of this conference. The one thing that's missing from the conference is that there's so much focus on reaction instead of protection up front and thinking about things up front, but it's a very valuable conference overall. 

Overall, I'd rate them an eight out of ten. They are well known in this field, and they do have good products that are niche to what they're doing.

Disclosure: My company has a business relationship with this vendor other than being a customer:
PeerSpot user
CTO at Aymira Healthcare Technologies, LLC
Real User
Ensures compliance and keeps us free of bad actors
Pros and Cons
  • "The most valuable feature is that the rule set is managed and that it can be run on a regularly scheduled basis."
  • "The pricing for the solution needs improvement."

What is our primary use case?

The primary use case for this solution was to run the rule set for the CIS 20 framework and HIPAA compliance.

How has it helped my organization?

This solution will ensure that we've got a more secure environment, mitigating any sort of bad actors coming in and either destroying or disrupting the environment.

What is most valuable?

The most valuable feature is that the rule set is managed and that it can be run on a regularly scheduled basis.

What needs improvement?

The pricing for the solution needs improvement.

What do I think about the stability of the solution?

The stability of this solution is very good. Very favorable.

What do I think about the scalability of the solution?

We have four people involved with this solution. They are administrators and DevOps resources.

The solution is currently used across our entire environment. I bought licenses for one hundred hosts and I only have twenty-eight. So, there will be no incremental cost for me until I exceed one hundred hosts, which is a long way away.

How are customer service and technical support?

Technical support is very good. They have been very responsive to various requests in the past.

Which solution did I use previously and why did I switch?

We did not use another solution prior to this one.

How was the initial setup?

The initial setup was very straightforward. RedLock was very helpful in setting up the environment. The deployment took approximately two hours.

Two people are required for deployment and maintenance.

What about the implementation team?

We worked with a reseller. They are Rocus Networks out of Charlotte, North Carolina. We had a very good experience with them.

What's my experience with pricing, setup cost, and licensing?

Our licensing fees are $18,000 USD per year. There are no costs in addition to the standard licensing fees.

Which other solutions did I evaluate?

We evaluated the Dome9 solution in addition to this one. RedLock was selected based on Rocus' recommendation.

What other advice do I have?

This is a product for which I had a very specific need, and my security partner recommended it. This product is one of the leaders. I would, however, suggest that you do a POC before implementing this solution.

It has very good support in all of the cloud environments. I think that they offer a lot of functionality in supporting that space. I don't think that this product is perfect, but it fits my needs perfectly.

I would rate this solution a nine out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer2152539 - PeerSpot reviewer
Cyber Security Professional at a tech services company with 1,001-5,000 employees
Consultant
Helps us with security posture management across multiple cloud accounts
Pros and Cons
  • "Integration is very easy. And because it supports security that spans multi- and hybrid-cloud environments, it's very easy to use."
  • "When it comes to compliance, the issue is that when we are exporting the reports, there is only a single compliance option. If I need to report on multiple compliance requirements, that feature isn't available. For example, I made a single report for ISO 27000 but I can't correlate it with GDPR."

What is our primary use case?

We are using the CSPM, CWP, and Code Security modules across our team. We are using the CSPM for our compliance system and the CWP for container security.

How has it helped my organization?

We are using multiple cloud accounts and the solution helps us with posture management. We have identified things that have optimized our posture across those accounts. We now have a single tool to protect all of our cloud resources.

We have also been able to integrate security into the CI/CD pipeline with touchpoints into existing DevOps processes. At runtime, it gives us risk clarity; the modules are really good and we have seen a decrease in alert investigation times.

What is most valuable?

Integration is very easy. And because it supports security that spans multi- and hybrid-cloud environments, it's very easy to use.

It's also a very good tool for helping us take a preventive approach to cloud security. The CSPM part is very easy.

It's pretty good when it comes to protecting the full cloud-native stack, but it depends on how you configure it and the kinds of rules you implement.

What needs improvement?

When it comes to compliance, the issue is that when we are exporting the reports, there is only a single compliance option. If I need to report on multiple compliance requirements, that feature isn't available. For example, I made a single report for ISO 27000 but I can't correlate it with GDPR.

Also, for the different modules we have to set up different policies. There should be a single console where we can implement and define all the rules in one go.

It provides visibility and control across our distributed cloud environments, apart from network segmentation. The network segmentation modules have very limited functionality.

And onboarding multiple Unix platforms is a little complex.

For how long have I used the solution?

I have been using Prisma Cloud by Palo Alto Networks for one and a half years.

What do I think about the stability of the solution?

Overall, it's stable.

What do I think about the scalability of the solution?

It's scalable.

How was the initial setup?

The initial setup was slightly complex, when it came to integrating everything.

What's my experience with pricing, setup cost, and licensing?

Almost all the CSPM tools are pretty expensive. I also explored Orca but it is also pretty expensive.

Which other solutions did I evaluate?

As of now, we are going to continue with this product. But we are also exploring. New tools are coming into the market so we have to keep up with all the tools and technologies. We are exploring what other kinds of features are available in the market.

What other advice do I have?

From the security automation point of view, it's a fairly good tool, but it still needs some enhancements. Sometimes, it becomes somewhat complex to implement everything.

Overall, Prisma Cloud is a pretty good tool. The only part that stands out for improvement is the reporting.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
PeerSpot user
Cloud Architect, Oracle ACE, Oracle DBA at Pythian
MSP
Top 20
Helps secure our client's Linux workloads on any infrastructure, with end-to-end encryption
Pros and Cons
  • "The dynamic workload identity creation, attestation, and assignment is the best feature. In addition, the application dependency map across heterogeneous environments for compliance is a striking feature."
  • "More documentation with real-world use cases would be helpful."

What is our primary use case?

Our client needed a solution which would be a true implementation of the concept "Trust, but verify," and Aporeto fulfills that notion as it decouples security from network and infrastructure. It services microservices in a nifty and seamless way.

How has it helped my organization?

Aporeto has accelerated our client's expansion to the cloud. With Aporeto, they have secured their Linux workloads on any infrastructure with end-to-end encryption and have a path for modernizing with a security layer that is future-proofed.

What is most valuable?

The dynamic workload identity creation, attestation, and assignment is the best feature. In addition, the application dependency map across heterogeneous environments for compliance is a striking feature.

It integrates quite well with the AWS products as it uniquely fingerprints each workload. Aporeto is designed to combine metadata from the orchestration layer, the container, the operating system, and the AWS instance identity document. By combining these information sources, along with dynamic attributes such as image scanner inputs, Aporeto is designed to create a strong cryptographic identity for each workload. It authenticates and authorizes all network communications within a virtual private cloud (VPC), across VPCs independent of their region or availability zone, and across cloud environments.

What needs improvement?

More documentation with real-world use cases would be helpful. Another useful feature would be greater transparency and visibility into the security checks being implemented.

What do I think about the stability of the solution?

In AWS, it scales with the cloud and we have found no issues at all with the stability.

What do I think about the scalability of the solution?

Aporeto is now available in AWS where it efficiently deploys, manages, and secures applications at scale on various platforms including Kubernetes, Docker, Linux, and Mesos, among others.

What's my experience with pricing, setup cost, and licensing?

The purchasing process was easy and quick. It is a very economical solution.

We chose to procure this solution via AWS Marketplace because that's where we get all other solutions and to make sure it's supported by AWS.

What other advice do I have?

I would rate it as a nine out of ten, due to its cloud-facing features which fit in nicely with the whole cloud ecosystem.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1687518 - PeerSpot reviewer
Engineer at a tech services company with 1,001-5,000 employees
Real User
Benefits organizations because it uses the newest technology to provide a safe cloud environment
Pros and Cons
  • "The most valuable feature of Prisma Cloud by Palo Alto Networks is the CSPM, which we use the most. Additionally, the investigation and alerts are useful, and the creation of queries."
  • "Support is an area that needs improvement."

What is our primary use case?

We provide our customers with a secure cloud platform. The client uses this solution for their architecture and we check the reports once a month and provide them with guidance on how to improve their cloud operation.

How has it helped my organization?

Prisma Cloud by Palo Alto Networks provides a security span in multiple cloud and hybrid cloud environments. This is an important step to be able to have visibility of all the cloud environments.

The solution has helped me to take a preventative approach to cloud security. This technology is what is going to be used predominantly in the future. The newest standards are being used in this solution technology providing us with a preventive approach.

This solution benefits organizations because it uses the newest technology to provide a safe cloud environment.

We do not have a very complex environment but for our usage, the solution provides us visibility and control.

The solution provides us with a single tool that protects all our cloud resources without having to manage and reconcile security compliance reports.

What is most valuable?

The most valuable feature of Prisma Cloud by Palo Alto Networks is the CSPM, which we use the most. Additionally, the investigation and alerts are useful, and the creation of queries.

The solution is improved frequently, approximately twice a month.

What needs improvement?

Support is an area that needs improvement.

For how long have I used the solution?

I have been using Prisma Cloud by Palo Alto Networks for approximately two years.

What do I think about the stability of the solution?

Prisma Cloud by Palo Alto Networks has been a stable solution.

What do I think about the scalability of the solution?

We have approximately six engineers using this solution in my organization.

The scalability of Prisma Cloud by Palo Alto Networks is good. If we want to scale, we only need to purchase another license.

How are customer service and support?

The technical support is not good at responding to questions compared to other companies. They can be slow to respond and not professional enough. There are times when we have a question and they give us a general answer that is not helpful.

How was the initial setup?

The initial setup of Prisma Cloud by Palo Alto Networks is easy.

What was our ROI?

The solution has saved us money.

What's my experience with pricing, setup cost, and licensing?

The pricing structure is easy to understand. Depending on the use case the pricing of the solution can be different. There are not any additional costs to the standard living fees.

What other advice do I have?

I rate Prisma Cloud by Palo Alto Networks an eight out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Prisma Cloud by Palo Alto Networks Report and get advice and tips from experienced pros sharing their opinions.
Updated: April 2025
Buyer's Guide
Download our free Prisma Cloud by Palo Alto Networks Report and get advice and tips from experienced pros sharing their opinions.