Primarily, we use this solution to detect security configurations in AWS environments.
Cloud Security Lead at a computer software company with 5,001-10,000 employees
Good reporting, and easy to install but the integration with ticketing systems could be improved
Pros and Cons
- "The reporting is quite good. It is the most powerful aspect of this solution."
- "In general, for the product to be successful, they need to improve security, and configuration detection."
What is our primary use case?
What is most valuable?
The reporting is quite good. It is the most powerful aspect of this solution.
It's user-friendly.
What needs improvement?
In general, we abandoned this solution this year.
Each component of this solution, in my opinion, could be improved.
Integration with ticketing systems, as well as the most important noise and completeness over findings, are definitely in need of improvement. They didn't take into account some additional context.
The UI is very slow.
There is room for improvement. Consider the entire context of the findings and try to avoid making a comparison between the rule and the entity's state. In general, for the product to be successful, they need to improve security, and configuration detection.
For how long have I used the solution?
I have been working with Check Point CloudGuard Posture Management for two years.
Buyer's Guide
Check Point CloudGuard CNAPP
January 2025
Learn what your peers think about Check Point CloudGuard CNAPP. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,020 professionals have used our research since 2012.
What do I think about the stability of the solution?
It generates a large number of false positives.
What do I think about the scalability of the solution?
We haven't attempted to scale the product because there are no additional plug-ins or add-ons.
How are customer service and support?
We have contacted technical support but were not satisfied. Technical support needs improvement.
How was the initial setup?
The initial setup was straightforward.
What's my experience with pricing, setup cost, and licensing?
Licensing fees are paid on a yearly basis.
From a pricing perspective, they are pretty expensive. You can find better offerings on the market.
What other advice do I have?
I would not recommend this solution to other users.
I would rate Check Point CloudGuard Posture Management a seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Cloud Solution Architect at Network Thinking Solutions
A complete solution that's reasonably priced, with good data security
Pros and Cons
- "The solution offers an excellent price, benefit, and installation relationship."
- "Currently, worldwide, there are many companies of all sizes that do not understand the value that their data has, but even with all existing clouds, they also do not understand what the shared responsibility model is. They only assume that by having a cloud, the provider must ensure safety, when the truth is that the providers only secure their sites. Everything we do in the cloud and how we configure it is actually our responsibility."
What is our primary use case?
I have been using it in my AWS-Azure multi-cloud schema in order to monitor and protect transactions and data from all escalations - not only what we have at the database level. It helps us protect the data of our big data.
It has been the complete solution to help cover our lack of security at the infrastructure level. Not only does it cover the servers, but at the workstation level, it is monitoring what users are doing. It identifies actions and can make automatic remediation at a user level.
How has it helped my organization?
The solution has helped us to detect possible attacks or access that is not allowed. It also has helped us to identify the configurations that do not meet the company standards and allows us to improve security practices. As a result, we were able to make the necessary adjustments to be more armored and work safely.
It gives us the peace of mind we need to continue exploring areas of our scheme that will help us with our projects in the short, medium, and long term. It will help us to continue innovating and reinventing ourselves with greater and greater security.
What is most valuable?
Data security has been very valuable because data is the soul of a company and if the data is not protected, the company has no possibility of existing.
In all areas of an organization, Check Point CloudGuard is not only in the cloud, as its name implies. It goes beyond. The areas of importance from the most important to the least important are: infrastructure, technological security, data administration, legal department, etc. Check Point solutions can provide a complete 360 security scheme to the entire cloud infrastructure. It transfers its vision to the entire peripheral network.
What needs improvement?
Today, globally, there are many companies of all sizes that do not understand the value of their data, but even with all the existing clouds, they also do not understand what the shared responsibility model is. They only assume that by having a cloud, the provider must ensure security, when the truth is that providers only protect their sites. Everything we do in the cloud and how we configure it is actually our responsibility, in this sense we can evaluate many solutions that help us protect our clouds, however, and after trying 5 different solutions, the checkpoint solution is by far The most complete
For how long have I used the solution?
I have been using the solution for 3 months.
Which solution did I use previously and why did I switch?
If we were using a similar but not as extensive solution. We were using Darktrace.
What's my experience with pricing, setup cost, and licensing?
The solution offers an excellent price, benefit, and installation relationship. Thus far, Check Point has offered us this very successful relationship.
Which other solutions did I evaluate?
We were evaluating several options before choosing Check Point. What we identified would be important aspects of the new provider were: simplicity in the installation and 360 vision of all our infrastructure. When we were evaluating, we looked at Palo Alto, Check Point, and Cloud Security.
What other advice do I have?
If you are looking for a complete solution for your cloud or clouds, with Check Point you can have everything from one place.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Check Point CloudGuard CNAPP
January 2025
Learn what your peers think about Check Point CloudGuard CNAPP. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,020 professionals have used our research since 2012.
Owner at Liversidge Consulting Ltd
A powerful solution for our clients to effectively deal with problems unique to AWS
Pros and Cons
- "People implementing this solution are concerned with addressing a significant risk, and within the AWS realm, this tool does de-risk substantially."
- "I would like to see some AI on the back-end, just to assist with doing analysis and making recommendations."
What is our primary use case?
We have been researching this solution as something to provide for clients who are interested in implementing a high-security AWS environment.
How has it helped my organization?
This solution provides some security around holes that are uniquely present on AWS. We try to convey to clients and customers that when you move to AWS, the whole attack surface is different, and therefore you can't take your existing tools to AWS and then secure it in the same way as you can your traditional environment. You need to have tools that understand the nuance of AWS, and that's the reason we use Dome9. It has these unique skills and attributes in the AWS world.
Specifically, we are interested in securing IAM. It controls everything in AWS such as who can create computing instances and who can destroy them. Given that all of the power is with IAM, you have to make sure that you haven't over-privileged, or through the combination of people being users, groups, or roles, that they haven't collected too many privileges that you weren't aware of.
What is most valuable?
The feature that I found most valuable is the ability to scan IAM, the Identity and Access Management tool, for all of the privileged accounts.
What needs improvement?
Integration with other security tools would be of benefit.
I would like to see some AI on the back-end, just to assist with doing analysis and making recommendations.
For how long have I used the solution?
Trial / evaluation.
What do I think about the stability of the solution?
The stability is rock solid.
What do I think about the scalability of the solution?
I have no concerns with the scalability of this solution.
How are customer service and technical support?
Technical support for this solution is excellent.
Which solution did I use previously and why did I switch?
We did not use another solution prior to this one.
How was the initial setup?
This solution is easy to get going, although it requires a lot of training to get the best out of it.
It took us weeks to set it up, which was very quick. In terms of setting it up for a client, the strategy would depend on what holes they have in their security infrastructure, and how we can use this solution to close them.
What about the implementation team?
We implemented the solution in-house and would assume this role for our customers.
What was our ROI?
This is the sort of tool for which ROI is not really considered. People implementing this solution are concerned with addressing a significant risk, and within the AWS realm, this tool does de-risk substantially.
What's my experience with pricing, setup cost, and licensing?
It is a standard licensing fee, with no additional costs.
Which other solutions did I evaluate?
We evaluated another solution called Evident.io, but it had a lot of overlap with traditional tools, whereas Dome9 was unique in its approach.
What other advice do I have?
This is a product that I would recommend because it does unique things that I'm not aware any other product can solve those issues. It is incredibly powerful and gives our customers a lot of assurance that we're taking AWS security seriously.
My advice for those implementing this product is to use every piece of it. Explore every option and feature and leverage it to the max.
I would rate this solution a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller.
Marketing at a tech vendor with 51-200 employees
Dome9 Cloud Street View for AWS Security: The Exponential Cloud Growth Visualization
Confidence is key when it comes to managing large IT systems. The tricky part is when a CIO tries to generate the trust and confidence of a company’s IT environment. Complete transparency is the answer. As you may recall, I’ve written about the need for transparency concerning Newvem’s services in the past. As the cloud industry market matures, the AWS cloud continues to grow at ground-breaking speeds, in addition to the usual individual cloud deployment. In either respect, transparency becomes an issue.
Cloud management vendors recognize the need for transparency and are taking the necessary steps to enhance their solutions to better support active visibility. The natural evolution of a typical management system begins with gathering data and presenting it in report tables. While traditional IT tools have had a similar evolution, the infinite cloud resources and dynamic manner of the environment take the lack of controllability issue to the extreme. This, makes visualization more crucial than in a traditional, finite data center.
This week, I met my good old `cloud friends` from Dome9 that released their new cloud security visualization solution, Dome9 Clarity –
“Think Street-view for AWS security. Transparency into on-premise security has been around for the last 15 years, we are simply extending this value to the cloud.” Zohar Alon, Co-Founder and CEO at Dome9.
Dome9 Clarity – Visualizing the data flows between AWS security groups
The value of IT management features has more than proven itself over the last two decades. Issues concerning systems’ availability, security and performance are anything but new in the world of IT services. Despite the fact that the cloud doesn’t eliminate any of these concerns, it does force a change to the key methodologies and processes. As an ex-Check Point employee, Zohar Alon, Dome9’s Co-Founder and CEO, built and led the security giant’s security firewall management systems. With this experience, the natural next step was to apply his knowledge to the world of the cloud.
Dome9’s Cloud Clarity provides cloud network security visualization within the AWS cloud. It is the sensible solution for optimized cloud security management. Controlling an environment with hundreds or thousands of EC2 instances that are grouped into as many as hundreds of security groups, not to mention the rapid and dynamic growth of inter-dependencies is far from an easy DevOps’ task. With Dome9, AWS users get a visual picture of their AWS VPCs and security group configurations. According to Alon, their new capability reduces such security audit efforts significantly and has been proven to condense four hours of auditing work into a mere 15 minutes – quite impressive!
As cloud deployments become more and more complex, consequently, the overall stack complicates as well. DevOps models evolve to be able to regain control supported by distributed systems’ methodologies. With the help of Clarity’s real visibility feature, customers are enabled with a clear understanding of their security system, which in turn enables control and support of the modern application stack.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior Consultant at a tech services company with 11-50 employees
Streamlines visibility of cloud environments to make management easy
Pros and Cons
- "Checkpoint posture management gives you visibility across your entire cloud infrastructure, so it helps you with management, maintenance, and compliance. With visibility across all these cloud platforms, you can protect against compromised credentials or identity theft."
- "I would like to see improvements in the vulnerability assessments in terms of how the solution discovers vulnerabilities or compromised workloads. Also, customizable reports would be nice."
What is our primary use case?
It is a good tool for a large enterprise operating across multiple cloud environments, like AWS, Azure, or a hybrid infrastructure. Check Point posture management gives you visibility across your entire cloud infrastructure, so it helps you with management, maintenance, and compliance. With visibility across all these cloud platforms, you can protect against compromised credentials or identity theft.
What is most valuable?
The assessment history lets you test each environment for each rule you set. You can see if the security tests have passed or failed, then plan a roadmap ahead on how to strengthen your security to defend against attacks on your cloud environment.
What needs improvement?
I would be great to have additional features when it comes to vulnerability assessments in terms of how the solution discovers vulnerabilities or compromised workloads and not just on security configurations with customizable reports would be nice.
For how long have I used the solution?
I'm a system integrator and a managed service provider. I've been using CloudGuard for a couple of years.
What do I think about the stability of the solution?
So far it works and we've had no major issues with stability. When it comes to managing clouds or gaining visibility, generating, or scanning different cloud environments, it meets all the requirements, especially if you're going through a specific compliance audit.
What do I think about the scalability of the solution?
When it comes to scaling up, it's very easy to just add licenses. But to prior implementing this solution, you need to have a good accounting of all your assets to onboard on this platform. CloudGuard is good for bigger, more complex cloud infrastructures. But if you have only one cloud infrastructure, I don't think you will see much advantage over other cloud posture management. That's why this is useful mainly for bigger enterprises with multiple cloud instances and different cloud environment providers.
How are customer service and technical support?
So far, they've met all the service-level agreements (SLAs) with no delay. When it comes to Check Point, they have local distributors to provide level one or level two support. For level two or level three, it will go directly to the Check Point support. And I think that's how their SLAs work. The first line of their support should be local. If it cannot be handled locally, it goes global Check Point support.
How would you rate customer service and technical support?
Positive
How was the initial setup?
Setup is usually simple. It's not hard to implement it and gain visibility across two or more cloud infrastructures. It's quite fast. As long as you have the right number of assets, workloads, and applications for each cloud environment, you can easily deploy CloudGuard.
What was our ROI?
In terms of pricing, it's in the middle but more on the high side. It's not steep. However, I think the price is right for its functionality and the value you get from it when you're managing multiple clouds. It solves a lot of your compliance problems.
What's my experience with pricing, setup cost, and licensing?
The licensing model is based on the size of your cloud infrastructure. So to estimate what you will pay, you need to count each and every asset. And when I say assets, that means every application, database, server, or virtual network on your cloud infrastructure.
I'd like to see more flexibility in their licensing model. It's based on assets, but we all know that assets keep on growing. I would recommend a flexible, upgradeable license, so when you add assets, they can easily bill you or upgrade you.
What other advice do I have?
I rate CloudGuard a nine out of 10.
I recommend CloudGuard posture management for anyone who needs to take control of multiple cloud environments. It streamlines visibility, so this is the right tool if you are trying to meet a specific compliance standard or you're managing hundreds or thousands of servers within your cloud environment. It unifies your cloud environment.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Cloud Security Architect at Kontex
Useful training, good support, and reliable
Pros and Cons
- "The most valuable feature of Check Point CloudGuard Posture Management is the training."
- "The security of Check Point CloudGuard Posture Management could improve. There are always new security issues coming out."
What is most valuable?
The most valuable feature of Check Point CloudGuard Posture Management is the training.
What needs improvement?
The security of Check Point CloudGuard Posture Management could improve. There are always new security issues coming out.
For how long have I used the solution?
I have been using Check Point CloudGuard Posture Management for a few months.
What do I think about the stability of the solution?
Check Point CloudGuard Posture Management is a reliable solution.
What do I think about the scalability of the solution?
The scalability of Check Point CloudGuard Posture Management is good.
How are customer service and support?
The support from Check Point CloudGuard Posture Management is very good.
How was the initial setup?
The initial setup of Check Point CloudGuard Posture Management difficulty depends on how you want to set it up. There are always some problems when you have to connect it to your cloud systems. However, this will only add time to the process.
What's my experience with pricing, setup cost, and licensing?
Check Point CloudGuard Posture Management is always known as a good solution but an expensive one. When you're using Cisco, Check Point, or Palo Alto, you know that you will pay more, but you know that it will work.
What other advice do I have?
I rate Check Point CloudGuard Posture Management an eight out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Implementer at a tech services company with 51-200 employees
Excellent posture management that's easy to implement
Pros and Cons
- "The most valuable feature is posture management, which gives you complete visibility of all your assets in the cloud and allows you to do governance and compliance."
- "CloudGuard could be improved by including integration with vendors other than AWS, especially Azure, especially in permissions."
What is most valuable?
The most valuable feature is posture management, which gives you complete visibility of all your assets in the cloud and allows you to do governance and compliance.
What needs improvement?
CloudGuard could be improved by including integration with vendors other than AWS, especially Azure, especially in permissions. In the next release, I would like them to include some kind of online scanning on code in the development phase.
For how long have I used the solution?
I've been working with this solution for two years.
How was the initial setup?
CloudGuard is easy to implement.
What other advice do I have?
For those looking into implementing CloudGuard, I would suggest contacting SharePoint professional services to get the job done easily. I would give CloudGuard a score of ten out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
DevSecOps Engineer at a tech services company with 11-50 employees
Stable, scalable container security that's great for a developer-focused environment
Pros and Cons
- "The way they offer container security is a big highlight that I have noticed. The solution is also agentless, so the scanning, runtime, really everything is offered directly by CloudGuard."
- "The technical support could be better, but I do not know of any other needed improvements."
What is our primary use case?
We resell the CloudGuard Workload Protection product. If a customer comes to us looking for a CSM tool, for example, we evaluate their needs and suggest a good option, like this solution.
What is most valuable?
The way they offer container security is a big highlight that I have noticed. The solution is also agentless, so the scanning, runtime, really everything is offered directly by CloudGuard.
What needs improvement?
The technical support could be better, but I do not know of any other needed improvements.
For how long have I used the solution?
My company has been involved with this solution for almost one year.
What do I think about the stability of the solution?
This is a stable product.
What do I think about the scalability of the solution?
The solution is scalable.
How are customer service and support?
I would rate technical support as an eight out of ten. It has some room for improvement.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is really easy. On a scale of one to five, I would rate it as a five.
What other advice do I have?
If your company's environment is more developer-focused, meaning it has more containers and is running on Kubernetes, I would certainly recommend choosing Checkpoint.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: reseller
Buyer's Guide
Download our free Check Point CloudGuard CNAPP Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2025
Product Categories
Vulnerability Management Cloud and Data Center Security Container Security Cloud Workload Protection Platforms (CWPP) Cloud Security Posture Management (CSPM) Cloud-Native Application Protection Platforms (CNAPP) Data Security Posture Management (DSPM) Compliance ManagementPopular Comparisons
Microsoft Defender for Cloud
Qualys VMDR
Tenable Security Center
SentinelOne Singularity Cloud Security
Orca Security
Lacework FortiCNAPP
Skybox Security Suite
Trend Vision One - Cloud Security
Rapid7 Metasploit
Arctic Wolf Managed Risk
Buyer's Guide
Download our free Check Point CloudGuard CNAPP Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the pricing for Check Point software?
- How inadvisable is it to use a single vulnerability analysis tool?
- What are the benefits of continuous scanning for vulnerability management?
- When evaluating Vulnerability Management, what aspect do you think is the most important to look for?
- What is a more effective approach to cyber defense: risk-based vulnerability management or vulnerability assessment?
- What are the main KPIs that need to be implemented to have better posture in vulnerability projects?
- Which is the best vulnerability scanner tool?
- What are your recommended automated penetration testing tools?
- How do you use the MITRE ATT&CK framework for improving enterprise security?
- Can you recommend API for Tenable Connector into ServiceNow